CIS Froozen highly infected machine

Discussion in 'other anti-virus software' started by guest, Dec 1, 2008.

Thread Status:
Not open for further replies.
  1. guest

    guest Guest

    Attached Files:

  2. guest

    guest Guest

    Now

    Test 3: Norton Antivirus 2009
     

    Attached Files:

    • 1.png
      1.png
      File size:
      149.4 KB
      Views:
      6
  3. JacquesPVX

    JacquesPVX Registered Member

    Joined:
    Mar 7, 2006
    Posts:
    2
    Hey Guest.

    Thanks for the test. Do you have any opinion about the cleanup procedure that you can share with us ?

    Regards,

    Jacques/Prevx
     
  4. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    So did Norton do anything or not? I just see the startup.

    It's very possible that only the Kaspersky GUI was closed, and you still could use the AV.
     
  5. C.S.J

    C.S.J Massive Poster

    Joined:
    Oct 16, 2006
    Posts:
    5,029
    Location:
    this forum is biased!
    i can, with my past testing of it.

    it requires far too many reboots, neccessary?

    scan > find 'some' > reboot.

    then scan > find 'some more' > reboot.

    this can go on forever, as is shown in this test-thread aswell.

    this is the only thing i dislike about the software so-far.

    (even though i am aware that its highly unlikely that any of my machines that i use will ever be so-highly-infected anyway)
     
  6. guest

    guest Guest

    bad points;

    1. Prevx EDGE requires internet connection, it is disadvantage on infected system. malware can be block internet. please look at attachment

    2. every malware popup over the all security soft's popup. it is bad.

    3. i dont like restart same as C.S.J. restart and restart again.

    4. Some trace files cant be deleted or cant be catched

    5. On demand scanner doesnt look like powerfull. please look at attachment


    good points;

    1. fast
    2. light
    3. better deletion than some av software
    4. there is no any blue screen, crash
     

    Attached Files:

  7. guest

    guest Guest

    Attached Files:

    • 36.png
      36.png
      File size:
      298.4 KB
      Views:
      5
  8. guest

    guest Guest

    Attached Files:

    • 1.jpg
      1.jpg
      File size:
      109.4 KB
      Views:
      2
  9. JacquesPVX

    JacquesPVX Registered Member

    Joined:
    Mar 7, 2006
    Posts:
    2
    Hey again,

    Thanks for the test and feedback. I can see that the reboots can be an issue to usability, but in some cases this is needed especially in this case. It’s like eating away at a big mountain, bit by bit. I do appreciate that it can get frustrating. We will see what we can do to make this process simpler. On the other hand, I see we missed some things, which we will correct, but thanks again for taking the time to do this, as I am always keen to see how this experience is for others.

    Also, we are working on doing a better job on the registry cleaning, so that is an upcoming improvement.

    Regards,

    Jacques
     
  10. guest

    guest Guest

    Attached Files:

    • 8.png
      8.png
      File size:
      246.8 KB
      Views:
      1
  11. guest

    guest Guest

    THE END

    hi everybody.
    my test are finished.
    i wont test more.
    i tested it only for fun. i am not virus makers, antivirus makers, virus analizer,...
    this is my hobby.
    i tested many software, i cant say they are good, they are bad.

    there is not perfect software.

    test machine is not normal for many normal user.
    it is highly infected. reel life is different.

    but removal problem is big problem many times.
    many user sad that "my av alert me for virus, but it cant delete it"

    this is important problem.
    i hope av vendors know and interested it.


    i must say;

    1. thank you emsisoft for double scan technology. it is very good malware dedector. it is good removal but has some problems

    with some malware.
    2. Drive senty is interesting behavioral blocker, it must be tested again with different malware. but its dialog popup has a
    less information for the malware.
    3. micropoint is unstable.
    4. prevx EDGE is good but too many restart, requires net connection, and some others disadvantage.
    5. i hope comodo correct to problems and i can test again. i believe this project. thank you MELİH.
    6. Avast boot scan is great.
    7. Eset is very good removal for this test
    8. All AV run (on the windows start) too late. malware can load faster than av.
    9. Malware alert over the av alert.

    Test metodology;
    1. i downloaded vmware workstation.
    2. installed winXP SP3 and updates
    3. found some malware (random)
    4. run malware in the test systems.
    5. vmware snapshoot

    6. run antivirus
    7. report.

    * i am not professional av testers, this test simulate normal av user.
    * i uploaded all malware files to rapidshare, and sent all links to av vendors
    * test is not easy job. i want to say thank you to all testers.

    i enjoyed it. i hope you do.


    hey djohn, open the new beer for me. joob is finished.
     
  12. mvdu

    mvdu Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    1,166
    Location:
    PA
    Re: THE END

    Again, how did Norton compare with the others? I could only see the one screenshot, as the .rar was empty.
     
    Last edited: Dec 3, 2008
  13. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    Can anyone post info on the Dr. Web Cure It scan test? I guess I reached my rapidshare free limit already.

    thanks
     
  14. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    Thank you Guest for your tests i hope you had fun makeing them ^^
     
  15. Kayracc

    Kayracc Registered Member

    Joined:
    Jul 5, 2008
    Posts:
    96

    i concur, good work may, interesting reads all around :)
     
  16. tsec

    tsec Registered Member

    Joined:
    Nov 18, 2008
    Posts:
    181
    Very interesting indeed.

    Thanks for your efforts, guest :)
     
  17. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Thanks guest for testing much much appreciated.:thumb:
     
  18. rseek

    rseek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    8
    Thanks Guest for the test.

    I looked at the cureit snapshots.Can u pls give the results in your words.I cannot make out anything from the screen shots.
     
  19. guest

    guest Guest

    it isnt emty. download again.

    i crashed. cant launch.

    Thank you too. i hope everybody like it.

    yeah. but it was heavy.
    ---
    what is yours idea?
    For tests? is it too heavy?
    For software? it is successfully or ...?
     
  20. vijayind

    vijayind Registered Member

    Joined:
    Aug 9, 2008
    Posts:
    1,413
    Thanks again, Guest.

    Just a heads up, on Norton 2009.Realtime and other components start kicking in after reboot only ( see remove-malware.com video also by Matt. Same issue).
    Plus I think you should enable "early load" option for real-time scanner. Which will make its start before all malware.
     
  21. Saraceno

    Saraceno Registered Member

    Joined:
    Mar 24, 2008
    Posts:
    2,405
    Captain guest, great stuff steering the malware ship. ;) :thumb:

    I noticed cureit crashed and norton wouldn't start. Prevx removed a number of threats, but suffered from a broken internet connection.

    This is some great testing and your screenshots have shown the mayhem that results when a user downloads malware, which then bring along many of their friends.

    You've tested the majority of popular products. How do you think ThreatFire would go, quarantining active processes, then running a scan with its integrated AV?

    Maybe, when you have the time (although you've given up heaps of your time already), you could throw in a free combo, say ThreatFire (with its AV scan) + a SAS/MBAM scan! :) Hey, maybe they all won't start so my 'combo' idea is no good!
     
  22. guest

    guest Guest

    i tested it with default settings.
    Many normal user dont know and use "early load".
    i have no time for repeat testing, but may be later i can try again with enable this fuction.
     
  23. guest

    guest Guest

    it is a good idea. Infected machine Vs. Security Combo. But it is hard job. more time, more effort.

    i think behavioral analizers mission are different. my machine is not good for this concept. Maybe i can test them with real dangerous virus, backdoor, rootkit.
    Fake av vs Behavioral blocker is not true test.
     
  24. Saraceno

    Saraceno Registered Member

    Joined:
    Mar 24, 2008
    Posts:
    2,405
    All ok. :thumb:

    I think you showed that almost every product installed after a system has been infected will struggle with these new fake AVs and malware programs which seem to dig their roots in deep.

    And the worrying part is, the majority of users don't even have the programs you tested installed in the first place. If they had any of the programs installed on a clean system to begin with, there would be a much better result/outcome.

    Instead, most average day-to-day users seem to rely on not using any security programs, and later rush out to buy something after the system has gone bizerk, or thinking they won't have a problem because they have an AV, although its subscription and updates are dated/expired several months or years ago.
     
  25. vijayind

    vijayind Registered Member

    Joined:
    Aug 9, 2008
    Posts:
    1,413
    Sure :thumb:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.