MRG Flash Tests 2011

Discussion in 'other anti-virus software' started by LODBROK, Jan 27, 2011.

Thread Status:
Not open for further replies.
  1. AlexC

    AlexC Registered Member

    Joined:
    Apr 4, 2009
    Posts:
    1,288
    Would be interesting to see how some simple OS hardening, like a limited user account with software restriction policies, will perform in these tests...

    Edit: just did that request to their contact e-mail.
     
    Last edited: Oct 22, 2011
  2. 22ndcitysaint

    22ndcitysaint Registered Member

    Joined:
    Sep 22, 2011
    Posts:
    62
    Location:
    PH
    They are referring to the rootkit named Tibia.
     
  3. AlexC

    AlexC Registered Member

    Joined:
    Apr 4, 2009
    Posts:
    1,288
    Just received a positive answer from Sveta Miladinov:thumb:

    The reason i pointed in the e-mail i sent was to know how effectively the correct use of some simple OS hardening prevents infections, before adding another layer of defense (a anti-malware application).

    "Hi Alex,

    This sounds like a good idea indeed. I am sure we can come up with a test scenario for this :)


    Best Regards,


    Sveta Miladinov
    Founder & CEO,
    MRG Effitas/Effitas Group"
     
    Last edited: Oct 25, 2011
  4. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Security software vendors disapproval on the way out? :argh: :D

    -edit-

    So, this brings back what I mentioned sometime ago - Sandboxie should be a candidate. ;)
     
  5. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    LOL Sandboxie would fail or pass all tests, if they run the malware inside the sandbox then it's 100% (I guess so :D, unless theres a vulnerability we don't know of) and if they run it outside then it's 0%? ;) :D

    The OS hardening part is really interesting!! Bring it MRG!!
     
  6. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    The point is: System hardening is not at the reach of the average user. The same way that Sandboxie hardening won't be either. So, if one qualifies for the test, why shouldn't the other?

    That's precisely the point. I got a pretty good feeling that either system hardening or Sandboxie would be both great, and better than the tested antimalware tools.

    And, as someone already mentioned quite a few posts back, it's not like the average user cares about these tests. So, why not show to the advanced users, in general, what Sandboxie can accomplish.

    If a test is downloading a piece of malware, and the the browser is running inside Sandboxie (obviously), and if there are start/run access restrictions, for example, no other process but the browser's own can run. End of story. ;)

    The only difference between system hardening (standard user account, SRP, AppLocker) and Sandboxie, is that one is system wide and the user per application. All you got to do is sandbox the critical applications, properly configure the sandboxes and it's done deal. :)
     
  7. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    But the thing is that i'm almost certain that SandBoxie would get 100% :D
    OS hardening on the other side can have mixed results unless they use SRP which disables everything executing.
     
  8. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Depends on the configuration. But yes, it would likely get 100%.

    As for SRP/OS-stuff. IDK about that. i mean, you can block literally everything on the system of course and be safe but that's hardly compatible.
     
  9. The Hammer

    The Hammer Registered Member

    Joined:
    May 12, 2005
    Posts:
    5,753
    Location:
    Toronto Canada
  10. Thankful

    Thankful Savings Monitor

    Joined:
    Feb 28, 2005
    Posts:
    6,871
    Location:
    New York City
    No Emsisoft?
     
  11. ichito

    ichito Registered Member

    Joined:
    Jan 14, 2011
    Posts:
    1,998
    Location:
    Poland - Cracow
    Very "nice" :blink:
    Few days later
     
  12. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    THIS!!! o_O
     
  13. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    What made EmsiSoft to withdraw?
     
  14. The Hammer

    The Hammer Registered Member

    Joined:
    May 12, 2005
    Posts:
    5,753
    Location:
    Toronto Canada
    Perhaps it was the testing change.
     
  15. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    Should I trust Malware Research group or not?
    Check this out:
    http://www.youtube.com/watch?v=uEMp9TVxdCA

    Than I found this:
    http://www.youtube.com/watch?v=AviNeuGna1s
    http://www.youtube.com/watch?v=-iSfUorRiT0

    I'm really confused, who should I trust?
    It seems to me I can't trust to anybody...
    Can anyone give me any advice at all?
    And I'm not a Comodo user, but DefenseWall user, but if this is true, it means all the tests provided by MRG are useless and should not be trusted?
    How do you know you can trust to any computer testers?
    Thanks to all.
     
  16. guest

    guest Guest

    i never trust them. it is easy to put 2-3 malwares that you are sure the apps will fail... don't rely on testing organizations, they are just informative. test your security software yourself.
     
  17. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,648
    Location:
    Milan and Seoul
    Hello there,
    keep in mind that there is a vested interest among security applications writers and critics to keep things on the anxiety level. Even if a machine gets infected it is really not end of the world as long as you have some backup strategy, at least for your private data. My systems are well protected and my choices don't change every other day, but if I were infected all of sudden my imaging software within 30 minutes max would return everything back to normal. I wish something similar would be available when we are very ill.
     
  18. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,123
    Location:
    Hawaii
    If the infection is a trojan with a keylogger payload, what then?
     
  19. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Nothing, he just looses all his lifetime savings after he did some E-Banking while he was being keylogged :D
     
  20. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,943
    Location:
    Outer space
    Emsisoft is back, they probably forgot to put it in the list.
     
  21. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    LOL yeah it is on the list now :)
    Is there a release date for these tests? :D
     
  22. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    You said that if you were infected all of sudden your imaging software within 30 minutes max would return everything back to normal. How did you do that?
     
  23. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    I guess if he finds out he is infected, he just reverts back to a previous image :)
     
  24. Dwarden

    Dwarden Registered Member

    Joined:
    Apr 11, 2003
    Posts:
    177
    Location:
    Czech Republic
    can't wait to see new test results :D :cool:
     
  25. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,648
    Location:
    Milan and Seoul
    'If' is conditional by definition, meaning the trojan has to be executed, it will have to bypass Avira, MBAM, find its way out of Sandboxie and ultimately get out unnoticed by look'n'Stop. Not a chance on my computer. Besides I don't use Windows anymore for online purchases.
     
    Last edited: Nov 10, 2011
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.