MAX AI Based Korean AV

What's your opinion about AI based AVs

  • Just a gimmick

    Votes: 24 27.0%
  • Better than Signatures

    Votes: 12 13.5%
  • The one to solve all our problems

    Votes: 2 2.2%
  • On the fence

    Votes: 9 10.1%
  • Waiting for more data

    Votes: 42 47.2%

  • Total voters
    89

Mops21

Level 35
Verified
Honorary Member
Content Creator
Oct 25, 2014
2,489
for everyone that used the Beta, there is no uninstallation entry at the usual place, go to C:/Program Files/MAX and run the uninst.exe

MAX v1 won't uninstall or stop MAX Beta but after a restart only the newest runs, so first uninstall the old then install the new.

Hi @mekelek

Have you send them this issue and any answers of it

With best Regards
Mops21
 
  • Like
Reactions: AtlBo
D

Deleted member 65228

I didn't report anything since I don't feel like this is a bug.
Yeah you're right it probably isn't even a bug. It's probably just like that by design. I am sure if they wanted to change it they could easily. So making the new version uninstall the beta and adding an uninstall entry in registry so it shows on Uninstall Programs area would be a feature request. Although I do think they should already do this for obvious reasons.
 

mekelek

Level 28
Thread author
Verified
Well-known
Feb 24, 2017
1,661
Yeah you're right it probably isn't even a bug. It's probably just like that by design. I am sure if they wanted to change it they could easily. So making the new version uninstall the beta and adding an uninstall entry in registry so it shows on Uninstall Programs area would be a feature request. Although I do think they should already do this for obvious reasons.
they might have a different version with Korean language cause remember, the Beta was in Korean.
they don't expect outside of SK people to have the old beta installed
 

Mikesierra

Level 2
Verified
Feb 26, 2018
97
I´ve been conducting one of my standard tests (simulation of polymorphism) with MAX and the results were...interestingly. My sample was composed of 91 malicious binaries gathered a few hours before by maruko. Nothing special, the usual stuff like trojans, coinminers, ransomware and all that nasties.

When I unpacked the samples MAX had a detection rate of 86/91. After using upx on the samples detection rate was going down to 70/91 but MAX submitted new IOCs to the cloud. About 10 minutes later I performed another manual scan with MAX to check whether detection was improved and indeed now 86/91 samples are being detected again. I´ll repeat my test with another sample set later to ensure correct results.

As a second opinion scanner MAX does a good job but I wouldn´t rely completely on it. I was in contact with the manufacturer a few months before and they told me that MAX is completely cloud dependent and there are/were no plans to implement an offline mode. Maybe they have changed their mind in the meantime but this is the information I got a while before.
 
Last edited:

mekelek

Level 28
Thread author
Verified
Well-known
Feb 24, 2017
1,661
I´ve been conducting one of my standard tests (simulation of polymorphism) with MAX and the results were...interestingly. My sample was composed of 91 malicious binaries gathered a few hours before by maruko. Nothing special, the usual stuff like trojans, coinminers, ransomware and all that nasties.

When I unpacked the samples MAX had a detection rate of 86/91. After using upx on the samples detection rate was going down to 70/91 but MAX submitted new IOCs to the cloud. About 10 minutes later I performed another manual scan with MAX to check whether detection was improved and indeed now 86/91 samples are being detected again. I´ll repeat my test with another sample set later to ensure correct results.

As a second opinion scanner MAX does a good job but I wouldn´t rely completely on it. I was in contact with the manufacturer a few months before and they told me that MAX is completely cloud dependent and there are/were no plans to implement an offline mode. Maybe they have changed their mind in the meantime but this is the information I got a while before.
yes i noticed this too, during malware testing after scanning the folder manually, in 3 minutes, MAX started flagging new files automatically in the same folder it scanned before.
 

brambedkar59

Level 31
Verified
Top Poster
Well-known
Apr 16, 2017
2,098
Installed it= windows couldn't boot correctly and many applications didn't start at at boot!it also uses hidden process.buggy and unstable so I removed it.
Same here. Touchpad became unresponsive several times after rebooting, with no other security soft installed on Win10. No pop-up/notifications, plus GUI won't open. Seems pretty unstable given as it's a beta version. I like the idea though.
 

minhgi

Level 2
Verified
Mar 10, 2017
60
anyone noticed that it used all of the upload bandwidth to share the cache database. I actually authenticated my email and API that when it start uploading.

Say if I have 2300 files in the cache database, I noticed that 53 were already processed. Does that meant I have 2250 more to upload. This could take are day to since it seem to be uploading whole file.
 

Attachments

  • 2018-04-04_073747.png
    2018-04-04_073747.png
    29.2 KB · Views: 432

mekelek

Level 28
Thread author
Verified
Well-known
Feb 24, 2017
1,661
anyone noticed that it used all of the upload bandwidth to share the cache database. I actually authenticated my email and API that when it start uploading.

Say if I have 2300 files in the cache database, I noticed that 53 were already processed. Does that meant I have 2250 more to upload. This could take are day to since it seem to be uploading whole file.
my guess is, it will only upload files that are unknown to the scanner.
 

minhgi

Level 2
Verified
Mar 10, 2017
60
I am pretty amaze at this software and think it have potential as a permanent anti-malware solution. At first it seem pretty heavy on the system and once it's finished gathering all the system information, the system load return to normal. A reboot is recommended so it get to scan the boot files. It only spike a little when it come across new files like when installing Norton and Voodooshield. It didn't come across any false positive flag yet. So far so good.
 
Last edited:

minhgi

Level 2
Verified
Mar 10, 2017
60
I have been testing on laptop and desktop for several days and found that it have a high idle cpu utilization. It also lock up the system when using it with malwarebytes.

My laptop AV combo with norton and Webroot hover around 3-4% at .88 Ghz. Stand alone MAX AI at 10-15% at 1.15 - 1.5 GHZ idle. not to good but other wise have good detection rate and fast learning AI engine.

Work with Norton, Avast, and Webroot as main AV
Work with Voodooshield and Zemania as second AV.
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top