Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 17th, 2010, 06:55 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default page heap enabled as global flag WinDbg crashing Prevx

WIN 7 64bit / Prevx 3.0.5.179 / WinDbg 6.12.0002.633

cannot undertake debugging this way, unless accepting the Prevx crashes (upon booting) or unistalling Prevx.
If this is part of Prevx self-defense it is questionable. and probably should be fixed.
  #2  
Old July 17th, 2010, 07:38 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: page heap enabled as global flag WinDbg crashing Prevx

Quote:
Originally Posted by vtol
WIN 7 64bit / Prevx 3.0.5.179 / WinDbg 6.12.0002.633

cannot undertake debugging this way, unless accepting the Prevx crashes (upon booting) or unistalling Prevx.
If this is part of Prevx self-defense it is questionable. and probably should be fixed.

Hi vtol,

Can I suggest that you send a scan log if able to report@prevxresearch.com as stated in this post: http://www.wilderssecurity.com/showp...81&postcount=1

TIA,

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #3  
Old July 17th, 2010, 09:09 PM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: page heap enabled as global flag WinDbg crashing Prevx

Quote:
Originally Posted by Triple Helix
Hi vtol,

Can I suggest that you send a scan log if able to report@prevxresearch.com as stated in this post: http://www.wilderssecurity.com/showp...81&postcount=1

TIA,

TH
I know it is your standard thing to post but scan logs are not the cure to everything. in particular not when it is about heaps and self-defense of the application, like it is for other av software. moreover, and as mentioned, prevx is crashing upon booting, hence there is no scan log relevant to it

Last edited by vtol : July 17th, 2010 at 09:14 PM.
  #4  
Old July 17th, 2010, 09:18 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,611
Default Re: page heap enabled as global flag WinDbg crashing Prevx

Quote:
Originally Posted by vtol
I know it is your standard thing to post but scan logs are not the cure to everything. in particular not when it is about heaps and self-defense of the application, like it for other av software. moreover, and as mentioned, prevx is crashing upon booting, hence there is no scan log relevant to it

1. Did you try a clean reinstall of Prevx? 2. Could there be some other security program conflicting with Prevx? 3. Are you open to a remote session with a Prevx engineer to figure out the problem?

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.145 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #5  
Old July 18th, 2010, 01:08 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,582
Default Re: page heap enabled as global flag WinDbg crashing Prevx

Quote:
Originally Posted by vtol
WIN 7 64bit / Prevx 3.0.5.179 / WinDbg 6.12.0002.633

cannot undertake debugging this way, unless accepting the Prevx crashes (upon booting) or unistalling Prevx.
If this is part of Prevx self-defense it is questionable. and probably should be fixed.

Could you clarify if Prevx is the application that's crashing or if normal debugging with page heap tracking enabled is crashing?

Prevx shouldn't affect other applications' heaps, but it might be worth lowering the Prevx self protection to minimum which will remove self protection incompatibilities directly. Personally, I always run with heap tracking enabled and debug applications but haven't had any problems with Prevx on maximum self protection.

Let me know what you find!
  #6  
Old July 18th, 2010, 06:33 AM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: page heap enabled as global flag WinDbg crashing Prevx

Quote:
Originally Posted by PrevxHelp
Could you clarify if Prevx is the application that's crashing or if normal debugging with page heap tracking enabled is crashing?

Prevx shouldn't affect other applications' heaps, but it might be worth lowering the Prevx self protection to minimum which will remove self protection incompatibilities directly. Personally, I always run with heap tracking enabled and debug applications but haven't had any problems with Prevx on maximum self protection.

Let me know what you find!
Prevx keeps on crashing upon boot. uninstalled now, since being in a useless state. used to run it with the out of the box settings

Description
Faulting Application Path: C:\Program Files\sxccrlfi\sxccrlfi.exe

Problem signature
Problem Event Name: APPCRASH
Application Name: sxccrlfi.exe
Application Version: 3.0.5.179
Application Timestamp: 4c2e649a
Fault Module Name: sxccrlfi.exe
Fault Module Version: 3.0.5.179
Fault Module Timestamp: 4c2e649a
Exception Code: c0000005
Exception Offset: 000000000006f102
OS Version: 6.1.7600.2.0.0.256.1
Locale ID: 2057
Additional Information 1: 7d91
Additional Information 2: 7d91235105e216824d3d7754c77dab31
Additional Information 3: 1a90
Additional Information 4: 1a90a3bed89e9f5c2557deb2540b2280

Name:  18-07-2010 12-27-36.png
Views: 427
Size:  172.7 KB
  #7  
Old July 18th, 2010, 01:11 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,582
Default Re: page heap enabled as global flag WinDbg crashing Prevx

I'd recommend uninstalling/reinstalling and then lowering self protection. We haven't changed anything with regard to self protection so I'm not sure why this would have just started happening but Prevx will prevent debuggers from attaching to it so it is possible that changing the global flags could affect it.

Let me know your results!
  #8  
Old July 19th, 2010, 06:04 AM
vtol's Avatar
vtol vtol is offline
Frequent Poster
 
Join Date: Apr 2010
Location: just around the next corner
Posts: 774
Default Re: page heap enabled as global flag WinDbg crashing Prevx

Quote:
Originally Posted by PrevxHelp
I'd recommend uninstalling/reinstalling and then lowering self protection. We haven't changed anything with regard to self protection so I'm not sure why this would have just started happening but Prevx will prevent debuggers from attaching to it so it is possible that changing the global flags could affect it.

Let me know your results!
of course changing the global flags caused the crash of Prevx. I am not doing testing for Prevx, uninstalled it and perhaps see in a couple of months whether is has been fixed or not.

However found it important to let the forum know as malicious code could replicate the mode to crash Prevx.
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:29 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums