Introducing, The New Prevx Edge.

Discussion in 'Prevx Releases' started by trjam, Nov 13, 2008.

Thread Status:
Not open for further replies.
  1. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Just curious... if this is an automatic process, why is it detected in the first place? Is it because the database looks at the behavior analyzed and when it's deemed completely legit and safe it gets whitelisted? Are you often personally involved in the process at all? :D
     
  2. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    Prevx still detects temp files from the new AntiVir beta - I don't have the log now, but has this been reported?
     
  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    No one actually clicked anything to determine the file - the file changed from being "new/suspicious" to "good" after enough data was gathered :) (And note: the new change we've rolled out over the last day or so will prevent almost all of these FPs from happening in the future ;))
     
  4. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I'm not aware of it - could you make a log so I can see why they're being detected?
     
  5. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,692
    Location:
    South Wales, UK
    That is how most if us are finding using the Edge...don't know its there and SUPERLATIVE support! :D
     
  6. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    The log does have some of the entries after all - it detects them as Community.OuterEdge. I'll send the log file now so I don't forget - what post had your e-mail address to send?
     
  7. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I PM'd you my email address - note that "Community.OuterEdge" in the log does not necessarily mean that Edge blocked/detected the files, just that they have that characteristic.
     
  8. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    It did block before, though, something about the age/spread again.
     
  9. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    I sent you the log.
     
  10. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Aww... this still makes me scratch my head (or not actually - why screw with my hair, I'm just thinking, LOL! :D)... How can it determine that if mostly good things are being done, but suspicious things like accessing or modifying in sensitive areas is happening, a file or similar is indeed safe - just as an example? :doubt:

    EDIT: Hmm... this is interesting... I downloaded the first crack for Norton I saw on a torrent site to test, opened it and here's the result: Prevx scans the file first for a while, returns no alert. Then TF pops-up (you're next! :D) with a VERY HIGH rating. It's trying to copy an executable file to a sensitive area. I open the details and take a screenshot of the windows - this is refering to my "Not completely confirmed for me yet" post. :) :p

    I obviously chose to kill and quarantine it. Take a look at it and see what you think. ;)
     

    Attached Files:

  11. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    No protection is 100% - whether this file is actually malicious or not is yet to be determined, all that Threatfire is warning on is copying a file into the system directory... which isn't anything too out of the ordinary. If you want, send me the file and I'll analyze it to see if it really is malicious or not :)
     
  12. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    it is a crack so maybe it is malicius:D
     
  13. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Symantec would certainly think so, but seeing the file would be more helpful :D
     
  14. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    yeap;) agree ofcourse
     
  15. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    It sure is common Symantec detects all sorts of cracks and keygens - testing it has shown that, but this is TF detecting through behavior, though I ofc get your point. :) Should I send it to you by e-mail?
     
  16. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Yes definitely :)
     
  17. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
  18. Dr33

    Dr33 Registered Member

    Joined:
    Jan 23, 2009
    Posts:
    103
    I just bought :
    5 PC 3 years Prevx Edge
    and when i activate it it shows Expiration 365 Days only o_O
    o_O
    is it a bug or what do i have to do o_O
    thanks
     
  19. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Could you try running a scan and see if it corrects it to your 3 years duration? If it doesn't, let me know and I'll see what's going on :)
     
  20. Dr33

    Dr33 Registered Member

    Joined:
    Jan 23, 2009
    Posts:
    103
    That was Quick and it worked lol :eek:
    Thanks!
     
  21. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I checked out the file and it is indeed malicious, but the reason why Edge didn't grab it is because you were the first user to see this variant and Threatfire blocked it before Edge had a chance to analyze the behavior at runtime.

    There appears to be two other variants of this infection (which are a ~90% match to this file) - both of which are found as "Malware Dropper" already but they were released back in February. This seems like a relatively new infection - I've marked it "bad" for now and forwarded it to the research team to see if they have any thoughts on updating a rule for it :)
     
  22. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    So, you're saying that Prevx would detect it after that through its Heuristics, which are set to default here; Medium. Did you get that result yourself?
     
  23. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Yes, I believe it would - I didn't actually test it as I'm a bit short on virtual machines at the moment but based on the way that it drops files, it does look like it would be found heuristically.
     
  24. Ed_H

    Ed_H Registered Member

    Joined:
    Nov 10, 2004
    Posts:
    662
    Location:
    Chicago, IL
    Avira 9 Beta
     
  25. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    cool,thanks may solve my problem here too:thumb:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice