Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #326  
Old July 10th, 2010, 05:13 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: New MRG test results

threatfire and PR Guard both fail this test
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #327  
Old July 10th, 2010, 05:18 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,631
Default Re: New MRG test results

Quote:
Originally Posted by jmonge
threatfire and PR Guard both fail this test

You better find something else to try Timmie's sounds good about now Extra Large Double Cream!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.155 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #328  
Old July 10th, 2010, 05:22 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: New MRG test results

you know what i am mad now i am going to drink coffee at timies untill i get really drunk
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #329  
Old July 10th, 2010, 05:49 PM
Noob's Avatar
Noob Noob is offline
Massive Poster
 
Join Date: Nov 2009
Posts: 5,330
Default Re: New MRG test results

Lol can't believe Zemana is so good in this test O_o
How do Zemana protects on already infected systems if it doesn't scans?
__________________
Emsisoft Anti-Malware v7.0.0.21 - Online Armor 6.0.0.1736
SRP - UAC - EMET

Browser: Google Chrome v25.xx

Windows 7 Ultimate x64
  #330  
Old July 10th, 2010, 06:06 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,930
Exclamation Re: New MRG test results

@jmonge and Triple Helix

Quote:
Originally Posted by jmonge

threatfire and PR Guard both fail this test

You mean PEGuard methinks
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #331  
Old July 10th, 2010, 06:07 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: New MRG test results

yes thanks ranger for the correction
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #332  
Old July 12th, 2010, 02:37 PM
Sveta MRG's Avatar
Sveta MRG Sveta MRG is offline
Frequent Poster
 
Join Date: Aug 2009
Posts: 204
Default Re: New MRG test results

Quote:
Originally Posted by jmonge
threatfire and PR Guard both fail this test

Hi,

In our unofficial part of the test we are testing quite a few applications. First round will include GeSWall, ThreatFire and PE Guard.
These applications are being tested using various settings, so if you see their name on the test site, that does not necessarily mean that the program in question failed the test.

Unofficial test results coming soon

Regards,
Sveta
__________________
Founder & CEO
MRG Effitas/Effitas Group
Efficacy Assessment & Assurance
  #333  
Old July 12th, 2010, 04:06 PM
Sveta MRG's Avatar
Sveta MRG Sveta MRG is offline
Frequent Poster
 
Join Date: Aug 2009
Posts: 204
Default Re: New MRG test results

Quote:
Originally Posted by Noob
Lol can't believe Zemana is so good in this test O_o
How do Zemana protects on already infected systems if it doesn't scans?

Hi,

Zemana has SSL protection technology - and this is enabled as a default setting. Zemana detects the action of the simulator and displays a clear warning via its HIPS function - but will also prevent data theft, even if you allow the action because of the SSL protection technology.

Regards,
Sveta
__________________
Founder & CEO
MRG Effitas/Effitas Group
Efficacy Assessment & Assurance
  #334  
Old July 12th, 2010, 08:44 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: New MRG test results

thanks alot Sveta for your value tests and time thanks again man
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #335  
Old July 13th, 2010, 10:24 AM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,631
Default Re: New MRG test results

@Sveta where are the recent results?

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.155 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
  #336  
Old July 14th, 2010, 07:44 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,930
Question Re: New MRG test results

Name:  br.gif
Views: 1093
Size:  6.5 KB

http://malwareresearchgroup.com = So ?
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #337  
Old July 16th, 2010, 03:56 AM
Sveta MRG's Avatar
Sveta MRG Sveta MRG is offline
Frequent Poster
 
Join Date: Aug 2009
Posts: 204
Default Re: New MRG test results

Day 20 results published.

Regards,
Sveta
__________________
Founder & CEO
MRG Effitas/Effitas Group
Efficacy Assessment & Assurance
  #338  
Old July 16th, 2010, 07:53 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: New MRG test results

thanks Sveta
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #339  
Old July 20th, 2010, 08:39 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: New MRG test results

Quote:
Originally Posted by Sveta MRG
Day 20 results published.

Regards,
Sveta
waiting for geswall results!
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #340  
Old July 20th, 2010, 01:14 PM
Sveta MRG's Avatar
Sveta MRG Sveta MRG is offline
Frequent Poster
 
Join Date: Aug 2009
Posts: 204
Default Re: New MRG test results

Day 24 results published.

In the latest report we have included the results for ThreatFire, GeSWall and PE Guard.

Regards,
Sveta
__________________
Founder & CEO
MRG Effitas/Effitas Group
Efficacy Assessment & Assurance
  #341  
Old July 20th, 2010, 07:46 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: New MRG test results

where are the results for PE Guard as i dont find it?
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #342  
Old July 21st, 2010, 04:05 AM
Sveta MRG's Avatar
Sveta MRG Sveta MRG is offline
Frequent Poster
 
Join Date: Aug 2009
Posts: 204
Default Re: New MRG test results

Quote:
Originally Posted by jmonge
where are the results for PE Guard as i dont find it?

