Put your Anti-Spyware Apps to the Test!

Discussion in 'other anti-malware software' started by lotuseclat79, Apr 28, 2006.

Thread Status:
Not open for further replies.
  1. Blitzen

    Blitzen Registered Member

    Joined:
    Dec 16, 2006
    Posts:
    11
    I think someone posted similar results here for WD...in this same thread I think.
     
  2. ejr

    ejr Registered Member

    Joined:
    Nov 19, 2005
    Posts:
    538
    Spyware Doctor 4.0:

    HKLM_RunOnceEx : Spycar change blocked

    Allowed all others.

    I don't know whether to question the validity of the test or my AS program.
     
  3. Blitzen

    Blitzen Registered Member

    Joined:
    Dec 16, 2006
    Posts:
    11
    So I guess I'm not hallucinating then. Just sent the following e-mail to tech service at SD:

    My license expires in under 20 days and I just thought I'd look around to kick the tires of other apps like Spyware Doctor. In doing so, I ran into a security test called Spycar and tried it on SD. To my dismay, SD did not block a single thing. Unless some clear explanation of this can be brought forth, I'm thinking I won't be renewing, especially since free software that I installed afterwards managed to block everything thrown at it.

    Thoughts?

    Thanks!
     
  4. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    Hmm! I'm gonna switch to ArovaxShield right now. Here are my results with Cyberhawk when the resident shields in AVG AntiVirus and AntiSpyware were disabled. Damn! o_O

    Best regards,
    Firefighter!
     

    Attached Files:

  5. duke1959

    duke1959 Very Frequent Poster

    Joined:
    Jul 21, 2006
    Posts:
    1,238
    Firefighter, did you try it with AVG Spyware Shield enabled? I was going to, but if decide you want to try it I would appreciate it. I didn't even download the Spycar Test yet and won't be able to try it until tomorrow. It would be nice to see your results with AVG AS enabled. I have AVG ISS, but have added Arovax Shield today. Take care.
     
  6. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    AVG AntiSpyware 7.5 failed in all tests.

    ArowaxShield, although the notifier jumped up in every test and I made a Block rule against all of them, scored only a bit better than Cyberhawk. o_O

    Best regards,
    Firefighter!
     

    Attached Files:

  7. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    My BOClean 4.22.002 was almost as good as yours. The only failed one was deleted after the second try. :) I'm still confused. Because BOClean deleted all my test files except the report/clean one, was that only because it has signatures to them? :doubt:

    But if BOClean really is capable to protect all these kind of attacks, should I throw AVG Anti-Spyware away and all my HIPS too, so that my only security applications should be COMODO Free Firewall, SpywareBlaster, BOClean and AVG Antivirus 7.5? :'(

    Best regards,
    Firefighter!
     

    Attached Files:

  8. Tommy

    Tommy Registered Member

    Joined:
    Dec 24, 2002
    Posts:
    1,169
    Location:
    Buenos Aires - Munic
    Lets say it this way for my case.
    What SSM does not catch, catches BoClean and reverse, as a lot of registry entries are observed with SSM.

    In your case i think it is not nececarry to run two background watcher like BoClean and AVG simultaniasly. I would use AVG for on demmand scan as this feature lacks in BoClean.
     
  9. MaB69

    MaB69 Registered Member

    Joined:
    Dec 9, 2005
    Posts:
    540
    Location:
    Paris
    Hi everybody,

    Firefighter, i think you unchecked " Guard Windows Policies " or there is something wrong with your install

    MaB
     
  10. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    There may be something wrong in my just full patched/reinstalled WinXP Home. I can't make a full C:\ scan with DrWeb, F-Prot and some other av:s for instance. Sometimes they'll shut down this laptop when the scan reaches HP PSC 1510 system files and sometimes in Windows/System32 folder files. I only have 448 MB RAM and everything possible installed in this d...ed laptop. o_O

    No, the only what was unchecked was the Opera Browser, because I haven't that one. Look at the setup.

