Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Всичко за WiseVector

Featured Replies

Много добра защита, детекта е въз основа на евристика и поведение, ето малко снимки:

image.png.d8a69a71772a8b4c7842f423eb41a8f9.png

 

 

image.png.9c9b5f67f12762adc5fbd97068a3492d.png

image.png.734509989d08990d8f40e3148dedec51.png

  • Отговори 75
  • Прегледи 26,1k
  • Създадено
  • Последен отговор

Потребители с най-много отговори

Най-популярни публикации

  • Отговор на WiseVector за теста: https://malwaretips.com/threads/wisevector-free-ai-driven-security.87965/post-926990 @RudeBoy писах му и за твоя проблем.

  • Не, не съм съгласен за инсталирането и на нова инсталация на Windows. А това, че засича драйвери от антивирусните програми е нормално, защото те използват рууткит техники. На мен засега ми намери само

  • Появи се версия 2.71. Промените: 1. Fixed the issue that ransomware rollback may fail to rollback some encrypted files. 2. Redesigned the rollback window, now users can adjust the window size

Публикувани изображения

  • Автор

Линк към актуалната версия:  https://www.wisevector.com/WiseVector_StopX.exe

ето го и сайта на програмата: https://www.wisevector.com/

 

 

ето как изглеждат засичанията на практика:

2020-01-03-Log.txt

преди 2 часа, B-boy/StyLe/ написа:

Всъщност засичането основно се дължи на Artificial Intelligence.

 

  • Автор
преди 12 часа, B-boy/StyLe/ написа:

Да де:

WIBD => AI based behavioral detection

https://www.youtube.com/watch?v=CYiv5GG8GnQ

Т.е. програмата е с подобна технология като SparkCognition DeepArmor 

За разлика от DeеpArmor e напълно безплатна.

За сега се справя  добре със зловредни изпълними файлове, скриптове, bat файлове, заразени pdf и документи.

Също не забелязвам фълшиви аларми, както при APEX  на SecureAPlus

Да, т.нар. NextGen технология, която я има и в Cylance, CrowdStrike и подобните.Тя също хич не е лишена от уязвимости и дори скоро от Cylance бяха пуснали пач за нея, че и бяха надушили концепцията и как да я заобикалят.

https://www.scmagazineuk.com/cylance-protect-av-vulnerability-patched/article/1593075

  • Автор
преди 5 минути, B-boy/StyLe/ написа:

Да, т.нар. NextGen технология, която я има и в Cylance, CrowdStrike и подобните.Тя също хич не е лишена от уязвимости и дори скоро от Cylance бяха пуснали пач за нея, че и бяха надушили концепцията и как да я заобикалят.

https://www.scmagazineuk.com/cylance-protect-av-vulnerability-patched/article/1593075

Др. безплатна програма с тази технология май няма?

преди 1 минута, ТHEBOSS написа:

Др. безплатна програма с тази технология май няма?

Предполагам. Всичко направено от човек сигурно може да бъде преодоляно от човек в повечето случаи след определено време. Пък и там играят много пари...има ли вируси били те компютърни или човешки...

  • 2 седмици по-късно...

Ето един хубав отговор от автора на програмата от преди няколко часа какво точно представлява тя:

Цитат

The Real-Time protection include:

. Active processes scanning (Scan running processes)
. Process Execution Scanning (Scan application being executed)
. File Scanning (Scan files being created)

AI based Behavior Detection, The AI makes desicision based on multiple events, such as file metadata, API call, etc. Recently we realized the behavior name is not so user-friendly. Since many users don't understand why the program has been blocked, so we changed the behavior name to reflect the most important actor to let the Ai decide to block the program. For example, If there is a program make multiple API calls(CreateProcess->VirtualAlloc->WriteProcessMemory->CreateRemoteThread). Actually the most important API call is CreateRemoteThread. In this case the behavior will be named WIBD:Heur.Injector.XX. The XX usually are combination of numbers and letters which present the special API call graph. So we can understand what'the extract way the malware used to inject other process. The typical important actors are listed below,
.MBR Write
.Low-Level Disk Write
.Persistence
.Various registry events
.AppLocker Bypass
.Generic behavior (The detection name will be:"WIBD:HEUR.MalBehavior.XX")
.Suspicious file system events (Ransomware detection)
.Fileless malicious executions (Will be impoved in the next version)
.Process Manipulation (Will be impoved in the next version)
.Process Injection (Will be impoved in the next version)
.Credential stealing (Will be included in the next version)
.Memory events (Will be included in the next version)

