MRG Flash Tests 2011

Discussion in 'other anti-virus software' started by LODBROK, Jan 27, 2011.

Thread Status:
Not open for further replies.
  1. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    spotless, thanks to FD-ISR.;)
     
  2. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    With the frequent changes you make...:argh:
     
  3. Rompin Raider

    Rompin Raider Registered Member

    Joined:
    May 6, 2010
    Posts:
    1,254
    Location:
    Texas
    HIPS okay? I have my wife's pc and son's pc at college both on ESET 5....I alternate back and forth with it...my pet peeve is that it must be light on the system and ESET 5 seems to be at the top, on Win 7 anyway. Thanks :thumb:
     
  4. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    So we will start 2012 with Eset Trjam! :D
    Hahahaha back on topic, can't wait to see more releases of the tests :ninja:
     
  5. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,791
    Single Product Flash Test – Symantec Norton Antivirus
    For those interested Norton scored a 92% on MRG's latest test.......
    http://malwareresearchgroup.com/
     
  6. The Hammer

    The Hammer Registered Member

    Joined:
    May 12, 2005
    Posts:
    5,753
    Location:
    Toronto Canada
    Always interested thanks.
     
  7. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Woa Norton did pretty well actually!! :D
     
  8. ALiasEX

    ALiasEX Registered Member

    Joined:
    Mar 30, 2010
    Posts:
    240
    How on earth did they test 19.1.1.3? If they ran a LiveUpdate 19.2.0.10 would have been installed.
     
  9. King Grub

    King Grub Registered Member

    Joined:
    Sep 12, 2006
    Posts:
    818
    Version 19.1.1.3 is the version you get if you download the latest version from the official http://www.norton.com/nis12. Sounds weird - didn't they update the product before testing?
     
  10. Sveta MRG

    Sveta MRG Registered Member

    Joined:
    Aug 16, 2009
    Posts:
    209
    Yes we tested the 19.2.0.10 version, I just made a mistake and posted the version that was downloaded, all sorted now.


    Regards,
    Sveta
     
  11. King Grub

    King Grub Registered Member

    Joined:
    Sep 12, 2006
    Posts:
    818
    Cool, thanks for the update. :thumb:
     
  12. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
  13. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    Nice showing by Ikarus. Is anyone using this program? I use Emsi which I am very satisfied with...I am assuming Emsi uses the latest Ikarus scanning engine? Also, does Ikarus incorporate any of the Emsi products in their anti-virus?

    Do any of these 50 malware sample tests have criticism of some tests being easier to score well on than others? If so I with the MRG would be able to rate tests as easy/medium/difficult to pass...any thoughts?
     
  14. Sveta MRG

    Sveta MRG Registered Member

    Joined:
    Aug 16, 2009
    Posts:
    209
    Hi,

    These tests are created to show effectiveness of chosen security product against 0-day malware threats that are released into the wild not more then 90 minutes before the test starts.

    I can't say that any of these tests is easier then the other one (or tougher), we tend to use only the widest spread malware samples in their earliest stage. If you take a closer look, you will notice that we are using about 120 of the most common threats that users get infected with. Each of the samples used has A LOT of variants that will be released into the wild over the next few hours...(I am sure that you know how this works).

    Why only 50 samples? Well the way modern AM applications work, there is a strong chance (from our experience 9/10 times) that if they catch one sample, they will catch most of the variants too (if not all). This is mostly thanks to generic, heuristic and behavior detection methods.


    Regards,
    Sveta
     
  15. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  16. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,491
    Nice IKARUS, i would still got for EAM since it has a bit more oomph :D (Behavior Blocker, Surf Protection, Emsisoft engine) :rolleyes:
     
  17. skokospa

    skokospa Registered Member

    Joined:
    Apr 1, 2009
    Posts:
    177
    Location:
    Srbija
    I use and I am satisfied.
     
  18. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  19. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    I'd like to see a grading system for the malware used,therefore a product failing against 2 less serious threats would still be graded "better" than one failing against a single,more damaging malware.

    That said,I'm pleased to see that you're using malware samples that people might actually encounter in the real World,rather than obscure stuff that the average user would never realistically come across.
     
  20. pianistaPL

    pianistaPL Registered Member

    Joined:
    Jan 20, 2012
    Posts:
    9
    Ikarus=amazing protection :)

    @Sveta MRG
    When will you do Kaspersky and Panda test?

    Sorry for my bad english
    Cheers
     
  21. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    What would you consider a damaging threat? Consider the following scenario:

    1) User A gets infected with a piece of malware lurking in user land. This piece of malware, obviously isn't detected by the antivirus the user has. This piece of malware steals bank credencials. User A does perform on-line transactions.

    Question: Damaging?

    2) User B gets infected with a piece of malware that gets kernel access. This piece of malware, obviously isn't detected by the antivirus the user has either. This piece of malware also steals bank credentials, but User B never performs on-line transactions.

    Question: Damaging?

    :D
     
  22. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Great to see continued activity.
     
  23. carat

    carat Guest

    ... but Ikarus=amazing false positives as well :(
     
  24. pianistaPL

    pianistaPL Registered Member

    Joined:
    Jan 20, 2012
    Posts:
    9
    Can not have everything, and thinking the user first check the file that Ikarus detected, for example on virustotal.com
     
  25. Sveta MRG

    Sveta MRG Registered Member

    Joined:
    Aug 16, 2009
    Posts:
    209
    Hello everybody,


    Let me start by saying that we plan to use almost all of the known AM applications in these single product Flash Tests. We are always open for suggestions tho;)

    When it comes to categorizing samples by their threat level and by that I mean Low, Medium, High and Severe, this is a good idea indeed although we tend to use only High and Severe ones in our tests. One thing that we can talk about is how to label certain samples, I am sure that most of you have seen how one vendor label something as Medium Risk, ofter one as High and third one as Severe. Now, you may think "well let the vendors do their own thing and you do it like you think is right", and this would be OK, but will the vendors agree with this....lets take Rogues for example, most are labeled as Low Risk, but are they? How can some malware that uses MiTB attack method be labled as Medium Risk? These are just a few examples but there are many more.

    A lot of cool tests/reports coming this year so stay tuned:)

    Regards,
    Sveta
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.