Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 27th, 2009, 02:13 AM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Prevx detected Trojan... FP?

Hi all, I have a problem deciding if this is a FP detected by Prevx.

C:\windows\mota113.exe

Could someone please confirm this as being a threat or false positive?

I have done the usual google search, and their seems to be no concise answer.
Half saying it is malicious the other half saying it is a FP.
  #2  
Old May 27th, 2009, 02:21 AM
innerpeace's Avatar
innerpeace innerpeace is offline
Very Frequent Poster
 
Join Date: Jan 2007
Location: Mountaineer Country
Posts: 1,940
Default Re: Prevx detected Trojan... FP?

You can upload the file to http://www.virustotal.com/ or http://virusscan.jotti.org/

At those sites it will be scanned by multiple scanners. Just don't post the results here as it's against forum rules.

Also, welcome to Wilders .
__________________
XP Home SP3, Nat router, Firefox3.5, Online Armor Premium 4.5, AntiVir 9 free, Sandboxie, and Returnil RVS
Are you running vulnerable programs? Check online now with the Secunia Online Software Inspector.
  #3  
Old May 27th, 2009, 02:49 AM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,721
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by overangry
Hi all, I have a problem deciding if this is a FP detected by Prevx.

C:\windows\mota113.exe

Could someone please confirm this as being a threat or false positive?

I have done the usual google search, and their seems to be no concise answer.
Half saying it is malicious the other half saying it is a FP.

Do a single file scan of this file with Prevx, save the log file and send it to Joe (PrevxHelp) via PM. I found this so it could be malware http://spywarefiles.prevx.com/RRHJEF...TA113.EXE.html If the results of the online scan(s) indicate it is malware there are several sites that will look at your HijackThis log. You can download the program here http://www.trendsecure.com/portal/en...ols/hijackthis. This site can help you http://www.bleepingcomputer.com/forums/

Last edited by G1111 : May 27th, 2009 at 02:59 AM.
  #4  
Old May 27th, 2009, 02:58 AM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by innerpeace
You can upload the file to http://www.virustotal.com/ or http://virusscan.jotti.org/

At those sites it will be scanned by multiple scanners. Just don't post the results here as it's against forum rules.

Also, welcome to Wilders .

I have done that, some engines report it as a trojan (7.5%)
  #5  
Old May 27th, 2009, 02:59 AM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,721
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by overangry
I have done that, some engines report it as a trojan (7.5%)
see my above post.
  #6  
Old May 27th, 2009, 03:00 AM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by G1111
Do a single file scan of this file with Prevx, save the log file and send it to Joe (PrevxHelp) via PM. I found this so it could be malware http://spywarefiles.prevx.com/RRHJEF...TA113.EXE.html

I'll do that, and thank you for your quick replies
  #7  
Old May 27th, 2009, 03:03 AM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,721
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by overangry
I'll do that, and thank you for your quick replies

If you are using the paid version of Prevx they will assist you with removal.
  #8  
Old May 27th, 2009, 03:22 AM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by G1111
If you are using the paid version of Prevx they will assist you with removal.

I have the paid version, but at the moment PM are unavailable.
I'll try again in a few hours
Thanks
  #9  
Old May 27th, 2009, 12:56 PM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,721
Default Re: Prevx detected Trojan... FP?

Okay, Good luck. Let us know what happens.
  #10  
Old May 27th, 2009, 06:28 PM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by G1111
Okay, Good luck. Let us know what happens.

Again thanks for your advice. Yes the file was bad but was sucsesfully removed...
  #11  
Old May 27th, 2009, 09:07 PM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,721
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by overangry
Again thanks for your advice. Yes the file was bad but was sucsesfully removed...

Good news. Any ideas how you got the bug. Was Prevx running at the time. Just curious because I also use Prevx 3.0.
  #12  
Old May 27th, 2009, 10:01 PM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by G1111
Good news. Any ideas how you got the bug. Was Prevx running at the time. Just curious because I also use Prevx 3.0.

It may have been resident for some time, I,m sure it wasn't prevx that let it through.
The file didn't execute but it slipped through some how
I assume geswall didn't allow it to do any harm.
Over the past month or so I have been testing many AV's and malware apps, before I setteled on my current configuration.
Fact is, Prevx was the only application that detected the threat
Their support was top notch...
  #13  
Old May 27th, 2009, 10:23 PM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,721
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by overangry
It may have been resident for some time, I,m sure it wasn't prevx that let it through.
The file didn't execute but it slipped through some how
I assume geswall didn't allow it to do any harm.
Over the past month or so I have been testing many AV's and malware apps, before I setteled on my current configuration.
Fact is, Prevx was the only application that detected the threat
Their support was top notch...

Glad to hear it. I have been using Prevx for maybe 2 months now. Good protection.
  #14  
Old May 27th, 2009, 10:45 PM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by G1111
Glad to hear it. I have been using Prevx for maybe 2 months now. Good protection.

I agree, I've only been using prevx for about 1 week. I had tried earlier versions, but found them to be to buggy.
With this release they seem to have hit the nail on the head.
Purchased prevx after 2 days, so far it seems to be a good investment
  #15  
Old May 28th, 2009, 06:42 AM
Saraceno's Avatar
Saraceno Saraceno is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 2,395
Default Re: Prevx detected Trojan... FP?

