Introducing, The New Prevx Edge.

Discussion in 'Prevx Releases' started by trjam, Nov 13, 2008.

Thread Status:
Not open for further replies.
  1. galileo

    galileo Registered Member

    Joined:
    Dec 10, 2005
    Posts:
    72
    @PrevxHelp

    I tend to agree with the above comment as well. A "View Threats" button would intuitively lead one to think that it would present a "review" or a "log" of what threats had been found as of that moment....i.e. before another scan. It would seem - IMHO - that given that a "Scan" button already exists, one would assume that there is/was a difference between "Scan" and "View Threats". Initiating a scan upon clicking the "View Threats" is not what one would expect...albeit from my limited perspective...:argh:

    galileo
     
  2. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    The View Threats button "should" lead to a screen which lists the threats. Could you let me know what build you're using so I can try and track down what might be wrong?
     
  3. galileo

    galileo Registered Member

    Joined:
    Dec 10, 2005
    Posts:
    72
    This behavior was occurring under the 3.0.1.50 build (sorry, I should have noted that in my post) - I have not had any threat issues show up as yet under the 52 or 53 builds.

    galileo
     
  4. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Damn Joe, thread need a bump.:cautious:
     
  5. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Well, I was waiting to see if anyone would complain about the newest build, 3.0.1.55, with the new, less washed-out GUI :D
     
  6. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    well then, that is a good thing. Also reports of FPs are down and that is good. Edge burped, it was time.:thumb:
     
  7. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Is the right click scanning working now with the new beta 3.0.1.55?
    With 3.0.1.52 it was not.
    Also I assume the FP's associated with Rollback Rx are fixed o_O
     
  8. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Yes and yes :)
     
  9. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,784
    Thanks :thumb:
     
  10. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Are the GUI changes there? :D
     
  11. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Yes :) The odd color is now toned down and it looks better all around IMO :)
     
  12. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    Cool, it looks awesome - tell the creator that. :D Only thing I don't get is the thing on the right, if you know what I mean..? Is that also a part of it, which just goes behind the main-content of Prevx?
     
  13. Retadpuss

    Retadpuss Suspended Member

    Joined:
    Apr 4, 2009
    Posts:
    226
    Looks much better now. Running perfectly on my system, no FPs in ages.
     
  14. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    Chit, I just got infected. I went to the F-Secure blog and visited the site they showed. Yeah it lead to porno but I ran a scan afterwards and it showed nothing. Now when I try to go somewhere, or actually this is the 3rd time I have tried to post this, I get this

    http://billingpayment.net/pp/?id=226

    This sucks as F-Secure is what is loaded. Damn, I cant even fathom this.:thumbd:
     
  15. Baldrick

    Baldrick Registered Member

    Joined:
    May 11, 2002
    Posts:
    2,675
    Location:
    South Wales, UK
    +1 :thumb:

    .55 sitting here quietly minding the shop...as they say. :D No new or old FPs as far as I can make out so far, even when tying to force them. :D

    Can't wait for the beta with the new functionality the promise of which Joe has been torturing us with for the last few week. :doubt: :D
     
  16. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    The large set of new functionality is still a few weeks away :doubt: The Prevx 3.0 release (of 3.0.1.55) is scheduled for tomorrow then we're going to continue developing through the new features :)

    They're getting close, but we don't want to release anything unfinished :)
     
  17. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    The right blob is a continuation of the curve behind the main content which starts at the bottom and continues up, reaching a maximum mid-way through the Security Status area and falls/shrinks as it reaches the right side.

    I hope that helps, trying to describe partially obscured non-regular Beizer curves layered behind a rounded rectangle isn't exactly my area of expertise :D
     
  18. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    ok, here is what Edge just found. I can assure you one is the Twitter worm.
     

    Attached Files:

  19. Retadpuss

    Retadpuss Suspended Member

    Joined:
    Apr 4, 2009
    Posts:
    226
    The problem is these rogues change so frequently that AMs find it hard to keep up.

    I recently tested Edge, MBAM, SAS, Avira and F-Secure against 10 rogues - all 10 installed and running on a system and also another test with them being installed whilst one of the AV/Ams was active. SAS only found 2 and removed them, MBAM found four, but destroyed the system trying to remove them, Avira got all of them and removed them all, F-Secure got six amd Edge got them all. Interestingly, Edge would allow some of them to install - and then find them. Other times, edge allowed them to install AND run. In all cases, Edge found them on a system scan and was able to remove them all.

    In every case when Edge missed a rogue installing, Zemana detected it.

    My advice would be:

    1) Always run your browser in a sandbox (I use sandboxie) - If you use Vista, Always use UAC and use protected mode with IE (but Sandboxie is better)

    2) Use a traditional HIPS like Zemana - it does catch things Edge misses.


    If you want to go mad - use Returnil as well!

    Does edge detect anything when you do a on demand scan?

    Try rebooting and then doing a scan with Edge.

    EDIT________________________________________________

    @trjam - I see Edge has the blighter already!
     
  20. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    After running through a cleanup, could you send me a scan log via email? I'll double check that we've cleaned everything up.
     
  21. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    will do
     
  22. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Chances are that in this case, you may have been an early user to see them. We're working on keeping up with the rogues and adding detection for quite a few new ones every day so that could explain why it got past the first line of defense. Also, the rogues have changed their methodology to move away from actually installing malware and are now primarily using social engineering, which is jarringly effective :(

    If you do see any which we don't find, let me or any other Prevx member know and we'll investigate. These rogue AVs unfortunately do require manual analysis in almost all cases but we're working on finding similarities between them (some of them are developed by the same people) to detect them more heuristically.
     
  23. Retadpuss

    Retadpuss Suspended Member

    Joined:
    Apr 4, 2009
    Posts:
    226
    I was stunned to see how many rogues there are - hundreds of them! Also, they change so frequently. One that Edge detected one week was undetected a week later (on install).

    I will probably do another test in a few days and will let you know if any slip by. I will PM you a list of URLs for these rogues as well at some point, so your team can have a look.
     
  24. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Thanks :) It is quite incredible how popular they are... and how good some of them look compared to commercial AVs :p
     
  25. a320ca

    a320ca Registered Member

    Joined:
    Mar 21, 2008
    Posts:
    97
    Location:
    USA
    Joe, 3.0.1.55 looking good here! :D :thumb:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.