Deprecated WiseVector Free AI Driven Security

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
Hi@Nagisa@Vitali Ortzi

I understand why users want a demand scanner only, since if running more than one AV with real time protection, they may incompatible with each other or cause high resources usage.

It’s easier for us to design WiseVector StopX as a demand scanner, however, we think it's not very safe to use WiseVector StopX as a demand scanner only with a popular AV, since popular AV is always a target for attackers and according to our tests, we have found there are many kinds of threats (such as DLL Side-loading, hijack threads, post-injection attacks and stealer malware ) can’t be stopped by popular AV in the first place.

There is one way can make WiseVector StopX working as a demand scanner: turn off real time protection and all options in advanced settings.
 
Last edited:

Nagisa

Level 7
Verified
Jul 19, 2018
342
@WiseVector Thanks for your reply 🙏

however, we think it's not very safe to use WiseVector StopX as a demand scanner only with a popular AV, since popular AV is always a target for attackers and according to our tests, we have found there are many kinds of threats (such as DLL Side-loading, hijack threads, post-injection attacks and stealer malware ) can’t be stopped by popular AV in the first place.

I think this should only be in the user's decision. What If I don't even want to run any real-time software at all? If it's easier to develop/fork on-demand version of WiseVector, doing it would be much better for people who don't have premium or who simply want a small and portable(from USB) scanner.

And I think this will increase the popularity of the WiseVector as because a portable software could be suggested more frequently than install-required software.
 

Vitali Ortzi

Level 24
Verified
Top Poster
Well-known
Dec 12, 2016
1,368
@WiseVector Thanks for your reply 🙏



I think this should only be in the user's decision. What If I don't even want to run any real-time software at all? If it's easier to develop/fork on-demand version of WiseVector, doing it would be much better for people who don't have premium or who simply want a small and portable(from USB) scanner.

And I think this will increase the popularity of the WiseVector as because a portable software could be suggested more frequently than install-required software.
Even better it can be sold as a technician product just like Malwarebytes and many companies do.
 

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
@WiseVector Thanks for your reply 🙏

I think this should only be in the user's decision. What If I don't even want to run any real-time software at all? If it's easier to develop/fork on-demand version of WiseVector, doing it would be much better for people who don't have premium or who simply want a small and portable(from USB) scanner.

And I think this will increase the popularity of the WiseVector as because a portable software could be suggested more frequently than install-required software.
Thanks for your suggestion.
We would like to take your advice if we get a way to be more competitive in this market.:)

Good day!
 

JB007

Level 26
Verified
Top Poster
Well-known
May 19, 2016
1,580
Hello @WiseVector
This morning WiseVector StopX detected "C:\Windows\SysWOW64\rundll32.exe" as malware on my PC.
I think it is a false positive and I reported it.
WV.PNG
 

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
I got system files detections aswell.

Sorry for the inconvenience. We found that run command "regsvr32 /i c:\windows\system32\shell32.dll" under certain version of windows 10 will cause file created in C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp. Which will be considered malicious by the behavior detection modules. We have fixed this problem. Thank you.
 

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
Hello @WiseVector
This morning WiseVector StopX detected "C:\Windows\SysWOW64\rundll32.exe" as malware on my PC.
I think it is a false positive and I reported it.

Hi,

"MEMRAY" belongs to WiseVector StopX's memory protection module. Which means WiseVector StopX found hidden code or hidden modules in process. And the code or module is detected as malware by our AI based memory scanner.

We have analysed all memory logs generated today. We only found one false positive and we have fixed it. The problem is caused by programs come from www.essentialobjects.com. We don't know what exactly the product is. The program will call "rundll32.exe" to load a Dll, then the Dll ("eoloader.dll") will load two another Dlls directly in memory. The two Dlls only exists in memory you can't see them in hard disk. Our memory scanner detected the Dlls as malware. Anyway, if you have used any product from essentialobjects.com, you should know it is a FP and we have fixed it.

By the way, after V2.63 was released, we have spent a lot of time to analyse the memory logs from our users who have enabled "Help fight malware by providing threat statics" ( really appriciate for their help and trust. We got tons of memory logs. Note, we don't know who sent these logs, If you are interested in what's in the logs, please refer to the page: https://www.wisevector.com/en/en-privacy/). Most in-memory threats will cause system process being alarmed, and we know well that this might make our users feel WiseVector StopX is aggressive, so we spend lots of time to analyse to ensure the detection is correct. We find 98% of them are malicious. Once a system process is detected as " MEMRAY: MalThread" or" MEMERAY: MalCode.", please pay special attention. You'd better do a full system scan immidiatly or contact us directly.

It's difficult to explain memory threat to our users. Since it is just code in memory without files in hard disk. We are trying to figure out a better way to help users understand this.
 
Last edited:

pxxb1

Level 10
Verified
Well-known
Jan 17, 2018
473
Hi@Nagisa@Vitali Ortzi

I understand why users want a demand scanner only, since if running more than one AV with real time protection, they may incompatible with each other or cause high resources usage.

It’s easier for us to design WiseVector StopX as a demand scanner, however, we think it's not very safe to use WiseVector StopX as a demand scanner only with a popular AV, since popular AV is always a target for attackers and according to our tests, we have found there are many kinds of threats (such as DLL Side-loading, hijack threads, post-injection attacks and stealer malware ) can’t be stopped by popular AV in the first place.

There is one way can make WiseVector StopX working as a demand scanner: turn off real time protection and all options in advanced settings.

Do you have any plans to implement a schedule scan feature?

When will you release this product, in weeks, months or maybe - a year?
 

pxxb1

Level 10
Verified
Well-known
Jan 17, 2018
473
Hi@pxxb1,

Thanks for your suggestion.
Actrually, if you keep running WiseVector StopX in your PC, you might don't need a schedule scan feature.:)

To see the result after a scan gives more CERTAINTY on the Pc`s condition. To be able to create that visable certainty is worth a lot. Don`t underestimate that.

And what about my other question, do you have a clue. Weeks, years or what? I am not looking for an absolute date just an approximate one.
 

Xjoker

Level 1
Feb 19, 2020
38
When will you release this product, in weeks, months or maybe - a year?

And what about my other question, do you have a clue. Weeks, years or what? I am not looking for an absolute date just an approximate one.

What do you mean when it's going to be released? The version 2.63 is a stable version released on the 20th of May.

Καταγραφή.PNG
 

pxxb1

Level 10
Verified
Well-known
Jan 17, 2018
473
What do you mean when it's going to be released? The version 2.63 is a stable version released on the 20th of May.

View attachment 240994

Official release, it is just under development still. When that occurs they are going to splitt it into 2 versions, one paid and one free.

We still do not know what features will be missing in the free one and what it will cost, or when they are going "Live" with the program. So if you use it now and do not want to pay in the future, thats it.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top