I've been testing a few more AV suites this last week or two; BitDefender 2010, Comodo IS, GDATA 2011 etc along with the usual suspects. As far as I'm concerned, MSE is still not very good, Avira is slipping and generating ever more FPs, Avast 5 is getting worse and GDATA is excellent as ever.
The real surprise for me though, and the reason for my post, is Comodo Internet Security, specifically the new version 5 beta. CIS 4 has surprised me in the past with its excellent detection and removal capabilities, so I decided to take the new v5 beta for a whirl in a virtual machine. The UI is a nice improvement over v4:
I threw over 50 (yes
fifty) 0day threats at it (from MDL), including trojans, worms, bots, irc backdoors, droppers, rogues/fake AVs, TDSS, sality, bredolab etc etc. As a rule I find that the industry leaders catch between 95% and 99% (Avira, GDATA, Kaspersky, NOD32) and the poorer ones (MSE, Avast, AVG etc) score between 50% and 90%.
Comodo Internet Security 5 beta scored (for the second time I tested in a fortnight) 100%. The few samples the actual signatures missed, Defense+ (HIPS/behavioural analysis) caught with style. I had a couple of hits thanks to their new cloud checker too.
Definitely one to keep an eye on imho, and free to boot. It's beaten everything I've thrown at it this week, and none of the paid-for suites have come close. It's times like this I regret the money I threw at NOD32, Kaspersky and Avast.
Memory usage is a ridiculously low 6MB varying up to 12MB as I surf around the web. Yes that includes the GUI, services and scanner combined footprint! Scanning speed is phenomenal. Very, very impressed.
I've been running this on all our machines since the last 100% result I got, and I've had no issues. It's maybe a little chatty for noobs but once set up initially (10 mins maybe) you shouldn't hear from it again unless you encounter a threat so it's not too bad. v5 definitely cuts down on the chatter compared to v4 too. I've found it runs very nicely alongside MalwareBytes real-time scanner (layered security ***) and for free you can't beat it. I just found out that Matousec testing has been giving Comodo 100% this year too, so it's not just me.
Matousec said:
Comodo Internet Security perfect again! (2010/05/01 16:10)
Many of our visitors were eager about results of Comodo Internet Security against the latest set of tests in
Proactive Security Challenge.
And finally, the results are here! Comodo Internet Security goes on the top again with the perfect result. Congratulations!
EDIT: For those who want to try it out, I suggest you install following any defaults offered. Open CIS and then update the virus database signatures. Then right click the tray icon and go to Configuration and select Proactive Security. This will set up Comodo for optimal protection (better than default anyway).
Then in the main GUI window go to Antivirus > scanner settings and (if you're using the new beta 5) enable cloud scanning in the manual and scheduled scan tabs. On anything but really old/slow machines I also recommend you switch from Stateful to On Demand scanning. The only difference is that Stateful won't re-scan files you open once they've been checked, unless you've since updated the virus signatures database. On Demand will scan everything, no matter what. Given the teeny tiny memory footprint I can't see any real valid argument for not going full on with the On Demand scanner to be safe.
You might also want to go to the firewall tab and run the Stealth Ports Wizard. For optimal protection and usability I suggest you choose the middle option to stealth ports on a case-by-case basis. Finally you may wish to extend the time that popups remain on display for Defense+ and the sandbox (default is 120 seconds) so you have more time to read and decide what to do. If you miss any popups you can always access the settings later through the main GUI (specifically the "x unrecognised files" section of the Defense+ box under Summary). I hope someone finds this useful.