Introducing, The New Prevx Edge.

Discussion in 'Prevx Releases' started by trjam, Nov 13, 2008.

Thread Status:
Not open for further replies.
  1. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    Px_Edge.png

    When given those Alert boxes, how can we do to NOT clean them (test files) up?

    I don't see any other choice than to push this "Cleanup Now" button. It seems to me that this box should also give us at least an alternative...
     
  2. doktornotor

    doktornotor Registered Member

    Joined:
    Jul 19, 2008
    Posts:
    2,047
    Shrug... Default install with settings untouched... In fact, this was detected on the initial configuration scan, so no chance whatsoever to chance the settings. :D
     

    Attached Files:

  3. PrevxWebDesigner

    PrevxWebDesigner Former Prevx Moderator

    Joined:
    Nov 13, 2008
    Posts:
    89
    In the small window - click the "X" in the top right. Then in the main window you should be able to click "Back to Status Screen" if you don't want to cleanup :)
     
  4. simmikie

    simmikie Registered Member

    Joined:
    Nov 11, 2006
    Posts:
    321
    are there check boxes? i don't recall off-hand, and myself am experiencing a disappearing GUI.
     
  5. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    By any chance, were you in the process of downloading the Norton Removal Tool when the scan was running? This is Edge's rootkit scanner generating a false positive, definitely something worth looking into.

    EDIT: Disregard the rest of this message - I sorted it :) It won't happen again - thanks for the submission!
     
    Last edited: Nov 16, 2008
  6. simmikie

    simmikie Registered Member

    Joined:
    Nov 11, 2006
    Posts:
    321
    for that obvious of an FP, i would have guessed maxed out heuristics. sorry.
     
  7. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I got your email and I'm not really sure what would have caused that to be honest :D If you try rebooting and can get it again, that would be excellent.

    There are a couple different malware alert screens, and if it doesn't have checkboxes on the screen, then clicking Cleanup Now will not immediately clean it up. (You are always given the option to deselect files)
     
  8. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We are in the process of adding this feature and will have it implemented in the next release :)
     
  9. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I'll contact you by PM to get this sorted :)
     
  10. doktornotor

    doktornotor Registered Member

    Joined:
    Jul 19, 2008
    Posts:
    2,047
    No, not downloading at all... the file has been sitting there for a couple of days already. Anyway, the only relevant line in the log is:

    Code:
    [R<R00000098>] C:\Install\Security\Norton Removal Tool\Norton_Removal_Tool.exe	[PX5: 2A7925670038A6621085252C4F0F5C007832CB35]	Malware Group: Caution.HiddenFile
    
    Also, note that the location is incorrect in the log for whatever reason. It's D:\Install\... in fact, not C:\
     
  11. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I'm going to be analyzing your remaining samples shortly, just to check that they are malicious, and then I'll add them into the DB :)
     
  12. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    This definitely looks like a false positive - right clicking on Report FP will send it to the research team, but if you want it fixed immediately, click Tools and Settings > Save Scan Results and then send me a scan log - I'll get it corrected right away :)
     
  13. ruinebabine

    ruinebabine Registered Member

    Joined:
    Aug 6, 2007
    Posts:
    1,096
    Location:
    QC
    Thanks for your reply, but I already know this way of doing it. :) I was just suggesting that it could might be a good idea to add an alternative choice for the user, other than by closing/ignoring those alert boxes.
     
  14. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    The full scan is generally an unnecessary feature to use when realtime protection is enabled. We highly recommend just using the Deep Scan as it is nearly as thorough and takes far shorter to complete.
     
  15. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    A CSI cleanup license will currently not work for Edge, as it is a cleanup-only license. I don't believe we have an upgrade from CSI Cleanup > Edge yet, and if you do want to install Edge, you have to first uninstall CSI or put an Edge license into CSI (it will convert it then as well).
     
  16. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Yes, that's true. A "cancel" button on there would be useful :) I'll add it to the infamous ToDo List :D
     
  17. simmikie

    simmikie Registered Member

    Joined:
    Nov 11, 2006
    Posts:
    321
    hey Joe,

    a reboot brought the GUI back. strange, but stuff happens. back to running keygens :argh:


    Mike
     
  18. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    good ;)

    i think Marco might be dealing with it though.

    again, good :)

    ive noticed here and there, that during new scans, my Prevx picks up on a couple more infected files every few hours when i re-check it. :thumb:
     
  19. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    For those who are interested,

    I purchased Prevx Edge(PE) 3.0 yesterday and tested it against the same 77 malware samples that I tested against Primary Response SafeConnect(PRSC) 3.5 beta. FYI, this 77 sample test set consists of a good variety of new and old malware(keyloggers, rootkits, trojans, viruses and worms);(ex. - stealth/obfuscated, ransomware, exploit, password-stealers/banking, botnet, SSDT kernel unhookers, MBR/low-level disk, system-modifying, security program disabling, rogue anti-virus/malware, file infector, autorun, downloader, etc...)

    Under Vista 32 SP1 with UAC disabled and hardware DEP(OptOut) enabled, PE with default heuristic settings detected 62 out of 77 samples for a detection rate of over 80.5%. In contrast, PRSC 3.5 beta detected only 25 out of 77 samples for a detection rate of over 32.4%.

    In conclusion, despite the impressive results of PE, it is my opinion that one still needs to run it alongside a sandbox and/or limited-user account(LUA) + Software Restriction Policy(SRP) for comprehensive protection.


    Peace & Gratitude,

    CogitoErgoSum
     
  20. EraserHW

    EraserHW Malware Expert

    Joined:
    Oct 19, 2005
    Posts:
    588
    Location:
    Italy
    Hello :)

    Thank you for your test. Could you test even higher heuristic settings? And, moreover, would you be able to share undetected samples with us so that we can better tune our heuristic engine?

    Thank you :)
     
  21. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    Hello Prevx,

    Does Prevx Edge(PE) protect against buffer-overflows such as Prevx 2.0 does? Does PE have outbound network control such as Prevx 2.0 has? Until proven otherwise, I assume that it does not have the latter. Thanks in advance.


    Peace & Gratitude,

    CogitoErgoSum
     
  22. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    That is automated research for you ;) I think Marco will be adding the rest in shortly if they don't all get automatically blocked by behavior in the meantime :D
     
  23. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We detect threats employing buffer overflow exploits, but we do not have any network control. Network control duplicates functionality seen in free firewalls which we are compatible to run against, so, we recommend that if the user wants monitor/control outbound network access that they use one of those 3rd party firewalls.

    Thank you for your test as well :) If you get a chance, send those samples over to Marco or myself and we'll get rules added into the database to block them :)
     
  24. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    That's not too shabby for default settings tho. Try it again at Max/Med/Med on the sliders and see what happens if you have the time, Cognito. Thats what settings I have been using all along.
     
  25. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    Hello EraserHW,

    Yes, I will retest the missed samples with higher heuristic settings and would be more than willing to share the missed samples with Prevx. Where specifically do I need to send these samples? Thanks in advance.


    Peace & Gratitude,

    CogitoErgoSum
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.