Pros and Cons of MBAM/HMP/EEK/CCE

Status
Not open for further replies.
P

Plexx

Thread author
This thread was an original request from Unknown at page 2 of this thread:

Unknown said:
I Would suggest you to use some second opinion scanners.

On-Demand Scanners (All of Them) (Recommended)
-Malwarebytes
-Comodo Cleaning Essentials
-Emsisoft Emergency Kit
-Hitman Pro (Scanner Only)

Unknown said:
Sir Please tell me the Pros & Cons of 4 them just for knowledge

So here we go:

Malwarebytes Anti-Malware (MBAM) (Paid and Free):
+ Very good detection and removal capabilities
+ Chameleon Technology: Access from Chameleon folder which includes several renamed MBAM.EXE's to bypass specific infections such as fake av's
+ Heuristic based protection
+ Offers Real Time protection (paid only). Can be argued if it is needed or not, despite being reliable. Such protection includes web protection, faster scan speed (as opposed to free version's fast speed), Heuristics based protection and Priority updates
+ Fast scanning speed
+ 3 types of scan: Quick, Full, Flash
+ Ability to ignore/exclude files/folders
+ Easy to use and clean GUI (Graphical User Interface)
+ Small updates size
+ Default settings are fine for most users.
+ Ability to include FileASSASSIN (here)
+ Not Cloud based so user can download latest updates and place it on a USB Stick
+ 1 License Per PC £19.95 (UK price). Can be argued of not needing one for average user
+ Ability to detect Rootkits and Fake AVs for example

- In my opinion, Heuristics based protection should be somewhat included in free version at least
- Installation is required (Not fully portable: you can include the installer or chameleon version installer on a USB)

HitMan Pro (HMP) (Paid and Free):
+ Fast Scanning
+ Decent Removal
+ Small client size download
+ Good I/O/CPU/RAM ration usage
+ Scans based on Behavior of the files apart from Cloud (more information here)
+ Force Breach mode: holding the left Ctrl-key while starting Hitman Pro (hold until its window appears) will terminate all non-essential processes that run in the user's system.
+ 5 Decent Engines for detection (Ikarus having most false positives)
+ Implementation of Virus Total account (optional)
+ Easy to use and clean GUI (Graphical User Interface)
+ Default settings work just fine for most needs
+ Ability for Scheduled Scan
+ Ability to untick Potentially Unwanted Programs (PUP). Default is set to detect but ignore.
+ Command line features (i.e /fb to use force breach mode)
+ Ability to detect Rootkits and Fake AVs for example
+ $19.95 for 1 year for 1 pc - decent price

- Only able to scan and not remove (Free version only)
- Unable to exclude folders/files from scanning (no option)
- Some false positives due to Ikarus Engine
- Cloud based only, meaning if you do not have internet, you can forget about using it properly since it will be based solely on Behavior detection.
- Being cloud based, can take some time to upload to HMP servers unknown/suspicious files depending on your connection
- Installation required if used for removal


Emsisoft Emergency Kit (EEK) (Free):
+ Several tools in one:
* Emsisoft Commandline Scanner option for the advanced users who know how to operate this option
* Emsisoft Hijack Free which is another option to advanced users to inspect what is running and set to run on the system and other options
* Emsisoft BlitzBlank which is only usable by advanced users
+ Easy to use and clean GUI (Graphical User Interface)
+ Fast scan speed
+ Emsisoft and BitDefender engines (way less false positives as opposed to when running Ikarus engine)
+ Default Scannings are good enough for most users usage
+ Ability to ignore/exclude files/folders (Scan Whitelist)
+ 3 Scans: Quick, Smart, Deep + Ability to custom scan
+ Very good Detection and Removal Capabilities
+ Ability to detect Rootkits and Fake AVs for example
+ Fully portable (no installation required)
+ Completely Free

- CPU/RAM/I/O usage is a bit high when scanning which can be a problem on heavily infected machines
- No Force Breach Mode (HMP)/Chameleon(MBAM)/ Agressive Mode (CCE) technology - Someone correct me here if I am wrong please
- Relatively big updates upon first use mainly


Comodo Cleaning Essentials (CCE) (Free):
+ 3 tools in one:
* Killswitch (system monitor tool) - more information here
* Autorun Analyzer (improved tool based on Autoruns concept by Systernals) - more information here
* Scanner - detailed guide about each section of CCE as a whole is available here
+ Ability to use Agressive Mode: press and hold 'Shift' key
+ 2 scan options (Quick and Full) + Custom Scan ability
+ Ability to detect Rootkits and Fake AVs for example
+ Fully portable (no installation required)
+ Decent detection ability and very good removal capabilities
+ Comodo Cloud Scanning integration (aside from signatures)
+ Easy to use GUI (Graphical User Interface)

+/- CPU/RAM/I/O is not the lightest but not the heaviest either (compared to MBAM/HMP/EEK) - Can be considered either Pro or Con depending on the user

- Relatively slow scan speed (compared to MBAM/HMP/EEK)
- Killswitch/Autorun Analyzer would require Internet Connection to check with cloud servers - someone correct me if I am wrong or if KS/AA refers to whitelist as well please
- Big 1st database update (over 90mb if I am not mistaken)

Edit:

Additional users information:

Littlebits said:
Like to add from my experience using all of them:

MBAM: Pros- Very little if any false positives
HMP: Cons- Many false positives because it uses several AV engines.
EEK: Cons- Moderate false positives, mostly cause by BitDefender engine.
CCE: Cons- Many false positives, I don't know why since it only uses one AV engine.

anitac said:
Perhaps add:
Cons for HMP:
Does not upload files to server bigger than 25MB (after compression)
 
P

Plexx

Thread author
Unknown said:
Thanks for this thread :D

You are welcome.

I however suggest you really try all 4 solution first before recommending people to use, so you are aware on how they work.
 

Exterminator

Level 85
Verified
Top Poster
Well-known
Oct 23, 2012
12,527
Once again thanks for a very informative post! It's a nice reference to have these comparisons together in one thread.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
Nice & Informative post.

Good to see what can be used for Infected PCs and ones that are not, and why you shouldn't recommend such programs to average PC users.

:D
 

Spirit

Level 2
May 17, 2012
1,832
Hi Biozfear you can add one more point in HMP cons list:
Its unable to scan specific file /folder like other on demand scanners
 
P

Plexx

Thread author
Stranger said:
Hi Biozfear you can add one more point in HMP cons list:
Its unable to scan specific file /folder like other on demand scanners

You actually can: command line mode

HitmanPro36_x64.exe C:\downloads\test.txt

HitmanPro36_x64.exe C:\downloads\wallpapers\


Also under settings u can enable shell integration (not sure if its for paid only or not tho)
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
Shell Integration doesn't require a license, but turned off by default.
 
P

Plexx

Thread author
Earth said:
Shell Integration doesn't require a license, but turned off by default.

Thanks Earth. Wasn't sure since it has been a bit since I last used it properly.

MalwareCenter said:
Heuristics is included in free version.

That was what I initially thought but according to this no:
http://www.malwarebytes.org/products/malwarebytes_free/

I am unable to check at the moment as I have no on demand scanner installed.

Can someone cross check?

Thanks
 

anitac

New Member
Nov 29, 2011
43
Perhaps add:

Cons for HMP:
Does not upload files to server bigger than 25MB (after compression)

Cons for MBAM:
Full database download needed when updating free version (but the database is not very large)
 

Littlebits

Retired Staff
May 3, 2011
3,893
Like to add from my experience using all of them:

MBAM: Pros- Very little if any false positives
HMP: Cons- Many false positives because it uses several AV engines.
EEK: Cons- Moderate false positives, mostly cause by BitDefender engine.
CCE: Cons- Many false positives, I don't know why since it only uses one AV engine.

Excellent review!!:D
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top