Deprecated WiseVector Free AI Driven Security

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
I have noticed WV v2.70 and 2.71 are using a lot more CPU than the previous version. It also takes much longer to analyze a newly downloaded applications with a big delay. Is it due to the new rollback feature?
Hi Evjl's Rain,
Long time no see.:) Thanks for your feedback!
1. When you notice the high CPU usage what are you doing with your PC?
2. What do you mean by analyzing the application? The big delay occured when you just executed the APP or completed the downloading?
Our rollback feature is designed to remain lightweight and users can hardly notice any delay, so the issue you discribed is probably not caused by it.
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Hi Evjl's Rain,
Long time no see.:) Thanks for your feedback!
1. When you notice the high CPU usage what are you doing with your PC?
2. What do you mean by analyzing the application? The big delay occured when you just executed the APP or completed the downloading?
Our rollback feature is designed to remain lightweight and users can hardly notice any delay, so the issue you discribed is probably not caused by it.
hello, long time no see. I disappeared because WV 2.6x was too good and too stable that I had nothing to comment
1. I noticed the high CPU usage when I launched a program (relatively large) which I just downloaded. Downloading doesn't cause any issue
2. When the program launched for the first time, WV analyzed that program which caused a noticeable delay in start time. Later, the program boots instantly

I noticed it when I tried to update my chromium portable using chrlauncher. These are the steps I did:
1. download the program here: https://github.com/henrypp/chrlauncher/releases/download/v.2.5.7/chrlauncher-2.5.7-bin.zip
2. Extract the "64" folder -> run "chrlauncher.exe"
3. The launcher will download chromium and install automatically
4. after it finishes, chromium will be launched automatically -> now, I see a 10-second delay + high CPU usage from WV
5. With version 2.6x, there was almost zero delay. I verified this

This is what I think
v2.67: lets the program runs -> analyzes the program later/simultaneously
v2.71: pauses the program and analyzes -> when it finishes -> the program is allowed to run -> this causes delay
 
Last edited:

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
hello, long time no see. I disappeared because WV 2.6x was too good and too stable that I had nothing to comment
1. I noticed the high CPU usage when I launched a program (relatively large) which I just downloaded. Downloading doesn't cause any issue
2. When the program launched for the first time, WV analyzed that program which caused a noticeable delay in start time. Later, the program boots instantly

I noticed it when I tried to update my chromium portable using chrlauncher. These are the steps I did:
1. download the program here: https://github.com/henrypp/chrlauncher/releases/download/v.2.5.7/chrlauncher-2.5.7-bin.zip
2. Extract the "64" folder -> run "chrlauncher.exe"
3. The launcher will download chromium and install automatically
4. after it finishes, chromium will be launched automatically -> now, I see a 10-second delay + high CPU usage from WV
5. With version 2.6x, there was almost zero delay. I verified this

This is what I think
v2.67: lets the program runs -> analyzes the program later/simultaneously
v2.71: pauses the program and analyzes -> when it finishes -> the program is allowed to run -> this causes delay
Thank you for telling me the details.
We have tested and didn't reproduce the issue you encountered. There was no delay when start chromium portable using chrlauncher in our testing.
This program is not large, just 1800KB. Can you please try to run it directly throught " Chrlauncher->64->bin->chromium.exe" to see whether or not the delay will happen again?
 

Evjl's Rain

Level 47
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
Thank you for telling me the details.
We have tested and didn't reproduce the issue you encountered. There was no delay when start chromium portable using chrlauncher in our testing.
This program is not large, just 1800KB. Can you please try to run it directly throught " Chrlauncher->64->bin->chromium.exe" to see whether or not the delay will happen again?
Hello, thank you for the reply. It's very difficult to explain just by words so I decided to record 2 videos to clearly demonstrate the difference
in these videos, you can clearly see there was a big big delay after I pressed "check for update" which would launch the application
in version 2.67, the delay was non-existent. Furthermore, chromium seemed to lag a lot as my computer was unresponsive during the first run with v2.71
The second run was instantaneous

v2.67

you can skip to 1:12

v2.71

skip to 1:16
 

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
Hi,
Thanks a lot for your videos.
We guess the delay was due to there were two large files (150mb) named Chrome.dll and Interactive_ui_tests.exe in Chrlauncher/bin/64. WVSX V2.71 took times to scan them. But 10 seconds delay was too long which was probably related to the hardware configurations.
V2.67 didn't have this problem may be because the files have been scanned and cached.
In the next version 2.72 We will get WVSX improved to scan large files.
 

