Skip to content

Posts from Antivirus software is essential for safe internet browsing.

No ratings yet — be the first to rate!
Open
Which antivirus program do you prefer?
57 voters
Single choice
Sign in to participate in this poll.
Poll results will be visible after you vote or when the poll closes.
User Avatar
16 years ago
Auto-translated
Well, I decided to optimize my Windows today, removed a couple of hundred viruses and other unnecessary junk, including, of course, avast 4.0:rolleyes: but it wouldn't uninstall, so I had to use soft-mod, I don't like it when developers create such obstacles...[br][/br]Now I have a brand new NOD 32, and I'm wondering how to cure it of its bad habit of requiring registration after a month... does anyone have any ideas? :)
User Avatar
16 years ago
Auto-translated
Now I have a brand new NOD 32, and I'm trying to figure out how to cure it of its bad habit of requiring registration after a month... does anyone have any ideas?
There's a website where you can get working keys for free, which I'm currently doing successfully. For example, the expiration date of my current "license" is March 21st of next year. And there you can find another key. Perhaps it would be better to send the link in a private message?
User Avatar
16 years ago
Auto-translated
Of course.
http://nod123.cn/
User Avatar
16 years ago
Auto-translated
Okay, thanks, everything worked out.
I have one more small question... how do you hack the admin panel on a forum like vBulletin v3.5.0? *scratch*
User Avatar
16 years ago
Auto-translated
How do you hack the admin panel on a forum like vBulletin v3.5.0?
Not funny.
User Avatar
16 years ago
Auto-translated
yes, that's how it is, continuing the topic... although, never mind).
User Avatar
16 years ago
Auto-translated
I came across an interesting article today

I'm not the first to copy it, so the author (Geser) won't be offended.

How to Compare Antiviruses

For several years now, disputes have raged over which antivirus is better; however, the problem is that most of those arguing have no idea what parameters should be used to compare antiviruses. In this regard, I want to share my view on the criteria for evaluating antiviruses. Comments and additions are welcome.

Clarifications:
1. Since there are many types of malicious programs, in order to avoid writing long explanations every time where the specific type of malware does not matter, I will use the word "beast"
2. Comparing antiviruses is not the goal of this article; therefore, even though I will provide specific antiviruses as examples, please treat all examples strictly as abstract examples.

So, the criteria for evaluating antiviruses:

1. Number of known "beasts".
Phrases like "Kaspersky is better than DrWeb because Kaspersky knows 100000+ 'beasts', while DrWeb knows 60000+" are often encountered. In reality, it's not that simple. The number published by antivirus companies is not the number of known "beasts," but the number of entries in the antivirus databases. At the same time, using a single entry, an antivirus can identify several varieties of a "beast," and even several different "beasts." Therefore, there is no direct link between the number of entries in the antivirus databases and the number of "beasts" that the antivirus identifies.

Furthermore, even the developers themselves do not know exactly how many "beasts" their antivirus identifies, since an entry added for a specific modification of a "beast" may also identify new modifications that the developers might not have even seen.
Thus, the number of entries in the antivirus databases cannot serve as a criterion for the reliability of the antivirus.

2. Tests on "beast" collections.
It would seem simple: take a collection of "beasts" and compare which antivirus finds more. This is the most common comparison methodology, but it does not necessarily give a correct idea of the antivirus's reliability. Why?
2.1 The question is—how was the collection gathered? Suppose I have KAV installed, and I save all the "beasts" that it detects. Now I take several antiviruses and compare the results of scanning my collection. Obviously, KAV will find all the "beasts," while other antiviruses will find fewer. But this does not mean that KAV is better than all other antiviruses.
Nevertheless, such results still have some value, because if you remove KAV from the results, you can get some idea about the other antiviruses.
2.2 An additional problem is what to consider a "beast" and what not. For example, KAV with extended databases considers adware, spyware, hijackers, and other programs that do not cause serious harm as "beasts," whereas DrWeb and some other antiviruses today do not consider such programs dangerous and do not identify them. So on a collection where half the files are various kinds of adware, spyware... KAV will find twice as many. But this does not mean that it will also be twice as good at catching truly dangerous "beasts."
Some other shortcomings of comparing antiviruses using collections will be discussed further.
Thus, tests on "beast" collections do not provide a full picture and are not a reliable criterion for antivirus reliability.

3. Reaction speed to new "beasts," i.e., the amount of time from the moment a "beast" appears until the antivirus begins to detect it.
Consider this situation. The official NAV website states that updates are released once a week. The KAV offsite states that updates are released every hour. Suppose both statements are true. Now imagine that cool hacker Vasya Pupkin wrote a virus that destroys all information on the disk 3 days after infecting the computer, and posted it on a crack site under the name Norton Antivirus 2005 crack.exe. This guarantees that in a couple of days, hundreds, if not thousands, of people will download and run it. It is easy to see that in such a situation, NAV users are almost guaranteed to lose all information on their disks, while KAV users have a good chance of detecting and removing the virus before it manages to do anything.
This leads to another disadvantage of comparative tests based on "beast" collections. Obviously, most "beasts" in a collection are quite old, and there is no difference between antiviruses with high reaction speeds and those with low ones. In reality, however, antiviruses with high reaction speeds are much more reliable.
A few words about something that probably own one has thought about. How are antivirus databases updated, or how do antivirus developers find out about new "beasts"?
Developers can find some number of "beasts" themselves by browsing various "seedy places." However, system administrators of various firms and advanced users play a major role in detecting new "beasts," as they manually discover suspicious files and send them to virus analysts for analysis. Therefore, a widely distributed, popular antivirus will almost certainly be better than an obscure or recently appeared one.

