PDA

View Full Version : Prevx RC 3.0.4.221


sded
October 12th, 2009, 11:49 AM
Installed automatically over 3.0.4.218 with no issues. Running fine alongside Avast! 5.0.150. Tested against badpx5.exe and all is well-have not had a "fail to detect anything" issue for a few weeks, so seems to be solved.

LagerX
October 12th, 2009, 12:04 PM
Updated finely, but task icon is missing now.
Can't terminate 2 Prevx.exes at Task manger, and starting Prevx manually doesn't give anything.

I'll restart computer.

PrevxHelp
October 12th, 2009, 12:43 PM
Hello all,
This build fixes a few incompatibilities and issues. To retest the changes after upgrading, just close/reopen your browser. The download links are still:

32bit: http://info.prevx.com/download.asp?grab=edgebeta
64bit: http://info.prevx.com/download.asp?grab=edgebeta64

The changelog is:

- Fixed an issue supporting user switching in x64
- Fixed an issue blocking browser instances from communicating in some cases
- Fixed an issue opening an Opera window from a shortcut
- Added a Reset button to reset default settings
- Fixed some issues in the warning dialog for protected credentials
- Made credential protection more generic to cover other data types
- Fixed some incompatibilities with Sandboxie/similar technologies

Known Issues:
- Incompatibility with Digsby account management (will be fixed in .222)
- Possible (unreplicated) issue with Threatfire v4.6.0.19
- Possible issue cleaning the Trojan Simulator
- Possible incompatibility with KeyScrambler
- Some incompatibilities with Fritz!Protect firewall

Conceptual Incompatibilities:
- Defensewall is expected to block Opera support as it prevents browsers from reaching trusted components (Prevx) so we are not able to load some protection/monitoring into an Opera browser protected by Defensewall

- SAS and MBAM scanning is sometimes slowed when Prevx is active: This is an issue stemming back a while and is solved by stopping Prevx protection while scans are taking place. We're investigating whether it would be possible to identify the operations SAS/MBAM are making in the system to prevent us from intercepting their file reads to improve their scan times.

Next Steps:
- Add Safari Support
- Add Iron Support
- Add Maxthon Support

Please let me know what you find and thanks again for the testing!

ace11
October 12th, 2009, 12:50 PM
any graphic indication @ maxthon that safeonline is active ?

I dont see any ....

PrevxHelp
October 12th, 2009, 12:51 PM
-{ Quote: "any graphic indication @ maxthon that safeonline is active ?

I dont see any ...." }-

SafeOnline does not currently support Maxthon but it will in a future version :)

Dark Star 72
October 12th, 2009, 01:22 PM
Bld 221 installed over 218 , no problems.

However I have WinPatrol Plus installed and tried to look at the Plus Info for Prevx.exe and got a Phishing Alert (first screenshot) Tried to continue by clicking 'Ignore' and FireFox blocked the connection but a page opened up in IE7 - second screenshot. The gist of the WinPatrol info is that Prevx.exe is a part of the W32/IRCBot-TF worm ???
Any comment Joe?

This is 100% reproducible on my machine, if you need details of how to do it let me know.

PrevxHelp
October 12th, 2009, 01:47 PM
-{ Quote: "Bld 221 installed over 218 , no problems.

However I have WinPatrol Plus installed and tried to look at the Plus Info for Prevx.exe and got a Phishing Alert (first screenshot) Tried to continue by clicking 'Ignore' and FireFox blocked the connection but a page opened up in IE7 - second screenshot. The gist of the WinPatrol info is that Prevx.exe is a part of the W32/IRCBot-TF worm ???
Any comment Joe?

This is 100% reproducible on my machine, if you need details of how to do it let me know." }-

This looks like two FPs, one from WinPatrol and one from Prevx on their URL. I'll see what is triggering the phishing warning from our end - could you give me the full URL it goes to when it triggers this? (I can see most of it in the screenshot but it would be best to look at the entire URL at once :))

Thanks!

