Make your video test requests!

simmerskool

Level 38
Verified
Top Poster
Well-known
Apr 16, 2017
2,784
nope its windows apps. ;)
ok, I did search online first as sometimes my memory fails, but Mac did come on top, but now see underneath Mac it mentions Windows. I think it was first developed for Mac, but I could be wrong about that... I see @Shadowra tested it circa Nov 2021 who confirmed it was better known in Apple circles.

 

roger_m

Level 42
Verified
Top Poster
Content Creator
Dec 4, 2014
3,187
ok, I did search online first as sometimes my memory fails, but Mac did come on top, but now see underneath Mac it mentions Windows. I think it was first developed for Mac, but I could be wrong about that... I see @Shadowra tested it circa Nov 2021 who confirmed it was better known in Apple circles.

Yes it was originally only available for Macs.
I know you are busy, I don't want more product reviews like request parts, but we need a test for intego. I'd be happy to add it to your list, even if it's at the end.
When @Shadowra last tested it, he didn't recommend it. But they've released version 3 since then and possibly it would do better. Although I wouldn't be surprised if there's not much difference.
 

Shadowra

Level 37
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
Sep 2, 2021
2,630
Hello,

I've seen all your requests. Know that I take time but I try to do them all :)

Have you considered doing just web protection tests for some products?
I have been wondering how effective the web protection (browsing security module) of Adguard Premium is and cannot find a relevant test online.
I think it would be interesting to see how effective a system security is with hardened defender (DefenderUI) + Adguard browsing security set to ON.

I'm working on it ;)
I'm thinking of combining them with CyberLock or something else to spice up the test. What do you think?
 

Gangelo

Level 6
Verified
Well-known
Jul 29, 2017
296
Hello,

I've seen all your requests. Know that I take time but I try to do them all :)



I'm working on it ;)
I'm thinking of combining them with CyberLock or something else to spice up the test. What do you think?
Sure, this will be interesting.
This was my previous setup (Defender with DefenderUI recommended settings + Cyberlock + Adguard Premium)
 

Freki123

Level 16
Verified
Top Poster
Aug 10, 2013
753
I'm working on it ;)
I'm thinking of combining them with CyberLock or something else to spice up the test. What do you think?
I would say it will be hard enough to be clear how to count the results of Cyberlock better not add to much other stuff on top of it. What will count as block (unsafe or even suspicious) and what as a fp? Unsigned files can result in a lot of "suspicious" even when they are safe. Blocks of fp?
Tldr: I would like to see a test of CL but please be crystal clear how you will count what for a fair comparison.
 
F

ForgottenSeer 109138

In your videos, you have process explore open on the right hand side, with CPU showing and processes, you can toggle Virus Total and move the column next to CPU so that as samples execute the total amount of detection's can be viewed live during the test this way. I noticed you removed tcpview, its integral to showing connections spawned to drop payloads or transmit information to C&C's, during and after testing checking system files most relevant places malicious items are dropped to see if the product actually removed all traces is also relevant. Autoruns will record changes to start up entries as well and help catch changes to the files system.
It seems like a hassle, not easy to throw together, but the amount of information is helpful both for determining which products are fairing well at the time and for the makers of the products to adjust when needed.

If this seems like a lot, you should see the preparations for doing full real tests that used to take place in the Malware Hub. Much credit is do to those that used to take time to test the products thoroughly.
 

Shadowra

Level 37
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
Sep 2, 2021
2,630
In your videos, you have process explore open on the right hand side, with CPU showing and processes, you can toggle Virus Total and move the column next to CPU so that as samples execute the total amount of detection's can be viewed live during the test this way. I noticed you removed tcpview, its integral to showing connections spawned to drop payloads or transmit information to C&C's, during and after testing checking system files most relevant places malicious items are dropped to see if the product actually removed all traces is also relevant. Autoruns will record changes to start up entries as well and help catch changes to the files system.
It seems like a hassle, not easy to throw together, but the amount of information is helpful both for determining which products are fairing well at the time and for the makers of the products to adjust when needed.

If this seems like a lot, you should see the preparations for doing full real tests that used to take place in the Malware Hub. Much credit is do to those that used to take time to test the products thoroughly.

I haven't deleted it, just don't think I'll be posting it regularly.
In the videos I'll be posting, it's making a comeback.

I'll make a note for Autoruns and the rest for the next ones!
 

Shadowra

Level 37
Thread author
Verified
Top Poster
Content Creator
Malware Tester
Well-known
Sep 2, 2021
2,630
I would say it will be hard enough to be clear how to count the results of Cyberlock better not add to much other stuff on top of it. What will count as block (unsafe or even suspicious) and what as a fp? Unsigned files can result in a lot of "suspicious" even when they are safe. Blocks of fp?
Tldr: I would like to see a test of CL but please be crystal clear how you will count what for a fair comparison.

I can activate WhiteListeCloud ;) I can upgrade to the Pro version if needed for testing :D
 

Freki123

Level 16
Verified
Top Poster
Aug 10, 2013
753
I can activate WhiteListeCloud ;) I can upgrade to the Pro version if needed for testing :D
After rereading the posts above if you were thinking about a CL (with or without WLC) vs DefenderUI (Pro or not Pro) it would be a interesting thing.
But my plea as a CL user with WLC still stands (about being clear what you count which way). Because in most tests fp result in "minus" points and that rule should also apply here (at least in my mind)
Thanks for your time to produce all these tests. They are fun to watch and have an easy to understand summary in this forum here :)
 
Last edited:

rashmi

Level 12
Jan 15, 2024
578
I would say it will be hard enough to be clear how to count the results of Cyberlock better not add to much other stuff on top of it. What will count as block (unsafe or even suspicious) and what as a fp? Unsigned files can result in a lot of "suspicious" even when they are safe. Blocks of fp?
Tldr: I would like to see a test of CL but please be crystal clear how you will count what for a fair comparison.
CyberLock will always score well in these tests because it's a default-deny product and prompts for everything. It's a product suited for advanced users only, certainly not for the majority. Yes, it will effectively block malware, but it will equally block safe programs too.

What would be a fair comparison? It will do well even if you count only unsafe ones, but you get a lot of unsafe ones for safe programs too. A fair comparison would be to test products like CyberLock or Comodo for usability. Because effective protection is inherent in default-deny products.
 
Last edited:

ShenguiTurmi

Level 3
Well-known
Feb 28, 2023
126
I know you've got a load of requests and AVs on your list. But when can we expect the test of Deep Instinct with the latest version?
I don't know what problems they're having, but their service timelines in Asia have been pretty anticlimactic lately.
Asian users got the 5.0.11 update almost two months after US users, and there was no "Detect DirectSyscalls" option after the update.
 
F

ForgottenSeer 109138

I have a fabulous idea.

How about a vid of Windows default security. With a folder of executable's and URLs on the desktop for testing. This time though trying something so simple. Upload each executable to Virus Total, if its flagged, you delete the sample, same with the URLs, instead of navigating to them directly, copy the URL and upload it to VT if its flagged, the same it gets deleted, then scan the system at the end with MD.
 

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
I don't know what problems they're having, but their service timelines in Asia have been pretty anticlimactic lately.
Asian users got the 5.0.11 update almost two months after US users, and there was no "Detect DirectSyscalls" option after the update.
I also received the new policies within the dashboard a few days after the actual client updated.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top