drfedja je napisao(la):
Za sve AV programe osim NOD-a je neophodan redovan scan sistema da bi bili 99% sigurni da nema infiltracije. Za svakog ko zna sta radi sa svojim racunarom bice mu dovoljan i AVG da nema viruse, ali sa tacke gledista nekog slabo "potkovanog" usera koji gotovo ni da ne ume da startuje AV scan, ne seti se da updateuje AV, a pri tom voli da posecuje "bezobrazne" :d sajtove, NOD32 je keva.
Prema tome, ono sto pricam, govorim iz praxe i iz analize korisnika koji nemaju razvijenu kulturu koriscenja internet servisa.
Evo da se nadovezhem na ovaj deo tvog posta, da pokazhem da nije bash tako, tj. da AVG nije uopshte dovoljan i da NOD heuristika u nekom realnom scenariju bash i nije od neke koristi:
Postoji jedan zgodan automatizovan sajt na koji ljudi koji pishu viruse ili oni koji sumnjaju da je neshto virus, mogu da uploaduju fajl koji ce biti skeniran sa nekoliko razlichitih antivirusa i na sajtu ce se dati rezultati.
Taj sajt zapravo uglavnom koriste oni koji prave nove virusa, pa shalju da vide koliko su bili uspeshni.
Ako se sajt posmatra na duzhe staze (osvezhava se svakih par minuta), lepo se vidi da statistichki KAV nalazi vishe od NODa, a takodje se vidi ono shto sam pominjao da ako KAV i NOD ne nadju odmah virus u uzorku, posle kraceg vremena kada se poshalje isti uzorak KAV ga nalazi a NOD i dalje ne.
Usput, pokazalo se ono shto sam napisao - AVG je ochajan!
Evo ja sam danas oko pola sata "skidao" rezultate sa tog sajta:
13:23
Last file scanned at least one scanner reported something about: 11515, detected by:
Scanner Malware name
AntiVir X
ArcaVir X
Avast X
AVG Antivirus X
BitDefender Trojan.Banker.Delf.86BEACA1
ClamAV X
Dr.Web X
F-Prot Antivirus X
Fortinet X
Kaspersky Anti-Virus Trojan-Spy.Win32.Banker.ahy
NOD32 X
Norman Virus Control X
UNA X
VBA32 Trojan-Spy.Banbra.19
13:26
Last file scanned at least one scanner reported something about: IEDown2.cab, detected by:
Scanner Malware name
AntiVir X
ArcaVir X
Avast X
AVG Antivirus X
BitDefender X
ClamAV X
Dr.Web BackDoor.IeDown
F-Prot Antivirus X
Fortinet X
Kaspersky Anti-Virus X
NOD32 X
Norman Virus Control X
UNA X
VBA32 BackDoor.IeDown
13:36
Last file scanned at least one scanner reported something about: a-bomb11.zip, detected by:
Scanner Malware name
AntiVir Kit/AnsiBomb.11
ArcaVir Trojan.Constructor.Ansibomb.Darkbomb.11
Avast X
AVG Antivirus X
BitDefender Constructor.A-bomb.A
ClamAV Kit.AnsiBomb.11
Dr.Web Trojan.AnsiBomb
F-Prot Antivirus virus construction tool
Fortinet Ansi.KITC-tr
Kaspersky Anti-Virus Constructor.DOS.DarkBomb.11
NOD32 AnsiBomb.1_1 Constructor
Norman Virus Control X
UNA Constructor.AnsiBomb.11
VBA32 Dropper.AnsiBomb.1_1
13:42
Last file scanned at least one scanner reported something about: d[1].txt, detected by:
Scanner Malware name
AntiVir X
ArcaVir X
Avast X
AVG Antivirus X
BitDefender Win32.Worm.Feebs.G
ClamAV X
Dr.Web Win32.HLLM.Graz
F-Prot Antivirus W32/Feebs.I
Fortinet X
Kaspersky Anti-Virus Worm.Win32.Feebs.j
NOD32 X
Norman Virus Control X
UNA X
VBA32 X
13:51
Last file scanned at least one scanner reported something about: serasa-reports-6002.scr, detected by:
Scanner Malware name
AntiVir X
ArcaVir X
Avast Win32:Banker-ACM
AVG Antivirus X
BitDefender Trojan.Banker.Delf.DAD16A20
ClamAV X
Dr.Web Trojan.PWS.Banker.based
F-Prot Antivirus X
Fortinet X
Kaspersky Anti-Virus Trojan-Spy.Win32.Banker.ahy
NOD32 X
Norman Virus Control X
UNA X
VBA32 Trojan-Spy.Banbra.25
13:56
Last file scanned at least one scanner reported something about: alg.exe, detected by:
Scanner Malware name
AntiVir Trojan/Lowzones.U
ArcaVir Trojan.Lowzones.Bb
Avast Win32:LowZones-Z
AVG Antivirus X
BitDefender Trojan.LowZones.Gen
ClamAV X
Dr.Web DLOADER.Trojan
F-Prot Antivirus X
Fortinet X
Kaspersky Anti-Virus Trojan.Win32.LowZones.bb
NOD32 X
Norman Virus Control X
UNA X
VBA32 X
14:00
Last file scanned at least one scanner reported something about: atip.exe, detected by:
Scanner Malware name
AntiVir Trojan/Dldr.Agent.ZD
ArcaVir Trojan.Downloader.Agent.Zd
Avast X
AVG Antivirus X
BitDefender X
ClamAV Trojan.Downloader.Agent-217
Dr.Web Trojan.DownLoader.5284
F-Prot Antivirus W32/Trojan.ATK
Fortinet W32/Small.CCA-dldr
Kaspersky Anti-Virus Trojan-Downloader.Win32.Small.cca
NOD32 Win32/TrojanDownloader.Agent.KW
Norman Virus Control W32/DLoader.NNN
UNA TrojanDownloader.Win32.Agent
VBA32 Trojan-Downloader.Win32.Agent.zd
14:16
Last file scanned at least one scanner reported something about: msgalo.dll, detected by:
Scanner Malware name
AntiVir Trojan/Spy.Goldun.ci.2
ArcaVir Trojan.Spy.Goldun.Ci
Avast X
AVG Antivirus PSW.Generic.CMM
BitDefender Trojan.Spy.Goldun.CI
ClamAV Trojan.Spy.Goldun.U-unp
Dr.Web Trojan.PWS.Egold
F-Prot Antivirus W32/Banker.FBQ
Fortinet Spy/Banker
Kaspersky Anti-Virus Trojan-Spy.Win32.Goldun.ci
NOD32 Win32/Spy.Goldun.AV
Norman Virus Control W32/Goldun.DI
UNA Trojan.Spy.Win32.Goldun
VBA32 Trojan-Spy.Win32.Goldun.ci
Sajt je
http://virusscan.jotti.org/ pa ko ima vremena da ga prati par dana (ja sam to radio pre neki mesec), lako ce uochiti da KAV mnogo vishe nalazi kada je ovako "bombardovan" sa neta nego NOD.
Znachi, ono shto sam pisao nije bilo napamet - KAV kao celina (baza+heuristika) mnogo vishe nalazi nego NOD kao celina (baza+heuristika) iako je NOD heuristika bolja...ali svi mi imamo cele antiviruse a ne komponente