Dark Star 72
October 12th, 2009, 03:07 PM
Joe,
I cannot get any more of that address than you can see in the screenshot, sorry about that.

lorenzet
October 12th, 2009, 04:49 PM
accents do not work on keyboard ABNT2

ludo021288
October 12th, 2009, 05:58 PM
I just purchased PrevX yesterday and i'm running this lastest beta alongside NIS2010. So far so good but i encountered two minor issues:
- First, the tray icon seems to disappear randomly at reboot, which is resolved by killing prevx process and restarting it. I'm running Windows 7 64 RTM and previously had the same issue with Eset Smart Security (same OS, same hardware, another installation). No other software seems to be affected.
- SafeOnline feature is not present in x64 version, too bad :( Do you plan to launch it simultaneously for x64 and x86 version? Or the x64 version will be released later (or never)?
Otherwise, everything is perfect, program is running light on system ressources and works even with a quite slow internet connection (3G+, approximately 1000kb/s effective)

PrevxHelp
October 12th, 2009, 06:54 PM
-{ Quote: "I just purchased PrevX yesterday and i'm running this lastest beta alongside NIS2010. So far so good but i encountered two minor issues:" }-

Good to hear and welcome to the forum :)

-{ Quote: "- First, the tray icon seems to disappear randomly at reboot, which is resolved by killing prevx process and restarting it. I'm running Windows 7 64 RTM and previously had the same issue with Eset Smart Security (same OS, same hardware, another installation). No other software seems to be affected." }-

Could you click the small tray arrow and click Customize and see if there are any settings configured for Prevx to hide the tray icon? Windows 7 manages the system tray differently and it "may" be automatically hiding Prevx... :-\

-{ Quote: "- SafeOnline feature is not present in x64 version, too bad :( Do you plan to launch it simultaneously for x64 and x86 version? Or the x64 version will be released later (or never)?" }-

We will have a x64 version of SafeOnline but it will be some distance down the roadmap.

-{ Quote: "Otherwise, everything is perfect, program is running light on system ressources and works even with a quite slow internet connection (3G+, approximately 1000kb/s effective)" }-

Great :) Let me know if you have any other questions/problems!

Threedog
October 12th, 2009, 08:01 PM
221 running smoothly on my XP SP3 with Online Armor ++. Have Run Safer enabled on browsers and no conflicts with SafeOnline.

Mongol
October 13th, 2009, 12:03 AM
OK, my first issue and it's with this version. Now Prevx is not recognized by Windows Security Center. I'm running Windows 32 bit home version and Online Armor Premium alongside...::) :)

SvS
October 13th, 2009, 04:18 AM
For build 206 I reported the following problem:

> There appears to be a slight incompatibility with SafeOnline and the
> Identity Safe feature of Norton Internet Security (using NIS 2010
> on Windows 7 x32).

> I use Identity Safe to store my address information and part of my
> Credit Card info in a password protected Identity Card. While visiting
> any online shopping site (using the https protocol) I'm unable to type
> the Identity Card password into Identity Safes password dialog using
> the keyboard. Copy & Paste works, typing the passoword does not.

Using build 221 the problem still exists and does not only affect Identity Safe. I decided to buy a copy of O&O Defrag from http://www.oo-software.com/home/en/products/oodefrag/index.html. Using Identity Safe to fill in my password protected adress data on the order page did not work since the Identity Safe password prompt did not accept any keyboard input. This happened again some time later while attempting to fill out the credit card data.
After the payment was processed my registration data was displayed on the order page. So I left the browser window open, installed O&O Defrag and started the application. The first screen displayed prompted for the registration data which I was unable to enter since the dialog would not accept keyboard input. After closing the browser window protected by SafeOnline this started to work immediately again.

Dark Star 72
October 13th, 2009, 07:38 AM
-{ Quote: "221 running smoothly on my XP SP3 with Online Armor ++. Have Run Safer enabled on browsers and no conflicts with SafeOnline." }-
Running the same combination here seemingly without any problems :thumb:

However I got a BSOD last night when enabling Shadow Defender, I also had this happen several builds ago. Not sure if this has anything to do with Prevx or not as I had been using SD without any problems. Are there any known incompatibilities between Prevx and Shadow Defender?