We have a powerful unsupervised clustering algorithm running in the cloud. The purpose of the clustering operation is to put the similar programs into different subsets. So, the same subset of objects will have the similar the properties. For missed samples or false positives, The algorithm will extract unique signatures from the properties and then deliver it to the end users automatically. The whole process will only take seconds.
Samples do not belong any of the clusters will be analyzed manually. In this case it will take hours.

 

Има бета версия, която още дори не е публична и ако всичко е наред другата седмица ще я пуснат, но ако на някой му се занимава и по-рано:

https://www.wisevector.com/WiseVector_Setup_V25.exe

Вчера я тествах и писах на поддръжката, че нещо не се разбра с Comodo. А по принцип е създадена да работи с други програми за защита и да ги допълва. То е ясно, че Comodo си е своенравен и той де, но все пак. Иначе забелязах, че на CUstom сканиране, времето за проверка на дял C:\ отне доста време, но направи доста дълбока проверка (малко в стил Windows Defender). Отне доста време, но пък не товареше много. Явно е била с нисък приоритет. Забелязах, че подобно на AppCheck и подобните програми за защита от ransomware създава и тя скрити папки на всички дялове от сорта на HoneyPot. Като цяло не съм особен фен на примамките HoneyPot, но пък може при тях да действа по-ефективно.

  • 3 месеца по-късно...

Появи се и новата бета 2.6

Промените са доста:

Цитат

1. Upgraded the AI engine to improve detection rate and reduce false positives. Users can adjust the protection level according to their needs. It should be noted that the protection level only affects static scanning and basic real-time monitoring, and does not affect behavior analysis and memory protection.

2. Added the instruction tracer module.This technique makes identifying the original source of the malicious behavior in applications. It can effectively detect hidden threats such as DLL Side-Loading, thread hijacking and so on. At the same time, it can also detect stealth attacks in post-injection phase.

3. Improved the detection of Info stealer malware. Info stealer malware is designed to harvest a variety of data (Browser Passwords, Cookies, FTP credentials, etc.,) on the computers. They usually minimize their behavior to decrease the chance of detection by AV. Most of them hide their presence on the system by using advanced malware stealth techniques such as injection, hollowing, etc.,
Based on their characteristics, we have added multiple models to memory protection and behavioral analysis to detect them.

4. Improved the memory protection. Besides the Info stealer detection module we mentioned above. We also added multiple RAT detection modules, which can detect RAT uses DLL hijacking to evade the behavior monitoring (Gh0st, Parallax, etc.,). At the same time, the conflicts between memory protection with other security software is resolved. and also reduces the CPU consumption.

5. Ransomware detection improved, we added several ransomware detection models which can terminate the behavior of ransomware at an earlier stage.

6. Privacy protection got improved which can protect users from webcam and microphone spying.

7. Improved MBR and partition table protection.

8. Fixed an issue that may cause BSOD under certain conditions.

9. The user can set whether to turn on a specific component of the basic real-time monitoring.

10. We optimized code to reduce CPU consumption and disk I/O. 2.6 is even lighter than the previous versions.

11. Other bug fixes.

Изтегляне:

https://www.wisevector.com/WiseVector_StopX_V26.exe

Сега я тествам много интересна програма заслужава внимание евала на китайците.

 

  • 3 седмици по-късно...

Появи се Wise VectorX 2.6.3.

