![]() |
|
#1
|
||||
|
||||
|
Hey Guys,
I am interested in trying Prevx Edge, so tonight I downloaded the installer from their site - http://info.prevx.com/downloadcsi.asp. Before I install it, I've uploaded the installer to VirusTotal which returned one hit from eSafe. I gathered this was a FP, so I then uploaded the installer to Comodo Instant Malware Analysis and it reported: Suspicious Actions Detected Creates files in windows system directory See HERE. I know this is a legit program but am confused by the test results, can anybody explain please? Thanks . |
|
#2
|
||||
|
||||
|
It is the newest version and some AV's still will see it as a False Positive!
So it is very safe to download from there website an install, just disable your AV before you install. TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14 VIP Member Of ASAP - (Alliance of Security Analysis Professionals™) Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's. Last edited by Triple Helix : April 20th, 2009 at 08:10 PM. |
|
#3
|
||||
|
||||
|
As Joe (PrevxHelp) pointed out in the "mother" Prevx Edge thread, AV and AM programs themselves are particularly prone to being FPed by other security softwares just by virtue of the kind of things they do and the depth to which they penetrate the system files and hooks. So, this FPing of Prevx software is not really surprising at all. It's ironic nonetheless and it's not surprising that it can cause some confusion or concern.
__________________
"Ignorance more frequently begets confidence than does knowledge..." - Charles Darwin - |
|
#4
|
||||
|
||||
|
Thanks, Triple Helix and crofttk,
That would explain VirusTotal's result. Any ideas on the report by Comodo Instant Malware Analysis? Suspicious Actions Detected Creates files in windows system directory |
|
#5
|
||||
|
||||
|
Quote:
I wouldn't concern yourself with that as it says • Verdict Auto Analysis VerdictRated as Suspicious� No big deal
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14 VIP Member Of ASAP - (Alliance of Security Analysis Professionals™) Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's. |
|
#6
|
||||
|
||||
|
Well, I am equally unsurprised on both counts, VT's AND CIMA's. I can't comment authoritatively on either one's weakness or FP rate. I just think you're in an area where "all bets are off" and you could expect anything from nothing to a severe ultra bad designation as an FP.
Ultimately, you have to decide who you trust and there are plenty of folks here to vouch for Prevx's website and the cleanliness of their downloads. For VT in particular, only one hit in 40 scans (or however many different scans they do now) is not all that damning. Hopefully, someone here can comment specifically on CIMA for you.
__________________
"Ignorance more frequently begets confidence than does knowledge..." - Charles Darwin - |
|
#7
|
||||
|
||||
|
Just shows how VT and CIMA are prone tp picking up FPs.
__________________
Webroot SecureAnywhere |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|