GDATA AntiVirus 2009 Review

FYI – I uploaded the GDATA antivirus 2009 review last night.  YouTube.com/mrizos

I really enjoyed working with GDATA.  I firmly beleive that multiple scan engines are the furture (along with whitelisting).  GDATA removed 95% of the malware on the test PC, however it couldn’t remove Qhost or any malware related registry entries.

My official rating for GDATA is:  Awesome! – hat’s off to the GDATA crew!!!!

Here is the HiJackThis Log (I’ve bolded leftover infections).

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:09:35 AM, on 10/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesJavajre1.6.0_04binjusched.exe
C:Program FilesVMwareVMware ToolsVMwareTray.exe
C:Program FilesVMwareVMware ToolsVMwareUser.exe
C:Program FilesG DATAAntiVirusAVKTrayAVKTray.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesCommon FilesG DATAAVKProxyAVKProxy.exe
C:Program FilesG DATAAntiVirusAVKAVKService.exe
C:Program FilesG DATAAntiVirusAVKAVKWCtl.exe
C:Program FilesVMwareVMware ToolsVMwareService.exe
C:Program FilesJavajre1.6.0_04binjucheck.exe
C:WINDOWSsystem32wuauclt.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe

R0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://google.com/
F2 – REG:system.ini: Shell=Explorer.exe C:WINDOWSshell.exe
O2 – BHO: G DATA WebFilter Class – {0124123D-61B4-456f-AF86-78C53A0790C5} – C:Program FilesG DATAAntiVirusWebfilterAvkWebIE.dll
O2 – BHO: (no name) – {01BA2111-5518-D0C8-A667-01E739079356} – C:WINDOWSsystem32tnxqilzf.dll (file missing)
O2 – BHO: BhoApp Class – {32131238-5434-4234-4234-432432423432} – C:Program Filessyscmdmscmp32.dll (file missing)
O2 – BHO: SSVHelper Class – {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} – C:Program FilesJavajre1.6.0_04binssv.dll
O2 – BHO: (no name) – {7C109800-A5D5-438F-9640-18D17E168B88} – C:Program FilesNetProjectsbmdl.dll (file missing)
O2 – BHO: e404 helper – {8F10DE2B-E923-4548-B524-4D9C5FA80777} – C:Program FilesHelper1208921198.dll (file missing)
O2 – BHO: 717305 helper – {963916CD-6311-485D-93DC-3BD1B9E2D2CB} – (no file)
O2 – BHO: Mirar – {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} – C:WINDOWSSystem32WinNB58.dll (file missing)
O2 – BHO: iSecurity – {A8311E8F-E459-4D22-89B4-CB9DCF10A425} – C:WINDOWSSystem32ISECUR~1.CPL (file missing)
O2 – BHO: ContextProgram – {E4D1D56C-3EC9-2F5D-FAA3-4112CCDD61DC} – C:Program FilesContextProgramContextProgram-2.dll (file missing)
O2 – BHO: cj helper – {F10587E9-0E47-4CBE-84AE-7DD20B8684BB} – C:Program FilesIE Extensionscj.v2.dll (file missing)
O3 – Toolbar: Mirar – {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} – C:WINDOWSSystem32WinNB58.dll (file missing)
O3 – Toolbar: G DATA WebFilter – {0124123D-61B4-456f-AF86-78C53A0790C5} – C:Program FilesG DATAAntiVirusWebfilterAvkWebIE.dll
O4 – HKLM..Run: [SunJavaUpdateSched] “C:Program FilesJavajre1.6.0_04binjusched.exe”
O4 – HKLM..Run: [VMware Tools] C:Program FilesVMwareVMware ToolsVMwareTray.exe
O4 – HKLM..Run: [VMware User Process] C:Program FilesVMwareVMware ToolsVMwareUser.exe
O4 – HKLM..Run: [iSecurity applet] rundll32.exe iSecurity.cpl,SecurityMonitor (GDATA KILLED THIS)
O4 – HKLM..Run: [wofgrqls] C:WINDOWSsystem32wofgrqls.exe (GDATA KILLED THIS)
O4 – HKLM..Run: [apadibub] regsvr32 /u “C:Documents and SettingsAll UsersApplication Dataapadibub.dll” (GDATA KILLED THIS)
O4 – HKLM..Run: [MSDisp32] rundll32.exe C:WINDOWSSystem32drvboj.dll,startup (GDATA KILLED THIS)
O4 – HKLM..Run: [G DATA AntiVirus Trayapplication] C:Program FilesG DATAAntiVirusAVKTrayAVKTray.exe
O4 – HKCU..Run: [MSMSGS] “C:Program FilesMessengermsmsgs.exe” /background
O4 – HKLM..PoliciesExplorerRun: [rTwrdHqj21] C:WINDOWSwpopejyl.exe (GDATA KILLED THIS)
O4 – HKLM..PoliciesExplorerRun: [J286hthVnp] C:WINDOWSwpopejyl.exe (GDATA KILLED THIS)
O4 – HKLM..PoliciesExplorerRun: [some] C:Program FilesNetProjectscit.exe (GDATA KILLED THIS)
O4 – Startup: .protected
O4 – Startup: LimeWire On Startup.lnk = C:Program FilesLimeWireLimeWire.exe
O4 – Global Startup: .protected
O7 – HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem, DisableRegedit=1
O9 – Extra button: (no name) – {9034A523-D068-4BE8-A284-9DF278BE776E} – http://www.gateietool.com/redirect.php (file missing)
O9 – Extra ‘Tools’ menuitem: IE Anti-Spyware – {9034A523-D068-4BE8-A284-9DF278BE776E} – http://www.gateietool.com/redirect.php (file missing)
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra ‘Tools’ menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:Program FilesMessengermsmsgs.exe
O15 – Trusted Zone: http://click.getmirar.com (HKLM)
O15 – Trusted Zone: http://click.mirarsearch.com (HKLM) (
O15 – Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 – Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 – DPF: {2F0E7094-51A2-ECEB-8CF6-EF32B5ECD15E} – http://virusremover2008.com/VRM_Free.exe
O16 – DPF: {7D5DD829-6C90-42C5-B54C-2AFA82F988BA} (CLoader Object) – http://www.av-xp2008.com/tools/virusremover.dll
O16 – DPF: {C931FDF3-0319-0CAE-6DFD-8D061EABF08D} – http://virusremover2008.com/VRM_Free.exe
O20 – AppInit_DLLs: C:WINDOWSsystem32wowfx.dll (QHOST INFECTION STILL RESIDES)
O20 – Winlogon Notify: wingvd32 – wingvd32.dll (file missing)
O21 – SSODL: zip – {177ab526-6b94-4cc2-b303-c1b6a4070316} – C:WINDOWSInstaller{177ab526-6b94-4cc2-b303-c1b6a4070316}zip.dll (file missing)
O21 – SSODL: CheckMon – {b62df42a-0f78-46d6-81d0-3f0ae0d8dc6b} – C:WINDOWSInstaller{b62df42a-0f78-46d6-81d0-3f0ae0d8dc6b}CheckMon.dll (file missing)
O21 – SSODL: iSecurity – {A8311E8F-E459-4D22-89B4-CB9DCF10A425} – C:WINDOWSSystem32ISECUR~1.CPL (file missing)
O22 – SharedTaskScheduler: frowardness – {b0fdc513-46b9-46fc-8e70-d575ee546dae} – C:WINDOWSSystem32zfaiqwr.dll (file missing)
O23 – Service: G DATA AntiVirus Proxy (AVKProxy) – G DATA Software AG – C:Program FilesCommon FilesG DATAAVKProxyAVKProxy.exe
O23 – Service: G DATA Scheduler (AVKService) – G DATA Software AG – C:Program FilesG DATAAntiVirusAVKAVKService.exe
O23 – Service: AntiVirus Monitor (AVKWCtl) – G DATA Software AG – C:Program FilesG DATAAntiVirusAVKAVKWCtl.exe
O23 – Service: VMware Descheduled Time Accounting Service (vmdesched) – VMware, Inc. – C:Program FilesVMwareVMware Toolsvmdesched.exe
O23 – Service: VMware Tools Service (VMTools) – VMware, Inc. – C:Program FilesVMwareVMware ToolsVMwareService.exe


End of file – 6360 bytes

Please +1 this post if you like me :)

, , , , , , , ,

  • robin

    Awesome, Gdata is great:)

  • malwarekilla

    Yeah, I loved it! I’m going to check out their boot cd too.

  • James

    Yer well to be honest, it should be great, because it uses 2 antivirus engines (avast and somethign else). It also has minutely updates

  • Adel

    Nice video…

    Im waiting for a test on Agnitum’s Outpost Pro Security Suite now :)

  • dany

    I don’t understand something….why is xp antivirus still on your screen(desktop) after the normal mode scan?

  • VJ

    Since Gdata 2009 uses Avast & BD, I am not surprised it missed Q-Host. As you said, only a few products like Avira,Kaspersky,Norton are able to remove it.

    Maybe if they had stuck to Kaspersky, it would have removed that one.

  • Jukka

    Hi

    Nice work you have done.
    Try new a-squared antimalware withc including ikarus-antivirus. At least detectionrate is nice but how it will clean pc is another question. So if you could run some test with that one.

  • Adel

    BTW how was the system resource usage of GDATA??

  • Dan

    Hey.. I have just installed G DATA Internet Security, and so far i love it….

    But… It uses ~150MB of ram.. That sucks..

    What would you chose:

    Kaspersky Internet Security og G DATAs IS..???

    Thanks

  • http://youtube.com/azlan96 AZLAN210396

    Where to download G DATA?

  • Adel

    @ Dan… Kaspersky Internet Security (Latest Build) uses about 30-35 MB on an average… thats very very light…

  • http://www.ultimateinternetsecurity.com Matt

    Hi Guys

    You can download evaluation software at http://www.ultimateinternetsecurity.com or GDATA.de

    regards

    Matt

  • Adel

    I have tried this. Actualy GDIS 2009.
    Detection is very good. Ofcourse using two engines was a smart decision.

    For the average user its seems to be a good package but i assume it does need some help from other softwares (IF user is suspicious of an undetected infection). May be advanced users would prefer to use (GDAV) other firewall and HIPS applications etc.

    The only major negative that i could see is its memory usage and multiple background processes. But people with sufficient resources should be fine.

    The guys at http://www.ultimateinternetsecurity.com are very helpful too :)

  • hatrec

    Yeah, I loved it!

  • Stephen Billard

    Well, Initially I really liked G-data. Nice configurable firewall, etc. But then I had a problem. The firewall is blocking my Retrospect backup to a client PC. Have to disable the firewall to get it to make a connection. No rules changes seem to stick to let things pass through.

    Submitted a support request–maybe there is a way.

    Then I found an annoyance. My sound card software seems to want to set itself in the “run” registry key each time that Windows boots. Perhaps that is not nice behavior, but it is what it is. Can’t find a way to tell G-Data to shut up and ignore it. Sent another support request.

    So far I have not even got acknowledgement that my requests have been received. (Maybe they have not, the only contact is a web form, so no way to get a mail received receipt.)

    In my opinion, G-Data support does not exist. Use this product at your own peril.

  • LonelyNightHowl

    try Iobit.com iobit360 to remove the left 5%!

  • bcmalloy

    Great virus detection but found the following problems.

    Create boot CD function does not work in windows 7 x64, try it.

    GDATA Firewall causes world at war server fresh to work intermittently and does not actually get fully disabled when you choose the disable firewall function it must be uninstalled.

    Works great with a third party firewall as purely anti virus software.


Remove-Malware Traffic Stats