Prevx = top notch

Just out of interest, do you remember which other AVs detected the file?
__________________
Fine Art Landscape Photography
  #16  
Old May 28th, 2009, 08:11 AM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by Saraceno
Prevx = top notch

Just out of interest, do you remember which other AVs detected the file?
Quote:
Originally Posted by overangry
Fact is, Prevx was the only application that detected the threat

But Comodo AV, A-Squared, Super-Antispyware, Avira and Kasparsky failed to detect the threat during a scan of my PC.
  #17  
Old May 28th, 2009, 11:36 AM
Saraceno's Avatar
Saraceno Saraceno is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 2,395
Default Re: Prevx detected Trojan... FP?

All depends what the threat was doing. Causing slowdowns, problems?

Or it might have just been sitting there doing nothing. Either way, as long as you have no problems, you'll be happy.
__________________
Fine Art Landscape Photography
  #18  
Old May 28th, 2009, 12:46 PM
egghead's Avatar
egghead egghead is offline
Frequent Poster
 
Join Date: Aug 2005
Location: The Netherlands
Posts: 439
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by overangry
I agree, I've only been using prevx for about 1 week. I had tried earlier versions, but found them to be to buggy.
With this release they seem to have hit the nail on the head.
Purchased prevx after 2 days, so far it seems to be a good investment

I agree with your agreeing.

Trialed some earlier versions but had mixed feelings. With this version Prevx is heading in the good direction. Like it very much. It is doing a good job in protection (double checked with Dr.Web & Counterspy). Good support also.

I have had it with hour long scans. I use Prevx now as my main protection, but keep the good Dr.Web & Counterspy installed (have disabled real time protection of both).

I'm using Prevx for 8 days now and have purchased it.
__________________
THE RATIONAL MIND IS A WONDERFUL SERVANT, BUT A TERRIBLE MASTER.

Panda Cloud, HitmanPro, LookNStop, Shadowprotect, AdMuncher, SyncBack SE & MST defrag.
  #19  
Old May 28th, 2009, 12:58 PM
G1111's Avatar
G1111 G1111 is offline
Very Frequent Poster
 
Join Date: May 2005
Location: USA
Posts: 1,721
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by overangry
I agree, I've only been using prevx for about 1 week. I had tried earlier versions, but found them to be to buggy.
With this release they seem to have hit the nail on the head.
Purchased prevx after 2 days, so far it seems to be a good investment

Same here. Used it a few years ago and it really slowed down my system. The new version Edge (now 3.0) is fast and works well with my other security. Hope they don't change things too much with future editions. It is great right now.
  #20  
Old June 6th, 2009, 05:52 PM
Steven Avery Steven Avery is offline
Regular Poster
 
Join Date: Nov 2007
Posts: 104
Default finding the original source of the malware

Hi Folks,

This is an area where I think a certain type of security-utility software might be helpful. One that reads the dates and time of a file install and matches that up to other files on the system .. was it part of a team .. or an orphan ? Was it a day ago, or a month ago ? Has it been accessed since the install ? (If your looking at the file itself changes the access date .. not sure if it does, think not .. then this might be checked on a recent backup copy. If one exists.)

Possibly this could also integrate with browser download logs that x-refs file names and sites and files downloaded and date and time. (Conceptually such logs should be kept for a long time, in reality, probably very little.)

I did the first section of this by hand on a recent false positive and found the solid source of a file that emsi flagged. (They were totally disinterested in that type of process and finding since it did not fit into their bureaucracy.) It took a bit of effort, but was well worthwhile, the file had come in as a .dll on a task manager program and was all fine. (The false positive basically had it coming from Venus, going back to the fact that an earlier iteration of the .dll was used in a parental control keylogger program a decade ago. The experience made me quite wary of such flags.)

Is there a security product that assists or automates this type of process ? It all seemed very logical to me, yet seems to be rarely considered. Where did this file come from, let's see if I can figger it out on my system post-facto.

Sidenote: One reason this type of thing is necessary is that so many programs throw .dll's into other stuff in Windows system folders. The loosey-goosey OS.

Shalom,
Steven Avery

Last edited by Steven Avery : June 6th, 2009 at 06:00 PM.
  #21  
Old June 20th, 2009, 05:46 AM
catnotspam's Avatar
catnotspam catnotspam is offline
Infrequent Poster
 
Join Date: May 2009
Location: haifa
Posts: 42
Default Re: Prevx detected Trojan... FP?

i think that shadow-defender may be rouge antimalware
__________________
Windows Vista SP2 ru Kaspresky Internet Security 2010 (8.0.0.506) Internet Explorer 7 and Google Chrome 3 antivirushelp2009@yahoo.com
  #22  
Old June 20th, 2009, 11:42 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,579
Default Re: Prevx detected Trojan... FP?

Quote:
Originally Posted by catnotspam
i think that shadow-defender may be rouge antimalware

Shadow Defender is a legitimate program, as long as you have received it from the legitimate sources. Could you PM me the link which you think is malicious and I'll check it out
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:17 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums