Playing with spywares and scanners

Discussion in 'other anti-malware software' started by aigle, Jun 1, 2006.

Thread Status:
Not open for further replies.
  1. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    plus if u have an execution control HIPS with a good blacklist.
    BTW, by just trying them against few malware samples u can,t say anything.
    However now I removed defender and put Spyware Doctor, the good thing is that real time protection is free. For on demand scanner I will use superantispyware( it is better tahn spybot and adaware).
     
  2. MikeNash

    MikeNash Security Expert

    Joined:
    Jun 9, 2005
    Posts:
    1,658
    Location:
    Sydney, Australia
    Sorry, missed this post...

    We're looking at both, still with a focus on the whitelist (for now).

    Feel free to PM me (or just post) suggestions for improvements over at the Tall Emu forums. We do tend to listen to requests and act on them.


    Mike
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Thanks, I will do, just need to collect my thoughts over food real time protection features.
     
  4. tobacco

    tobacco Frequent Poster

    Joined:
    Nov 7, 2005
    Posts:
    1,531
    Location:
    British Columbia
    aigle

    Be very careful with Spyware Doctor.I decided to run chkdk one day but no go.Then wanted to boot into safemode, no go.Couldn't figure it out.After a SD false positive trashed a legit program, i removed it and wouldn't ya know.Chkdk finally ran and could finally boot into safemode again.
     
  5. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hi, thanks for the warning. I will take care.
    BTW I installed a new version of RollBackRx 2 days back and Spyware Doctor just today and in last few hours I got one chdsk run and one BSOD! I thought it is due to RollBackRx but noe I suspect Spyware Doctor might eb the cause.
     
  6. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    BSOD could be SD, but why would SD cause a chkdsk run. That sounds more like Rollback.

    Pete
     
  7. Mrkvonic

    Mrkvonic Linux Systems Expert

    Joined:
    May 9, 2005
    Posts:
    10,224
    Hello,
    First, nice work, kudos for the effort, however, I have certain doubts about your tests:
    You cannot compare anti-virus, anti-spyware and anti-trojan in the same pot.
    What you downloaded mainly were spyware items - so naturally ewido or some anti-virii will find less.
    The number of detected items means little - some programs flag every single file and entry as an item, some programs detect a family as a whole. For instance, Spybot will flag all items under a family xxx as 1 item, even though it could be 5 files, 3 registry keys and 8 registry values.
    Furthermore, you must compare the detected items with reality - how many false positives were there? Would removing them all improve or cripple your system? What about the performance in safe mode? What about items left behind? It's enough to leave one exe or one dll and everything can respawn with vengeances.
    You seem to be doing so much installations, so massively, that sometimes conflicts, errors and bsods you get really do not surprise - and such a system is not a good ground for testing - because it is difficult to separate symptoms.
    Mrk
     
  8. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hi Mrkvonic! Thanks for ur input. All u said is mostly correct. But I will clear some points. If u see the title and start of my thread u can see I have clearly said and warned that these are no tests at all, just I played a bit and I was excited to share it here at wilders. I never think that I am in a position to run any sort of tests but I do play around with all these things to have an idea about them. And I will not suggest anybody to base his choice on this post.
    Putting different types of scanners( AV, AS, AT) against spywares was just to get an idea that how much they overlap in this regard and I was happy to see that Antivir was quite good in this regard( at least with these samples).]

    About the conflicts-- they are always possible but my too much installations are mostly covered by RollBackRx. I install watever software I like and after a while when i feel it is becoming a mess, I RollBack to a clean snapshot( I know that RollBackRx has proved not to be solid but still it is working for me).

    Now about BSOD,s, I have got only twice, first time few months back and all those were caused by Sunbelt Kerio, I never got any more after I switched ober to an older version of Kerio.
    And now it is the second time that I am getting BSODs and I am still investingating whts is the cause. I may post a thread about this as I do need some input.
     
    Last edited: Jun 5, 2006
  9. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Ok, I jsut tried them with Prevx1 ABC trial version.
    When I tried to download them from web site Prevx! did not interfered( unlike SpySweeper who straight away jumps and blocks ur access to the site- a real nice featue). I did not downloaded all the exes then and tried from already present exe files on a CD.
    Prevx! blocked all of them though still some icons etc were able to intall themself but unusable( I saw with spyware doctor also that it immediately blocked the exe but still it was installed and even I was able to run them with spyware doctor turned off but not when it was turned on, however I don,t remember taht it was the case will all blocked programmes or only one or two).
    Also I noted taht new version of Prevx is not slowing down my PC as it did many months back when I tried it last time.
    I am thinking to pu it as my HIPS-- will go for PrevxR1 as it is free.
     
    Last edited: Jun 9, 2006
  10. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Also tried with trial version of super antispyware and it blocked all three but again some components were installed in spite of blocking( as was teh case with spyware doctor), can,t explain the deatils as I just tried and then Rolled Back to clean snapshot.
     
  11. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    BTW, after recent mega update of AntiVir I noted it did not gave any warning when I tried to download winfixer while the previous version was doing this. It is strange.
     
    Last edited: Jun 9, 2006
  12. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Next I am going to try KIS, just want to see its Proactive defence.
    BTW as I posted already I tried with NOD trial with default settings but it did not catch anything even by on-demand scanning.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.