simmerskool

Level 9
Verified
Malware Tester
I am currently running WV 2.65 on both win10_vm and on win7, but on win7 not in real-time.
c:\Program Files (x86)\WiseVector\Eg.dll.rar
c:\Program Files (x86)\WiseVector\EgAddtionalHelper.dll.rar
the 2 above files are on the win10 along with .dll, I assume unpacked
but on win7 which is not real-time, these 2 .rar files are not found the in the directory.
RogureKiller (adlice) considers these .rar files malware, I excluded them at false positives in RK.
But wonder why not seen in win7 directory?
 

WiseVector

From WiseVector
Verified
Developer
Hi@simmerskool,

Yes, they are FPs. Please send them to RogureKiller for analysis if possible.
The two files: EgAddtionalHelper.dll.rar and Eg.dll.rar were incomplete update files. They were created when WiseVector StopX failed to update to V2.65 automatically. We have disabled the automatic update temporarily, so the two files are on the Windows 10 along with .dll. Our update server couldn't work efficiently when a great number of users tried to update at the same time. We are finding a way to make our update server more reliable and robust.

Good day!
WiseVector
 
Last edited:

Vitali Ortzi

Level 20
Verified
Hi@simmerskool,

Yes, they are FPs. Please send them to RogureKiller for analysis if possible.
The two files: EgAddtionalHelper.dll.rar and Eg.dll.rar were probably created when WiseVector StopX failed to update to V2.65 automatically. Our update server couldn't work efficiently when a great number of users tried to update at the same time. Now we are deploying more servers to fix the problem.

Good day!
WiseVector
Since you made a great program demand is growing 😁👍
 

WiseVector

From WiseVector
Verified
Developer
True that. However the suggestion was to improve their SEO which requires attention, especially taking care of spaces when searching for results
Hi,

Thanks for your suggestion.
Our company is named WiseVector and our product is named WiseVector StopX. There is no space between wise and vector originally. We will improve our SEO to get more exposure.:)

Regards,
WiseVector
 

WiseVector

From WiseVector
Verified
Developer
Hi WiseVector!
I found a strange bug - self-defense doesn't work on Windows 10 and antivirus processes are easily killed with the task manager. On Windows 7 everything is OK .

Hi NorthernF0x

Thanks for your test. What's the build and version of Windows 10 you have?
Did you terminate WiseVector.exe by "Task Manager->Details->WiseVector.exe->End task"?
 

WiseVector

From WiseVector
Verified
Developer
It was tested on two systems - Windows 10 1909 Enterprise x64 and LTSC 1809 x64.
Yes, exactly.

Please make sure "Prevent WiseVector StopX from being kill" is checked in Advanced settings. WiseVector StopX's processes are protected by kernel mode driver. Normally you can't terminate them in Ring3. Can you use Process Hacker or Process Explorer to terminate WiseVector.exe to see what happens?
 

NorthernF0x

New Member
Please make sure "Prevent WiseVector StopX from being kill" is checked in Advanced settings. WiseVector StopX's processes are protected by kernel mode driver. Normally you can't terminate them in Ring3. Can you use Process Hacker or Process Explorer to terminate WiseVector.exe to see what happens?
Of course, self-defense is turned on.
No, I didn't use these programs and killed processes with the standard task manager, which surprised me. I can make a video of my actions, but my system in Russian and I don’t know if this will be clear.
 

WiseVector

From WiseVector
Verified
Developer
Hi @WiseVector

Any new Infos for the Thread to post False Positives and Samples here on MT Forum available

With best Regards
Mops21
Hi,

Sorry, I have sent a message to @Jack, but no reply till now. So I don't know whether it's OK to do this and in which part of the forum I can start the Thread...Can you please send FP and samples to virus@wisevector.com or just upload them through WiseVector StopX before I get infos from Jack?

Regards,
WiseVector
 
Last edited:

Mops21

Level 29
Verified
Trusted
Content Creator
Hi,

Sorry, I have sent a message to @Jack, but no reply till now. So I don't know whether it's OK to do this and in which part of the forum I can start the Thread...Can you please send FP and samples to virus@wisevector.com or just upload them through WiseVector StopX before I get infos from Jack?

Regards,
WiseVector

Hi @WiseVector

Yes I will do that

With best Regards
Mops21