PrevxHelp
October 13th, 2009, 09:45 AM
-{ Quote: "Running the same combination here seemingly without any problems :thumb:

However I got a BSOD last night when enabling Shadow Defender, I also had this happen several builds ago. Not sure if this has anything to do with Prevx or not as I had been using SD without any problems. Are there any known incompatibilities between Prevx and Shadow Defender?" }-

I'm unaware of any, but if you could mail the latest crashdump from c:\windows\minidumps\ to report@prevxresearch, I'll be able to investigate the source of the BSOD :)

overangry
October 13th, 2009, 09:46 AM
Not working on my system.
I am unable to perform a scan, and it is not detecting any threats.
I am also unable to cancel the scan for aprox. one minute after which time I receive the corresponding warning.
Windows FW is activated and Threatfire is enabled. disabled TF and safeonline to no avail.
SB and PCTFW are uninstalled.
Edit: The GUI also freezes even if restarted.

PrevxHelp
October 13th, 2009, 09:53 AM
-{ Quote: "
I am unable to perform a scan, and it is not detecting any threats. " }-

Are you using any other programs which could affect Prevx's connectivity (like K9 Web Protection or another internet filter)? There are no global issues so I suspect it is something on your PC - have you tried rebooting at all since upgrading? :-\

overangry
October 13th, 2009, 10:02 AM
-{ Quote: "Are you using any other programs which could affect Prevx's connectivity (like K9 Web Protection or another internet filter)? There are no global issues so I suspect it is something on your PC - have you tried rebooting at all since upgrading? :-\" }-
No. Curently all I have installed is Threatfire 4.5.0.24 and I'm using windows firewall.

overangry
October 13th, 2009, 10:19 AM
I had to do a hard shutdown of my system after I tried to save a log scan. After rebooting all seems fine.
I wouldn't have noticed this had I not initiated a scan, The previous build worked fine with an identical setup.
There is another issue, I download and stored the eicar test virus which is still on my system. Prevx usually picks up on this.

ludo021288
October 13th, 2009, 05:45 PM
-{ Quote: "Good to hear and welcome to the forum :)



Could you click the small tray arrow and click Customize and see if there are any settings configured for Prevx to hide the tray icon? Windows 7 manages the system tray differently and it "may" be automatically hiding Prevx... :-\



We will have a x64 version of SafeOnline but it will be some distance down the roadmap.



Great :) Let me know if you have any other questions/problems!" }-

Windows is configured to display all tray icons (i hate having too much background processes so there are not much icons to display). I also checked in prevx config and it was configured to display a tray icon. But the problem seems to be fixed since i haven't encountered any problem today. Maybe it's related to the update process (from .218 to .221).

How does the update process work? Does it kills temporarily the prevx process to update? I'll tell you if the problem occurs again with the next update.

Otherwise, everything is running smoothly so it's no big deal :)

Good night and sorry for my (not native) english

Mongol
October 13th, 2009, 06:34 PM
-{ Quote: "OK, my first issue and it's with this version. Now Prevx is not recognized by Windows Security Center. I'm running Windows 32 bit home version and Online Armor Premium alongside...::) :)" }-

I gave this problem the old Microsoft Windows fix it strategy. Clean uninstall - reboot - reinstall and SHAZZAM it now shows in the Windows Security Center...:o :blink: ...problem solved...8)

Romagnolo1973
October 13th, 2009, 07:14 PM
Joe the new RC seems working great in Italy ;D
italians ask me if is possible making on the right click of the try icon (when there is Stop Protection) even a "Stop SafeOnLine" that is more userfiendly than open the screen and stop it
I don't know if is a good or bad idea, I am only the messenger of that request;D

PrevxHelp
October 14th, 2009, 08:57 AM
-{ Quote: "Joe the new RC seems working great in Italy ;D " }-

Great ;D

-{ Quote: "italians ask me if is possible making on the right click of the try icon (when there is Stop Protection) even a "Stop SafeOnLine" that is more userfiendly than open the screen and stop it
I don't know if is a good or bad idea, I am only the messenger of that request;D" }-

Right now, the Stop Protection button will also stop SafeOnline (we haven't split the options). However, I agree that differentiating between disabling SafeOnline and the anti-malware components is a good idea and I'll see how we can make this fit in :)

Thank you, Italian Users (and messenger :)) :thumb:

PrevxHelp
October 14th, 2009, 08:58 AM
-{ Quote: "
How does the update process work? Does it kills temporarily the prevx process to update? I'll tell you if the problem occurs again with the next update." }-

I suspect you're correct - the update does require the tray icon to be destroyed/recreated which could potentially be the cause for the issues as we've been releasing a handful of updates over the last couple weeks.

