Spread Detected Files

Discussion in 'Prevx Betas' started by vtol, May 5, 2010.

Thread Status:
Not open for further replies.
  1. iNsuRRecTioN

    iNsuRRecTioN Registered Member

    Joined:
    Sep 5, 2003
    Posts:
    303
    Location:
    Germany
    Hi there,

    Joe, I must agree and support vtol here, sorry :)

    But he is right.

    It is misleading for novices and new users.

    I thought PrevX should be as simple as possible, especially for beginners..

    But the warning is incorrect for [d] files detection..

    PrevX has to distinguish between real threats aka malicious files and something strange/too new/etc. and NOT ONLY internally.

    PrevX has to show it on the GUI as well in plain english, but it always say Malware blocked or such, even it is based on age/popularity heuristrics or it simple is an crack or keygen.. (I don't say that I use these stuff, but I'm scanning many friends computers with PrevX in order to check them..)

    Joe your team have to change the behavior and GUI warnings in order to reflect the differences in findings. (Real malicious files, heuristic detection, etc. and name it different, not all is malware..)

    regards,

    iNsuRRecTiON
     
  2. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    If you really want to know the Logs are for Prevx support to help us with problems if we have them and not for us so the novice user would not even look at the log files IMO. And the [d] and files don't do anything to slow down Prevx so again it is of no consequence that they are there.

    TH
     
  3. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    We do have the name clearly differentiated - Age/Spread detected files vs. "Medium Risk Malware" for example.

    Changing heuristic settings will logically create more warnings but the warning dialogs differentiate between these detections. You'll see that in the dialog in the original post, the green circle is overwriting the detection name which is:

    "Community.OuterEdge"

    which is an Age/Spread detection. The dialog posted initially will only show if the user has already seen a standard "Block" dialog with Age/Spread Detection in the title and then clicked Block to that (if they have the default setting of automatically block files).

    Let me know if you have any other questions :)
     
  4. horseman

    horseman Registered Member

    Joined:
    Apr 11, 2004
    Posts:
    128
    Location:
    Hove - UK
    Admirable patience as you're obviously "trying to repair bridges", but didn't Euclid have similar difficulties with his 5th postulate and some of his students......?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.