Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 28th, 2009, 08:03 PM
Rabiddog
 
Posts: n/a
Default Weather Pulse

How come all of a sudden Prevx is picking up on "Weather Pulse"
Had it installed before Prevx.
Changed the default settings 3 day ago, Why so long and now?
Seem's like Prevx is too nosy.
When I have to send in the log's of every program installed and just not the FP.
Call me paranoid, that's why I joined this forum.

Last edited by Rabiddog : August 28th, 2009 at 08:12 PM.
  #2  
Old August 29th, 2009, 02:18 PM
Rabiddog
 
Posts: n/a
Default Re: Weather Pulse

Good work Prevx!

I found some information on this;

This virus is actually several months old and all AV companies were blind. Why?

Till now, file infectors (like Virut, Sality, Parite, …) have modified executable files on the victim’s machine. They appended their body and changed the entry point – “thats all”. Win32:Induc is different. The infected file looks for the Borland Delphi compiler on the victim’s machine. If Delphi is found, the source file SysConst.pas is replaced by a malicious one and is compiled into SysConst.dcu. Each new build (using SysConst.dcu – practically all) of any Delphi project on an infected machine produces an infected file. This malware is produced by “white” programmers without their permission. Many files are digitally signed and distributed globally through download servers.

A few statistics: A few hours after VPS update 090818-0 (contains detection Win32:Induc) we received hundreds of suspected “false positive alerts” – all of them were infected. In the last 12 hours (since VPS was released) avast! has found ~200 000 infected files.
  #3  
Old August 29th, 2009, 04:56 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Weather Pulse

Indeed Induc is a new, widely spread file infector which is infecting the build process of many software companies that use the Delphi programming language.

Weather Pulse is one of the affected programs and this shows that software can't be trusted just because it is digitally signed or written by a "trusted" vendor.

If you do see any cases of Prevx being too "noisy", please let us know but I believe this detection is correct.
  #4  
Old August 29th, 2009, 07:02 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,204
Default Re: Weather Pulse

I was under the impression the problem had been fixed. http://www.wilderssecurity.com/showp...67&postcount=1
  #5  
Old August 29th, 2009, 07:18 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Weather Pulse

Quote:
Originally Posted by ronjor
I was under the impression the problem had been fixed. http://www.wilderssecurity.com/showp...67&postcount=1

The Induc infected version which we and a number of other AVs are flagging was first seen within the Prevx community on July 10th. I suspect they've cleaned the new version now but anything earlier than 2.20 will have the "false positive" (not really a false positive )

It would definitely be good to uninstall and download the newest from the link you posted.
  #6  
Old August 30th, 2009, 02:06 AM
Rabiddog
 
Posts: n/a
Default Re: Weather Pulse

Quote:
Originally Posted by PrevxHelp
Indeed Induc is a new, widely spread file infector which is infecting the build process of many software companies that use the Delphi programming language.

Weather Pulse is one of the affected programs and this shows that software can't be trusted just because it is digitally signed or written by a "trusted" vendor.

If you do see any cases of Prevx being too "noisy", please let us know but I believe this detection is correct.

I was saying noisy because sending it a report of everything running on the computer. Why not just the problem?
  #7  
Old August 30th, 2009, 10:41 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Weather Pulse

Quote:
Originally Posted by Rabiddog
I was saying noisy because sending it a report of everything running on the computer. Why not just the problem?

Prevx scans your entire system to find possible threats by sending data about files and their behavior into our centralized servers which then automatically detect new threats. It needs to analyze everything on your PC so that it can be sure that it will find any active threats.
  #8  
Old September 2nd, 2009, 04:25 PM
mvdu mvdu is offline
Very Frequent Poster
 
Join Date: Oct 2003
Location: PA
Posts: 1,151
Default Re: Weather Pulse

So the WeatherPulse latest version is clean? I don't know if I can trust WeatherPulse, since on their download page they passed it off as a "false positive." What does PrevxHelp think?
  #9  
Old September 2nd, 2009, 07:00 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Weather Pulse

Quote:
Originally Posted by mvdu
So the WeatherPulse latest version is clean? I don't know if I can trust WeatherPulse, since on their download page they passed it off as a "false positive." What does PrevxHelp think?

Their latest version is clear of Induc but I also dislike their blatant dishonesty as regarding it as a false positive but quite a few other weather programs have even worse spyware in them

Personally, I don't trust any of them - I tend to just look out the window to see what weather it is now Any further in the future than right now, the weather predictors are almost always wrong so I try not to bother
  #10  
Old September 2nd, 2009, 08:01 PM
Habakuck's Avatar
Habakuck Habakuck is offline
Frequent Poster
 
Join Date: May 2009
Posts: 543
Default Re: Weather Pulse

Quote:
the weather predictors are almost always wrong so I try not to bother
you are so right! I am a sailor and i only trust my personal weather forecast.
__________________
"If You Run Naked Around a Tree, at about 87 km/h, there is a possibilty of f4cking your self."
Albert Einstein
  #11  
Old September 2nd, 2009, 09:11 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,204
Default Re: Weather Pulse

Quote:
Any further in the future than right now, the weather predictors are almost always wrong so I try not to bother
It pays to be informed about potential weather events for your own safety.
Quote:
quite a few other weather programs have even worse spyware in them
Can you name names so we can avoid such programs?
  #12  
Old September 2nd, 2009, 10:39 PM
mvdu mvdu is offline
Very Frequent Poster
 
Join Date: Oct 2003
Location: PA
Posts: 1,151
Default Re: Weather Pulse

Quote:
Originally Posted by PrevxHelp
Their latest version is clear of Induc but I also dislike their blatant dishonesty as regarding it as a false positive but quite a few other weather programs have even worse spyware in them

Personally, I don't trust any of them - I tend to just look out the window to see what weather it is now Any further in the future than right now, the weather predictors are almost always wrong so I try not to bother

LOL - I know what you mean. But as I currently use WeatherPulse, would you advise I drop it due to the Induc dishonesty?

I'd also like to know the worse programs.
  #13  
Old September 3rd, 2009, 04:41 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Weather Pulse

Quote:
Originally Posted by mvdu
LOL - I know what you mean. But as I currently use WeatherPulse, would you advise I drop it due to the Induc dishonesty?

I'd also like to know the worse programs.

Probably not - I think they're clean now and while I don't appreciate the dishonesty, they do have a good product.

WeatherBug is the worst example I've seen. They have cleaned up their act recently but I still come across people whose PCs have WeatherBug installations from ~2005 that get frequent popups and random annoyances they thought were because of a virus infection when they're actually caused just by the WeatherBug.

A bit before that was WeatherCast, and then FreshWeather around '07...

I guess I may just have a cold shoulder when it comes to weather applications. Now I just use the weather gadget that comes by default with Windows 7
  #14  
Old September 3rd, 2009, 04:52 AM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Weather Pulse

weather.com is a favorite of mine. It is surprisingly accurate, even with their 10 day forecast. If I had to pin a number on it, I'd say their forecasts are correct about 75% of the time. I will even say I rely upon their forecasts.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #15  
Old September 3rd, 2009, 11:30 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,612
Default Re: Weather Pulse

I use Weather Eye here in Canada without problems have been using it for years!

http://www.theweathernetwork.com/des...home_wxeyeperm

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #16  
Old September 4th, 2009, 07:43 PM
Rabiddog
 
Posts: n/a
Default Re: Weather Pulse

Well I got rid of Weather Pluse and use Weather1 now. Nice program. Paid for, but it's clean.
I guess, you get what you pay for.
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:21 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums