Introducing, The New Prevx Edge.

Discussion in 'Prevx Releases' started by trjam, Nov 13, 2008.

Thread Status:
Not open for further replies.
  1. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We would rather not release an incomplete product, so, it looks like we're going to have to wait until every one of the components is translated/supports x64's architecture. We will begin working on it soon, but, as you may have seen from other antivirus products, it does require a significant amount of extra work, for a relatively small userbase still.
     
  2. webbit

    webbit Registered Member

    Joined:
    Nov 2, 2008
    Posts:
    223
    right this is my set up now, im going to run prevx edge and drive sentry, should be no conflicts and as of running for 1 hours all is good
     
  3. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    what is the AlfaFF.dll file located in system32?

    is it a part of Prevx EDGE?

    if not, can someone be kind enough to tell me.
     
  4. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Hello,
    This is not a part of Edge - the only components of Edge are:

    C:\windows\system32\drivers\pxark.sys
    C:\program files\prevx\prevx.exe
    and a handful of small files in the All Users\Application Data folder.

    From a quick search, AlfaFF.dll might be malicious. If you want us to take a look at it, please forward it on to me and I'll analyze it for you.
     
  5. rolarocka

    rolarocka Guest

    Upload it to virustotal.
     
  6. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    yes, i would like you to check it out please.

    if possible, id like to know what software i have installed that has placed it there.
     
  7. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    That's generally a relatively difficult thing to do as there is no "papertrail" of installed files within the system.

    Could you email the file in question to me (I believe you still have my email address :))
     
  8. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    of course, the file is sent.
     
  9. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    0/36

    malwarebytes detected nothing either, still need to know what it is though.

    :rolleyes:
     
  10. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I've finished my analysis and the file is not malicious (Virustotal agrees as well - 0/36). The file is a component which communicates with a minifilter driver made by the company "Alfa Corporation".

    Minifilters are the new, Microsoft-recommended way for a file system developer to design their software and are being used quite frequently now. The architecture is designed so that multiple minifilters can be loaded simultaneously, however, if one of them has a bug, it is possible that there will be multiple program failures.

    You may want to contact both Alfa Corporation and Dr. Web to see what is conflicting between the two.

    Hope that helps :)
     
  11. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    thanks, drweb are already analyzing it aswell :)


    the file sucks-ass, it cant cope with drwebs new self protection and gives me a BSOD every 5-10 minutes.
     
  12. rolarocka

    rolarocka Guest

    Running both NIS2009 and PrevxEdge here without problems. Both are super light :thumb:
     
  13. n8chavez

    n8chavez Registered Member

    Joined:
    Jul 19, 2003
    Posts:
    3,715
    Location:
    Location Unknown
    I think I found a couple issue. I found what I can only hope is a false positive. The new Drivesnap (DriveSnapshot frontend) that markymoo released today is flagged as infected. It hink this is in error. But ehen I click on the "Contact Support" button in Edge to try and submit the file but it crashed.
     
  14. Rivalen

    Rivalen Registered Member

    Joined:
    Oct 18, 2005
    Posts:
    413
    Uninstalled verything but Antivir - put Edge back on - smooth and fast. All Heuristics on highest.
    Next move - add DW in a couple of days.
    Think conflict was with ThreatFire - hope it wasnt with DW.

    Best Regards
     
  15. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    I thought I read the self protection was fixed? when I enable this option it shuts its self down.Minus this option No problems.
     
  16. Rivalen

    Rivalen Registered Member

    Joined:
    Oct 18, 2005
    Posts:
    413
    Same here.
     
  17. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    What version are you using? Can you download the newest (v3.0.0.180) from the website to make sure that you're using the fixed version?
     
  18. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Hello,
    Can you send me a scan log or the entry of the false positive? I'll get that sorted.

    Also, we've seen the Contact Support issue intermittently and are looking for a way to fix it. We have another update scheduled for tomorrow which should address this and other issues.
     
  19. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    This version I reinstalled it from scratch.Ok I enabled self protection again so far its holding its own.If if goes down again I will run with it disabled and see what happens.
     
    Last edited: Nov 20, 2008
  20. Nunes

    Nunes Registered Member

    Joined:
    Apr 4, 2006
    Posts:
    103
    Location:
    AMADORA,Portugal
    How can we see what version are we using?
     
  21. mhallerman

    mhallerman Registered Member

    Joined:
    Nov 11, 2005
    Posts:
    180
    It's in the lower right-hand corner....

    Best,
    Mark.
     
  22. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Ok great, thank you for your information. We are still investigating a subtle issue with self protection but it should be overall fixed in v3.0.0.180.
     
  23. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Have been running Edge and DefenseWall together since beta testing started - nooooo problems :thumb: :)
    Very light, conflict free.
     
  24. GES/POR

    GES/POR Registered Member

    Joined:
    Nov 26, 2006
    Posts:
    1,490
    Location:
    Armacham
    I really hope so maitey - 1 month is worth waiting upon
     
  25. mhallerman

    mhallerman Registered Member

    Joined:
    Nov 11, 2005
    Posts:
    180
    (Well, I wanted to like it)

    Installed it and ran it for an hour or so, did scans etc. Found 2 files, one I know to be a FP and another I've used for years and never came up on any scans, but to be safe I let it clean that one.

    Then Edge automatically rebooted (which I think should be addressed, it should tell you to reboot but then give you the option to do it then or defer it until you want to - I needed to close some programs and it didn't allow for the time to do that.)

    When system rebooted it bluescreened with a "Unmountable_Boot_volume" error - thank the Lord I imaged my system right before installing Edge - after restoring from that image everything is back to normal.

    Of course, no other software was installed and all the usual checks were done - and while you can never be 100% sure, I really, really believe it was Edge.

    Dissapointed.
    Mark.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.