Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 16th, 2011, 05:56 AM
hrnayy hrnayy is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 22
Default Prevx SafeOnline vs. Zeus & SpyEye

Question: Does Prevx SafeOnline work against Zeus and SpyEyes on x64 OS?
  #2  
Old June 16th, 2011, 06:51 AM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,195
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

No

http://forums.malwareresearchgroup.c...t=582&start=20

Quote:
We received our invitation to test Webroot AntiVirus Beta today (Prevx 4 Beta) and can confirm it still fails against our simulator on Windows 7 64.

Best regards,

Chris Pickard
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/
  #3  
Old June 16th, 2011, 07:12 AM
Scoobs72 Scoobs72 is offline
Very Frequent Poster
 
Join Date: Jul 2007
Location: Sofa (left side)
Posts: 1,084
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

What Lordraiden meant to say was "I don't know". Prevx SOL fails the form grabbing elements associated with Zeus and Spyeye, but as Joe has always said there are other aspects of Prevx SOL designed to catch these nasties.

I'd suggest waiting for Joe to respond on this one.
  #4  
Old June 16th, 2011, 08:25 AM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,195
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

Quote:
Originally Posted by Scoobs72
What Lordraiden meant to say was "I don't know". Prevx SOL fails the form grabbing elements associated with Zeus and Spyeye, but as Joe has always said there are other aspects of Prevx SOL designed to catch these nasties.

I'd suggest waiting for Joe to respond on this one.

If those aspects of Prevx SOL were not able to catch the MRG simulator and the simulator/malware is able to steal your bank passwords...
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/
  #5  
Old June 16th, 2011, 09:17 AM
BoerenkoolMetWorst BoerenkoolMetWorst is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: Outer space
Posts: 2,060
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

This is a bit dissappointing. We were told that the new SafeOnline would work under the hood in a totally different way to provide better protection also on x64 and this vulnerability was known to Prevx for quite some time and it was supposed to be fixed now.
  #6  
Old June 16th, 2011, 09:41 AM
Scoobs72 Scoobs72 is offline
Very Frequent Poster
 
Join Date: Jul 2007
Location: Sofa (left side)
Posts: 1,084
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

Quote:
Originally Posted by lordraiden
If those aspects of Prevx SOL were not able to catch the MRG simulator and the simulator/malware is able to steal your bank passwords...

That is correct if Prevx SOL were a standalone tool, but Prevx SOL includes the realtime scanning engine so the malware may be detected by that instead. Don't get me wrong, it's not good that the SOL element of Prevx SOL fails against the form-grabbing of Zeus and Spyeye, but it doesn't necessarily mean that there is no protection. So the answer to "does it protect" is "possibly".
  #7  
Old June 16th, 2011, 10:49 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is online now
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

We haven't received details of their simulator and are uncertain how it operates but we have tested it against Zeus and SpyEye and it does protect against them.
  #8  
Old June 16th, 2011, 12:51 PM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,195
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

Quote:
Originally Posted by PrevxHelp
We haven't received details of their simulator and are uncertain how it operates but we have tested it against Zeus and SpyEye and it does protect against them.


Maybe you can contact with Sveta at MRG or send him a private in this forum.
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/
  #9  
Old June 17th, 2011, 04:01 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,413
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

Quote:
Originally Posted by PrevxHelp
We haven't received details of their simulator and are uncertain how it operates but we have tested it against Zeus and SpyEye and it does protect against them.


Hmmm.... according to MRG forums, Prevx 3 and 4 beta both failed with this simulator and it was verified by prevx people as they were given acess to this simulator.

Later on they said that they are removing all posts about prevx beta from their forums as per request from Prevx people. So I can,t find these now.

It,s really disappointing to see the issue still not fixed. God knows how many more issues will be still there.
__________________

Ubuntu 12.10
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #10  
Old June 17th, 2011, 04:14 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,614
Default Re: Prevx SafeOnline vs. Zeus & SpyEye

Quote:
Originally Posted by aigle
Hmmm.... according to MRG forums, Prevx 3 and 4 beta both failed with this simulator and it was verified by prevx people as they were given acess to this simulator.

Later on they said that they are removing all posts about prevx beta from their forums as per request from Prevx people. So I can,t find these now.

It,s really disappointing to see the issue still not fixed. God knows how many more issues will be still there.

Have a look here: http://www.wilderssecurity.com/showp...3&postcount=12

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.147 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:44 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums