CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Prevx1r and new Ewido4Beta

 
Post new topic   Reply to topic       All -> FavForums -> Prevx [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
horseman

Lieutenant
Lieutenant
Premium Member

Joined: Apr 15, 2003
Posts: 235

Premium

PostPosted: Tue Apr 25, 2006 10:25 am    Post subject: Prevx1r and new Ewido4Beta
Reply with quote

As I've no doubt missed a heap of stuff has any other Px1 user tried Ewido4Beta?

Two initial preliminary observations:

1. New Ewido beta now appears to lock down the registry by attempting to disable the registry editor. Quite rightly (as currently designed)Px detects this....and blocks it!

Ok in Family addition you have access to Control Centre and then you can re-configure the appropriate policy from "prevent" to "query" but this is a pain to repeatedly do this for same program(s) so surely it really begs for an exclusion list you can update?
As well as an invidual license presumably still won't be able to change these policies?....yet! Wink

2. Curiously some ewido modules appear flagged as amber on console (unknown) but green (or even unflagged!) on communal database?
Somehow I just don't believe they suddenly got updated! Wink so I'm probably having one of my all too frequent geriatric mental outages and missing something... ??
Example screenshots 2-a/b attached.


Comments anyone please?




1202-status2-b.jpg
 Description:
Shown as Amber on console but Green (Safe) here? So does console reflect Amber due to Registry blocking or just that this is flagged as unknown on local database?
 Filesize:  173.49 KB
 Viewed:  40 Time(s)

1202-status2-b.jpg



1202-status2-a.jpg
 Description:
Note the Ewido components flagged as Amber. Double clicking on these and typically you get the community database disposition for Ewido module as in 2-b
 Filesize:  143.63 KB
 Viewed:  34 Time(s)

1202-status2-a.jpg



_________________
Regards Tony

Draco Dormiens Nunquam Titillandus
Back to top
View users profile Send private message MSN Messenger
JacquesE

Prevx Host
Premium Member

Joined: Jan 09, 2005
Posts: 50
Location: Uk
Premium

PostPosted: Sat Apr 29, 2006 12:04 am    Post subject:
Reply with quote

Hi Tony,

You might be the first user to have run Ewido V4 in the community, thus it being firstly flagged as unknown on your box, and after the data has been submitted to the community, the centralized heuristics marking it good centrally. That would explain such behavior.

You raise a good point with your first suggestion, and we will look into it.


_________________
Regards,

Jacques
Back to top
View users profile Send private message Visit posters website
horseman

Lieutenant
Lieutenant
Premium Member

Joined: Apr 15, 2003
Posts: 235

Premium

PostPosted: Sat Apr 29, 2006 8:45 am    Post subject:
Reply with quote

JacquesE wrote:

You might be the first user to have run Ewido V4 in the community, .....
.


Thanks Jacques
I thought that at first but dates of first report preceeded my install by 1 day so I was just curious as to how long it took Px to update a users local db - 24hrs to 72 hrs potentially it would seem.
While checking that I also found 1 or 2 anomalies with dates "First Seen" and "Last Seen" on Description Page apparently reflecting the first country reporting dates and not the aggregated dates of all countries?

So eg if you look up "Guard.exe" for EW4Beta on Db and see for yourself that Finland's dates appear to be used on Description page for "Last Seen" (currently 24April) instead of (what I expected to be) a constantly rolling date as new users loaded this application component in any country? So when I look today it currently shows 27 April (USA,Uraquay,Brazil) under Propagation notetab for "Last Seen" which conflicts with first page's Last Seen date!?.

Just another nit-picking observation!. Wink

JacquesE wrote:

You raise a good point with your first suggestion, and we will look into it.

Thanks for noting it but realistically I wouldn't expect that to become anything more than a very minor nuisance issue until a lot more users with existing multiple real time monitors/reg protectors etc start to use Px.


_________________
Regards Tony

Draco Dormiens Nunquam Titillandus
Back to top
View users profile Send private message MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Prevx All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer