Test was good however there are few cons as well :
The last file blocked by DG should be mostly by unknown hash not through malicious behavior
since it is blocked the second file is executed which confirms the above assumption
The pro active part should be further more enhanced by adding worms, Boot time ransom/trojans
Deep Guard should be thoroughly tested based on behavior part not on unknown hash blocking