Check the bottom of the report

Regards,
Sveta
__________________
Founder & CEO
MRG Effitas/Effitas Group
Efficacy Assessment & Assurance
  #343  
Old July 21st, 2010, 08:10 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: New MRG test results

thanks sveta
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #344  
Old July 21st, 2010, 11:42 AM
Sveta MRG's Avatar
Sveta MRG Sveta MRG is offline
Frequent Poster
 
Join Date: Aug 2009
Posts: 204
Default Re: New MRG test results

Hi,

For the last few days of this project, we will be taking more requests from you. If you wish us to test additional applications (that are suitable for this test), feel free to let us know. Also you may request particular settings ect.

Regards,
Sveta
__________________
Founder & CEO
MRG Effitas/Effitas Group
Efficacy Assessment & Assurance
  #345  
Old July 21st, 2010, 12:13 PM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,091
Default Re: New MRG test results

It would be interesting to see if the simulator can also capture data from a sandboxed browser, Sandboxie would be a good choice for that. Also, quite some of the security suites have some kind of "safe run" or sandbox for browsers, testing those would also give us some indication about which also have good protection from the outside, not just the inside(malware and drive-by downloads etc.)
  #346  
Old July 21st, 2010, 12:27 PM
1000db's Avatar
1000db 1000db is offline
Frequent Poster
 
Join Date: Jan 2009
Location: Missouri
Posts: 672
Default Re: New MRG test results

Quote:
Originally Posted by Sveta MRG
Hi,

For the last few days of this project, we will be taking more requests from you. If you wish us to test additional applications (that are suitable for this test), feel free to let us know. Also you may request particular settings ect.

Regards,
Sveta

Please test the latest Appguard version and the beta with MemoryGuard.
  #347  
Old July 21st, 2010, 01:32 PM
shadek's Avatar
shadek shadek is online now
Very Frequent Poster
 
Join Date: Feb 2008
Location: Sweden
Posts: 1,817
Default Re: New MRG test results

I'd like to see Immunet 2.0 in the test.
  #348  
Old July 21st, 2010, 04:12 PM
Eirik Eirik is offline
Frequent Poster
 
Join Date: Oct 2008
Location: Chantilly, Virginia
Posts: 544
Default Re: New MRG test results

Quote:
Originally Posted by 1000db
Please test the latest Appguard version and the beta with MemoryGuard.

Unfortunately, MemoryGuard is not supported on WinXP. We're researching the practicality of implementing it there but this may never bear fruit.

So, the only differences between the new AppGuard for XP (next month) and the current production version is that rundll32.exe, cmd.exe, and regsrv.exe (I'm not certain about the exact executable name) are to be guarded by default, and more types of scripts in user-space are suppressed.

AppGuard is primarily a preventative tool. Once AppGuard has been intentionally disabled to allow the simulator to run from user-space, AppGuard would not prevent it from stealing data.

There are other mechanisms in our trusted enclaves framework that can address this in whole or in part in the future. However, in the interests of a user-friendly consumer experience, we have already begun reserving some capabilities for the enterprise versions. On Vista and 7, versus XP, we have options such as MemoryGuard and others that can do more to counter pre-existing malicious executables.

Cheers,

Eirik
  #349  
Old July 21st, 2010, 09:48 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: New MRG test results

Quote:
Originally Posted by Sveta MRG
Hi,

For the last few days of this project, we will be taking more requests from you. If you wish us to test additional applications (that are suitable for this test), feel free to let us know. Also you may request particular settings ect.

Regards,
Sveta
Can you explain how the DefenceWall Passed and GesWall failed the test?

Did geswall allow the data to be captured ans sent over internet?
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #350  
Old July 22nd, 2010, 10:45 AM
Sveta MRG's Avatar
Sveta MRG Sveta MRG is offline
Frequent Poster
 
Join Date: Aug 2009
Posts: 204
Default Re: New MRG test results

Quote:
Originally Posted by aigle
Can you explain how the DefenceWall Passed and GesWall failed the test?

Did geswall allow the data to be captured ans sent over internet?

Hi Aigle.

In terms of an explanation, until we liaise with the vendors and discuss the action of the simulator with them, we really don’t have any clear technical detail for you.

You should consider that both GesWall and PrefenseWall fail the pre-infected system test and both pass if the simulator is run as un trusted / isolated.

We are contacting all the vendors over the next couple of days and hope to be able to provide some more detail for you soon.

In answer to your question – for the test where the infection is downloaded and executed on a system protected by the security application, GesWall failed to alert on the action of the simulator and consequently, it was able to capture data and send it to us.

Regards,
Sveta
__________________
Founder & CEO
MRG Effitas/Effitas Group
Efficacy Assessment & Assurance
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:08 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums