Prevx RC 3.0.4.183

Discussion in 'Prevx Betas' started by PrevxHelp, Sep 4, 2009.

Thread Status:
Not open for further replies.
  1. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    The right click scanner doesn't take into account the possibility for the file being registered in the registry or embedded in another critical process (as it is just a quick check on the individual file(s)) which is why we require a rescan after a detection in the right click scanner.

    It isn't a perfect situation for usability but it does improve the consistency and reliability of the cleanup process by requiring a rescan in some cases.
     
  2. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    Green tab coming up on both here, Joe. I tried it out on a couple of banking sites that I use and no issues there either.
     
  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Great, thank you! :)
     
  4. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    It's fine with me thanks for the explanation.
     
    Last edited: Sep 5, 2009
  5. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    I might add that the only other security apps I have active at the present besides the Beta are Defensewall and Returnil. No conflicts to report with this setup so far. Last nite I had Avira Premium and SAS Pro active with it and wasn't running into any issues.

    Now Joe, what would make you think that us Wilderites would have any different set ups than 99% of the rest of the web community? :p
     
  6. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Have now installed DefenseWall and working OK on the citicards link you gave, browser tab goes green in both FF and IE7 - however, I notice that with any secure site while the Prevx browser tab is green and I am on the site concerned the top blue bar on the browser screen shows (DefenseWall Status: Untrusted) but when I exit the site the (DefenseWall Status: Untrusted) disappears although the DW icon in the system tray shows 1 untrusted process running which is FF. So although the DW status disappears off the top bar it appears that it is in fact still running FF untrusted :doubt:
    Same situation with IE.
     
  7. s4u

    s4u Registered Member

    Joined:
    Oct 24, 2007
    Posts:
    441
    Strangely enough this build just detects a malware sample the regular version did not detect
     
  8. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    There is a new detection/protection engine in v3.0.4.183 which will improve both components. If you have any doubts in the detection (i.e. if it may be a FP), feel free to send it over to report@prevxresearch.com and we will analyze it there and report back :)
     
  9. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    After closing the window, could you see if the process still exists within Task Manager? It is possible that the method DefenseWall is using to look into the process is blocked by Prevx which could be where the issues are stemming from.
     
  10. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    Confirmed here too. Never noticed it the first time I checked the sites. Good catch. Browsers still showing up as untrusted in Defensewall tho. Just no status posted at the top of the browsers.
     
  11. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    Just did another test with it. Downloaded a couple files and they were untrusted so Defensewall is working, just the banner at the top of the browser isn't indicating it.

    Here's what process monitor is showing Joe.

    View attachment Processes.TXT
     
  12. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    That looks like Firefox is freezing/hung in the background - was the instance of Firefox actually doing anything at that point or was this after it was "closed"?
     
  13. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    No firefox was working normally.

    BTW check your PM's.
     
  14. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Same findings as Threedog Joe.
    Both FF and DW seem to working OK except for the status issue at the top of the browser.
     
  15. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    I've done some testing with the Defensewall issue. After looking at the Defensewall logs I see it as the untrusted browser trying to manipulate the trusted Prevx. I tried excluding it but it wouldn't work. Ilya should be able to supply a fix once Prevx gets done tweaking. Browser is running as untrusted and anything downloaded is inheriting the "Untrusted" status. It's just not showing up in the title bar that the browser is running as untrusted. Other than that small niggle they have been getting along great.
     
  16. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I have seen a some postings regarding Prevx/DefenseWall combination. You will see from my screenies posted here - https://www.wilderssecurity.com/showpost.php?p=1536701&postcount=91 that I am using DefenseWall.

    I can that say that I have not see any issues with the combination.

    Also, I have had no issues with CPU usage in Opera 10(Alpha). I will be installing Prevx into another snapshot later today which has the final release of Opera 10 that came came out a few days ago.


    See screenshot showing (Defensewall: Untrusted) status, which is showing as it should. :)
     

    Attached Files:

  17. sded

    sded Registered Member

    Joined:
    Jun 4, 2004
    Posts:
    512
    Location:
    San Diego CA
    Prevx stopped detecting anything again, at least notpad.exe and badpx5.rar, even with fresh install of 3.0.4.183. Sent files in C:/Program Data/PrevxCSI as requested. But THE FIX DOES NOT WORK RELIABLY!!!
     
    Last edited: Sep 5, 2009
  18. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Replied by PM with a request for remote support to help diagnose the root of the problem.
     
  19. Defenestration

    Defenestration Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    1,108
  20. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Hi Defenestration,

    I was wondering for myself why would you not let it install into the default folder?

    TH
     
  21. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    Tarnak, try going to a site that's protected, or you could just click the add protection on the prevx bar for this site and then restart your browser, go to a protected site, then go to an unprotected site and see if the Defensewall banner is still there and let us know.

    Thanks
     
  22. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Hi Threedog

    I don't see any problem.....perhaps the following screenshots will make things clearer.:)
     

    Attached Files:

  23. Threedog

    Threedog Registered Member

    Joined:
    Mar 20, 2005
    Posts:
    1,125
    Location:
    Nova Scotia, Canada
    Maybe where you are using Opera the processess are manipulated different. I don't see in the screenies where Defensewall is listing it as untrusted tho.
     
  24. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Now, would I lie to you...:D

    Edit: Sorry, I forgot the screenie
     
  25. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Sorry, again, but the edit didn't work.....here is the screenie ;) Fingers crossed!;)

    Edit: I don't know what is going, but now I can't post a screenshot. I will try to post one in testing.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.