I'll keep an eye out during the next upgrade process as well :) Thanks!

PrevxHelp
October 14th, 2009, 08:58 AM
-{ Quote: "I gave this problem the old Microsoft Windows fix it strategy. Clean uninstall - reboot - reinstall and SHAZZAM it now shows in the Windows Security Center...:o :blink: ...problem solved...8)" }-

:-\ Nothing too unusual there ;D If the problem comes back.... let me know :)

Habakuck
October 15th, 2009, 01:21 AM
-{ Quote: ":-\ Nothing too unusual there ;D If the problem comes back.... let me know :)" }-
I do have Security Center Problems with this built too!

All other builts were Ok. I think something is broken. Security Center shows that PrevX is not active.

Win7-64-bit

Triple Helix
October 15th, 2009, 11:12 AM
Works fine with me on Win 7 RTM 32bit!

TH

spm
October 15th, 2009, 02:55 PM
Just tried Prevx RC 3.0.4.221 and had to uninstall it again. Running WinXP Pro + SP3, fully updated...

... I use the Foxmarks bookmarks synchroniser in Firefox, together with the attendant desktop agent called Xmarks (which synchronises IE favorites). With the Prevx beta installed, Xmarks reports errors synchronising with its server (it uses https for this) every time IE8 is started. Turning off Prevx's SafeOnline module makes no difference - I had to uninstall the beta completetly and revert to the public 3.0 release to solve the issue.

egghead
October 15th, 2009, 02:59 PM
I have just installed this RC.

I'm running a proggie called Winflip (gives Flip 3D Vista effect on XP).

This proggie does not function when SafeOnline Browser Security is enabled.
When I disable SBS > Winflip functions.

PrevxHelp
October 15th, 2009, 03:09 PM
-{ Quote: "Just tried Prevx RC 3.0.4.221 and had to uninstall it again. Running WinXP Pro + SP3, fully updated...

... I use the Foxmarks bookmarks synchroniser in Firefox, together with the attendant desktop agent called Xmarks (which synchronises IE favorites). With the Prevx beta installed, Xmarks reports errors synchronising with its server (it uses https for this) every time IE8 is started. Turning off Prevx's SafeOnline module makes no difference - I had to uninstall the beta completetly and revert to the public 3.0 release to solve the issue." }-

Hello,
Could you please click Tools > Save Scan Results and send us a scan log to report@prevxresearch.com? This should allow us to find/correct the issue.

Thank you for the testing! :)

PrevxHelp
October 15th, 2009, 03:10 PM
-{ Quote: "I have just installed this RC.

I'm running a proggie called Winflip (gives Flip 3D Vista effect on XP).

This proggie does not function when SafeOnline Browser Security is enabled.
When I disable SBS > Winflip functions." }-

Hello,
Could you please try changing the protection from Maximum to High and then restart your browser? This should allow Winflip to work properly :)

Let me know if this works!

spm
October 15th, 2009, 03:11 PM
-{ Quote: "Hello,
Could you please click Tools > Save Scan Results and send us a scan log to report@prevxresearch.com? This should allow us to find/correct the issue.

Thank you for the testing! :)" }-
I have reverted to version 3.0.1.65 - which version do you want me to scan with?

PrevxHelp
October 15th, 2009, 03:17 PM
-{ Quote: "I have reverted to version 3.0.1.65 - which version do you want me to scan with?" }-

.65 works fine :)

spm
October 15th, 2009, 03:26 PM
-{ Quote: "Hello,
Could you please click Tools > Save Scan Results and send us a scan log to report@prevxresearch.com? This should allow us to find/correct the issue." }-
Done. You should have the email + attachment now.

PrevxHelp
October 15th, 2009, 03:30 PM
-{ Quote: "Done. You should have the email + attachment now." }-

Thank you for the log :) Can you please try running another scan and upgrade to the newest test release to see if that fixes it?

