I think that Prevx has too many FPs.

Discussion in 'other anti-malware software' started by bonedriven, May 4, 2009.

Thread Status:
Not open for further replies.
  1. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Can you send me a link to these files?
     
  2. softtouch

    softtouch Registered Member

    Joined:
    Jan 31, 2006
    Posts:
    415
    I just created again a new exe file, uncompressed, no code at all added, just an empty delphi 2007 project,compiled as exe.

    bir.exe - get flagged as adware
    abc.exe - binary identical, just another filename, not flagged.

    abc.exe is bir.exe, just renamed...

    http://www.delphifreeware.com/downloads/avtest.zip
     
  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We've corrected this FP - could you try making another program and see if that is still detected?
     
  4. softtouch

    softtouch Registered Member

    Joined:
    Jan 31, 2006
    Posts:
    415
    I did create some more exe, and they are not detected anymore.
    I also created some exe with Delphi 2009, also not detected.
    I then molebox them, and it also is fine now.

    What was the cause why it was always detected? I am quiet interested to know from the programmers perspective.

    But now, Borland C++ 2009 exe are detected...

    Here is an empty, compiled c++ project:

    http://www.delphifreeware.com/downloads/testc.zip
     
    Last edited: May 7, 2009
  5. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We had a very old rule still in place from the Prevx1 days which was a bit too touchy :) The Borland issue should now be fixed as well :)
     
  6. Necropsie

    Necropsie Registered Member

    Joined:
    May 6, 2009
    Posts:
    31
    A little update.
    Seems like Prevx does not like Internet Download Manager. Seconds ago, it's "threat detection" window opened and tagged ALL of the files inside Internet Download Manager folder as medium risk malware.
    I became paranoid and scanned my whole system with a2squared, SAS and MBAM. Fresh and updated installs. Nothing.
    Really weird..

    Also, sent the updated log file.
     
    Last edited: May 7, 2009
  7. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    o_O It might be doing something strange with the files, could you send me another scan log with these files?
     
  8. softtouch

    softtouch Registered Member

    Joined:
    Jan 31, 2006
    Posts:
    415
    Great, thanks a lot. Will check tomorrow. Its almost 1am here.
     
  9. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    The issue with Internet Download Manager should be fixed now also :)
     
  10. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    566
    Prevx says "combofix.exe" and "killbox.exe" in Hiren's bootable cd are malwares.

    Is she right?
     
  11. webster

    webster Registered Member

    Joined:
    Feb 23, 2004
    Posts:
    285
    Location:
    Denmark
    No, but Combofix is detected by many other applications, because it contains some malware related files.
     
  12. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Exactly - many apps like this are sadly abused by malware frequently. Can you send me a scan log? I'll see if I can get them whitelisted but it is a delicate situation to try and handle.

    There are many applications like this which are legitimate but misused: mIRC, ServU, a number of programs by SysInternals, radmin, WindowHider, etc. the list is extensive :doubt:
     
  13. bonedriven

    bonedriven Registered Member

    Joined:
    Jan 14, 2007
    Posts:
    566
    It's just those two files in an original hiren's bootable cd in my usb drive.

    B] k:\hbcd\wintools\combofix.exe [PX5: 0ECE4AA2C82DA010C2BB2C456E748D00006C4640] Malware Group: Medium Risk Malware
    [BP] k:\hbcd\wintools\killbox.exe [PX5: CACA42C0006886C56AC901BFA1672E005A17DA21] Malware Group: Medium Risk Malware

    IMHO,for a user there are simply two sides. Malicious or Not. So I think you need to whitelist those two?
     
  14. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I have marked them good, however, there isn't always a 100% "good or bad" for many programs but these are farther on the good side than the bad side :)
     
  15. lordpake

    lordpake Registered Member

    Joined:
    Aug 7, 2004
    Posts:
    563
    Location:
    Helsinki ~ European Union
    Not quite :) some companies use PUA or PUP (pot. unwanted app/program) designation for software in the grey area. This category would include for example mIRC, process killers, pw sniffers, port scanners etc. that can be used either for good or bad.

    This is used to alert users to presence of such apps. Good or bad would depend on if the user actually downloaded/launched such app himself.
    Unfortunately IMHO this classification is needed. Fortunately those regular users rarely use stuff that'd trigger such alerts. We who use irc clients etc. should be able to understand the situation.
     
    Last edited: May 10, 2009
  16. tipstir

    tipstir Registered Member

    Joined:
    Jun 9, 2008
    Posts:
    830
    Location:
    SFL, USA
    I ran the PrevX Business on a laptop. I had install software that I know has two files in it. But I had thought PrevX would detect the files as it monitors the files on the system. I even ran the file and nothing from PrevX. I had to do a full scan with PrevX before it detected one has a medium Worm and the other was Cloaked-Malware. Both were easy to spot in the W\system32 folder.. PrevX Business did clean them differently this time around. Removed the cloaked one first then rebooted the system. The second one was gone also. I ran GMER and SmithFraudfix to see afterward to see if anything is still there. None!
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.