I don't know much about Ewido either. I had a² (free edition) installed on
my sytem. IIRC it does only on demand scanning as you pointed out.
The stories were (are) indeed that is very good, but I must say it's
scanning was awfully slow and it never ever found anything on my system, so
I got rid of it.
It also makes me wonder if I need a program like this. I have a anti-virus,
a firewall and the usual anti-spyware programs.
I know what you mean.I use spywareblaster ,teatimer etc and did use avast
(im using nod32 now).Heres a log of what boclean stopped.
------------------------------
08/09/2004 18:33:21: C:\WINDOWS\TEMP\STB1120.TMP
Trojan horse was found in above file
QUICKBAR TROJAN STOPPED by BOCLEAN!
Above file copied to C:\evidence.boc for examination.
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.
------------------------------
08/09/2004 18:33:26: C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL
Trojan horse was found in above file
NEWDOTNET2 TROJAN STOPPED by BOCLEAN!
Above file copied to C:\evidence.boc for examination.
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.
------------------------------
08/09/2004 18:33:32: BUNDLE TROJAN VARIANT STOPPED!
Trojan horse was found in memory.
C:\WINDOWS\TEMP\BUNDLE.EXE contained the trojan.
Active trojan horse WAS shut down. System safe.
------------------------------
08/09/2004 18:34:52: KEENVALUE TROJAN VARIANT STOPPED!
Trojan horse was found in memory.
C:\PROGRAM FILES\COMMON FILES\UPDATER\WUPDATER.EXE contained the trojan.
Active trojan horse WAS shut down. System safe.
------------------------------
08/09/2004 18:35:12: C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL
Trojan horse was found in above file
NEWDOTNET2 TROJAN STOPPED by BOCLEAN!
Above file copied to C:\evidence.boc for examination.
Active trojan horse was shut down. System now safe.
Trojan horse was removed, registry cleaned.
------------------------------
08/09/2004 18:37:33: EZULA/BOOT TROJAN STOPPED by BOCLEAN!
Trojan horse was found in memory.
C:\WINDOWS\ILOOKUP\TTIL.EXE contained the trojan.
Active trojan horse WAS shut down. System now safe.
It was supposed to be a moving desktop angel image.It contained about 4
pieces of malware.TDS3 did not detect it , but added it within 1
day.Trojanhunter took 3 days to add.Avast did not detect it.Maybe because
its adware/spyware the others had a point in not detecting it initially ,
howver boclean did and on numerous other occasions has been ahead of the
game in detection (imo).As you can see from the log and log times ,there
were about 4 pices of scumware trying to install in one go. Personally
unless you had a good av such as KAV or something on that level i would use
a good AT.
me