- May 30, 2015
- 277
when you click on the file, it doesn't even get a chance to open, so yes, probably.... but that's good thing, eh?probably the dropper behaviour gets intercepted by wv, not the eicar test itself.
when you click on the file, it doesn't even get a chance to open, so yes, probably.... but that's good thing, eh?probably the dropper behaviour gets intercepted by wv, not the eicar test itself.
Yes, indeed.when you click on the file, it doesn't even get a chance to open, so yes, probably.... but that's good thing, eh?
Hi Evjl's Rain,I have noticed WV v2.70 and 2.71 are using a lot more CPU than the previous version. It also takes much longer to analyze a newly downloaded applications with a big delay. Is it due to the new rollback feature?
hello, long time no see. I disappeared because WV 2.6x was too good and too stable that I had nothing to commentHi Evjl's Rain,
Long time no see. Thanks for your feedback!
1. When you notice the high CPU usage what are you doing with your PC?
2. What do you mean by analyzing the application? The big delay occured when you just executed the APP or completed the downloading?
Our rollback feature is designed to remain lightweight and users can hardly notice any delay, so the issue you discribed is probably not caused by it.
Thank you for telling me the details.hello, long time no see. I disappeared because WV 2.6x was too good and too stable that I had nothing to comment
1. I noticed the high CPU usage when I launched a program (relatively large) which I just downloaded. Downloading doesn't cause any issue
2. When the program launched for the first time, WV analyzed that program which caused a noticeable delay in start time. Later, the program boots instantly
I noticed it when I tried to update my chromium portable using chrlauncher. These are the steps I did:
1. download the program here: https://github.com/henrypp/chrlauncher/releases/download/v.2.5.7/chrlauncher-2.5.7-bin.zip
2. Extract the "64" folder -> run "chrlauncher.exe"
3. The launcher will download chromium and install automatically
4. after it finishes, chromium will be launched automatically -> now, I see a 10-second delay + high CPU usage from WV
5. With version 2.6x, there was almost zero delay. I verified this
This is what I think
v2.67: lets the program runs -> analyzes the program later/simultaneously
v2.71: pauses the program and analyzes -> when it finishes -> the program is allowed to run -> this causes delay
Hello, thank you for the reply. It's very difficult to explain just by words so I decided to record 2 videos to clearly demonstrate the differenceThank you for telling me the details.
We have tested and didn't reproduce the issue you encountered. There was no delay when start chromium portable using chrlauncher in our testing.
This program is not large, just 1800KB. Can you please try to run it directly throught " Chrlauncher->64->bin->chromium.exe" to see whether or not the delay will happen again?
ok, just an observation... I have a
Test File: PDF With Embedded DOC Dropping EICAR
by Didier Stevens
with 2.71 the file did not get a chance to open, as WVSX jumped all over it.... but with 2.72 the DOC file opens, and I get this warning... View attachment 252929
there doesn't seem to anything of interest in Temp.... just thought you'd like to know...
yeah, that's what used to happen..... but now the PDF opens, and I get the malware warning... very odd.hmm, thats interesting, I've got 2.72 installed and it detects the pdf as soon as it is extracted.
Confirmed not leaking with Kaspersky anymore. Thanks!Hi everyone!
V2.72 is released!
V2.71 can update to V2.72 directly when "Automatically download and install program updates" is enabled.
Sorry,V2.67 can't update automatically now.
The download link:
Update log:
1. Fixed a particular resource leak.
2. Fixed the issue that the behavior detection might fail to clean up malicious leftovers.
3. Speed up scanning on large files.
4. Improved the stability of ransomware rollback.
5. Performance improved.
Good day!
Hi,I just downloaded and installed WVSX from the homesite, the installation said v.2.67.
13, but it should not be 2.67 then. .71 could be expected.Hi,
I just checked, the installer on our official website is V2.72.
Can you please check the date of the installer you had downloaded? The date should be 2021/1/14.
Thanks!@WiseVector Hi!
I was testing some viruses yesterday and I noticed something strange.
Video.
WiseVector is closed and in notify mode. I started the virus then opened WiseVector and it found the virus and blocked it. I clicked on many notifications and once I was done, part of the virus process remained open. (Apparently that process doesn't look malicious). There is also a.bat file left in the folder created by the virus.
I have written this so that you can understand the problem (assuming it is one), solve it or improve something.
I sent the sample to you privately.
Thanks @Der.Reisende for the sample on the hub.
VIdeo: 2021-01-05 19-49-58_Tri