tipo

Level 8
Well-known
Jul 26, 2012
353
i just tested wv on windows sandbox under shadow defender (just to be sure i`m safe) against the following ransomwares:
conti, darkside, loki 1, loki 2, maze, modi loader, revil, ryuk, stop, wasted, zepelin

the basic protection was off. copied some pics and some useless text files on desktop to see if they will get encrypted. the result was great! nothing was encrypted, the behavioural blocker simply works. the rollback feature alerted me whenever it was the case. you are doing a great job @WiseVector

did the same test with mbam. real time shield off, ransomware shield was up and running- it caught nothing.. all the system was encrypted, it only alerted me from time to time about accessing a ransomware website. (if the moderators think the off topic is not permited, please delete/edit it.
 
Last edited:

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
:)Hi everyone!

V2.72 is released!
V2.71 can update to V2.72 directly when "Automatically download and install program updates" is enabled.
Sorry,V2.67 can't update automatically now.

The download link:

Update log:
1. Fixed a particular resource leak.
2. Fixed the issue that the behavior detection might fail to clean up malicious leftovers.
3. Speed up scanning on large files.
4. Improved the stability of ransomware rollback.
5. Performance improved.

Good day!;)
 

porkpiehat

Level 6
Verified
Well-known
May 30, 2015
277
ok, just an observation... I have a

Test File: PDF With Embedded DOC Dropping EICAR​

by Didier Stevens

with 2.71 the file did not get a chance to open, as WVSX jumped all over it.... but with 2.72 the DOC file opens, and I get this warning...
Screenshot 2021-01-13 203218.png

there doesn't seem to anything of interest in Temp.... just thought you'd like to know...
 

Antimalware18

Level 11
Verified
Top Poster
Well-known
Jan 17, 2014
503
ok, just an observation... I have a

Test File: PDF With Embedded DOC Dropping EICAR​

by Didier Stevens

with 2.71 the file did not get a chance to open, as WVSX jumped all over it.... but with 2.72 the DOC file opens, and I get this warning... View attachment 252929
there doesn't seem to anything of interest in Temp.... just thought you'd like to know...

hmm, thats interesting, I've got 2.72 installed and it detects the pdf as soon as it is extracted.
 

porkpiehat

Level 6
Verified
Well-known
May 30, 2015
277
hmm, thats interesting, I've got 2.72 installed and it detects the pdf as soon as it is extracted.
yeah, that's what used to happen..... but now the PDF opens, and I get the malware warning... very odd.

ok, that is odd... I was testing with a saved zip file, but if I download a fresh PDF(zip) file, it is stopped on execution... would there be any reason for that?

so, if I extract the file from the downloads folder, it is stopped on extraction.... but if I extract the file from a different folder, the PDF file is opened, and WVSX issues the warning... :confused:
 
Last edited:

dlr5668

New Member
Jan 4, 2021
9
:)Hi everyone!

V2.72 is released!
V2.71 can update to V2.72 directly when "Automatically download and install program updates" is enabled.
Sorry,V2.67 can't update automatically now.

The download link:

Update log:
1. Fixed a particular resource leak.
2. Fixed the issue that the behavior detection might fail to clean up malicious leftovers.
3. Speed up scanning on large files.
4. Improved the stability of ransomware rollback.
5. Performance improved.

Good day!;)
Confirmed not leaking with Kaspersky anymore. Thanks!

MK8BDQ8.png
 

WiseVector

From WiseVector
Verified
Top Poster
Developer
Well-known
Dec 14, 2018
643
@WiseVector Hi!

I was testing some viruses yesterday and I noticed something strange.
Video.
WiseVector is closed and in notify mode. I started the virus then opened WiseVector and it found the virus and blocked it. I clicked on many notifications and once I was done, part of the virus process remained open. (Apparently that process doesn't look malicious). There is also a.bat file left in the folder created by the virus.
I have written this so that you can understand the problem (assuming it is one), solve it or improve something.
I sent the sample to you privately.
Thanks @Der.Reisende for the sample on the hub.

VIdeo: 2021-01-05 19-49-58_Tri
Thanks!
We tested the sample.
Since you exited WVSX before started the sample , WVSX was unable to record the relationship between processes, for example the parent-child relationship. In this case, the parent process wasn't blocked completely and the child process was started repeatedly.
Please keep WVSX running when testing malware.:)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top