False positives / Missing detections thread

Discussion in 'Prevx Releases' started by EraserHW, Jun 14, 2009.

Thread Status:
Not open for further replies.
  1. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I believe I've fixed the false positive - if you try running another scan, it should be fixed :)
     
  2. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    My last Hitman Pro scan did not produce and avast! fp's from Prevx.
    Can this be added?
     
  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We will consider it but currently there isn't much of a demand for it - users rarely see FPs and adding an extra checkbox in the interface could overcomplicate the decision process for the average user.
     
  4. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    By not much of a demand, do you mean no one else has suggested it? As for overcomplicating the decision process, I think you could slip one little "Select all" into this dialog without confusing the masses. ;)
     

    Attached Files:

  5. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Indeed we haven't had any other suggestions of it but it would be a worthy addition :)
     
  6. rolarocka

    rolarocka Guest

  7. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Fixed - I knew this would happen sooner or later :D GMER's random file name downloads look increasingly suspicious :)
     
  8. Dave53

    Dave53 Registered Member

    Joined:
    Feb 23, 2009
    Posts:
    123
    GesWall 2.9 is being flagged as a High Risk Worm on a new installation on a new netbook. VirusTotal shows it detected by Prevx, Sophos, and McAfee Artemis. I had this problem on another machine when I was getting a FP with AntiVir.

    Prevx is not flagging this file on my other machines (older installations).

    File can be found here:

    http://gentlesecurity.com/download.htm

    Thanks,

    Dave
     
  9. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I believe I've corrected the false positive - could you try running another scan?
     
  10. Dave53

    Dave53 Registered Member

    Joined:
    Feb 23, 2009
    Posts:
    123
    I deleted my override and ran 2 scans, and it appears to be fixed.

    Thanks!

    Dave
     
  11. StevieO

    StevieO Registered Member

    Joined:
    Feb 2, 2006
    Posts:
    1,067
  12. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    This does look like a FP - I've corrected it but its hard to say if I got the exact file which you're referring to. Can you try running another scan to see if it is fixed?

    Thanks! :)
     
  13. StevieO

    StevieO Registered Member

    Joined:
    Feb 2, 2006
    Posts:
    1,067
    All GREEN now

    psff.gif

    Thanx
     
  14. webster

    webster Registered Member

    Joined:
    Feb 23, 2004
    Posts:
    285
    Location:
    Denmark
  15. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    It is :) Thanks for the report!
     
  16. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Joe,
    A FP with Shadow Defender when trying to commit a downloaded PDF file, this version has been around some while, have been committing files without any problems for ages - no idea why it should suddenly start now. Also tried committing several downloads I know are clean - same result on all of them.
     

    Attached Files:

  17. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    That's strange indeed - could you try once again now to see if I've fixed the right file?
     
  18. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    :thumb: Working OK now without any problems.
     
  19. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    I have received two emails from Prevx saying my system is infected, each the result of a scan. The Prevx icon in the systray is green and when I search for the offending file, it is nowhere to be found. The filename is MEL-69047DAA0D94FF11128201E40FA144001643EE50.EXE
     

    Attached Files:

  20. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    That's the Prevx test virus (which I believe you've been testing with in a different thread). It says it is currently in your recycle bin which is probably why you can't find it - it might be worth just emptying your recycle bin to see if that clears it up :)
     
  21. Pain of Salvation

    Pain of Salvation Registered Member

    Joined:
    Apr 21, 2005
    Posts:
    399
    ogacheckcontrol.dll is a malware or a FP?

    Log file is attached
     

    Attached Files:

  22. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    It was the latter, now it's neither :) Thanks for the report!
     
  23. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    Question is, how did it get into the recycle bin?
     
  24. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Not sure :doubt: Prevx doesn't move anything to the recycle bin on cleanup (or any other time).
     
  25. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    I tried adding Recycler folder to Detection Overrides and then scanning. The scan, again, came up clean green, but an email arrived within seconds saying I am infected (I posted the MyPrevx screen shot). Then I emptied the recycle bin using CCleaner and re-scanned with Prevx. Scan came back clean green and another email arrived from MyPrevx saying I am infected.

    I will try the configuration change you suggested in the other thread (unticking both of the last items) and will report back.

    Edit in: Reported back on specific thread, if that's okay.
     
    Last edited: Aug 25, 2009
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.