Strange events

Discussion in 'Prevx Releases' started by m00nbl00d, May 9, 2011.

Thread Status:
Not open for further replies.
  1. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Is it normal for Prevx to report it finds malicious crap, by changing its icon to red color, but then when scanning nothing comes up?

    I'm talking about a system that I'm aware it's infected with a rootkit. So, Prevx is up to something, but when I performed scans, it always came up clean.

    It happened quite a few times. Unfortunately, it wouldn't provide info about what it detected.
     
  2. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    If you could send me the file CSICleanupLog.log from C:\Documents and Settings\All Users\Application Data\PrevxCSI (or C:\ProgramData\PrevxCSI on Vista/7), that should shed some light.

    If you don't have one, could you save a scan log and send that?

    Thanks!
     
  3. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    I'll try and see if I can do that later on, as I don't have the laptop in question with me right now.

    Thanks
     
  4. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    3,771
    Location:
    Outer space
    I did notice that behaviour before, however different as it was on a clean system and that was with the free facebook version and the icon turned red after executing an application which was flagged by the age/spread heuristics, there's no warning since there's no protection license, but scans show nothing as there is no malware found. Perhaps the free version could be altered to show the age/spread warning but not block it?
     
  5. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Oh, the system I'm talking about is also running the facebook version. I thought that it would alert, though?
     
  6. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    It would likely not show a warning message on screen - the Facebook version is intended to stay out of the user's way as best as possible. It's likely that it was a temporary file or other file that was removed by something other than Prevx if it then returned back to green on the next scan.
     
Thread Status:
Not open for further replies.