Which is Better? Malwarebytes’ Anti-Malware Versus. A-squared Free Part 2

Article by Donna Buenaventura (8,660 pts ) , published Oct 22, 2009

In Part of 1 this article, we described the installation, system requirements, updating and features in MBAM and A2. On this final part, we will compare the performance and detection ability of both programs.

Performance – Scanning and Memory Usage - Winner: MBAM (memory usage)/A2 (scanning)

During a scan, A2’s processes will use 180MB  which is huge compared to MBAM’s 70MB  memory usage. MBAM’s quick scan finished scanning in 2 minutes and 27 seconds a total of 89,068 files while A2’s quick scan is really quick that if finished scanning in 34 seconds, a total of 507 files.

When I let both program scan the system drive, A2 has scanned 168,377 files in 29 minutes while MBAM finished in 1 hour and 24 minutes scanning a total of 184,065 files.

False Positive or Other Detections – Winner: MBAM

A2 Free is using two type of signatures (provided by Emsi themselves and a third party signature, Ikarus). During a full system scan, A2 detected one false positive . As mentioned in Part 1 of this article, there is option within the A2 program to report an item if you are positive it’s a false detection. MBAM did not give me a false positive but it provided an extra detection about my setting on Windows Update as ‘disabled ’ in which I put in ignore list  because I prefer to manually scan the system for updates. Some might think it is false positive by MBAM but you should understand that there are malware that will disable security center that MBAM will not be able to guess, if you or an infection is the cause why it is disabled.

Malware Detection – Winner: A-squared

The free editions of MBAM and A2 do not have real-time protection so I put to test the on-demand scanners using 100 positive malware samples. Note: You will find in below screenshots that each malware sample have unique MD5. Legend: X means detected.

MBAM is able to detect 58 out of 100 malware samples while A2 Free detected 92. [Note: The screenshot shows it detected 93 because of the sample file (filename: sexvod.exe contains Player2.exe and SexPlayer.exe) is self-extracting file containing 2 files]. MBAM is able to detect 2 infected registries that A2 did not detect. The infected registry is located in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ for setup.exe and Install.exe. This registry key is often being taken advantage by malware or rogue installer because this particular registry key allows the redirection of the execution of one application to another.

MBAM failed to detect malware samples with .pdf, .swf, .zip and .rar file extensions.

Images

Malware Detection 1Malware Detection 2Malware Detection 3Malware Detection 4

Removal of Detected Malware Samples – Winner: A-squared

I put to test the removal engine by MBAM and A2. The program should be able to remove or delete what their scan engine has detected. MBAM scan engine detected 58 out of 100 samples and 2 registry entries which it successfully removed (although a system reboot is required). A2 Free’s scan engine has detected 92 samples out of 100. Like MBAM, A2 successfully delete all of the detected items but no reboot is required. One of the file that A2 says it cannot remove is actually deleted already. The said file is the one of the malware sample that is self-extracting file containing files (see Malware Detection section above for the said details).

Images

MBAM requires reboot to remove 58 malware filesA-squared deleted 92 detected items

The Bottom Line

Both programs are offering the best options and features but it’s quite obvious that the detection (scan engine) by A-squared Free out-performs Malwarebytes’ Anti-Malware, but the malware removal engines offer almost identical performance. These are excellent products and, as they are free, there is no reason not get both!

Comments

Nov 13, 2009 3:34 AM
RE: Which is Better? Malwarebytes’ Anti-Malware Versus. A-squared Free Part 2
Only that particular week because I happened to have NOD32 vs Avira and A2 vs MBAM for that month/week and I collected them before the reviews (not old positive samples but new positive samples).
Nov 13, 2009 3:27 AM
DJ
RE: Which is Better? Malwarebytes’ Anti-Malware Versus. A-squared Free Part 2
Are the tests run with the same malware samples each time?
Nov 10, 2009 10:51 PM
RE: Which is Better? Malwarebytes’ Anti-Malware Versus. A-squared Free Part 2
Both, DJ - VPC, VMware and non-virtual. That's how I try to repro things to make sure there's no difference of the scan and removal result.

Some malware is from malware spam and reputable sources: malware submissions site submitted by security researchers.

Note that the samples in this article (Oct. 23) are the same samples I use when I test NOD32 vs AntiVir Premium (Oct. 28) http://www.brighthub.com/computing/smb-security/articles/53944.aspx
Nov 10, 2009 10:11 PM
DJ
RE: Which is Better? Malwarebytes’ Anti-Malware Versus. A-squared Free Part 2
Do you test the malware on a virtual machine? How do you get the malware samples?
Nov 10, 2009 8:42 PM
RE: Which is Better? Malwarebytes’ Anti-Malware Versus. A-squared Free Part 2
No worries DJ :)
Yes, A2 free includes Ikarus engine too.
Like you, I am surprised to see MBAM failed to detect 62 items (I'm MBAM, A2, SAS, SS&D, AAW, Windows Defender user - all of them are installed as I often check any sample I will get against their current database) but it's the result after few times I tried to re-scan the samples. And as you can see in the screenshot - 42 remain undetected but detected 58 only. BTW, correction in my earlier reply: MBAM failed to detect 42 (not 62).

Thanks!
Nov 10, 2009 8:30 PM
DJ
RE: Which is Better? Malwarebytes’ Anti-Malware Versus. A-squared Free Part 2
Sorry if I came off the wrong way, everone is entitled to their opinion. Does A-squared free use the Ikarus engine as well? I have a hard time believing MB missed that much malware.
Nov 10, 2009 8:23 PM
RE: Which is Better? Malwarebytes’ Anti-Malware Versus. A-squared Free Part 2
Thanks for the comment, DJ. I hope you are NOT accusing every person who will oppose your review or test. I got a backup of rules file (definition file) that was use during this review and I have the backup of the malware samples which MBAM failed to detect 62. I'm sure you are aware that A-squared is using 2 signatures (Ikarus and Emsi) which is why it is detecting more. As for removal, my article stated that MBAM successufly removed ALL what it found.
Nov 10, 2009 7:57 PM
DJ
MBAM vs A-squared
It sounds to me like you never used MB or how much did you get paid to write this review. I have done extensive testing with MB and it has removed most if not all malware from a virutual machine. Go to remove-malware.com and see the tests for yourself. Matt has videos on both.
 
Subscribe to Computer Security
RSS
Get free weekly updates, directly to your inbox.
Browse Computer Security