Free Prevx CSI

Discussion in 'other anti-malware software' started by koliko, Sep 24, 2007.

Thread Status:
Not open for further replies.
  1. Espresso

    Espresso Registered Member

    Joined:
    Aug 1, 2006
    Posts:
    976
    What file "information" does it send? Does it upload complete files that it flags as suspicious? Shouldn't it warn you when it's going to be sending information? It could theoretically flag an executable multimedia presentation of confidential research material as "suspicious" and upload it to your team of "researchers". I think the process should be a little more transparent and the software should warn you about all communications with external servers.
     
  2. Montpellier

    Montpellier Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    20
    10 minutes!?

    Not sure if the scanner works in the way you describe (I'll wait for someone from Prevx to confirm), but the scan of my entire machine only took a minute or so and I definitely didn't see any huge amount of data being uploaded?
     
  3. Espresso

    Espresso Registered Member

    Joined:
    Aug 1, 2006
    Posts:
    976

    I only have 15kB/s upstream bandwidth.
     
  4. StevieE9

    StevieE9 Registered Member

    Joined:
    Jan 16, 2007
    Posts:
    139
    I have used Prevx versions since the original and, frankly, I find those comments a complete load of nonsense. I have had fewer FPs with Prevx than any other security software. I have experimented with Cyberhawk/Threatfire and found it totally inferior.
     
  5. Montpellier

    Montpellier Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    20
    Ah ok then ;)

    Would still be interesting to know how much data on average the scanner uploads.
     
  6. mikel108

    mikel108 Registered Member

    Joined:
    Dec 10, 2004
    Posts:
    1,057
    Location:
    SW Ontario, Canada
    I know I certaily have questions about the product....especially when you cannot distinquish a popular antiviruses files:rolleyes:
     

    Attached Files:

  7. koliko

    koliko Registered Member

    Joined:
    Dec 13, 2006
    Posts:
    105
    I don't think that the PrevX is a spy company, for if they were, other anti-malware software would certainly detect their products as malware, don't you agree?

    Thanks for the explanation.
     
  8. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    In my eyes this is a subvertion and violation of privacy, every user has to be able to decide whether he wants to send suspicious files or not, therefore it looks like a black sheep in security business that aggressively grabs anything it can get.
     
  9. Dalgy

    Dalgy Registered Member

    Joined:
    Sep 25, 2007
    Posts:
    5
    Hi,

    The details of what the Prevx software does is included in the terms and conditions, I include the paragraph below.
    Regards
     
  10. ghiser1

    ghiser1 Developer

    Joined:
    Jul 8, 2004
    Posts:
    132
    Location:
    Gloucester, UK
    The sort of data transmitted by Prevx CSI is related to the file itself and areas that refer to it in the registry. For example, take MSN Messenger:

    Location: %programfiles%\MSN Messenger
    Name: msnmsgr.exe
    Vendor: Microsoft Corporation
    Product: Messenger
    Version: 8.1.0178
    Registry: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr = "c:\program files\MSN Messenger\msnmsgr.exe" /background
    Events: REGRUNKEY
    MD5:c4281ad865739e71fd1e4dac19a68d60
    SHA1:a1ff1546af2aa41b343852d04cc239537820936c
    + up to 7 prevx file identification signatures (if available)

    The anonymous attack and file data captured by Prevx CSI is a subset of that gathered by Prevx 2.0. Both products have an extensive section in their license terms and conditions that cover this subject. We are grateful to all users that volunteer to help Prevx in its fight against malware and Internet crime.

    When running Prevx CSI you have to agree to those terms and conditions each time the tool is run. If you do not wish to help Prevx in its fight against malware and Internet crime simply close Prevx CSI without accepting the terms and conditions and no data will be transmitted.
     
  11. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    It´s always respectable to fight against real! Malware (and not slander Software as Exploit that is totally harmless), if there is only data transmitted and not the suspicious files then this would be not that critical.
    In case of file submission you should definitely ask the user before transmission.
     
  12. Perman

    Perman Registered Member

    Joined:
    Nov 23, 2005
    Posts:
    2,161
    Hi, folks: Newly updated version has been just released. The TF F.P. has been addressed. A raid response team indeed. This is One of the many reasons that I stay comfortably with Prevx. Have a nice one.
     
  13. Sportscubs1272

    Sportscubs1272 Registered Member

    Joined:
    Apr 9, 2007
    Posts:
    341
    I don't think Prevx is forcing people to use their products so just use something else or none at all.
     
  14. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Very true,as that would also pertain to any piece of software,but I do get your point.:D

    This issue with Prevx CSI disussed here also
     
    Last edited: Oct 3, 2007
  15. midway40

    midway40 Registered Member

    Joined:
    Jul 24, 2006
    Posts:
    1,257
    Location:
    SW MS, USA
    I don't know what to make of this o_O
     

    Attached Files:

  16. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Odd.

    I occasionally and almost often get those same equal returns with ThreatFire. It has to be a code identity problem or something within these respective programs design that needs sharpening.
     
  17. JerryM

    JerryM Registered Member

    Joined:
    Aug 31, 2003
    Posts:
    4,306
    What does Prevx CSI do that a good AV or AS does not do? Is it just another case of double checking?
    Thanks,
    Jerry
     
  18. midway40

    midway40 Registered Member

    Joined:
    Jul 24, 2006
    Posts:
    1,257
    Location:
    SW MS, USA
    I examined explorer.exe and noticed that it was modified 10-3. Earlier yesterday evening I had applied some Vista updates Nick had posted in the software forum so one of them must have modifed the file. The new explorer.exe may resemble the trojan mentioned so all Prevx needs to do is update it's sigs.
     
  19. midway40

    midway40 Registered Member

    Joined:
    Jul 24, 2006
    Posts:
    1,257
    Location:
    SW MS, USA
    In my case it was more of double-checking and just plain curiosity. I try some of these type scanners every now and then just to see if Norton is doing it's job (and it is I am pleased to report :) ).

    If anything I just helped Prevx identify a FP.
     
  20. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,065
    nothing found here and the scan was very fast.
    when i clicked on secuirty infomation it opened up a page in IE7 and correctly identifyed i have kis7.0 119 installed.
    lodore
     
  21. EraserHW

    EraserHW Malware Expert

    Joined:
    Oct 19, 2005
    Posts:
    588
    Location:
    Italy
    midway40, please can you send me log created by Prevx CSI at the e-mail address I sent you by pm?

    Thanks
     
  22. midway40

    midway40 Registered Member

    Joined:
    Jul 24, 2006
    Posts:
    1,257
    Location:
    SW MS, USA
    Siete benvenuti :) You should have it soon.
     
  23. EraserHW

    EraserHW Malware Expert

    Joined:
    Oct 19, 2005
    Posts:
    588
    Location:
    Italy
    replied ;)
     
  24. midway40

    midway40 Registered Member

    Joined:
    Jul 24, 2006
    Posts:
    1,257
    Location:
    SW MS, USA
    Now this is service! Just a little more than an hour ago PrevxCSI still showed the Explorer FP when I rescanned to get the log Marco wanted. Then a while ago I saw where lodore mentioned a report I must have missed seeing so I ran it again (btw it correctly identified NIS Version 15.0.0.60) only to be surprised by a clean scan this time :D

    A big :thumb: for Marco and the folks at Prevx :)
     

    Attached Files:

  25. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    ROFL :p
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.