Detection rate comparatives about CIS and 3rd party final AV products by darcjrt

Thank you darcjrt :slight_smile:

I do this with pleasure!!

I’m not doing this to criticize CIS, on the contrary. :ilovecomodo:

I’m doing this because I believe in COMODO as a security company and in CIS as the best internet security out there!!

I do have some doubts. There are AVs that have great cleaning techs. Example, if the AV detects Antivirus2009 it will remove the exe, some dlls and every single file it creates including desktop shortcuts.

I noticed that CAVs and other AVs like Avira does not do this. Is this really necessary?? I know lots of these files are not harmful but if I want to clean any PC…I want it clean!
One example is malwarebytes. I know this is no AV, however I and I know lots of people would like to see CAVs reach that point of cleaning power!!!

Anyway I just want Melih or someone from the COMODO staff clear this out for me(I am really curious)!! :stuck_out_tongue:

So anyway here are AVG results.
ENJOY!!!

PS. I cant wait to test the new beta with full heur and the real DB!!! Remember guys, CIS is no ordinary Internet Sec Suite. It prevents your computer to get infected. It is not designed to CLEAN a nasty infected PC(yet). It will prevent your PC to get infected almost 99.99% of the time. You dont believe me?? Come to my house and see by yourself!!! LOL. I really put CIS to the test here. PORN, FAKE APPS, ROOTKITS…lots of baddies!!! I hope I can upload a video sometime soon! It will be like Matts from remove-malware.com…only better LOL

EDIT: AVG same as a-squared for some reason detected explorer.exe as malware and messed up my PC.

[attachment deleted by admin]

It’s most likely a similar Situations to the likes of Registry Keys. Malware Registry Keys are completely harmless when the actual malware is removed from the system. This is where Comodo System Cleaner comes in to play, You use Anti-Malware tools like Malwarebytes’ Anti-Malware and CIS to remove a malware, and clean up the rest of the junk with Comodo System Cleaner.

But I also believe disinfection will improve in CIS also.

Cheers,
Josh

In some circumstances it may be beneficial to leave the malwares registry remants behind, as some use the presence or absence of these key to determine whether to reinfect or not.

Why not use some of their own smarts against them?

Ewen :slight_smile:

Don’t worry about it, Facts are facts. No matter how you look at them. :wink: “It is what it is”

Thanks Josh!
I asked this because in some cases there is malware that runs at startup(almost everything) and it creates a reg key. So, I had a case(I really dont remember which AV was) that it removed the EXE file but not the registry entry and when windows booted up, I got an err message about windows not finding some file.

But like you said, I use CSC for cleaning my reg and I love it! And yes, I hope disinfection improve in CIS. We all know it will.

PS. My next post will be CIS Db version 940

Yep, This is why I love CIS for Prevention. It Alerts me if anything drops in the Registry or changes in the Registry, etc… Which is yes off course 99% common in all malware. It would be nice to have Comodo System Cleaner integrated into CIS (When CSC is ready off course), I think the suite would rock… And CSC would be light in real time too, since it cleans and doesn’t watch things like CIS does, Which is, as you know already light.

Cheers,
Josh

Isnt CSC ready? How come I have it installed?
Do you mean Comodo System Cleaner??

Sorry I should of explained my self better.

I mean when Comodo System Cleaner IMPROVES, And when it’s ready to be integrated into CIS - If it gets integrated at any point in the future.

Cheers,
Josh

Ohhh I see. Hope it gets integrated! It is a great piece of software!!!

Now, Here are the results of CIS 439 DB version 942. I added more malware!! I recovered a backup I had on the internet. I believe I added old samples but also lots of trojans.

I will scan again with avira and a-squared and i you want me to scan with other AV let me know. I will keep adding samples to the PC. I am attaching screenshots of my PC so you can see how infected it is.

[attachment deleted by admin]

[attachment deleted by admin]

darcjrt, all scanned files were malware? So CAV has detected over 2000 from 14000? If that’s truth, you should send these samples to Comodo as soon as possible :). BTW nice collection you have :slight_smile:

No, Not every file is malware. Sorry I forgot to mention that before. At the moment of the scan, there were 3,200+ samples on my PC(excluding rogues and trojans downloaded by the rogues). So there are a lot of files.

I scanned the whole PC with CIS. I will scan it now with Avira just to compare. And I will keep scanning with other AVs. I want to keep track of CAVs sigs DB. Later I will scan with the beta version when they release it.

CIS 3.8.61948.459 DB version 1

Samples…3200+ on a single folder. There are also over 13 rogues running at the same time, downloading ■■■■ and other trojans downloaders also downloading stuff…so it can easily add up to 3500 samples!!

[attachment deleted by admin]

[attachment deleted by admin]

Avira results

Nice heuristics results.

[attachment deleted by admin]

A-Squared results

Excellent disinfecting results. Huge traces database!!!
I think this is what CAVs is missing. Traces. Registry and file traces cleaning!! It will be awesome to have that on CAVs!!

[attachment deleted by admin]

New beta 459 db version 2
Nice heuristics

[attachment deleted by admin]

Hello Darcjrt,

Thank you for these comparisons!

Would it be possible to keep a simple table with all scores, in text/numbers, instead of 1Mb screenshots and attachements? It takes me literally 5 minutes to check 1 result…

Would be much obliged,

Bgrds,
mack

Great idea…
Great work Darcjrt and this simple table would be so very valuable.

thanks
Melih

+11. :wink:

Ideally, list the total number of threats in the test and the quantity detected. We can do the maths a get a percentage from this.

Cheers and thanks for the testing. Much appreciated.

Ewen :slight_smile:

there is almost 40% difference between a-squared and comodo!!! :o :o :o