Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 6th, 2009, 06:12 AM
ako's Avatar
ako ako is offline
Frequent Poster
 
Join Date: Nov 2006
Posts: 602
Default SAS real-time protection fails - Prevx saves!

I did a small very unscientific test. I installed Superantispyware Pro, Winpatrol, Hitman pro and Prevx free. Then I started installing 5 nasty malwares. SAS was almost blind preventing only one from installing. Winpatrol and Prevx both warned of the infections.

http://img80.imageshack.us/i/sas3.jpg/
http://img231.imageshack.us/i/sas6.jpg/ (look at Winpatrol warning!)

The system was soon full of pop-ups.

http://img44.imageshack.us/i/sas5.jpg/

I scanned with SAS, cleaned and rebooted. It could remove quite a lot, but after reboot only Prevx could run, and malware prevented all execution of other programs.

http://img26.imageshack.us/i/sas7.jpg/

I scanned with Prevx, put licence key, cleaned

http://img39.imageshack.us/i/sas8.jpg/

and rebooted. Now the PC was clean, but file associations for exe-files had not been corrected,so the system was still unusable.

http://img401.imageshack.us/i/sas9.jpg/

I booted to safe mode (command prompt), restored a clean system and booted. Evething was ok now! Programs could start, and Hitman pro also told system is clean. Prevx rocks!

Ps. I've found Winpatrol very useful in my tests! SAS real-time protection seems poor,and SAS cleaning capabilities seem clearly inferior to Prevx.
__________________
"Si vis pacem, para bellum"
Author of Probably the best free security list in the world

Last edited by ako : August 6th, 2009 at 09:03 AM.
  #2  
Old August 6th, 2009, 07:01 AM
Retadpuss's Avatar
Retadpuss Retadpuss is offline
Suspended Member
 
Join Date: Apr 2009
Posts: 226
Default Re: SAS real-time protection fails - Prevx saves!

Very interesting. Whilst the test uses a tiny number of malware samples and could therefore be seen as having little meaning, it does fit with my experience of testing. Whenever I have tested SAS on current and new malware, it has always been the worst.

Puss
  #3  
Old August 6th, 2009, 07:34 AM
ako's Avatar
ako ako is offline
Frequent Poster
 
Join Date: Nov 2006
Posts: 602
Default Re: SAS real-time protection fails - Prevx saves!

Quote:
Originally Posted by Retadpuss
Very interesting. Whilst the test uses a tiny number of malware samples and could therefore be seen as having little meaning, it does fit with my experience of testing. Whenever I have tested SAS on current and new malware, it has always been the worst.

Puss


It is also interesting that Prevx could resist killing, while SAS could not.

P.S: Could someone french speaking look these videos on Prevx and make a summary?

-http://www.youtube.com/user/PegHorse-
__________________
"Si vis pacem, para bellum"
Author of Probably the best free security list in the world
  #4  
Old August 6th, 2009, 10:57 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,769
Default Re: SAS real-time protection fails - Prevx saves!

Quote:
Originally Posted by ako
I did a small very unscientific test. I installed Superantispyware Pro, Winpatrol, Hitman pro and Prevx free. Then I started installing 5 nasty malwares. SAS was almost blind preventing only one from installing. Winpatrol and Prevx both warned of the infections.

http://img80.imageshack.us/i/sas3.jpg/
http://img231.imageshack.us/i/sas6.jpg/ (look at Winpatrol warning!)

The system was soon full of pop-ups.

http://img44.imageshack.us/i/sas5.jpg/

I scanned with SAS, cleaned and rebooted. It could remove quite a lot, but after reboot only Prevx could run, and malware prevented all execution of other programs.

http://img26.imageshack.us/i/sas7.jpg/

I scanned with Prevx, put licence key, cleaned

http://img39.imageshack.us/i/sas8.jpg/

and rebooted. Now the PC was clean, but file associations for exe-files had not been corrected,so the system was still unusable.

http://img401.imageshack.us/i/sas9.jpg/

I booted to safe mode (command prompt), restored a clean system and booted. Evething was ok now! Programs could start, and Hitman pro also told system is clean. Prevx rocks!

Ps. I've found Winpatrol very useful in my tests! SAS real-time protection seems poor,and SAS cleaning capabilities seem clearly inferior to Prevx.
did you tried the new malwarebytes againts same test and wooooo winpatrol is getting betteri also wonder what would happen if your answer for winpatrol in the alert is no,no,no will winpatrol block the malware?what kind of malware were they?thanks
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #5  
Old August 6th, 2009, 11:28 AM
ako's Avatar
ako ako is offline
Frequent Poster
 
Join Date: Nov 2006
Posts: 602
Default Re: SAS real-time protection fails - Prevx saves!

Quote:
Originally Posted by jmonge
did you tried the new malwarebytes againts same test and wooooo winpatrol is getting betteri also wonder what would happen if your answer for winpatrol in the alert is no,no,no will winpatrol block the malware?what kind of malware were they?thanks

Can't test MBAM real-time, I have no key to it.

In my tests Winpatrol sometimes blocks, sometimes queries again and again. Anyway, it is very good at telling what's going on.

Fake AV:s, trojans.

PS. Does anyone know how to recover file association for .exe without system recovery (see my first post)?
__________________
"Si vis pacem, para bellum"
Author of Probably the best free security list in the world

Last edited by ako : August 6th, 2009 at 11:35 AM.
  #6  
Old August 6th, 2009, 11:31 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,769
Default Re: SAS real-time protection fails - Prevx saves!

thanks
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #7  
Old August 6th, 2009, 11:59 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,578
Default Re: SAS real-time protection fails - Prevx saves!

Quote:
Originally Posted by ako
PS. Does anyone know how to recover file association for .exe without system recovery (see my first post)?

Our removal routines "should" have cleaned them but apparently there is some issue (just received a few reports from other users of ours about that failing aspect of cleanup as well so we will be fixing it).

However, try renaming regedit.exe to regedit.pif and then running it and edit:

HKEY_CLASSES_ROOT\.exe

set the default value to:

exefile

and then open HKEY_CLASSES_ROOT\exefile\shell\open\command and set the default value to

"%1" %*

That should fix it - let me know if it doesn't, however, and I'll investigate further on this particular infection
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:40 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums