I'm testing AV products against zeroday malware

Discussion in 'other anti-virus software' started by bradtech, Oct 12, 2009.

Thread Status:
Not open for further replies.
  1. xpsunny

    xpsunny Registered Member

    Joined:
    Jul 16, 2006
    Posts:
    163
    I would like to see Microsoft Secuirty Essentials...
     
  2. sbwhiteman

    sbwhiteman Registered Member

    Joined:
    Jul 20, 2009
    Posts:
    88
    Thanks for your reviews, Brad. I see you tested PC Tools Spyware Doctor with Antivirus, which includes BehaviorGuard. As I understand it, BehaviorGuard is a cut-down version of Threatfire. How about testing Threatfire on its own?

    As far as that goes, if you'd be willing, I'd love to see the results with Threatfire paired with free signature-based products, like Avira and Avast. (I understand there may still be a conflict between Threatfire and AVG.) When I configure security for friends, I pair Threatfire with one of these and assume it's a solid setup. Would love to see what your testing turns up.

    Thanks.
    Steve
     
    Last edited: Oct 13, 2009
  3. smage

    smage Registered Member

    Joined:
    Sep 13, 2008
    Posts:
    378
    Hi thanks for your reviews.
    I would like to see Symantec and Comodo.
     
  4. InfinityAz

    InfinityAz Registered Member

    Joined:
    Jul 23, 2005
    Posts:
    828
    Location:
    Arizona
    All great points from an expert and further points out the need for testing to be:
    • Unbiased
    • Structured and based on standards (scoring, etc.)
    • Based on the scientific method (i.e., testing methodology)
     
  5. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,077
    Location:
    DC Metro Area
    Norton Internet Security 2010 please.
     
  6. lifetweaker

    lifetweaker Registered Member

    Joined:
    Jun 24, 2009
    Posts:
    63
    Location:
    127.0.0.1
    Subscribed :D

    I would also like to see Microsoft Security Essentials, and maybe the latest McAfee o_O .
     
  7. Baz_kasp

    Baz_kasp Registered Member

    Joined:
    May 1, 2008
    Posts:
    593
    Location:
    London
    Regarding your test of KAV- the IRCBOT that "got by" didn't technically "get by"...kav correctly deleted the .reg file that would add the ircbot to run at the computer startup (if you notice the backdoor.win32.ircbot popup as you run it....e.g. after reboot it is inactive), and I am more than sure that the actual IRC client is detected using the "riskware" detections (other threats) which isn't enabled by default....because the IRC client itself is a legitimate application, which can be misused, as in this case.
     
  8. simisg

    simisg Registered Member

    Joined:
    Nov 6, 2008
    Posts:
    412
    Location:
    Greece
    i must say i have test all these products before against zero threats and only threatfire stop it all completely there is not a traditional antivirus stop it all !!
     
  9. bradtech

    bradtech Guest

    Thank you for the information
     
  10. bradtech

    bradtech Guest

    Mcafee with Artemis is something I'd like to see in action. I have personally uploaded zero days to virusltotal and witnessed it, and maybe one other AV vendor the only ones detecting it.. I just hope their client has improved.
     
  11. bradtech

    bradtech Guest

    Traditional AVs that have implemented some kind of "behavior" based detection seem to do well if they can get the "pattern" that most of these zero day fake avs, and malware perform..
     
  12. bradtech

    bradtech Guest

    I'd also like to add that I'm not a professional tester.. These are my first batches of video reviews.. I mainly have done them because it's my job function at work to guard against these.. Any suggestions on testing procedures from anyone will only help me do better so please feel free to critique. Thanks to the Sunbelt Vipre rep above.. I was really impressed with Vipre.. I didn't expect any product to block everything I threw against them. I do submit the samples to a lot of different companies..
     
  13. Coolio10

    Coolio10 Registered Member

    Joined:
    Sep 1, 2006
    Posts:
    1,124
    So who's winning?
     
  14. bradtech

    bradtech Guest

    I am testing Immunet Protect
     
  15. YeOldeStonecat

    YeOldeStonecat Registered Member

    Joined:
    Apr 25, 2005
    Posts:
    2,345
    Location:
    Along the Shorelines somewhere in New England
    Another vote to see Microsoft Security Essentials tossed into the mix. Quite a few posts up above asking for it, but you're dodging it.
     
  16. Miyagi

    Miyagi Registered Member

    Joined:
    Mar 12, 2005
    Posts:
    426
    Location:
    None
    I agree but wouldn't it be more enticing to see the registry garbage to be removed too? My question is why just wash a car but not vacuum it?
     
  17. bradtech

    bradtech Guest

    I just started today :)
    I have been testing it at work, and impressed thus far.. I am just starting at the first posts and working my way down :ninja:
     
  18. bradtech

    bradtech Guest

    A lot of AV makers just remove the necessary stuff, and leave junk behind.. I have noticed a lot of the traditional "Spyware Only" tools like PC Tools, Malwarebytes, and etc remove the unneccessary garbage also..
     
  19. bradtech

    bradtech Guest

    On a side note I am making all the videos just one video instead of 2 or 4.. I was not sure how large the files were going to be, and youtubes limit file size.. It seems that I can upload one video, and be fine..
     
  20. bradtech

    bradtech Guest

    Now starting F-Secure 2010 AV
     
  21. Baz_kasp

    Baz_kasp Registered Member

    Joined:
    May 1, 2008
    Posts:
    593
    Location:
    London
    Because removing registry entries can trash a computer.....and it is time consuming cross checking each one to make sure it legit/bad
     
  22. Miyagi

    Miyagi Registered Member

    Joined:
    Mar 12, 2005
    Posts:
    426
    Location:
    None
    Thank you bradtech and Baz_kasp.
     
  23. bradtech

    bradtech Guest

    No problem fellow Malware Warrior
     
  24. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    there was a time when I would love to have joined a thread like this. Ahh, just sticking to what I use for now own. Go get them Brad. We wont know, if you dont try.:thumb:
     
  25. bradtech

    bradtech Guest

    Holy crap!!!! Great product
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.