Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Betas
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 18th, 2012, 06:48 PM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,944
Default Quarantine > Detection Configuration

Yesterday, I downloaded a package to my desktop as per post #2 in > Windows XP Pro Critical Updates (after SP3)


WSA detected the following two files:



Automated Cleanup Engine
Starting Cleanup at 17/09/2012 - 19:56:18 GMT

Starting Routine> Removing c:\documents and settings\<MyName>\desktop\wsusoffline742\wsusoffline\client\updateinstaller.exe...#(PX5:

3DEC44F4B11CF89AE3F40924FDD9040074440C6D - MD5: 0010E6CBB04DC0215A7A8BE410FF5292)...
Deleting File> c:\documents and settings\<MyName>\desktop\wsusoffline742\wsusoffline\client\updateinstaller.exe

Automated Cleanup Engine
Starting Cleanup at 17/09/2012 - 19:56:45 GMT

Starting Routine> Removing c:\documents and settings\<MyName>\desktop\wsusoffline742\wsusoffline\updategenerator.exe...#(PX5:

3DEC44F4D71CF89A28F40A24FDD90400844DF673 - MD5: A86E772A10990CFB63FD09036B6A5F4C)...
Deleting File> c:\documents and settings\<MyName>\desktop\wsusoffline742\wsusoffline\updategenerator.exe


I had them scanned at Virus Total and determined that they were safe, so I removed them from quarantine.

Now, I have noticed that they have been allowed under Quarantine > Detection Configuration, automatically.

Name:  ScreenShot_WSA_8.0.2.6_new look_03.jpg
Views: 169
Size:  60.2 KB

I had removed the whole download package from my desktop to another another location as can be seen from the following screenshot.

Name:  ScreenShot_WSA_8.0.2.6_new look_08.jpg
Views: 169
Size:  62.9 KB







However, I would not necessarily want WSA to now allow, automatically.

P.S. If I hadn't gone exploring, I would have been none the wiser.
  #2  
Old September 18th, 2012, 07:56 PM
Techfox1976 Techfox1976 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 574
Default Re: Quarantine > Detection Configuration

If you remove something from quarantine, it sets it to an override of "Allow" otherwise, unless it's whitelisted in the cloud system, it will be re-detected. The allow is by file hash, not by file name/location, it just shows the last-known location of that hash. Or first known, I forget. You can right-Click on the entry to Do Things.

Also, if you're not sure about something, VT is not always the best place to check if WSA flagged it, unless you are absolutely 100% sure it's safe. I've seen stuff that WSA flagged that VT said was clean and was originally scanned several months ago. Rescan and still clean. But inspect the file more deeply just out of curiosity and sure enough, it was bad juju. So WSA caught something that nothing else on VT caught for over a month. Never found out if anything else on VT ever caught it. Lack of threat evidence is not evidence of lack of threat. I'm giving that as a general statement, mind you, not on those files specifically, which I make no warranty as to the status of.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense
My scans take 22 seconds. How long are yours?
  #3  
Old September 19th, 2012, 12:11 AM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,944
Default Re: Quarantine > Detection Configuration

Where did they all go?

Name:  ScreenShot_WSA_8.0.2.6_new look_09.jpg
Views: 158
Size:  25.4 KB
  #4  
Old September 19th, 2012, 12:27 AM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,944
Default Re: Quarantine > Detection Configuration

@ Techfox1976

Thanks for chipping in with that info.

I was hoping Joe, would have added something in reply...He has been in and out, in the forum.



Quote:
Originally Posted by Techfox1976
If you remove something from quarantine, it sets it to an override of "Allow" otherwise, unless it's whitelisted in the cloud system, it will be re-detected. The allow is by file hash, not by file name/location, it just shows the last-known location of that hash. Or first known, I forget. You can right-Click on the entry to Do Things.

Also, if you're not sure about something, VT is not always the best place to check if WSA flagged it, unless you are absolutely 100% sure it's safe. I've seen stuff that WSA flagged that VT said was clean and was originally scanned several months ago. Rescan and still clean. But inspect the file more deeply just out of curiosity and sure enough, it was bad juju. So WSA caught something that nothing else on VT caught for over a month. Never found out if anything else on VT ever caught it. Lack of threat evidence is not evidence of lack of threat. I'm giving that as a general statement, mind you, not on those files specifically, which I make no warranty as to the status of.
  #5  
Old September 19th, 2012, 12:32 AM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,944
Default Re: Quarantine > Detection Configuration

Quote:
Originally Posted by Tarnak
Where did they all go?

Attachment 234621

I just checked again, and they are back!
  #6  
Old September 19th, 2012, 12:04 PM
Techfox1976 Techfox1976 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 574
Default Re: Quarantine > Detection Configuration

Quote:
Originally Posted by Tarnak
@ Techfox1976

Thanks for chipping in with that info.

I was hoping Joe, would have added something in reply...He has been in and out, in the forum.

He's probably super-extra-ultra-OMFG busy as all heck since they are probably releasing the new stuff so soon.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense
My scans take 22 seconds. How long are yours?

Last edited by Techfox1976 : September 19th, 2012 at 12:13 PM.
  #7  
Old September 19th, 2012, 12:51 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,578
Default Re: Quarantine > Detection Configuration

Techfox is correct - it depends on the file, but it will usually be the last seen instance of it which is listed in the detection configuration window. Restoring a file from quarantine adds it as 'Allow', otherwise it would just be removed automatically instantly.
  #8  
Old September 19th, 2012, 07:48 PM
Tarnak Tarnak is offline
Very Frequent Poster
 
Join Date: Feb 2007
Posts: 1,944
Default Re: Quarantine > Detection Configuration

Quote:
Originally Posted by PrevxHelp
Techfox is correct - it depends on the file, but it will usually be the last seen instance of it which is listed in the detection configuration window. Restoring a file from quarantine adds it as 'Allow', otherwise it would just be removed automatically instantly.


The only files I have restored from quarantine are the two mentioned above, and an old archive rootkit file, apispy9x.dll which I know about but will never use.

The others on that list such as Vipre, Defensewall, Opera and $isr have never been restored (by me) from quarantine. So, can see no reason for them appearing there.
  #9  
Old September 19th, 2012, 08:36 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,606
Default Re: Quarantine > Detection Configuration

Quote:
Originally Posted by Tarnak
The only files I have restored from quarantine are the two mentioned above, and an old archive rootkit file, apispy9x.dll which I know about but will never use.

The others on that list such as Vipre, Defensewall, Opera and $isr have never been restored (by me) from quarantine. So, can see no reason for them appearing there.

As you do allot of Beta testing of many products you must have allowed them at one point because they were not known to the cloud database at the time!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #10  
Old September 20th, 2012, 10:50 AM
Techfox1976 Techfox1976 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 574
Default Re: Quarantine > Detection Configuration

Quote:
Originally Posted by Triple Helix
As you do allot of Beta testing of many products you must have allowed them at one point because they were not known to the cloud database at the time!

TH


Aye. I would surmise that going to the Control Active Processes and changing something from Monitor to Allow would also make it show up there. It would be silly for it to be set to "allow" in control and "block" in overrides.
__________________
Windows 7 + Webroot SecureAnywhere Complete + Brains and Common Sense
My scans take 22 seconds. How long are yours?
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Betas « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:31 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums