PDA

View Full Version : False Positive (I hope...) - Firefox 3.5.5


RetroDrake
November 7th, 2009, 07:28 AM
I have run into what I hope is a false positive. I updated Firefox from 3.5.4 to 3.5.5 earlier this evening without any problems. I browsed some of my regular websites and then logged out for a few hours. I later went to use Firefox again and was suprised to see an "Active Threat Alert" popup from Prevx. It listed the file firefox.exe in the normal Firefox installation directory with an option to click for details. When clicked the main Prevx window opened and initiated a scan. The scan, which took much longer than usual, ended with "System Status: Clean". I am still greeted with the alert any time I attempt to start Firefox. Do I have a botched/hacked Firefox upgrade or is this a false postive?

Thanks in advance for any help you can provide :)

EDIT: I realize that all possible FP reports should be sent to report@prevxresearch.com but I am unable to obtain a scan log because the scan always reports "System Status: Clean.

Baldrick
November 7th, 2009, 09:45 AM
Must be a momentary aberration as I have done the same as you and Prevx has remained silent. Had several scans since then and nothing. I suspect that this will heard or next to impossible to reproduce.:-[

If you can perhaps you should download the complete download of the new version and install that rather than sticking with the incremental upgrade which is how I presume you got to 3.5.5? All you need to do is run the executable and it will install over the top. Might be worth a try?

rollers
November 7th, 2009, 01:48 PM
Don't worry you are not the only ones
http://www.wilderssecurity.com/showthread.php?t=257632

I tried earlier with both the firefox update and complete installer and got the same detection. I even turned all heuristics to their lowest setting. On the last occasion I undid the quarrantine and it has been good since, no more jumping on firefox.

Hopefully this FP is a thing of the past

PrevxHelp
November 8th, 2009, 01:54 PM
-{ Quote: "
EDIT: I realize that all possible FP reports should be sent to report@prevxresearch.com but I am unable to obtain a scan log because the scan always reports "System Status: Clean." }-

If you click Tools > Save Scan Results, it will allow you to save the scan log to your PC regardless of your infection status. Could you send this to report@prevxresearch.com so that we can correct the FP if it still exists?

Thanks!

funkydude
November 8th, 2009, 03:44 PM
-{ Quote: "
Hopefully this FP is a thing of the past" }-

Prevx has had these bad FP's since the release of 3.x and I don't see how it's possibly going to go away, it's the only reason I removed it, it's not reliable enough to keep on a system.

PrevxHelp
November 8th, 2009, 06:18 PM
-{ Quote: "Prevx has had these bad FP's since the release of 3.x and I don't see how it's possibly going to go away, it's the only reason I removed it, it's not reliable enough to keep on a system." }-

There are two sides to every story and it's generally best to not try and assume things when dealing with these detections.

From the two scan logs I've seen so far, these are users that have Maximum Age + Popularity + Heuristic settings enabled. This will logically trigger any new software update to be detected - including Firefox.

At no point was this file determined as bad - it was just triggered by Age/Popularity detection being that its age was low and the popularity was low when it was first released.