Go Back   PassMark Support Forums > BurnInTest

Reply
 
Thread Tools Display Modes
  #1  
Old 12-02-2007, 11:06 PM
passmark's Avatar
passmark passmark is offline
Administrator
 
Join Date: Jan 2003
Location: Sydney Australia
Posts: 2,215
Default False positive with Prevx CSI malware scanner

For the second time, Prevx is incorrectly flagging our software as "Malicious". (See the previous correspondence from 2006 for details for their past mistakes)

PrevxCSI V1.2.101.104 incorrectly flags the file,
C:\Program Files\BurnInTest5.3\bit.exe (3.98MB)
as Malicious, with the Adware.Betterinternet malware.

It appears Prevx looking at the file name (bit.exe) and not the content of the file, nor the code signing checksums, nor any malware signatures, nor even the directory in which the file is found. Which would seem to be a somewhat flawed method to detect malware, to say the least.

It means the Prevx CSI scan is fast, but hopelessly superficial.

Real malware would only need to re-name the file to avoid detection. And legitimate software gets incorrectly flagged if the name of the file co-incidentally happens to be the same as some malware.

To verify this we renamed the bit.exe to bitnew.exe, then rescanned, and detection was avoided. The way Prevx promote this CSI product will surely, in my opinion, give people a misplaced sense of security.

We have contacted Prevx on the issue, and await their response.
Reply With Quote
  #2  
Old 12-17-2007, 05:24 AM
passmark's Avatar
passmark passmark is offline
Administrator
 
Join Date: Jan 2003
Location: Sydney Australia
Posts: 2,215
Default

After 2 weeks and a bunch of E-mail, Prevx agreed it was a mistake in Prevx CSI.

Quote from Prevx:
"I believe I have sorted the problem,so all future files will not be caught by Prevx as malware".

They didn't mention when the fix would be made available, but I assume it would be this month some time (Dec 2007).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 09:11 AM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright PassMark Software Pty Ltd 2007