Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 19th, 2011, 07:27 PM
Hugger Hugger is offline
Very Frequent Poster
 
Join Date: Oct 2007
Location: Hackensack, USA
Posts: 1,003
Default What just happened?

Look at the MRG test results and please tell me I'm hallucinating.
Prevx failed 3 of 4.
  #2  
Old July 19th, 2011, 08:36 PM
d0t d0t is offline
Regular Poster
 
Join Date: Apr 2011
Posts: 177
Default Re: What just happened?

Pretty sad
  #3  
Old July 19th, 2011, 09:38 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: What just happened?

The Flash tests are over single samples which don't reflect the tens of thousands of other samples we're blocking every day. There isn't an issue - no vendor finds 100% and it is easy to find files that would bypass every vendor listed every day if wanted - it is just the nature of today's malware.
  #4  
Old July 19th, 2011, 11:56 PM
Kirk Reynolds Kirk Reynolds is offline
Regular Poster
 
Join Date: May 2011
Posts: 78
Default Re: What just happened?

Quote:
Originally Posted by PrevxHelp
The Flash tests are over single samples which don't reflect the tens of thousands of other samples we're blocking every day. There isn't an issue - no vendor finds 100% and it is easy to find files that would bypass every vendor listed every day if wanted - it is just the nature of today's malware.
You don't think that the MRG flash tests have any value? That is the essence of what you're saying, isn't it? I'm not saying that I do, I'm just trying to clarify, is all.

Last edited by Kirk Reynolds : July 20th, 2011 at 12:04 AM.
  #5  
Old July 20th, 2011, 12:06 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: What just happened?

Quote:
Originally Posted by Kirk Reynolds
You don't think that the MRG flash tests have any value? That is the essence of what you're saying, isn't it?

No, they do have value. They are a point-in-time snapshot of single file threats and need to be understood as such. Just because we missed SpyEye today doesn't mean that we miss all SpyEye - it could very well just be that we missed that single sample. To put it in perspective - we have detection over several hundred thousand unique versions of SpyEye alone.

I don't have the MD5s/samples of the samples so I couldn't get further metrics on the scope of these files but most infections today are designed to only ever affect a very small number of users.
  #6  
Old July 20th, 2011, 12:21 AM
Kirk Reynolds Kirk Reynolds is offline
Regular Poster
 
Join Date: May 2011
Posts: 78
Default Re: What just happened?

Ah ok, I gotcha.
  #7  
Old July 20th, 2011, 05:33 PM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,309
Default Re: What just happened?

It should be pointed out that any missed samples are sent to the vendor before the test results are published - quote by Sveta of MRG:
Quote:
Missed samples are submitted to vendors, this is done before the tests are published.
So Prevx should actually have copies of those three undetected malware.
  #8  
Old July 20th, 2011, 05:37 PM
Triple Helix's Avatar
Triple Helix Triple Helix is offline
Prevx Forum Helper
 
Join Date: Nov 2004
Location: Oshawa, Ontario
Posts: 9,634
Default Re: What just happened?

Quote:
Originally Posted by TonyW
It should be pointed out that any missed samples are sent to the vendor before the test results are published - quote by Sveta of MRG:So Prevx should actually have copies of those three undetected malware.


Also Prevx would have them in there database when MRG scan them that's the good thing about full cloud based Anti-Malware we don't have to wait for a signature download to be protected!

TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14

VIP Member Of ASAP - (Alliance of Security Analysis Professionals™)

Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.155 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's.

Last edited by Triple Helix : July 20th, 2011 at 05:50 PM. Reason: added more info
  #9  
Old July 20th, 2011, 09:06 PM
Zorak's Avatar
Zorak Zorak is offline
Regular Poster
 
Join Date: Jan 2010
Location: Australian Capital Territory
Posts: 139
Default Re: What just happened?

MRG test with programs at default settings. If age/popularity based heuristics were increased, I would assume Prevx's detection rate would increase in these tests.

I have always run max program heuristics and high age/popularity and don't find false positives to be excessive, but am now considering an increase to max for both.

PrevxHelp (Joe) are you able to tell from your end what difference an increase in age/popularity based heuristics would have made in each of the missed samples from the MRG tests?
__________________
Win7 Pro x64 SP1 - SUA - UAC(max) - SRP - EMET 3.5 Realtime: Webroot SecureAnywhere - Windows Firewall On Demand: Hitman Pro - Emsisoft Emergency Kit - OTL - Secunia PSI Imaging: Windows Backup & Restore - Macrium Reflect Free Router: Linksys
  #10  
Old July 20th, 2011, 09:11 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,600
Default Re: What just happened?

I'm not sure - I haven't been able to find who within Prevx is receiving the samples from MRG so I still don't have visibility into them. I'm still investigating and should hopefully have an answer by the morning.
  #11  
Old July 24th, 2011, 03:06 PM
d0t d0t is offline
Regular Poster
 
Join Date: Apr 2011
Posts: 177
Default Re: What just happened?

Could you get ur hands on them? I'm curious eheh
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:55 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums