Forum Home
Press F1
 
Thread ID: 111394 2010-07-25 01:11:00 SuperAntiSpyware Update Analysis kahawai chaser (3545) Press F1
Post ID Timestamp Content User
1122227 2010-07-25 01:11:00 Using SuperAntiSpyware, they seem to have almost daily 4MB updates- which seems a lot. So anyone have any ideas on how to capture, open, and test, the downloads and then compare with future downloads. Basically to verify if all these updates are significantly different and to what extent they contribute.

Anyone here done diagnostics on update comparisons and viewed the update codes for any antivirus/spyware/etc? or can suggest "real mode" updates/programs to dissect and analyse all these anti-virus updates? I realize it's academic, as I would like to diagnose updates, and possibly write about it for one of my blogs. I have done odd reviews, but so has many others, and all are much the same, nothing at another level - Update analysis.
kahawai chaser (3545)
1122228 2010-07-25 01:19:00 Surely the program tells you what has been added to the data base if you click on the link.....'frinstance from 5 minutes ago.....

Database Definition Information

The following contains information regarding the latest public database definitions available for SUPERAntiSpyware. We recommend that you always update to the latest definitions before scanning.


Definition Set Version Date / Time Size Download

Core Definitions 5262 07/24/2010 11:16AM PDT 5244KB
Download
Installer
Trace Definitions 3074 07/24/2010 11:17AM PDT 177KB


Database Definitions Updates

The following are the updates and additions for the current version of our definition files. At times, there may be several definition updates in a 24 hour period as our rapid response team analyzes samples and deploys updates as needed to protect you from the latest threats.


Database Version 5262 - 07-24-2010

Trojan.Agent/Gen-CDesc[Gen] 1 Items Added/Updated
Trojan.Agent/Gen-FakeAlert 1 Items Added/Updated
Trojan.Agent/Gen-FakeAV 1 Items Added/Updated
Trojan.Dropper/Sys-NV 1 Items Added/Updated

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Just 4 items were added to the current definition files.
Terry Porritt (14)
1122229 2010-07-25 01:32:00 Yes it does - and their website blog about it - which in my view tells nothing much. I'm not after their info as such, but a way/program/advanced technique to test the effective of update sets. I have Googled and their seems to be nothing...but simple reviews.

e.g Trojan.Agent/Gen-FakeAV and compare (problematically/graphically) with earlier and future variants. In effect, what they (i.e. the antivirus vendors) must be doing in their antivirus test/labs before they release updates. Also I want to analyse any "threads" during scanning, like graphical analysis - sort of what Microsoft SysInternals have with their multitude of free diagnostic programs.
kahawai chaser (3545)
1122230 2010-07-25 01:43:00 I see. That does not sound an easy thing to do. Terry Porritt (14)
1122231 2010-07-25 02:55:00 I'm after a way/program/advanced technique to test the effective of update sets.
.

Get the latest infections.
Scan before updates. Scan after. Compare.
pctek (84)
1122232 2010-07-25 06:51:00 Get the latest infections.
Scan before updates. Scan after. Compare.

Well I have done that a few times. But results are the same - no detections. Yet they have released yet another update today, and I want to test inherently somehow, if they are truly valid and to what extent. Or if they have simply added extension/patch of files of a previous update. They seem more concerned about users to upgrade - as advertised on their web site.
kahawai chaser (3545)
1122233 2010-07-25 21:29:00 If it doesn't find known spyware infections even after an update - then I'd ditch it. pctek (84)
1122234 2010-07-26 06:10:00 If it doesn't find known spyware infections even after an update - then I'd ditch it.

Yeah well I just have. Though I have just read numerous favorable user reviews, of which a common thread was that it detected a lot of Trojans. But why would such users have numerous Trojans? Is it a trojan remover? I certainly have not detected any, so those users must be doing something (or not) for Trojans to be on their PC's.
kahawai chaser (3545)
1