Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 2nd, 2009, 04:36 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Prevx alerts on Hitman Pro and avast

I've grown used to Prevx telling me to remove avast files as threats. I wish it was otherwise (meaning I wish Prevx would check for new program versions of avast and make sure they didn't call the new drivers threats), but that doesn't seem to be happening. My Detection Override feature has about 13 avast files in it currently.

Also had Prevx alert on Hitman Pro just now, per attached images.

By the way, these detections all occur when scanning with Hitman Pro.
Attached Images
  
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #2  
Old December 2nd, 2009, 04:56 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,634
Default Re: Prevx alerts on Hitman Pro and avast

Your Program Age Heuristics settings are set to high try setting to medium!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.155 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #3  
Old December 2nd, 2009, 05:39 PM
Fajo's Avatar
Fajo Fajo is offline
Very Frequent Poster
 
Join Date: Jun 2008
Posts: 1,805
Default Re: Prevx alerts on Hitman Pro and avast

Quote:
Originally Posted by Page42
I've grown used to Prevx telling me to remove avast files as threats. I wish it was otherwise (meaning I wish Prevx would check for new program versions of avast and make sure they didn't call the new drivers threats), but that doesn't seem to be happening. My Detection Override feature has about 13 avast files in it currently.

Also had Prevx alert on Hitman Pro just now, per attached images.

By the way, these detections all occur when scanning with Hitman Pro.

I have Avast 5! on one computer and Prevx (Paid) Running next to one and other and I have not had any issues with it flagging the files. Avast 4.8 tho I don't know about sense I do not use that version on any of my computers.
  #4  
Old December 2nd, 2009, 05:47 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Prevx alerts on Hitman Pro and avast

Quote:
Originally Posted by Triple Helix
Your Program Age Heuristics settings are set to high try setting to medium!
It probably is heuristics, TH, but I'm a cake-and-eat-it-too type of guy. I like the heuristics cranked up and I don't want the fp's that go along with the territory. Thing is, these detections, as noted, only happen when scanning with HMP (and Prevx enabled). That's the weird part. Plus, I must say, even with heuristics set to max, I still would like to see Prevx ignore avast driver files.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #5  
Old December 2nd, 2009, 05:54 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Prevx alerts on Hitman Pro and avast

Quote:
Originally Posted by Fajo
I have Avast 5! on one computer and Prevx (Paid) Running next to one and other and I have not had any issues with it flagging the files. Avast 4.8 tho I don't know about sense I do not use that version on any of my computers.
Yes, v4.8 here. With avast 5, are you running Prevx heuristics maxed out, with Apply before Age/Popularity detection?
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #6  
Old December 2nd, 2009, 06:00 PM
Fajo's Avatar
Fajo Fajo is offline
Very Frequent Poster
 
Join Date: Jun 2008
Posts: 1,805
Default Re: Prevx alerts on Hitman Pro and avast

Quote:
Originally Posted by Page42
Yes, v4.8 here. With avast 5, are you running Prevx heuristics maxed out, with Apply before Age/Popularity detection?

Everything maxed. If you want PM Joe the files that keep changing I'm sure he could white list them or have a look how to get them not detected anymore.
  #7  
Old December 2nd, 2009, 06:12 PM
Page42's Avatar
Page42 Page42 is offline
Massive Poster
 
Join Date: Jun 2007
Location: Last Breath Farm
Posts: 4,580
Default Re: Prevx alerts on Hitman Pro and avast

Quote:
Originally Posted by Fajo
Everything maxed. If you want PM Joe the files that keep changing I'm sure he could white list them or have a look how to get them not detected anymore.
Do you have HMP onboard? If so, try running a Hitman scan with Prevx enabled.

As for Joe having a look, yes, that's an after-the-fact thing to do, but once I have them listed as trusted, it doesn't matter anymore.

What I'd really like to see, and I don't know why it isn't already happening, is for Prevx to be on top of these avast driver files, by whatever method they use to check on well-known and widely used security programs, so that fp's aren't constantly happening every time a program update takes place.

I really don't want to come off as a complainer. I just don't understand why even with heuristics set high, Prevx couldn't be more out in front of these avast files. It's like they are way behind the curve on these things.
__________________
To err is human; to forgive, infrequent. - Franklin P. Adams
  #8  
Old December 3rd, 2009, 07:30 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: Prevx alerts on Hitman Pro and avast

Quote:
Originally Posted by Page42
I really don't want to come off as a complainer. I just don't understand why even with heuristics set high, Prevx couldn't be more out in front of these avast files.

The problem with drivers in particular is that once they've entered the system, they essentially have free-reign and can do as they please, therefore, we have heightened heuristics against them, especially for ones that access the system in the manner that AV software does (which is identical to that done by rootkits).

As suggested, it might be worth sending over a scan log - I'll see if we can add dynamic whitelisting in particular for the Avast drivers, but we tend to be very weary for cases like this.
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:44 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums