MRG Flash Tests 2011

Discussion in 'other anti-virus software' started by LODBROK, Jan 27, 2011.

Thread Status:
Not open for further replies.
  1. 3x0gR13N

    3x0gR13N Registered Member

    Joined:
    May 1, 2008
    Posts:
    850
    So the screen was still locked after reboot?
    Ah, I see that DW has a conditional pass now. I take it that everything was fine after a reboot?
     
    Last edited: Feb 7, 2011
  2. Ilya Rabinovich

    Ilya Rabinovich Developer

    Joined:
    Sep 13, 2005
    Posts:
    1,543
    1. The Desktop locks up because of "topmost" window, but Win-Alt-A is working as it should, terminating malicious process.
    2. After reboot, everything's working normal way.

    In fact, I made some changes for 3.10 version, not to allow to apply the "topmost" style for untrusted windows, but will check out how it's compatible with games running untrusted.
     
  3. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,564
    Location:
    New York City
  4. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    Is this the first flash test that BluePoint failed? Maybe TDSS has a new execution method that BP's default deny doesn't cover.
     
  5. De Hollander

    De Hollander Registered Member

    Joined:
    Sep 10, 2005
    Posts:
    718
    Location:
    Windmills and cows
    They passed the previous nine tests
     
  6. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Good to see EAM back on track :D
     
  7. The Hammer

    The Hammer Registered Member

    Joined:
    May 12, 2005
    Posts:
    5,752
    Location:
    Toronto Canada
    Yes it is.:)
     
  8. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    So is Immunet protect..:)
     
  9. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Prevx is always there saying Passed!

    TH ;)
     
  10. De Hollander

    De Hollander Registered Member

    Joined:
    Sep 10, 2005
    Posts:
    718
    Location:
    Windmills and cows
    :) Indeed, and a couple of other products.
     
  11. Dermot7

    Dermot7 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    3,430
    Location:
    Surrey, England.
  12. Iangh

    Iangh Registered Member

    Joined:
    Jul 13, 2005
    Posts:
    849
    Location:
    Melbourne, Australia
    MBAM isn't a full-blown a-v but still does a great job with zero-day.

    How is that?

    I thought they focused on getting rid of known nasty malware, yet it seems they can also do zero-day.
     
  13. nosirrah

    nosirrah Malware Fighter

    Joined:
    Aug 25, 2006
    Posts:
    560
    Location:
    Cummington MA USA
    Research and tech is targeted towards anything that AVs do not do well against, this test actually favors both our tech and research.
     
  14. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
  15. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    MBAM is also a very good cleaner :D
     
  16. LODBROK

    LODBROK Guest

    According to the MRG forum, they're using MBAM Full (pro, paid, whatever) with Protection enabled. They don't say whether the Pass is a result of an IP block or a detection. Either way, the performance of MBAM Full is spectacular. It must be specifically recognized though that the free MBAM has no relevance whatsoever within the context of these MRG tests.
     
  17. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,564
    Location:
    New York City
  18. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,456
    Really strange, I wonder what they actually tested; whether it was an exe dropper or a sys driver. All recent TDSS rootkits were detected by ESET which cannot be said about some other AVs that allegedly detected it in the "test". Any chance of getting the appropriate MD5 for verification?
     
  19. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    In the final report of MRG Flash tests 2010, they said that IP blocking wasn't used, so it's all detection.

    I think MRG sends the samples tested to security vendors if they request them, you can contact them here:
    http://malwareresearchgroup.com/contact-us/
     
  20. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,564
    Location:
    New York City
  21. LODBROK

    LODBROK Guest

    True. But since they haven't revealed their current methodology my observation, "They don't say..." can be held as accurate at this point in time as your conclusion (as logical as it might be) that IP blocking isn't in actual use is mere speculation.

    They really scatter their stuff on that MRG site and I can't find where it is when explaining the gap in testing from Dec 9 to Jan 27 that significant changes were being made (they may have even posted it up here). There's a Jan 27 posting in their forum, "Methodology and additional information will be available later today." I'm burned out from navigating their site; if anyone can find that data, post up a link.
     
  22. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    I made a preliminary summary for the 2011 test, but it's only 14 tests so far.

    EDIT:Latest test just posted by Thankful is not included in my summary.
    EDIT2: Posted as image, layout was screwed up.. :rolleyes:
     

    Attached Files:

    Last edited: Feb 21, 2011
  23. LODBROK

    LODBROK Guest

    As a long-time Zemana user, I'm disappointed by AntiLogger's occasional failure but I'd be a fool to expect it to be perfect. I'll have to be satisfied with "almost perfect." ;)

    But I can't help but wonder if my settings overriding the defaults would result in a Passed in this series of MRG Flash tests. I disable "Let it run but block..." and "Block an app...but don't terminate it" and "Use the Internet to check...signature info" and "Use ZWLST" while setting "Ask for confirmation" for all. I think that's much tighter than default but definitely too restrictive and chatty for the mass market.
     
  24. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    First post
     
  25. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Why did Prevx pass only partially today? And were the two samples Zemana failed digitally signed?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.