Цитат

WiseVector StopX V2.61 beta:

1. Fixed a GUI bug that some options at the bottom of the settings page cannot be changed(Thread Statics and the Proxy Server).
2.Fixed a problem that memory protection might conflict with some virtualization-based portable software. And some security software released by Humming Heads inc.
Since those software will inject hidden modules into system process, WiseVector StopX detected them as malware.
3.Other bugs fixed.

WiseVector StopX V2.62 beta:

1. Fixed the problem that may cause increased memory usage under certain specific conditions.
2. Fixed the problem that after minimizing the window, it may not be restored from the taskbar.
3. Prevented flickering window once at startup.
4. Increase the detection rate of malware in Office format.
5. Fixed the problem that memory detection may cause a bit high CPU usage under certain specific conditions.
6. Some other adjustments on the UI.

WiseVector StopX V2.63:

1. Fixed a problem parsing particular files that may decrease the detection rate.
2. Fixed a problem that the tray icon occasionally missing after Windows Explorer restarted.
3. Fixed the problem that the scanner might stuck on “preparation to scan”.
4. Improved memory protection to reduce resources usage.
5. Fixed some logical problems in the settings.

Изтегли

  • 4 седмици по-късно...
Цитат

WiseVector StopX V2.65
June 7, 2020

1. Improved Memory protection to detect malware by abusing whitelist applications, such as Powershell, msbuild.exe, installutil.exe, regasm.exe, etc. It can effectively detect advanced threats based on tools such as PowerShell Empire, GreateSCT, nps_payload, ObfuscatedEmpire, unicorn, etc. Since it detects malicious payload in memory, it can effectively detect obfuscated malicious scripts.
2. Instruction Tracer improved. Recently, we have observed lots of RAT Trojans utilizing DLL hijacking to avoid detction by AV. These Trojans abuse whitelist APPs like Avast & ESET as well as APPs which are released by Samsung, TeamViewer, Citrix to perform DLL Side-Loading. We updated Instruction Tracer to make sure
they can be detected without signature updates.
3. Upgraded detection engine to improve accuracy.
4. Fixed the problem that Behavior Detection may fail to quarantine malware.
5. Improved detection of malicious RTF documents.
6. Fixed an uninstallation problem in Windows XP.
7. Fixed other bugs.

Само че имат проблеми със сървърите, защото страницата с промените не се отваря нещо, а инсталационния файл се тегли супер бавно. В malwaretips автора спомена, че правят "upgrade" на сървърите си в момента.

Преди броени дни не успях да инсталирам уж стабилната версия на WiseVector StopX V2.65  заедно с   Privatefirewall 7 -  блокира ползваната ОС.  Китайското безплатно недоразумение го деинсталирах в режим  Safe Mode.   Изглежда не може да се сработи със стени с хипс.

Не е недорозумение, но все пак още е в процес на развитие. При мен също създаваше проблеми с комбинацията Comodo Firewall, Kaspersky Security Cloud Free и се наложи да я деинсталирам. Иначе на теория би трябвало да може да работи съвместно със стандартните антивирусни решения, защото се явява един вид допълнение към тях, а не програма за първа линия на защита. Но нека да не забравяме, че PrivateFirewall отдавна е изоставена и проблема може да причинен и от нея.

Не вярвам.  Безплатният  Comodo Cloud Antivirus също е изоставен и умувам  пробно да го съчетая с Privatefirewall 7.  Сандбоксът на Комодко може да се настрои да блокира старт на всякакви неизвестни и неразрешени файлчета - влиза  в режим автосандбокс.Там е и  Viruscope (поведенческия анализ)  Това са силните компоненти на стената на варанчо - има си ги също безплатно и при неподдържания вече облачен антивирус.     Privatefirewall 7 настроена правилно с хипса си може да ме пази сама - обаче ми е интересно какво ще се получи като я накачуля заедно с най-добрите безплатни модули на Комодо.  

