Is there an AV that doesn't run in real time?

Discussion in 'other anti-virus software' started by Mortal Raptor, Oct 31, 2014.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,166
    Location:
    Texas
    Birds of a feather don't you know. :)
     
  2. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,440
    Location:
    Slovakia
    Herd Protect is pretty questionable product, not just legal issues, but its detection as well. Not to mention, that there are only about 20 real AV engines around, the rest is just re-branded or a combination of some of those 20, so saying 68 engines is like saying CocaCola is produces by 3 companies, because there is normal, zero and diet.

    http://malwaretips.com/threads/herd...anner-with-68-scan-engines.20519/#post-148759
    https://www.wilderssecurity.com/threads/i-am-liking-herd-protect-more.362804/
     
  3. snippits

    snippits Registered Member

    Joined:
    Jun 19, 2011
    Posts:
    201
    Might not be what you are looking for, but calling Hitman Pro a half baked cookie is nonsense.
     
  4. Mortal Raptor

    Mortal Raptor Banned

    Joined:
    Oct 6, 2014
    Posts:
    1,013
    Indeed! that's what I love about this forum, when it comes to security products, there is no other forum that even comes close! I have never heard of herdProtect! :)
     
  5. Mortal Raptor

    Mortal Raptor Banned

    Joined:
    Oct 6, 2014
    Posts:
    1,013
    Sorry but if a product can detect but not remove, it is a half baked cookie in my books. I know you can pay to have them removed, I wouldn't mind paying if it was a one time payment but subscription based, no way for such a product, might as well just get an Antivirus then

    Quote from this thread which is exactly what I think: https://www.wilderssecurity.com/goto/post?id=2363223#post-2363223

    "No permissions needed, period. Not sure why people keep saying he does. Personally I am excited. HMP is dead to me, only 2 engines, and fairly expensive, it serves no real purpose anymore. HP replaces it - immediately."
     
    Last edited: Nov 1, 2014
  6. siketa

    siketa Registered Member

    Joined:
    Oct 25, 2012
    Posts:
    2,718
    Location:
    Gaia
    Actually, it does not have many FPs.
    Those are behavior blocker alerts for some apps that are not digitally signed and are less known and used.
     
  7. Mortal Raptor

    Mortal Raptor Banned

    Joined:
    Oct 6, 2014
    Posts:
    1,013
    you're right, my bad I should've mentioned, no FPs, but man that behavioral blocker drove me nuts when I had a license until I finally gave up and got a refund.

    Example: I use SVP (smooth video project) to play my videos @ 60 FPS, everytime a little update happens to SVP and BAAM! it no longer works as EAM blocks it, then I have to visit the forums and wait till they whitelist it.

    Another problem with my VPN (Private Internet Access) one of the best VPNs that keep no logs and gives you a shared IP, every update and it is detected. I got really tired of this, these are just 2 examples I can quickly remember, basically at the time, it drove me nuts to the point that I really hated using my computer, 50% of what I use which are all legit and paid for software were blocked. So FP or behavioral detection to me, it is stopping me from doing what I do normally. That's why I said I wouldn't ever use it again.
     
  8. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    HerdProtect is very good. The guy behind GIANT Antispyware owns it. We use it daily - sometimes on hundreds of machines in the NOC, it's never let us down. A realtime version of it will be released by the end of the year, but only as an 'optional' version to the pure scanner. The portable version works perfect for us, and it picks up a lot of stuff other things miss. Our guidelines are to remove anything detected by 10 or more engines without question. 7-10 we look carefully. 5-7 we take a long look. Anything under 5 engines detecting something we ignore - generally. We've ceased use of HMP, and moved entirely to Herdprotect.
     
  9. Mortal Raptor

    Mortal Raptor Banned

    Joined:
    Oct 6, 2014
    Posts:
    1,013
    What I loved about it is that fact that it has a portable version, no ads, no facebook like us button, no bloat, purely does what it says!

    I hope he doesn't destroy it by adding bloat to it like most AVs and tools do these days.

    Example: SAS has Google Chrome installer, perfect! A security product that wants to throw a browser I don't want down my throat with 2 checkboxes that users who just click NEXT NEXT will blindly have a Chrome spying on them!
     
  10. snippits

    snippits Registered Member

    Joined:
    Jun 19, 2011
    Posts:
    201
    Giant was indeed very good back in its day before Microsoft bought it out.
     
  11. DX2

    DX2 Guest

    Does Herd detect PUP's like HMP does?
     
  12. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    Yes
     
  13. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Tried herdProtect again, but the portable version seems to be lacking custom scan. It can examine a file or process, but I don't think that's the same as scanning them and I'd prefer specific folder support. Is that also the case for the installed version? My new scan had 3 false positives, but only 1 selected (detected by 3 engines). It was an old setup file of my hardware drivers, while the other 2 were game DLLs. If herdProtect had custom scan, I would keep it.
     
  14. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    1) On the Graphic User Interface (GUI): DO: Settings (cog wheel)>Update>Virus Definitions>Settings>Check "Manual" box |||Then DO: Program>Settings>Check "Manual" box

    2) You can disable Avast shields in the GUI. However, I prefer to do so using the Avast Icon in the system tray as follows: Right-click Avast Icon>Shields Control>Disable Permanently.

    3) THEREAFTER: (a) Update by right-clicking Avast's system tray icon ||(b) Turn on shields when/if desired by using Avast's system tray icon. I turn on the shields whenever I am going to be away from my computer, & leave it running for a while. Then I turn the shields off again when I resume active use of the computer.||(c) I do an on-demand scan of every download, of course. I also do a complete scan of ALL HDs every so often. I use the boot scan and have it execute at night while I am sleeping. Works grrreat!
     
  15. Mortal Raptor

    Mortal Raptor Banned

    Joined:
    Oct 6, 2014
    Posts:
    1,013
    Thanks a lot for this detailed guide bro
     
  16. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,618
    Location:
    Milan and Seoul
    Interesting indeed, although 68 engines? Virustotal lists 53... Nevertheless it is offered free... I ran a scan, and it found ImgBurn and a MS process as malware, I'm pretty sure both are FPs but still a very low number considering they use so many engines. How do they make their money? I only hope their online cloud is not gathering our personal data...
     
  17. Mayahana

    Mayahana Banned

    Joined:
    Sep 13, 2014
    Posts:
    2,220
    Unless a lot of engines (5+?) detects something I rarely pay attention. Part of what he is doing is using the results to build his own very powerful Antivirus under 'Reason' software. That will be the realtime component of the additional product coming up later this year, or early next year. If you check the knowledge base you will find his 'Reason Heuristics' finding almost everything, that's part of the realtime engine he is building. Unless you are planning to license an engine it's pretty hard to come out with a new AV these days - but this is one way to do it.

    Also note, in the KB, 67% of all detected threats are Adware.
    http://www.herdprotect.com/knowledgebase.aspx

     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.