MRG Flash Test 18/10/2011

Threat Names: ZAccess, Tibia, Kbot, Ransom

Infection Vector: HTTP

Operating System: Windows 7 32-bit

Standalone Anti-Malware Applications

Program ZAccess
Tibia
Kbot
Ransom
Avira Failed Passed Passed Failed
Avast Passed
Passed
Passed Passed
AVG Passed
Passed
Passed
Failed
BitDefender Passed Failed Failed Passed
Coranti Passed Failed Failed
Passed
Emsisoft Passed Passed Passed Passed
Eset Passed Passed Passed Passed
F-Secure Passed Passed Passed Passed
G Data Passed Passed Failed Passed
Immunet Passed Passed Passed Passed
Kaspersky Passed Passed Passed Passed
Microsoft Failed Failed Failed Passed
McAfee Passed Failed Passed Passed
Norton Passed Passed Passed Failed
Panda Passed Passed Passed Passed
Webroot Passed Passed Failed Failed
Sunbelt Passed Passed Passed Passed

Complementary Anti-Malware applications

Program ZAccess
Tibia
Kbot
Ransom
Malwarebytes
Failed Passed Failed Passed
SUPERAntispyware
Failed Failed Failed Failed

HIPS, Behavior Blockers, Anti-Loggers

Program ZAccess
Tibia Kbot
Ransom
DefenseWall
Passed Passed Passed Passed
Zemana
Passed Passed Passed Passed

On Demand only

Program ZAccess
Tibia
Kbot
Ransom
Zemana Anti-Malware Passed Passed Passed Passed

Quick assessment of Webroot SecureAnywhere

Webroots’ latest security product “SecureAnywhere” was released yesterday. It uses technology gained from their acquisition of Prevx  so is a departure from their previous offerings.

We have received several requests from Prevx users that we run a quick test of the new product. Due to workload we have only had time to test the anti-logging / browser security component, but will assess its antimalware capabilities in a few days time.

Download Report: Quick assessment of Webroot SecureAnywhere

MRG Flash Test 30/09/2011 Part 2

Threat Names: SpyEye, TDSS, VBInject, Zeus

Infection Vector: HTTP

Operating System: Windows 7 32-bit

Standalone Anti-Malware Applications

Program SpyEye
TDSS
VBInject
Zeus
Avira Passed Passed Passed Passed
Avast Passed
Passed
Passed Passed
AVG Passed
Passed
Passed
Passed
BitDefender Failed Failed Passed Passed
Coranti Failed Passed Passed
Passed
Emsisoft Passed Passed Passed Passed
Eset Passed Passed Passed Passed
F-Secure Failed Failed Passed Passed
G Data Passed Passed Passed Passed
Immunet Passed Passed Passed Passed
Kaspersky Passed Passed Passed Passed
Microsoft Passed Passed Failed Passed
McAfee Passed Passed Failed Passed
Norton Passed Passed Passed Passed
Panda Passed Passed Passed Passed
Prevx Passed Passed Failed Passed
Sunbelt Passed Passed Passed Passed

Complementary Anti-Malware applications

Program SpyEye
TDSS
VBInject
Zeus
Malwarebytes
Passed Passed Passed Passed
SUPERAntispyware
Failed Failed Failed Failed

HIPS, Behavior Blockers, Anti-Loggers

Program SpyEye
TDSS VBInject
Zeus
DefenseWall
Passed Passed Passed Passed
Zemana
Passed Passed Passed Passed

On Demand only

Program SpyEye
TDSS
VBInject
Zeus
Zemana Anti-Malware Passed Passed Passed Passed

MRG Flash Test 30/09/2011 Part 1

Threat Names: Buzus, Carberp, Monder, Ruskill

Infection Vector: HTTP

Operating System: Windows 7 32-bit

Standalone Anti-Malware Applications

Program Buzus
Carberp
Monder
Ruskill
Avira Passed Passed Passed Passed
Avast Passed
Passed
Passed Passed
AVG Failed
Passed
Passed
Passed
BitDefender Passed Passed Failed Passed
Coranti Passed Passed Failed
Passed
Emsisoft Passed Passed Passed Passed
Eset Passed Passed Passed Passed
F-Secure Passed Passed Passed Passed
G Data Passed Passed Passed Passed
Immunet Passed Passed Passed Passed
Kaspersky Passed Passed Passed Passed
Microsoft Failed Passed Failed Failed
McAfee Failed Passed Passed Passed
Norton Passed Passed Passed Passed
Panda Passed Passed Passed Passed
Prevx Passed Failed Passed Failed
Sunbelt Passed Passed Passed Passed

Complementary Anti-Malware applications

Program Buzus
Carberp
Monder
Ruskill
Malwarebytes
Passed Passed Passed Passed
SUPERAntispyware
Failed Failed Failed Failed

HIPS, Behavior Blockers, Anti-Loggers

Program Buzus
Carberp Monder
Ruskill
DefenseWall
Passed Passed Passed Passed
Zemana
Passed Passed Passed Passed

On Demand only

Program Buzus
Carberp
Monder
Ruskill
Zemana Anti-Malware Passed Passed Passed Passed

MRG Effitas Antilogger & Browser Security Test RESULTS

We have just published our Antilogger & Browser Security Test results. The report assesses the ability of eleven dedicated antilogger and browser security applications to prevent the new MRG Effitas Crimeware Simulator capturing user credentials entered in to an online banking site.

You can download the test report by visiting MRG Effitas Tests Section

MRG Flash Test 26/07/2011

Threat Names: 4 Trojan Ransom Samples

Infection Vector: HTTP

Operating System: Windows 7 32-bit

Standalone Anti-Malware Applications

Program Ransom 1
Ransom 2
Ransom 3
Ransom 4
Avira Failed Failed Failed Failed
Avast Failed
Failed
Failed Failed
AVG Failed
Failed
Failed
Failed
BitDefender Failed Failed Failed Failed
Coranti Failed Failed Failed
Failed
Emsisoft Passed Passed Passed Passed
Eset Failed Failed Failed Failed
F-Secure Failed Failed Failed Failed
G Data Failed Failed Failed Failed
Immunet Failed Failed Failed Failed
Kaspersky Passed Passed Passed Passed
Microsoft Failed Failed Failed Failed
McAfee Failed Failed Failed Failed
Norton Failed Failed Failed Failed
Panda Passed Passed Failed Failed
Prevx Passed Passed Passed Passed
Sunbelt Failed Failed Failed Failed

Complementary Anti-Malware applications

Program Ransom1
Ransom2
Ransom3
Ransom4
Malwarebytes
Passed Passed Passed Passed
SUPERAntispyware
Failed Failed Failed Failed

HIPS, Behavior Blockers, Anti-Loggers

Program Ransom1
Ransom2 Ransom3
Ransom4
DefenseWall
Passed Passed Passed Passed
Zemana
Passed Passed Passed Passed

On Demand only

Program Ransom 1
Ransom 2
Ransom 3
Ransom 4
Zemana Anti-Malware Passed Passed Passed Passed

MRG Flash Test 22/07/2011

Threat Names: Banker, Inject, Qhost, Zeus

Infection Vector: HTTP

Operating System: Windows 7 32-bit

Standalone Anti-Malware Applications

Program Banker
Inject Qhost
Zeus
Avira Failed Failed Passed Passed
Avast Passed
Passed
Passed Passed
AVG Passed
Failed
Failed
Passed
BitDefender Passed Passed Passed Passed
Coranti Passed Passed Passed
Passed
Emsisoft Passed Passed Passed Passed
Eset Passed Failed Passed Passed
F-Secure Passed Passed Passed Passed
G Data Passed Passed Passed Passed
Immunet Passed Passed Passed Passed
Kaspersky Passed Passed Passed Passed
Microsoft Failed Failed Failed Passed
McAfee Passed Failed Failed Failed
Norton Passed Failed Failed Passed
Panda Passed Passed Passed Passed
Prevx Failed Failed Failed Passed
Sunbelt Passed Passed Passed Passed

