spywar said:
Something I don't understand ....
1. At 10:10 you start running samples undetected by avast.
2. You say "Not hearing anything from avast!" Why ? Are these samples bad or safe ? If they were safe it's normal to not hear anything from a AV program ...
What he means:
1st sample ran goes straight into memory but no alert was displayed. avast!
From my understanding, something would have alerted but then again if memory serves me right, default settings for most shields are set to automatic decisions which has always been my problem with avast (auto sandbox and behavior shield).
Anyhow, the very first file is a rather suspicious. Comodo flags it as Unknown.
If it was a safe file of such type, the analyses would be different.
What troubles me the most here is not so much how it performed but how it detected MBAM as a rootkit...
If only avast! had the option to submit instead of ignore or delete (drop down box).
Other than that, I really hope the free version will not have the extra spaces filled in by modules not available in the free version.
I understand a clean UI but listing options that do not exist in the free version but push you to buy is not something I endorse.
Thanks for the test MD.
@MD: Could you upload (if you still have the samples) the very first sample you run to VT? I am curious to see the report.