View Full Version : Runalyzer analysis results
LouieLouie
2006-03-17, 19:47
Very new member/customer- - I just downloaded Runalyzer and attempted to get an online analysis. It took about 15 minutes for the green progress bar to run its course. Now, how do I get the results of the analysis?:confused:
BCR CMPTR
2007-01-12, 06:44
I just installed and ran Runalyzer. I am also interested about the online results.
I'm a huge supporter of Spybot S&D, and have most of my clients running that.
I Have other questions regarding the simmilarities between the two mentioned
programs but I will take a look at the many other posts As I havent been here
in quite some time.
bcr
º¿º
RunAlyzer is able to classify entries as unknown (white standard background), open (yellow), good (green) or bad (red).
This classification comes from either a shipped database, or updates that are available online.
Submitting unknown stuff means our detectives will look at these entries and classify them - already did for over 100.000 entries :)
An immediate result of the Online Analysis is that already known, but not at the time the installer was created, results will be downloaded. Other classification will follow shortly after, though currently due to server changes, that may take some while longer than usual.
Here's how you can see the results of classification:
http://www.spybot.info/images/runalyzer/runalyzer-classifications-1.png
Or another example:
http://www.spybot.info/images/runalyzer/runalyzer-classifications-2.png
Sorry I didn't have any red (bad) entries at hand to show ;)
d_mccormick
2007-02-04, 04:40
How do I get access to the online results from the scan I requested from the online button? I am not sure how to access the download you refer to below.
Do I just enter RunAlyzer again and use the Online button to request the results? Do I receive an email with a download URL? or??
:bigthumb:I have a technical background in development and support. I am new to Spybot products. Having coded Microsoft programs, I am very impressed by the level of detail and professional presentation of your software. A boquet of atta-boys to you guys.
What sources do you use to get the details your programs exhibit. This information is often hard to come by. I have read Appleman and several other authors to learn what I know. Your knowledge level is very impressive.
RunAlyzer is able to classify entries as unknown (white standard background), open (yellow), good (green) or bad (red).
This classification comes from either a shipped database, or updates that are available online.
Submitting unknown stuff means our detectives will look at these entries and classify them - already did for over 100.000 entries :)
An immediate result of the Online Analysis is that already known, but not at the time the installer was created, results will be downloaded. Other classification will follow shortly after, though currently due to server changes, that may take some while longer than usual.
Here's how you can see the results of classification:
http://www.spybot.info/images/runalyzer/runalyzer-classifications-1.png
Or another example:
http://www.spybot.info/images/runalyzer/runalyzer-classifications-2.png
Sorry I didn't have any red (bad) entries at hand to show ;)
Thanks for the praise :)
You don't have to download anything, and emails will link data to a person, which is an unnecessary link ;)
Let me describe it another way. RunAlyzer uses two databases, one offline and one online. The offline one is shipped along with the installer, but of course not always up-to-date. Classification is automatically done by the offline version when you start RunAlyzer.
If you click the online button, all entries not already in the offline database thats on your computer get looked up (in an anonymized form where necessary!) on our server, and are then added, if known, to the offline database, so that whenever you're starting RunAlyzer, it'll show you the results from any previous online lookup as well.
If you decide to also transmit unknown entries, these will get stored on our server (again, in anonymized form, not even the username from file paths will be in there), and then classified by someone here (easy ones even automatically), and then re-uploaded to the online database.
So if you do the "online" lookup a week later (not sure how long the delay currently is, lots of new Vista entries if I saw this correctly ;) ), a few more entries should show up green, yellow or red (again, results will be stored in the offline database as well, so it won't repeat those that are in the database).
Sources for the details? A bunch of databases with data collected here and there... from automated whois-information collection over virus collections over external databases and much more...
e.g. for RunAlyzer classifications, we automatically compare each new entry to our database of bad files, which includes not only spyware, but also viruses etc... we basically try to index all the data we use daily, and link those databases together were useful.
Well, in my opinion, this is one of the most important thread in this RunAlyzer Forum - for proper understanding how Online Analysis works. Nevertheless, considering that the subject is a little bit complicated (at least for me) I would like to ask you for an answer to a few questions (I am a user of RunAlyzer ver. 0.7.1.6).
Namely, you have written:
Let me describe it another way. RunAlyzer uses two databases, one offline and one online. The offline one is shipped along with the installer, but of course not always up-to-date. Classification is automatically done by the offline version when you start RunAlyzer.
O.K. - but which offline version: outdated or updated ? Does it mean that not going through the Online Analysis mode of RunAlyzer I will always use the outdated database residing in my computer ? The above - up to date when a new version of the program will be installed into my computer; or - when I apply Online Analysis ?
If you click the online button, all entries not already in the offline database thats on your computer get looked up (in an anonymized form where necessary!) on our server, and are then added, if known, to the offline database, so that whenever you're starting RunAlyzer, it'll show you the results from any previous online lookup as well.
This is a very long and rather complicated sentence which is very difficult for me to understand it (English is not my native language:)). Could you please writing it in another way. Namely, does it mean that during "one action" initiated by clicking "Online Analysis" button - the new entries go from my computer to your server, and then (if known) - to my computer once again; updating in this way my offline database ?
Well, I am writing above on my hypothesis on the 2-stages process (i.e. sending data - and then - receiving data) because, in my computer, I observed that after accomplishing the first stage of the Online Analysis (progressive bar filled-in) - the analysis restarted.
The first phase of the above took some 1 hour time (or even more !) - and the second one was faster. I am using rather old computer: Pentium 4 - 32 bit - 1.5 MHz, without Hyper-Threading.
The next question: After initializing Online Analysis - do I exclusively update the offline database in my computer only - or I am doing a public job - and all the computers connected to your server via RunAlyzer will be updated as well ?
If you decide to also transmit unknown entries, these will get stored on our server (again, in anonymized form, not even the username from file paths will be in there), and then classified by someone here (easy ones even automatically), and then re-uploaded to the online database.
Once again, it is not clear for me: i.e. by what means "I decide to also transmit unknown entries ..." - when I am (in standard way) clicking the button: Online Analysis ? But in that time I do not know what entries are known and what entries are not known to you !
Moreover, am I doing some public job when sending you (I do not know how) exclusively unknown entries in the sense that all other computers having RunAlyzer launched will be updated as well ?
So if you do the "online" lookup a week later (not sure how long the delay currently is, lots of new Vista entries if I saw this correctly ), a few more entries should show up green, yellow or red (again, results will be stored in the offline database as well, so it won't repeat those that are in the database).
What do you mean by: "So if you do online look up a week later ...". Does it mean that I should undertake Online Analysis mode once again (say) one week later - or it is simply enough to launch my RunAlyzer and my offline database will automatically be updated ?
In other words: does my offline database is being updated every time I am simply launching RunAlyzer (not necessarily initiating Online Analysis mode) ?
How often should I undertake Online Analysis (what is time consuming): one time per month, or so ... ?
Summarizing, I have two general questions:
Does from the above follows that non-performing Online Analysis will cause that my set of offline data will be unchanged at every launch of RunAlyzer ?
Does from the above follows that for proper functioning of RunAlyzer - periodical (say - one time per month) - performing the Online Analysis is decidedly needed ?
Well, being a newbie in the area, I would be most grateful receiving an answer to the formulated above questions. In otherwise case - I would not be in a position to understand and successfully apply your RunAlazer. So, please - help :).
P.S. Do you realize PepiMK that your Private Messages Box is full and presently it is not possible to send to you any private mail ? Or - you know about it - but you have been killed by too curious RunAlyzer users ? A pity ...
Hi there.
P.S. Do you realize PepiMK that your Private Messages Box is full and presently it is not possible to send to you any private mail ? Or - you know about it - but you have been killed by too curious RunAlyzer users ? A pity ...
He may or may not realise his PM box is full.
We are working towards the Final release of Spybot-S&D 1.5 which is time consuming. ;)
Also it is the weekend, however I will leave a note for his attention.
Best regards.
Many thanks for your prompt reply.
And also for a very good message that the Final Release of yours Spybot S&D 1.5 will come soon (as I use beta version now).
Thus, I am waiting for both; i.e for the newest Spyboot and for an answer to my questions formulated in this thread, as well, :).
Best regards and