    Best regards,
    Firefighter!
     

    Attached Files:

    Last edited: Dec 17, 2006
  11. ejr

    ejr Registered Member

    Joined:
    Nov 19, 2005
    Posts:
    538

    What freeware did you install that blocked all?
     
  12. ejr

    ejr Registered Member

    Joined:
    Nov 19, 2005
    Posts:
    538
    QUESTION: Howa re you all copying and pasting your results here? What key sequence do you use?

    I was not able to highlight the results inside TOW TRUCK and copy them.
     
  13. duke1959

    duke1959 Very Frequent Poster

    Joined:
    Jul 21, 2006
    Posts:
    1,238
    Just want to say thanks to you Firefighter for the results. Also, how do like Arovax Shield so far?
     
  14. ggf31416

    ggf31416 Registered Member

    Joined:
    Aug 20, 2006
    Posts:
    314
    Location:
    Uruguay
    My Results:

    Arovax Shield

    HKCU_Run : Spycar change blocked
    HKCU_RunOnce : Spycar change blocked
    HKCU_RunOnceEx : Spycar change blocked
    HKLM_Run : Spycar change blocked
    HKLM_RunOnce : Spycar change blocked
    HKLM_RunOnceEx : Spycar change blocked
    IE-HomePageLock : Spycar change blocked
    IE-KillAdvancedTab : Spycar change blocked
    IE-KillConnectionsTab : Spycar change blocked
    IE-KillContentTab : Spycar change blocked
    IE-KillGeneralTab : Spycar change blocked
    IE-KillPrivacyTab : Spycar change blocked
    IE-KillProgramsTab : Spycar change blocked
    IE-KillSecurityTab : Spycar change blocked
    IE-SetHomePage : Spycar change blocked
    IE-SetSearchPage : Spycar change blocked
    AlterHostsFile : Spycar change blocked

    CyberHawk (blocked by signatures)

    HKCU_Run : Spycar test not performed
    HKCU_RunOnce : Spycar test not performed
    HKCU_RunOnceEx : Spycar test not performed
    HKLM_Run : Spycar test not performed
    HKLM_RunOnce : Spycar test not performed
    HKLM_RunOnceEx : Spycar test not performed
    IE-HomePageLock : Spycar test not performed
    IE-KillAdvancedTab : Spycar test not performed
    IE-KillConnectionsTab : Spycar test not performed
    IE-KillContentTab : Spycar test not performed
    IE-KillGeneralTab : Spycar test not performed
    IE-KillPrivacyTab : Spycar test not performed
    IE-KillProgramsTab : Spycar test not performed
    IE-KillSecurityTab : Spycar test not performed
    IE-SetHomePage : Spycar test not performed
    IE-SetSearchPage : Spycar test not performed
    AlterHostsFile : Spycar test not performed

    Spyware Terminator
    HKCU_Run : Spycar change blocked
    HKCU_RunOnce : Spycar change blocked
    HKCU_RunOnceEx : Spycar change blocked
    HKLM_Run : Spycar change blocked
    HKLM_RunOnce : Spycar change blocked
    HKLM_RunOnceEx : Spycar change blocked
    IE-HomePageLock : Spycar change allowed
    IE-KillAdvancedTab : Spycar change allowed
    IE-KillConnectionsTab : Spycar change allowed
    IE-KillContentTab : Spycar change allowed
    IE-KillGeneralTab : Spycar change allowed
    IE-KillPrivacyTab : Spycar change allowed
    IE-KillProgramsTab : Spycar change allowed
    IE-KillSecurityTab : Spycar change allowed
    IE-SetHomePage : Spycar change blocked
    IE-SetSearchPage : Spycar change blocked
    AlterHostsFile : Spycar test not performed

    WinPatrol Free

    HKCU_Run : Spycar change blocked
    HKCU_RunOnce : Spycar change blocked
    HKCU_RunOnceEx : Spycar change blocked
    HKLM_Run : Spycar change blocked
    HKLM_RunOnce : Spycar change blocked
    HKLM_RunOnceEx : Spycar change blocked
    IE-HomePageLock : Spycar change allowed
    IE-KillAdvancedTab : Spycar change allowed
    IE-KillConnectionsTab : Spycar change allowed
    IE-KillContentTab : Spycar change allowed
    IE-KillGeneralTab : Spycar change allowed
    IE-KillPrivacyTab : Spycar change allowed
    IE-KillProgramsTab : Spycar change allowed
    IE-KillSecurityTab : Spycar change allowed
    IE-SetHomePage : Spycar change blocked
    IE-SetSearchPage : Spycar change blocked
    AlterHostsFile : Spycar change blocked
     
    Last edited: Dec 17, 2006
  15. dah145

    dah145 Registered Member

    Joined:
    Jul 3, 2006
    Posts:
    262
    Location:
    n/a
    KIS passes them all. :)
     
  16. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    Just capture 3 images from TowTruck by Gadwin PrintScreen 3.5 and link them together to one picture in M$ Powerpoint. ;)

    Best regards,
    Firefighter!
     
    Last edited: Dec 18, 2006
  17. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    Have you turned IE7 on during the test, I didn't?

    BOClean too. Is this kind of blocking a valid result in this kind of test? Even my AVG Antivirus 7.5 alerted when I tried to execute the TowTruck.exe file during my first scans. :D

    Best regards,
    Firefighter!
     
    Last edited: Dec 18, 2006
  18. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    I have this problem too when I used Cyberhawk. First of all I made a new system restore point in my WiXP Home system before this test. Then I disabled resident shields in AVG Antivirus and Antispyware. After that I activated Trojan-Downloader.Win32.Zlob.asf as you can see in my VirusTotal scan, but Cyberhawk was silent. :doubt: o_O

    Best regards,
    FF again
     
    Last edited by a moderator: Dec 18, 2006
  19. ejr

    ejr Registered Member

    Joined:
    Nov 19, 2005
    Posts:
    538
    Based on countless reviews I have seen on my antispyware tool, I know that I have chosen an effective product. But it fails almost all of the Spycar tests.

    This makes me think that there may be something inherently wrong with the test. I am not certain that I trust the results.
     
  20. Blitzen

    Blitzen Registered Member

    Joined:
    Dec 16, 2006
    Posts:
    11
    I installed Spyware Terminator and RegDefend (I know it is technically shareware). Still waiting for the answer from SD tech service. They sent me a first response saying that SD is compatible with Windows XP. o_O o_O So I asked them to try again.
     
  21. Blitzen

    Blitzen Registered Member

    Joined:
    Dec 16, 2006
    Posts:
    11
    What do you use? Spyware Doctor kept getting great reviews and that's what I've had for a year now. Just want to know what their tech folks have to say about failing tests. I read in one place one guy saying that it's still the best at removing malware but isn't it better to prevent it in the first place?
     
  22. tobacco

    tobacco Frequent Poster

    Joined:
    Nov 7, 2005
    Posts:
    1,531
    Location:
    British Columbia
    And never trust reviews!.
     
  23. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    Folks, you are misunderstanding these tests. Most (if not all) antispyware are mainly signature-based scanners. Spycar should be tested against behaviour blockers, HIPS and antispyware with HIPS functions.
     
  24. Blitzen

    Blitzen Registered Member

    Joined:
    Dec 16, 2006
    Posts:
    11
    That's fine but I just want to see if SD will fess up to the fact that their software doesn't cover that.
     
  25. Firefighter

    Firefighter Registered Member

    Joined:
    Oct 28, 2002
    Posts:
    1,670
    Location:
    Finland
    Nice to see that!
    Arovax has so far behaved smoothly, even lower CPU impact than Cyberhawk had, at least the feeling in surfing. Yet I want to resolve one problem and it was the test issue. Has anyone else got the same results? :doubt:

    Best regards,
    Firefighter!
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.