4. Support for all kinds of packers and cryptors.
Many confuse packers with archivers. These are completely different things. Without going into detail, it can be said that packers and cryptors take the original executable file, encode it using a certain method, and insert a decoding procedure into it. The file remains executable, and no program is required to run it. When the file is launched, the unpacking procedure runs first, and after that, control is passed to the original code.
For the user, there is no difference between an original and an encrypted file. But for an antivirus, there is. From the perspective of an antivirus, which cares about the file's code rather than the execution result, an encrypted file is fundamentally different from the original.
That is, we take a "beast" known to the antivirus and pack it with some packer. As a result, the functionality of the "beast" is preserved (when run, it will do the same thing as the original). But if the antivirus does not know the packer used to wrap the "beast," then for the antivirus, the file has now become clean.
I want to say that packing and encrypting "beasts" is a very common technique used to prevent their detection by antiviruses. Therefore, the more packers and cryptors an antivirus supports, the more reliable it is, and the harder it is for a virus writer to hide a "beast" from it.
On the other hand, the more packers and cryptors an antivirus knows, the slower it works (for example, this is one of the reasons for the slow operation of KAV, which currently leads in the number of supported packers/cryptors). So if you find an antivirus that works quickly, its reliability most likely leaves much to be desired. Of course, the choice between speed and reliability is a personal matter.

5. Emulator
Probably few people have heard about antiviruses having emulators. What exactly is this?
Good antiviruses have the ability to emulate the launch of a program. That is, they track what the program actually does. Usually, not the entire program is executed, but only its initial part. In this way, an antivirus can detect programs encrypted by unknown cryptors and packers, as well as counter other methods used by virus writers to hide "beasts" from antiviruses. Obviously, the more sophisticated the emulator an antivirus has, the more reliable the antivirus is.
It is also clear that having an emulator does not increase the operating speed of the antivirus. Again—either speed or security. As far as I can judge, DrWeb, NAV, and KAV have good emulators.

6. Heuristic analysis
Many have heard of it, but I'm not sure everyone understands what it is.
First, one should understand how an antivirus finds "beasts" in general. It does so simply. For each "beast," a unique piece of code is found, a so-called signature. This piece of code is stored in the antivirus database, and if such a piece of code is found in a file, the file is identified as the corresponding "beast." Obviously, for a signature to appear in the antivirus database, this "beast" must first be sent for analysis to the company's virus analysts. That is, protection always appears only some time after the appearance of the "beast." Heuristic analysis works differently. It analyzes the contents of the file and looks not for a signature, but for sequences of operations typical for "beasts." In this way, "beasts" that have never reached virus analysts, and whose signatures are not present in the antivirus databases, can be detected. Of course, the more sophisticated the heuristic analysis algorithm an antivirus uses, the more reliable it is. However, today the heuristic analyzers of all existing antiviruses are largely ineffective and allow for the detection of no more than a few percent of unknown "beasts." Moreover, the more sensitive the antivirus heuristics are, the more frequent the false positives will be. An example can be DrWeb, which on one hand has good heuristics, but on the other—a bunch of false positives. Although in the latest version there are fewer false positives. Most likely due to a decrease in heuristic sensitivity. A quite decent heuristic was developed by specialists from the antivirus company "VirusBlockAda." Possibly the best existing at the moment.

7. Correct virus treatment.
Perhaps not everyone knows, but antiviruses are far from always able to correctly treat viruses. Suppose you get some harmless virus (i.e., the antivirus did not detect it before infection, which happens often), which does nothing except add itself to all executable files. At some point, the antivirus begins to detect it, and of course, you want to treat all files, i.e., return them to their original state. A not-so-good antivirus may restore files incorrectly, as a result of which some or all programs will stop working, and the harm from such treatment will be much greater than from the virus itself.

8. Operation on an infected system.
While detecting inactive "beasts" is more or less simple, detecting and removing active (running) "beasts" is much more complicated.
8.1. Let's start with the fact that some "beasts" hide their presence in the system. For example, rootkits. Far from all antiviruses are capable of detecting such "beasts." Some antiviruses simply do not see them and will not detect them even if they are in their databases.
Special technologies are used to detect such beasts, such as direct disk access (in KAV) or a special memory scanning technology (in DrWeb).
8.2. Another part of "beasts" try to terminate antivirus processes upon launch, or even delete antiviruses from the disk. An antivirus must be able to resist such attempts. For example, terminating the KAV process is no simple matter and is not within the power of every "beast." DrWeb operates at the driver level, and terminating its process does not lead to the cessation of same-antivirus monitoring.
8.3. Deleting an active "beast" file from the disk is a difficult task, since the system does not allow deleting files that are currently in use. It may be strange, but far from all antiviruses know how to delete such files. As a result, a not-so-good antivirus may detect a "beast" but be unable to do anything about it. On top of everything else, it will regularly bother you with messages that a virus has been found, which will further interfere with work. The technique for deleting files used by the system is very simple, but until quite recently, far from all antiviruses used it. Perhaps some antiviruses still cannot do this.

