Become a Site Supporter and Never see Ads again!

Author Topic: Does anyone use PREVX1 malware?  (Read 1238 times)

0 Members and 1 Guest are viewing this topic.

Offline balou2

  • Crippled, but still dancin'
  • Trade Count: (0)
  • Needs to get out more...
  • *****
  • Posts: 4442
  • Gender: Male
  • He was a friend of mine.
    • Little Mountain Sound Archive
Does anyone use PREVX1 malware?
« on: December 29, 2006, 12:15:43 AM »
So, I came across this security software online a few months back and absolutely LOVE it.  It is one of the most advanced systems pieces I've run continuously on my laptop.  I have not gotten a virus, spyware hit or other malware problem since installing this.

BUT...it has problems with FLAC when the program tags items.   Here is what it says re: FLAC:

AUTOMATED MALWARE PROFILE, ANALYSIS, REMOVAL AND SIGNATURE INFORMATION:
DEFINITION OF: METAFLAC.EXE

    * Safety Rating: Known Malware, do not run
    * Malware Family: Part of Malware group - Covert Sys Exec
    * Determination: Automatically determined using Prevx1 centralized heuristics
    * Malware Form: EXPLOIT
    * Protection: Prevx1 is a very powerful PC security product, it will protect, disinfect, cleanup and remove METAFLAC.EXE and safeguard your PC against viruses, trojans, worms, spyware, rootkits and adware
    * New Users: You can download the full Prevx1 product and use it to cleanup and remove METAFLAC.EXE and other infections free of charge, then leave it to monitor your PC for other infections
    * First seen: Dec 1 2006 (GMT)
    * Last seen: Dec 1 2006 (GMT)
    * File Size: 147,456 bytes

MALWARE ASSESSMENT: PREVX 4 AXES OF EVIL METHODOLOGY
1. COVERT ANALYSIS OF: METAFLAC.EXE

    * File Names Used: 2
    * Paths Used: 11
    * Common File Name: METAFLAC.EXE
    * Common Path: %WINDIR%\SYSTEM32\
    * Vendor Information: No Vendor details specified
    * File Name Structure: Normal
    * File and Path Structure: Normal

2. RELATIONSHIP ANALYSIS OF: METAFLAC.EXE

    * No relationship details available for this object

3. ACTIVITY ANALYSIS OF: METAFLAC.EXE

    * No activity has yet been observed for this object

4. PROPAGATION ANALYSIS OF: METAFLAC.EXE

    * Malware Group Propagation Rate: Moderate (spreading)
    * Malware Group: Covert Sys Exec
    * Copyright Prevx Limited 2005, 2006


If I read this right, it says that FLAC is known malware.  That's just not true, BUT, I see the SYSTEM32 notation, which makes me wonder if PREVX interprets that as problematic.

Anybody able to comment?
Socks are overrated.

Offline John Kary

  • Trade Count: (0)
  • Taperssection Regular
  • **
  • Posts: 125
Re: Does anyone use PREVX1 malware?
« Reply #1 on: December 29, 2006, 12:10:00 PM »
Interesting, but I think it's a flase-positive.  It looks as though metaflac.exe exists in both the installed FLAC folder and the /SYSTEM32/ folder and is identical, so it is most likely installed at the same time as the FLAC Frontend.

The Prevx official site returned this when I searched for metaflac.exe: http://virusinfo.prevx.com/pxparall.asp?PX5=e4c5fd7000fce6383eff0063e0e79400dbedddf0&psection=desc

I think some malware will change its name to one of that often found in the /SYSTEM32/ directory to attempt to go undetected.

The metaflac.exe version I have shows it as:
Size: 116 KB (118,784 bytes)
Created: Thursday, February 03, 2005, 9:59:48 PM

 

RSS | Mobile
Page created in 0.059 seconds with 27 queries.
© 2002-2024 Taperssection.com
Powered by SMF