MRG Flash Tests 2011

Discussion in 'other anti-virus software' started by LODBROK, Jan 27, 2011.

Thread Status:
Not open for further replies.
  1. 3x0gR13N

    3x0gR13N Registered Member

    So the screen was still locked after reboot?
    Ah, I see that DW has a conditional pass now. I take it that everything was fine after a reboot?
     
    Last edited: Feb 7, 2011
  2. Ilya Rabinovich

    Ilya Rabinovich Developer

    1. The Desktop locks up because of "topmost" window, but Win-Alt-A is working as it should, terminating malicious process.
    2. After reboot, everything's working normal way.

    In fact, I made some changes for 3.10 version, not to allow to apply the "topmost" style for untrusted windows, but will check out how it's compatible with games running untrusted.
     
  3. Thankful

    Thankful Savings Monitor

  4. 1000db

    1000db Registered Member

    Is this the first flash test that BluePoint failed? Maybe TDSS has a new execution method that BP's default deny doesn't cover.
     
  5. De Hollander

    De Hollander Registered Member

    They passed the previous nine tests
     
  6. Noob

    Noob Registered Member

    Good to see EAM back on track :D
     
  7. The Hammer

    The Hammer Registered Member

    Yes it is.:)
     
  8. Kernelwars

    Kernelwars Registered Member

    So is Immunet protect..:)
     
  9. Triple Helix

    Triple Helix Specialist

    Prevx is always there saying Passed!

    TH ;)
     
  10. De Hollander

    De Hollander Registered Member

    :) Indeed, and a couple of other products.
     
  11. Dermot7

    Dermot7 Registered Member

  12. Iangh

    Iangh Registered Member

    MBAM isn't a full-blown a-v but still does a great job with zero-day.

    How is that?

    I thought they focused on getting rid of known nasty malware, yet it seems they can also do zero-day.
     
  13. nosirrah

    nosirrah Malware Fighter

    Research and tech is targeted towards anything that AVs do not do well against, this test actually favors both our tech and research.
     
  14. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

  15. Noob

    Noob Registered Member

    MBAM is also a very good cleaner :D
     
  16. LODBROK

    LODBROK Guest

    According to the MRG forum, they're using MBAM Full (pro, paid, whatever) with Protection enabled. They don't say whether the Pass is a result of an IP block or a detection. Either way, the performance of MBAM Full is spectacular. It must be specifically recognized though that the free MBAM has no relevance whatsoever within the context of these MRG tests.
     
  17. Thankful

    Thankful Savings Monitor

  18. Marcos

    Marcos Eset Staff Account

    Really strange, I wonder what they actually tested; whether it was an exe dropper or a sys driver. All recent TDSS rootkits were detected by ESET which cannot be said about some other AVs that allegedly detected it in the "test". Any chance of getting the appropriate MD5 for verification?
     
  19. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    In the final report of MRG Flash tests 2010, they said that IP blocking wasn't used, so it's all detection.

    I think MRG sends the samples tested to security vendors if they request them, you can contact them here:
    http://malwareresearchgroup.com/contact-us/
     
  20. Thankful

    Thankful Savings Monitor

  21. LODBROK

    LODBROK Guest

    True. But since they haven't revealed their current methodology my observation, "They don't say..." can be held as accurate at this point in time as your conclusion (as logical as it might be) that IP blocking isn't in actual use is mere speculation.

    They really scatter their stuff on that MRG site and I can't find where it is when explaining the gap in testing from Dec 9 to Jan 27 that significant changes were being made (they may have even posted it up here). There's a Jan 27 posting in their forum, "Methodology and additional information will be available later today." I'm burned out from navigating their site; if anyone can find that data, post up a link.
     
  22. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    I made a preliminary summary for the 2011 test, but it's only 14 tests so far.

    EDIT:Latest test just posted by Thankful is not included in my summary.
    EDIT2: Posted as image, layout was screwed up.. :rolleyes:
     

    Attached Files:

    Last edited: Feb 21, 2011
  23. LODBROK

    LODBROK Guest

    As a long-time Zemana user, I'm disappointed by AntiLogger's occasional failure but I'd be a fool to expect it to be perfect. I'll have to be satisfied with "almost perfect." ;)

    But I can't help but wonder if my settings overriding the defaults would result in a Passed in this series of MRG Flash tests. I disable "Let it run but block..." and "Block an app...but don't terminate it" and "Use the Internet to check...signature info" and "Use ZWLST" while setting "Ask for confirmation" for all. I think that's much tighter than default but definitely too restrictive and chatty for the mass market.
     
  24. trjam

    trjam Registered Member

    First post
     
  25. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Why did Prevx pass only partially today? And were the two samples Zemana failed digitally signed?
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice