View Full Version : Prevx hard diffuculty for detect rogues
dorgane
August 1st, 2009, 08:06 AM
hi,
sorry for my bad english.
A friend is testing prevx edge 3.0 but we see than prevx don't detect rogues :O
3 rogues launch, 3 rogues installed :/
can you see video : http://infomars.fr/WordPress/peghorse/?cat=171
what prevx do in next version for stopping rogue ?
but nice self-defence, system security can't stop prevx =D
Retadpuss
August 1st, 2009, 08:46 AM
Detecting rogues can be tricky for several reasons - firstly, there are so many of them and they often reguarly change the setup files to avoid detection. Secondly, many of them do not do anything malicious, so cant be caught using behaavoural analysis.
On the whole, Prevx catches rogues and scareware better than most AMs / AVs. A test based on three samples does not carry much meaning as there are tens of thousands of rogues out there.
I have tested Prevx against over 1000 rogues over the last 6 months and have found it to do very well - aas good as A2 and better than pretty much anything else in realtime and on demand.
Puss.
TonyW
August 1st, 2009, 10:33 AM
Rogues/fraudulent software is an area which some anti-malware programs do better at dealing with than others. It's a classification issue and how they get added to databases as rogues/frauds/scams etc..
As Retadpuss says, there's so many of them, and if you submit any to some AVs for example, many will report the files to be clean because they don't actually contain malicious code. It's the intent and what these applications do that needs to be investigated, which means more analysis.
In the case of Prevx, if you believe a program to be a rogue, submit to report@prevxresearch.com - that way, it'll be analysed and if found to be a scam, it'll be added for detection.
hawki
August 1st, 2009, 01:51 PM
Prevx did a "fantastic" job blocking rogues in this test." ("fantastic" is how the tester described it's performance)
http://www.youtube.com/watch?v=AAx6Y2MW_uA&feature=channel_page
PrevxHelp
August 1st, 2009, 04:55 PM
TonyW/Retadpuss: thank you for the perfect responses :)
Rogues are indeed the most difficult area to deal with currently in the antimalware industry. Not only are the authors coming out with new rogues by the dozens, but the rogues actually look very close/better than legitimate applications so they require manual research and discussions - TonyW is right: even researchers in the same company can sometimes disagree if a program is a rogue :-\
As said, if you could send the information on where to get the samples or the samples themselves to report@prevxresearch.com, we will add them as quickly as possible :) Thanks!
dorgane
August 1st, 2009, 05:21 PM
hi,
i send 7 virus ( type of fake codec)
screen :
210942
now 5 hours ago and no reply/partial detected 4 on 7 :dry:
dorgane
August 1st, 2009, 06:42 PM
ok,
i support team writed me
overangry
August 2nd, 2009, 09:11 PM
Interesting reviews I was surprised at how poorly some of the major av's performed, using this limited sample of malware.
It seems that not only Prevx had detection difficulties:o
Some AV's I had never heard of performed quite well, some better than the big players...
I haven't looked at all the videos, but I did notice that for Drivesentry the tester updated the signature data base after he completed his tests???
???
Personally, I would like to see him test geswall.
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums