vizionar je napisao(la):
Dobro, provjerava, znam, ali GDJE to zapisuje? To me interesuje. A da zapise, znam sigurno. (Ko ne vjeruje nek ga deinstalira pa ce vidjeti koliko za sobom brise upravo te zapise o stanju/promjeni fajlova...)
Nije valjda da toliko ljudi koristi KAV a niko ne zna tacno sta im on to radi na njihovom PC-u?
Znam ja
🙂 A ima i na Kaspersky sajtu...ukratko, upisuje u svoju internu bazu i ne menja fajlove koje skenira.
iChecker je za FAT32, dok je iStream naziv tehnologije za NTFS, a vise o ovome:
IChecker and IStreams technologies: major information and working principles
IChecker and IStreams technologies were developed by Kaspersky Labs to reduce the scan time of the objects on the information carriers of your computer. Unlike 4.5 version Kaspersky Anti-Virus these technologies are now available both for anti-virus monitor and scanner.
These technologies work in the present versions of Kaspersky Labs anti-virus packages the following way (as an example one object scan will be shown but this scheme can be used for many objects as well):
# First the object and its contents are scanned for an infected code. The object scan sum and some other service parameters are counted, fixed and saved. These parameters define the state of the object by the moment of scan completion.
# The data received during the scan (CRC object, service parameters, the first scan date) are registered in the object stream (if the object is on the carrier with NTFS file system) and in internal data base (if the object is on the carrier with FAT32/NTFS file system).
# During the next anti-virus scan of the object the object data (CRC and service parameters) are compared with the data saved in the stream (if it exists). If there is no stream and data do not coincide, the parameters saved in the data base are scanned. If the data coincide, the object is not scanned.
In what case the object is not scanned repeatedly (if the Antivirus bases are not upgraded): - if the object was scanned earlier with “more powerful” settings (e.g. – “scan all” instead of “scan only objects that can be infected”)
- if the installed set of anti-virus base was released earlier than the date of the last object scan
- if the difference between the first and the last scan is more than the “quarantine period”.
Note: after the anti-virus bases update the full cycle of previously described actions is repeated. But if during the “quarantine period” of the CRC object none of the service parameters has been changed then during the next scan only CRC comparison and service parameters are fulfilled irrespective of the anti-virus bases installed. If by the end of the “quarantine period” during comparison of CRC and service parameters any mismatch will be found then the “quarantine period” will start from the beginning. And the previously described cycle of actions will be repeated.