Welcome, Guest. Please login or register.
September 07, 2008, 05:54:37 AM

Login with username, password and session length

189307 Posts
22050 Topics
52878 Members

Latest Member: tony_m

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Anti Virus/Malware Products/Other Security products
| | |-+  Prevx CSI
« previous next »
Pages: [1] Go Down Print
Author Topic: Prevx CSI  (Read 878 times)
grayhair
Comodo Loves me
****
Offline Offline

Posts: 164


« on: March 22, 2008, 11:28:37 AM »

   I recently ran Prevx CSI on one of my Vista machines.  It says I am "infected" w/Trojan horses C:\Windows\system32\drivers\ipinip.sys, and ~\drivers\blbdirve.sys.  No other scan shows this to be the case.  Is Prevx prone to false positives, and am I chasing my tail?
Logged
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #1 on: March 22, 2008, 12:23:05 PM »

I have an experience with PrevX's false positive result. I scanned a computer with it and it saw some fonts as trojan. Their extensions were TTF. These were normal windows fonts.

Blbdriver.sys (you have syntax error) is related to Microsoft Vista software. Ipinip.sys is IP in IP Encapsulation Driver of MS Windows.

aXes
« Last Edit: March 22, 2008, 12:29:30 PM by aXes » Logged

Don't be afraid your life will end; be afraid that it will never begin!
grayhair
Comodo Loves me
****
Offline Offline

Posts: 164


« Reply #2 on: March 22, 2008, 01:39:21 PM »

   Thanks for response aXes.  The syntax error is a typing error--my Typing Class teacher (yes, it was called Typing Class back then) did not believe boys belonged in her classroom, so I blame my typing mistakes on her (or, is it my big fat fingers?).  Prevx did want my money to "fix" these issues. Since no other scan sees them as bad I will chock it up to false positives (aimed at my wallet).

   Thank you and cheers.    Wave   Cheers   
Logged
aXes
Comodo Loves me
****
Offline Offline

Posts: 110


aXes for praxes!


« Reply #3 on: March 22, 2008, 02:41:14 PM »

You are welcome!

aXes
Logged

Don't be afraid your life will end; be afraid that it will never begin!
Vettetech
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 4539



« Reply #4 on: March 22, 2008, 03:24:00 PM »

Upload it here.

http://www.virustotal.com/
Logged
Info-Sec
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 549



« Reply #5 on: April 24, 2008, 09:55:58 PM »

   I recently ran Prevx CSI on one of my Vista machines.  It says I am "infected" w/Trojan horses C:\Windows\system32\drivers\ipinip.sys, and ~\drivers\blbdirve.sys.  No other scan shows this to be the case.  Is Prevx prone to false positives, and am I chasing my tail?

When I upload to virus total and Prevx returns the file as a virus, and no other vendor says it is, I ignore prevx.

IT HAS BEEN KNOWN, that prevx returns false positives.  I would NOT take prevx's word over:

*avira
*NOD 32
*Avast!

Or several other scanning engines.
Logged

*Vista *CFP V3 *Avira * Avast *Spyware Doctor
*XP *Zone Alarm PRO *NOD32 V2.7 *Spysweeper
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.67 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com