App Review Second opinion scanners - Detection test (TestMyAV's samples) - Part 2

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
I have no idea how to interpret the result of Kaspersky correctly. Please tell me what you think

EDIT: Correct result of KVRT (after deleting extracted files in the folder): 94.46%

 
Last edited:

Like a Western!

Level 9
Verified
Well-known
Apr 6, 2016
440
looks like my boy did a great job xD

<3 Thanks for the test

SAP was normal to detect most of them ... also Emsisoft, the real war was between Kasper and Doc :p

i heard about that Kasper fanboys all the time speaking about DrWeb low detection Rate , what now? : )))
 

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,664
I have to agree that KVRT is quite slow and not optimized at all (I think it is not upgraded since 2015), but I have to point out that KVRT does not run only an offline scan, it uses also KSN/Cloud...
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
looks like my boy did a great job xD

<3 Thanks for the test

SAP was normal to detect most of them ... also Emsisoft, the real war was between Kasper and Doc :p

i heard about that Kasper fanboys all the time speaking about DrWeb low detection Rate , what now? : )))
I have to agree that KVRT is quite slow and not optimized at all (I think it is not upgraded since 2015), but I have to point out that KVRT does not run only an offline scan, it uses also KSN/Cloud...
I think kaspersky AV/IS/TS will have a better detection rate because they have newer engine (KVRT engine is 2014) and they have KSN (UDS) and Heuristics
I had a look at KVRT's report, I didn't see any sample which has UDS: => KVRT lacks KSN detection
I saw Heur => KVRT has hueristics
Windows 7-2017-02-02-14-21-00.png
 

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,664
This is a screen-shot of a malware test from a different forum (ran by me 2 days ago: 31/01/2017) testing EIS and using KVRT as a second opinion scanner, as You can see KVRT detected with KSN/Cloud a leftover/remnant after the dynamic test:
OKVRT.png
So maybe at the time of Your test it was a temporal problem and KVRT couldn't access to KSN, but it usually does...
 

Evjl's Rain

Level 47
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Malware Hunter
Apr 18, 2016
3,684
herdProtect a good replacement for SAP with 68 engines
herdprotect is useful for slightly infected PCs but the problems are due to its 68 engines => slow processing time + prone to false positives
I like this program btw

I really want to test it but it would take 1-2 days to finish a scan of 668 samples with herdprotect :(
 

reboot

Level 3
Verified
Well-known
Jan 27, 2017
139
herdProtect a good replacement for SAP with 68 engines
herdprotect is useful for slightly infected PCs but the problems are due to its 68 engines => slow processing time + prone to false positives
I like this program btw

I really want to test it but it would take 1-2 days to finish a scan of 668 samples with herdprotect :(

Perhaps we could class Herdprotect as a THIRD opinion scanner. ;-) I like the program too.

As a general viewer it can be easy for one to forget just how much time and effort goes into the production of these videos especially when you speed things up for our benefit.

Please continue the great work. :)
 

woodrowbone

Level 10
Verified
Dec 24, 2011
480
Nice video as always ER! [offtopic]I hate sap,even it has good detection rate, but that huge popup alarm propellerhead with shiny color is pain in my old eyes[/offtopic]

Agree, there should be an grownup/serious alternative skin available during setup.

/W
 
  • Like
Reactions: BugCode

Dmitry_rus

Level 1
Feb 13, 2017
11
Thanks to Evjl's Rain for his great efforts!
I have one thought that I want to share with community. IMHO, most of modern AV-scanners install their own drivers (at least until rebooting) which may lock files and interfere with the removal process. This could skew the results of your testing. So, it wasn't good idea to start all AV-scanners at the same time. To be sure, I would have to restart the computer before each test.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top