Thanks!

egghead
October 15th, 2009, 03:34 PM
-{ Quote: "Hello,
Could you please try changing the protection from Maximum to High and then restart your browser? This should allow Winflip to work properly :)

Let me know if this works!" }-

Okidokie: it works ;D .

Thanx Joe.

rolarocka
October 15th, 2009, 03:35 PM
Running ThreatFire and Prevx together shows "Prevx is deactivated" in Security Center and "No protection against Spyware" (because i have Windows Defender off).
Now if you "Register ThreatFire in Windows Security Center" the problems in the Security Center disappear but only ThreatFire is shown in SC.
If you untick it again, Prevx shows deactivated in SC again. :argh:

spm
October 15th, 2009, 03:56 PM
-{ Quote: "Thank you for the log :) Can you please try running another scan and upgrade to the newest test release to see if that fixes it?

Thanks!" }-
Do you mean the (32bit) download here?

http://info.prevx.com/download.asp?grab=edgebeta

In that case, that is the build I tested with. Just downloaded again and it is identical.

PrevxHelp
October 15th, 2009, 05:02 PM
-{ Quote: "Do you mean the (32bit) download here?

http://info.prevx.com/download.asp?grab=edgebeta

In that case, that is the build I tested with. Just downloaded again and it is identical." }-

That is correct. Could you try rebooting your PC and run another scan with the RC build? I believe the issue is fixed now (at least it isn't happening for me anymore).

Let me know what you find! :)

spm
October 15th, 2009, 06:19 PM
-{ Quote: "That is correct. Could you try rebooting your PC and run another scan with the RC build? I believe the issue is fixed now (at least it isn't happening for me anymore).

Let me know what you find! :)" }-
No joy, I'm afraid. In fact, further testing reveals other issues too. Here goes...

1. I installed the 3.0.4.221 RC, re-booted and scanned.

2. On launching IE8, two Xmarks errors pop-up in sequence. The first reads:

Unable to post message to Xmarks synchronizer [126], please contact Xmarks for additional support.

On dismissing this, a second alert pops up, this time with the [126] replaced by [0]. The issue if fully reproducible with the RC installed, and occurs even when SafeOnline is disabled, and even when Prevx protection is fully disabled.

3. I have "My Documents" redirection configured on this (domain-joined) laptop. When Prevx 3.0.4.221 is installed, the offline files sync at logon and logoff proceeds horribly slowly. With 3.0.1.65, there is no such problem.

4. I normally use Firefox (version 3.5.3). If I use the IETab addin during a Firefox session then, when I close Firefox, the Mozilla Crash Reporter kicks in. Again this is reproducible consistently with the Prevx RC, but not 3.0.1.65. One interesting snippet with this is that the Mozilla Crash Reporter points the finger at my WebSiteWatcher addin. WDW is a web page change tracker, and it, like the PrevxRC, adds a small browser integration button to the Firefox and IE8 toolbars. It has always worked flawlessly though, so maybe the conflict is between WSW and the Prevx RC.

I have uninstalled the Prevx RC again, as this laptop is mission critical and I can't have these issues (though the effects of testing are isolated by use of Rollback RX).

PrevxHelp
October 15th, 2009, 06:21 PM
Hello spm,
Thank you for the testing - I'll forward all of this information onto our internal test team and let you know what we come up with.

Also, if you get a chance, it may be worth setting the protection of SafeOnline down to Medium to see if that fares any better.

spm
October 15th, 2009, 06:31 PM
-{ Quote: "Also, if you get a chance, it may be worth setting the protection of SafeOnline down to Medium to see if that fares any better." }-
Well, given that turning it off altogether makes no difference, I'm not ready to commit the effort necessary to make such a test. When you have a build you believe will resolve these issues, I'll try to test again.

PrevxHelp
October 15th, 2009, 09:27 PM
Hello all,
We've released the next test build and have moved the discussion to: http://www.wilderssecurity.com/showthread.php?p=1558108

There are still a couple issues which we're investigating - the changelog is posted within the new thread.

Thanks again for the testing! :)