9. Promptness of virus analysts' reaction to sent suspicious files.
Often you may find strange files on your disk or in startup. Most users are unable to understand themselves whether these files pose a danger or are part of installed programs. The solution to the problem can be sending such files for analysis to the antivirus company's virus analysts. KAV and DrWeb virus analysts usually respond within a day—both if the file is a "beast" and if it is clean. Virus analysts from many other firms never even respond to emails with suspicious files. So you will be left only to suffer through suspicions during sleepless nights

10. Absence of false positives
A good antivirus should have almost no false positives. Often an antivirus is configured for automatic removal of "beasts." A not-so-good antivirus, whose databases are not tested or insufficiently tested before release, may at some point delete important files, which can lead to programs stopping or a system crash. Unfortunately, DrWeb suffers from a relatively high number of false positives, although there are some improvements in this regard in the latest versions.

11. Stability of operation and absence of conflicts with other programs.
Since a good antivirus is deeply integrated into the system, errors in the antivirus can lead to a system crash. Also, to successfully fight "beasts," good antiviruses intercept many system functions. This can lead to all sorts of conflicts with other programs.
Unfortunately, there are no error-free programs, and often an antivirus that fights "beasts" most successfully due to deep system integration also causes the greatest number of possible conflicts.
So the "conflict-free" nature of an antivirus does not necessarily mean it is high quality. It is quite likely that it simply works, so to speak, "on the surface," and will be unable to handle complex "beasts" (in case they are launched for some reason).

12. System load
Of course, a running antivirus monitor takes up some of the computer's resources. Often antiviruses are evaluated on the principle of "it slows down - it doesn't slow down." Of course, everyone chooses for themselves what is more important. Just don't forget that usually an antivirus providing the greatest protection "slows down" more, and an antivirus that "doesn't slow down" most likely provides less reliable protection. Ease of operation is always inversely proportional to the level of security, and this applies not only to antiviruses.

article from resource http://virusinfo.info/showthread.php?t=1581
User Avatar
15 years ago
Auto-translated
Yesterday, I downloaded malware in the form of self-extracting ArhSMS archives for the second time. KIS 2011 detected them during the download, but they had already been added to the registry. It doesn't seem to cause any significant harm, but the notifications about the detected threat are annoying. And if they had unpacked, they would have bothered me even more with offers to use paid services or something else.
The anti malware bytes program helped again. It detects and removes infected registry keys and spyware that masks viruses. You can download it for free on the official website.
User Avatar
15 years ago
Auto-translated
However, it is extremely suspicious and flags system files, among other things, so it should be used with extreme caution.
User Avatar
15 years ago
Auto-translated
I never used any antivirus software before. When I realized I needed to use one, I would download a free 30-day trial of Dr.Web. On the 30th day, I would update all the databases, scan all the drives for viruses, and reinstall Windows. Then I used Dr.Web – I never quite understood Kaspersky's interface, but sometimes I had to work with it occasionally... Later, I had to use Kaspersky, and mostly just that. I figured out the interface; it's not that complicated. At home, I download a one-time Kaspersky version every two weeks and scan everything with it. In general, I recommend not spending money on a license at home, but simply downloading a one-time Kaspersky version from the website every week or two and scanning everything with it. I guess I'll vote for Kaspersky, although Dr.Web is just as good.
User Avatar
14 years ago
Auto-translated
I use Avast 5. I had version 4 installed on my old PC for several years. It's a good free antivirus. I also use Comodo Firewall 2.4, which is also free. From a security standpoint, it's very useful to use the Firefox browser with the NoScript extension: it protects against script-based attacks that an antivirus might not detect.
I also have Malwarebytes Anti-Malware and the AVZ utility.
In addition, I sometimes download DrWeb CureIt. I've also used Kaspersky AVP tool.
User Avatar
14 years ago
Auto-translated
Free antivirus programs don't help; on the contrary, they let viruses through. Then you'll want to get rid of them, but it will be difficult, and you'll have even more trouble with this software. It's better to use a paid antivirus like Kaspersky or Web, or, as suggested here, here's a good tip, I'll even quote it:
Install a paid antivirus like Dr.Web or Kaspersky. Here's a trick: if you don't want to pay, you can download a magazine key from the internet. Just enter "Magazine key for [antivirus name]" in the search engine. And download the antivirus itself from the official websites; there's a free trial version for a month. Activate it with the key, and you'll live happily for a little over a month.
13 years ago
AVAST ANTIVIRUS!
User Avatar
10 years ago
Auto-translated
Didn't vote. The entire list is garbage. The main antivirus is the brain of the person sitting at the computer, who understands what can and cannot be downloaded, and knows how to remove malware manually.

Statistics

Welcome our newest member: recijeb