Future Changes to Prevx

Discussion in 'Prevx Releases' started by Triple Helix, Jun 13, 2009.

Thread Status:
Not open for further replies.
  1. Habakuck

    Habakuck Registered Member

    Joined:
    May 24, 2009
    Posts:
    544
    I thought about all this and have to say that a HIPS is not what PrevX3 want to be or should be. It is fantastically light and clear to use and needs to remain like that.

    So i thought about how to protect the user against threats which are absolutely unknown and came to following conclusion:

    What about a holding stack for unknown executables:
    Start of an unknown Programm -> Prevx blocks the action and querys whether the programm should be blocked till the answer of the cloud is received or not.
    Implementing that as a function which is unchecked by default won't disturb the normal user while pros will get maximum protection.
    If you are sure that the programm you have executed is trustable you dont have to wait the clouds answer. If you are not sure you can hold the action till the cloud is sure.
     
    Last edited: Jun 16, 2009
  2. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Sadly this is kinda where the FPs reported come in and PX's reliability on Age/Spread heuristics (which I can see a point in, but it screws it for some people indeed to be honest). Sure, the current option to automatically remove "found threats" would be vastly improved with this - great suggestion! - but the problem which is "for all AVs" (I've said this before - products that find FPs that cause problems for me goes off my system. NOD... Don't forget that I dropped ThreatFire - and you know how much I'm used to go on about it, partly how I prefer its thinking more to the Age/Spread criteria) creates a problem.
     
  3. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Maybe you can Add HIPS/behaviour blocker as an addon or make a separate program with both and sell it as a choice like when you had CSI & Edge! I just think it would make it a more complete solution.

    TH
     
    Last edited: Jun 30, 2009
  4. Habakuck

    Habakuck Registered Member

    Joined:
    May 24, 2009
    Posts:
    544
    Will there be a possibility for the user to check why a file is blocked to verify a "heuristic", "age-spread" or "flaged bad by the server" detection? A Feature like this added into the "Found -> Block" PoPup would be very good!
     
  5. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    This is built in already - the block popup will say "Age/Spread Criteria Violation Detected" for an Age/Spread detection, "Edge Heuristics identified a threat in the file:" if found by the "Advanced Heuristics" slider-bar detection (note - this is only a small piece of our heuristics :)) and it will say a more descriptive name if it finds a threat using the database (i.e. Malicious Software/Fraudulent Security Program/etc.)
     
  6. Habakuck

    Habakuck Registered Member

    Joined:
    May 24, 2009
    Posts:
    544
    :D Wow. Cool. :) Hehe. Thats great. I think i never got an age spread detection so i thought it is not built in.
    Good to know! :D
     
  7. scmp

    scmp Registered Member

    Joined:
    Jun 14, 2009
    Posts:
    3
    Hello,

    This month I had 2 of my clients purchase PrevX licenses (140 licenses total). I did try renaming the installer as suggested and it does a silent install but it does not use the license key - I would still have to go to each client and enter the license - luckily I can leave their internal IT staff to deal with it :)
    Any advice?

    Thank you
     
  8. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Hello,
    We have had some reports of this functionality not working properly and we're working on correcting the issue. However, for now we have a workaround which may be viable for you.

    First: create a registry key named PxLic under HKEY_CURRENT_USER\Software\ and then create a REG_SZ value named CSILic under this key with data of the license key to be applied.

    Then, run the license-key-named installer and the installation will take place silently except for one initial prompt which shows a message to the user saying that the license is accepted. Besides this initial prompt, there are no other dialogs to be answered and the prompt will not show on subsequent uses.

    Please let us know if you have any questions with this and we will be correcting the license key automatic installation behavior in the next version.
     
  9. Phantasm

    Phantasm Registered Member

    Joined:
    Jul 29, 2009
    Posts:
    87
    Prevx needs a 'Last updated' kind of thing

    Example: Last Update: 1 minute ago
     
  10. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Prevx is constantly kept up to date so we don't have this. However, our volume of updates per day a couple years ago (the last figures I'm aware of) was about 250,000 updates per day, which equates to around 173 per minute so I think it would be safe to say that "Last Update:" will always be "Less than 1 second ago" :)
     
  11. Phantasm

    Phantasm Registered Member

    Joined:
    Jul 29, 2009
    Posts:
    87
    Any chance of a Prevx Bootable .iso for CD/DVD?
     
  12. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We currently don't have a need for a bootable ISO but we have it in the books if we do end up running into a need for it.
     
  13. Phantasm

    Phantasm Registered Member

    Joined:
    Jul 29, 2009
    Posts:
    87
    Seriously make the malware uploading much easier look at this for example 2.ly/2
    see how simple it is?
     
  14. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
  15. Phantasm

    Phantasm Registered Member

    Joined:
    Jul 29, 2009
    Posts:
    87
    Way too much :p Im not signing in to my e-mail just to send something, i guess it's just me so nvm.
     
  16. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    You can also just send a message here with an entry from a scan log and we can investigate it :) Also, uploading it to VirusTotal will get it sent to us (albeit with some thousand other files every day) but feel free to PM a link to what is missed from VT and we will investigate.

    At the current volumes of missed samples that we receive to our report@prevxresearch.com email address, we do not see it necessary to expand to a dedicated system. We already gather the necessary information automatically. If a threat was to start spreading quickly, we would latch onto it immediately and if a threat is extremely low volume, we still have the details on it so we can just as easily add protection.
     
  17. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Hi Joe,

    Possibility of an easier way to empty Quarantine in the Undo Cleanup window?

    TH
     
  18. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    and dont forget Joe, the actual number of processes being protected.
     
  19. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    This is a big component on the roadmap in v4 - it won't make it into 3.5 yet but we're developing a nice techie friendly tool for v4 :)
     
  20. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    :thumb: Added to the list :)
     
  21. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    you know Joe, in 3 months and 2 days, Edge will be 1 year old which is also the date of my 16th birthday. Who would have ever thunk it that you would be here, with the rest of the Prevx team, soaking the sun up at Wilders less then a year later..;)


    well, maybe one visionary.:cool:
     
  22. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    :D Wilders is definitely a great place to be - always sunny and warm by the beach (the crab, seagull, and dog seem to be there more than all of us though, but I guess one can never get enough Wilders sun :))
     
  23. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    And as a clarification, trjam, you aren't 16 years old (nice try :D) however, you're correct that your 16th birthday shares the date of your upcoming one ;)
     
  24. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    I actually believe him when he says he is - my sensors says so. :D
     
  25. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    That was a typo, he pressed the 1 before the 6 :D
    Perhaps he's like me, only 16 in mind and spirit - that's all that matters ;)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.