PrevX and F-Secure AV 2011

Discussion in 'Prevx Releases' started by whitedragon551, Sep 30, 2010.

Thread Status:
Not open for further replies.
  1. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    F Secure AV 2011 has DeepGuard which is like their heurstics engine. It detects PrevX as a bad file. The false positive has been submitted to F Secure on their end however looking at the DeepGuard logs from F Secure I believe the warnings are being thrown because PrevX is constantly trying to do something to F Secures files.

    Could someone please look into this?

    Im using F Secure AV 2011 and the PrevX SOL facebook version. BTW I already submitted the scan log a few days ago.
     
  2. kasperking

    kasperking Registered Member

    Joined:
    Nov 21, 2008
    Posts:
    406
    hi.........i am currently using f secure and prevx v.206(paid)....and both seem to co-exist quite peacefully that too with prevx on max setting...not sure if your issue has something to do with facebook version of prevx or not
     
  3. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    Do you have F Secures Deep Guard and the Advanced Process Monitoring on?
     
  4. kasperking

    kasperking Registered Member

    Joined:
    Nov 21, 2008
    Posts:
    406
    yup..........
     

    Attached Files:

  5. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    F Secure keeps throwing up prompts for system modification attempts on PrevX SOL end for a ton of different F Secure files.

    Heres just one of them.
     

    Attached Files:

  6. kasperking

    kasperking Registered Member

    Joined:
    Nov 21, 2008
    Posts:
    406
    well you can try excluding f secure files in prevx.......
     

    Attached Files:

  7. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    Tried and PrevX just crashed.
     
  8. kasperking

    kasperking Registered Member

    Joined:
    Nov 21, 2008
    Posts:
    406
    yikes..............:p :p :p

    better let joe aka prevxhelp sort this out out
     
  9. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    After uninstalling PrevX SOL I was able to add the ProgramFiles(x86) F Secure folder. However PrevX still tries to access it and throws up a warning.
     
  10. kasperking

    kasperking Registered Member

    Joined:
    Nov 21, 2008
    Posts:
    406
    well........the usual prevx way in such conflicts is ....
     
  11. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Hmm... not sure what would be going on here as Prevx would certainly not be trying to terminate F-Secure processes. A scan log may help bring some insight into it but as a bit of a random guess, could you try lowering the Prevx self protection to Minimum and rebooting?

    Let me know your results - I'll be having our internal testing team take a closer look at FSecure '11 :)
     
  12. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    Lowering self protection to minimum didnt change anything. If you need another log let me know.
     
  13. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    Any word on this yet?
     
  14. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    I haven't heard back from our internal testing team yet but will hopefully have some results by tomorrow.
     
  15. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    Seems to be fixed. Ive been testing for a day and nothing has popped up yet.

    EDIT- Spoke to soon. Its not fixed yet.
     
    Last edited: Oct 3, 2010
  16. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    I did a little troubleshooting on my own.

    I uninstalled PrevX with Your Uninstaller.
    I uninstalled F Secure with Your uninstaller.
    I ran the PrevX Force Uninstall tool for remaining traces.
    Rebooted.
    Cleaned out the %appdata% local and roaming, %programdata%, %temp%, and checked out Program Files and Program Files (x86) for left over traces.
    Ran CCleaner.
    Rebooted.
    Reinstalled with F Secure first this time and PrevX SOL after.
    Still not fixed.

    I added PrevX folder to F Secures Object list under Virus and Spyware Scan, Excluded Items List, Objects, ProgramFiles/PrevX folder.

    PrevXHelp when you have your guys testing are they testing on an x64 system with PrevX x64?
     
  17. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Aha - that is likely why we couldn't reproduce the problem: we were testing on FSecure '11 32bit :) I'll circle back with our testing team and hopefully get an answer shortly!
     
  18. whitedragon551

    whitedragon551 Registered Member

    Joined:
    Sep 30, 2008
    Posts:
    3,189
    Location:
    USA
    Ok cool. Glad we got somewhere.
     
  19. Duradel

    Duradel Registered Member

    Joined:
    Nov 26, 2010
    Posts:
    363
    Location:
    Melbourne, Australia
    I was getting the exact same problem. I hope there is a solution soon because I don't want to uninstall PrevX yet I want to complete the trial I have of F-Secure IS 2011. I am also using Windows 7 Professional 64 bit.

    Noticed its when Prevx Safe Online is set to high or above in the settings that the prompts seem to occur with F-Secure. If HTTPS settings are set to medium there is no prompts from F-Secure.
     
    Last edited: Jan 18, 2011
  20. mHazweiO

    mHazweiO Registered Member

    Joined:
    Jan 31, 2010
    Posts:
    21
    Location:
    Bavaria, Germany
    During the last weeks I played a little bit with F-Secure AV in combination with PrevX + SOL on a Win 7 x64 Home Premium system and observed exactly the same issues with the AV. Pop ups without no end.
    Turning off the advanced process monitoring feature in F-Secure AV improved the situation but didn't correct it fully, if I remember correctly

    I found out that F-Secure messages only appeared when I was log on with my admin account. When using my limited user account F-Secure stayed silent! I don't know if this has been a topic of a thread already but are different techniques used for hooking in the processes by PrevX depending on the user rights?

    Mainly because I didn't trust the peaceful coexistence of PrevX + SOL and F-Secure AV with limited rights I downloaded an executed the virus test files from eicar.org. With advanced process monitoring enabled in F-Secure AV the system froze for more than 15 s and the a PrevX message appeared that it found the virus test file. When the option was disabled F-Secure AV came up with the message that it found a virus but it took some seconds. So it seems that both F-Secure und PrevX try to catch the malware at the same time and get in each others way.

    Unfortunately I don't have any Scan logs to offer because the system got unbootable :doubt: soon after these tests so I had to install an older image with my usual combination of Avira Premium and PrevX, which is running fine btw. I'm not sure if this crash was related to the PrevX / F-Secure problem.

    PrevX settings:

    Self protection - Maximum
    Advanced heuristics- Maximum
    Program age - high
    Program popularity - medium
    SOL - enabled with standard settings

    Maybe this helps


    Some time ago a tried out this combination (PrevX evaluation + FSIS) on my sisters computer (Vista x86) for a short while and couldn't find any problems.
    Maybe the issue really occurs only on x64 systems which was already assumed by Joe.
    Another hint in this direction: In a Win XP VM with PrevX eval and the Technology preview of F-Secure IS I didn't notice an issues either.

    If it helps and is requested I could do some testing with a Vista x64 VM as well but I hesitate to test this configuration again on my life system.

    Best regards,

    mHazweiO

    edit: some typos
     
    Last edited: Jan 19, 2011
Thread Status:
Not open for further replies.