преди 1 час, attj написа:

Не вярвам.  Безплатният  Comodo Cloud Antivirus също е изоставен и умувам  пробно да го съчетая с Privatefirewall 7.  Сандбоксът на Комодко може да се настрои да блокира старт на всякакви неизвестни и неразрешени файлчета - влиза  в режим автосандбокс.Там е и  Viruscope (поведенческия анализ)  Това са силните компоненти на стената на варанчо - има си ги също безплатно и при неподдържания вече облачен антивирус.     Privatefirewall 7 настроена правилно с хипса си може да ме пази сама - обаче ми е интересно какво ще се получи като я накачуля заедно с най-добрите безплатни модули на Комодо.  

Не може да те пази сама, защото PrivateFirewall пропуска ransomware. Засичах го няколко пъти в темата за подпомагането. Както не може да те опази вече и HIPS-а на Outpost от ransomware. И не съм съгласен, че само Sandbox-a и VirusScope са силната страна на Comodo. HIPS-а му е един от най-добрите след тези на MalwareDefender и може би на OSSS. Доста по-добър е от този на PrivateFirewall със сигурност. Та по-скоро Comodo може да те пази сам, а не PF. PF си остава една от любимите ми програми, (както и PCTools Firewall и ThreatFire), но за съжаление вече са бити карти малко. За стара ОС и хардуер ако не може човек да си позволи да инсталира последната версия на Comodo, бих препоръчал или стара версия на Comodo в лицето на 5.12 или OnlineArmor дори. Тя беше добра срещу GPCode навремето и вярвам, че би се справила и със сегашния ransomware. Emsisoft с интегрирания Mamatu също е добър избор (макар и той чат-пат да пропуска). Всеки си решава де.

  • 2 месеца по-късно...

Нова версия WiseVector StopX V2.67

Цитат

Septemper 2, 2020

1. Improved the Memory Protection to detect IcedID, Dridex and other banker trojan.
2. Solved the problem that WiseVector StopX might stuck when it is scanning the Office files with XLM macro.
3. Improved the stability of Memory Protection when a large number of processes being executed at a time.
4. Improved the stability of Document Protection.
5. Fixed other bugs.

https://update2.wisevector.com/WiseVector_StopX.exe

  • 3 месеца по-късно...

WiseVector StopX V2.70

Промените:

Цитат

1. Added lightweight rollback to roll back changes caused by some destructive malware, such as ransomware. This feature has been designed to remain lightweight and users can hardly notice any performance degradation.
2. Redesigned the real-time file monitoring, it is more sensitive and faster than before.
3. Redesigned the Behavior Detection. Now the Behavior Detection can identify more unknown file infector viruses, being more capable of detecting advanced threats.
4. Improved Memory Protection to detect RAT trojan abuses legitimate processes to hide their malicious implants, such as Gh0st, Meterpreter and CobaltStrike.
5. Malware quarantine is now sorted by date. Quarantine reason is added.
6. The UI is not transparent now, so that the interface can be displayed more clearly. Some new skins are added.
7. Improved the ability to delete malicious files being locked.
8. Now users can select whether or not to automatically download and install program updates.

Линкове за изтегляне на приложението:

https://update2.wisevector.com/WiseVector_StopX_V27.exe
https://www.wisevector.com/WiseVector_StopX_V27.exe

Весели празници! :bighat::toboggan::santa5::snowballfight::champagne1:

  • 2 седмици по-късно...

Появи се версия 2.71.

Промените:

1. Fixed the issue that ransomware rollback may fail to rollback some encrypted files.
2. Redesigned the rollback window, now users can adjust the window size so that they can view the rollback items clearly.
3. Show cleanup progress when users are cleaning a large number of malware.
4. Fixed the issue that the file name may be garbled after restore from quarantine.
5. Fixed the issue that WiseVector StopX may cause other programs to get stuck.
6. Registry monitoring is more powerful, which can detect more malicious programs that modify the registry.
7. Added backup of php, jsp, asp files for ransomware rollback.
8. Reduced the resource usage. 

Линкове за изтегляне на приложението:

https://update2.wisevector.com/WiseVector_StopX_V27.exe
https://www.wisevector.com/WiseVector_StopX_V27.exe

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.