Complementary Anti-Malware applications

Program Banker
Inject
Qhost
Zeus
Malwarebytes
Passed Passed Passed Passed
SUPERAntispyware
Failed Failed Failed Failed

HIPS, Behavior Blockers, Anti-Loggers

Program Banker
Inject
Qhost
Zeus
DefenseWall
Passed Passed Passed Passed
Zemana
Passed Passed Failed Passed

On Demand only

Program Banker
Inject
Qhost
Zeus
Zemana Anti-Malware Passed Passed Passed Passed

MRG Flash Test 19/07/2011

Threat Names: Jorik, SpyEye, Ransom, StartPage

Infection Vector: HTTP

Operating System: Windows 7 32-bit

Standalone Anti-Malware Applications

Program Jorik
SpyEye Ransom
StartPage
Avira Passed Passed Passed Passed
Avast Passed
Passed
Passed Passed
AVG Passed
Passed
Passed
Passed
BitDefender Passed Failed Failed Failed
Coranti Passed Failed Passed
Failed
Emsisoft Passed Passed Passed Passed
Eset Passed Passed Passed Failed
F-Secure Passed Failed Failed Failed
G Data Passed Failed Passed Failed
Immunet Passed Passed Passed Passed
Kaspersky Passed Failed Passed Passed
Microsoft Failed Passed Passed Failed
McAfee Failed Failed Failed Passed
Norton Passed Passed Failed Failed
Panda Passed Passed Passed Passed
Prevx Failed Passed Failed Failed
Sunbelt Passed Passed Passed Passed

Complementary Anti-Malware applications

Program Jorik
SpyEye
Ransom
StartPage
Malwarebytes
Passed Failed Passed Passed
SUPERAntispyware
Failed Failed Failed Failed

HIPS, Behavior Blockers, Anti-Loggers

Program Jorik
SpyEye
Ransom
StartPage
DefenseWall
Passed Passed Passed Passed
Zemana
Passed Passed Passed Passed

On Demand only

Program Jorik
SpyEye
Ransom
StartPage
Zemana Anti-Malware Passed Passed Passed Passed

MRG Flash Test 29/06/2011

Threat Names: Zeus, SpyEye, Banker, Banbra

Infection Vector: HTTP

Operating System: Windows 7 32-bit

Standalone Anti-Malware Applications

Program Zeus
SpyEye Banker
Banbra
Avira Failed Passed Failed Passed
Avast Passed
Passesd
Passed Passed
AVG Passed
Passed
Failed
Passed
BitDefender Passed Passed Failed Failed
Coranti Passed Passed Failed
Failed
Emsisoft Passed Passed Passed Passed
Eset Passed Failed Passed Passed
F-Secure Passed Passed Failed Failed
G Data Passed Passed Failed Failed
Immunet Passed Passed Failed Failed
Kaspersky Passed Passed Failed Passed
Microsoft Failed Failed Failed Failed
McAfee Failed Passed Failed Passed
Norton Passed Passed Failed Failed
Panda Passed Failed Failed Failed
Prevx Passed Passed Passed Failed
Sunbelt Passed Failed Failed Failed

Complementary Anti-Malware applications

Program Zeus
SpyEye
Banker
Banbra
Malwarebytes
Passed Passed Passed Passed
SUPERAntispyware
Failed Failed Failed Passed

HIPS, Behavior Blockers, Anti-Loggers

Program Zeus
SpyEye
Banker
Banbra
DefenseWall
Passed Passed Passed Passed
Zemana
Passed Passed Passed Failed

On Demand only

Program Zeus
SpyEye
Banker
Banbra
Zemana Anti-Malware Passed Passed Failed Failed

Malware Research Group Project 28 – Results

Malware Research Group Project 28


Online Banking Security Project

 

Twelve months on from our Online Banking Security Project, we have just completed our latest Online Banking Security Report.

In this report we assess the efficacy of nineteen internet security applications and nine dedicated browser security / anti-logging applications against our latest financial malware simulator on both 32 and 64 bit versions of Windows 7.

You can download the Test Report by visiting MRG Tests section.