Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 11th, 2009, 09:49 PM
bonedriven's Avatar
bonedriven bonedriven is offline
Frequent Poster
 
Join Date: Jan 2007
Posts: 549
Default The reason Prevx detects Ahnlab as malware?

I temporarily study at this korean university. Here everyone is forced to install ahnlab security suite 2007 if you want to use the internet service provided by the university. Students here,at least those I know,consider ahnlab the biggest malware on their computers because it does nothing except that loads 5+ processes and 6+ services to keep itself on your pc.

People are trying every way to stop ahnlab while not being cut. But ahnlab updates new manners to monitor if it's running well on your pc. Recently,we found a new effective way that use brutal force to delete one of the Ahnlab install directories. It works well. *whisper* "Don't tell them!"

Now Prevx(it never did) detects some of ahnlab's files and registry entries as malware. But I think,maybe,Prevx intelligently finds that ahnlab is not a wanted program on my computer at the moment?

BTW,can someone send me snipped according to our TOS

Last edited by bonedriven : June 11th, 2009 at 11:46 PM.
  #2  
Old June 11th, 2009, 11:04 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,582
Default Re: The reason Prevx detects Ahnlab as malware?

Hello,
I've corrected the detection for the file you referenced. If there are more, please let me know and I'll look into them further Security software is always difficult to detect as good automatically because of the modifications it makes into the system. Antivirus software tends to hook system services and load driver components which perform suspicious behaviors, much like rootkits, so we generally need to whitelist these programs to prevent them from generating FPs.

However, the same happens against us whenever we release a new version - many AVs automatically detect new versions of Prevx software so we need to give other vendors pre-release copies to fix new FPs It is hard to blame them for detecting our software, however, because antimalware software does tend to look like malware on the surface level.
  #3  
Old June 11th, 2009, 11:33 PM
bonedriven's Avatar
bonedriven bonedriven is offline
Frequent Poster
 
Join Date: Jan 2007
Posts: 549
Default Re: The reason Prevx detects Ahnlab as malware?

Quote:
Originally Posted by PrevxHelp
Hello,
I've corrected the detection for the file you referenced.

Thank you. And SOGOUTSF.DLL.

It's a widely used chinese input method software which has been installed for a long time. Now Prevx begins to detect it as malware.

Sorry if I've hijacked the thread.

Last edited by bonedriven : June 11th, 2009 at 11:48 PM.
  #4  
Old June 11th, 2009, 11:36 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,582
Default Re: The reason Prevx detects Ahnlab as malware?

Fixed as well Thanks for the report!
  #5  
Old June 11th, 2009, 11:53 PM
Gaeko
 
Posts: n/a
Default Re: The reason Prevx detects Ahnlab as malware?

I'm from Korea, and I know what you are talking about.
Yes, Ahnlab is monopolizing the Korean security market.
It's interesting to know that PrevX detects Ahnlab as a malware.
Because Dr.Web also detects some Ahnlab files as a malware.
Take care.
  #6  
Old June 12th, 2009, 12:41 AM
bonedriven's Avatar
bonedriven bonedriven is offline
Frequent Poster
 
Join Date: Jan 2007
Posts: 549
Default Re: The reason Prevx detects Ahnlab as malware?

Quote:
Originally Posted by Gaeko
I'm from Korea, and I know what you are talking about.
Yes, Ahnlab is monopolizing the Korean security market.
It's interesting to know that PrevX detects Ahnlab as a malware.
Because Dr.Web also detects some Ahnlab files as a malware.
Take care.

Hi Gaeko,

I didn't make it clear myself. It is not every university that forces their pcs to install ahnlab here. The university I'm in may be one of a few cases.
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:12 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums