- Oct 22, 2016
- 409
hi, I have a small suggestion: can you enable virustotal lookup in Process explorer so the audiences can see the detection ratio of the running malwares when there are running
good test with many samples
1 malware was running
can you also check if there is any autorun entry? some malwares will only activate themselves on boot when AV has not been really yet
I think we can use only norton power eraser as the only second opinion scanner -> more chance we can catch the infected files while zemana and HMP can miss
you should restart only if there is autorun entry otherwise it's not usefulThanks for your suggestions. Next time I will also restart the operating system and try to use Norton.
Avast invested in right one(AVG's IDP)AVG uses to show some bugs from time to time (for example blocking it's own file removal when having detection by 2 components at the same time - IDP and FileRep), but I've been using v2017 for about a month and I'm really impressed by the protection it offers even in stock settings. Even if you cut it's signatures and the Online Shield, IDP stands up well most of the time
Great review, thank you @erreale
You can use both(AVG or AVAST) but my personal favorite is AVAST.I have a question.
Should i use AVG Free or Avast Free?
I am asking because in the test i see that signatures definitions have the names that Avast is using for a long time.
Only IDP detection is the old one from AVG.
Very good from AVG i didn't excpect to do that well.
Thanks @erreale for the review
Avast = AVG + Hardened mode => Avast is betterI have a question.
Should i use AVG Free or Avast Free?
I am asking because in the test i see that signatures definitions have the names that Avast is using for a long time.
Only IDP detection is the old one from AVG.
Very good from AVG i didn't excpect to do that well.
Thanks @erreale for the review
AVG uses to show some bugs from time to time (for example blocking it's own file removal when having detection by 2 components at the same time - IDP and FileRep), but I've been using v2017 for about a month and I'm really impressed by the protection it offers even in stock settings. Even if you cut it's signatures and the Online Shield, IDP stands up well most of the time
Great review, thank you @erreale
Exactly this. Why would I use AVG when Avast is identical in every way except for the extra feature in Avast - Hardened mode.Avast = AVG + Hardened mode => Avast is better
they are identical except hardened mode
Great review @erreale. AVG seems to be keeping up very well.
One thing that I'm concerned about (regarding the detection) here is that most of the samples look to be from MalwareHub (correct me if I'm wrong).
While there's nothing wrong in testing AVG against them, it is bound to have an almost perfect detection ratio owing to the regular tests and SUDs done for those samples by testers from MH.
I used testmyav before. It's good for testing detection rate but when we execute the files, 80-90% of them are not able to run, with error popupHi, truly are mixed as origin, although the greater part comes from Mthub. Others come from Hybrid Analysis, and also from testmyav.
Extremely good result there.I used testmyav before. It's good for testing detection rate but when we execute the files, 80-90% of them are not able to run, with error popup
useless source of samples
I downloaded the lastest malware pack with 50 ransomwares, only <10 of them could run but didn't encrypt the documents
sorry I don't understand what you mean and I think you didn't understand what I meant tooExtremely good result there.
I was referring to when you said this:sorry I don't understand what you mean and I think you didn't understand what I meant too
I meant 50 samples could not be executed due to errors, not because of any AV
similar to this video, when he ran Trump... sample at 6:24
testmyav's samples are very bad and should not be used for testing realtime protection
only for detection rate
I downloaded the lastest malware pack with 50 ransomwares, only <10 of them could run but didn't encrypt the documents
I think because the samples were modified/neutralized/disinfected and they were no longer maliciousI was referring to when you said this:
Ahh, Ok. Got ya. I misunderstood my apologies.I think because the samples were modified/neutralized/disinfected and they were no longer malicious
ransomwares not being able to encrypt files
I suspected this and tried to run these 50 samples without any AV and none of them worked