Jump to content

Gualano Marco

Members
  • Posts

    21
  • Joined

  • Last visited

  • Days Won

    1

Posts posted by Gualano Marco

  1. Hi,

    I made an advanced memory test to see if it is efficient or not ..

    I launcehed a trojan while all eset module are disabled, then I enabled these modules and found that advanced memory scanner cannot clean the trojan (a variant of ..), also startup scanner cannot do the job.

    I updated the security program, and whereupon startup scanner now can clean the same trojan after it has a new name (after db has been updated):



    So, why advanced memory and startup scanners could't clean the trojan before updating the database in spite of the two scanners had detected it?

    post-0-0-92894500-1387529557_thumb.png

  2. Hi,

     

    these are mini-bugs that I found in ESS v. 7.0.302.26, hoping that will be fixed ..

     

    1- When the mouse pointer moves from eset desktop notification to taskbar directly, it stays opaque and doesn't return to transparent situation:

     

    hxxp://www.gulfup.com/?sKFpax

     

    2- When scanning autoit files 'and perhaps NSIS archives', number of infected files is not compatible with number of cleaned files!:

     

    post-1889-0-52313200-1386329788_thumb.jpg

     

    post-1889-0-46281500-1386329795_thumb.jpg

     

    3- In the previous example, we can see the abnormal multiple logged item for the same scanned object!

    'This problem can be found in archived objects only'

     

    4- Bug in browsing logged items although optimizing logged files!:

     

    hxxp://www.gulfup.com/?w8NCga

     

    And another bug when browsing the logged items in 'detected threats' and 'computer scan' sections:

     

    hxxp://www.gulfup.com/?upej6c

     

    5- Idle scanning log stays 'in progress' in spite of it stopped by 'log on system for example':

     

    post-1889-0-81101500-1386329803_thumb.jpg

     

    6- Watch activity tool pretends that the graph view covers 10 minutes, but in fact it covers only less than 3 minutes:

     

    post-1889-0-44038100-1386329809_thumb.jpg

     

    7- Desktop notification disappears when the ess main window closes!:

     

    hxxp://www.gulfup.com/?UXWRC8

     

    8- There are several options in the program that are useless and perhaps they must be removed:

     

    I- This option is useless in real-time file system protection because in spite of setting it to make the real-time file system protection module scan archives, this module can't scan the archives at all! 'you can try it ..'

     

    post-1889-0-56910100-1386329816_thumb.jpg

     

    II- Although activating these two options, they still useless because you can't scan operating memory and boot sectors from context menu scan:

     

    post-1889-0-75376900-1386329823_thumb.jpg

     

    III- This option is useless in the following modules 'because this option can't log all items scanned by these modules':

     

    real-time file system protection

    document protection

    web protection

     

    post-1889-0-38638300-1386329827_thumb.jpg

     

    IV- These two options are useless in document protection module; because this module scans Microsoft Office documents only:

     

    post-1889-0-01480500-1386329834_thumb.jpg

     

    post-1889-0-94706800-1386329840_thumb.jpg

     

     

  3. The difference between the number of scanned and cleaned objects is most likely that your Autoit malware also contains some clean files inside. Try enabling logging of all scanned files so that you also see clean files in the scan log. The fact that the results are displayed doubled or tripled in the case of archives has been noted as a bug.

     

    Hi Marcos,

     

    the autoit malware has three clean files an only one malicious file:

     

     

    post-1889-0-39966500-1383735469_thumb.jpg

     

     

    So, can you now explain why eset claims that it had cleaned two files?

×
×
  • Create New...