From: "Steve Basford" <
[email protected]>
|
| Yep, you're correct but does that *really* matter:
|
| a) how may 1991 dos viruses do you get emailed to you

|
| b) try using Jotti/VirusTotal to submit two or three malwares, you'll
| see that ClamAv does a pretty good job of picking up recent viruses, in
| some cases it's beats Mcafee and Trend...
|
| eg: one test sample: loader2.ocx (sorry about word wrap):
|
| AntiVir 6.30.0.7 04.07.2005 TR/Dldr.Agent.EX
| AVG 718 04.07.2005 no virus found
| BitDefender 7.0 04.07.2005 no virus found
|
| ClamAV devel-20050307 04.07.2005 Trojan.Downloader.Agent-86
|
| DrWeb 4.32b 04.07.2005 Trojan.DownLoader.2106
| eTrust-Iris 7.1.194.0 04.07.2005 no virus found
| eTrust-Vet 11.7.0.0 04.07.2005 no virus found
| Fortinet 2.51 04.07.2005 W32/Agent.EX-tr
| F-Prot 3.16a 04.07.2005 no virus found
| Ikarus 2.32 04.07.2005 Trojan-Downloader.Win32.Agent.EX
| Kaspersky 4.0.2.24 04.07.2005
| Trojan-Downloader.Win32.Agent.ex
|
| McAfee 4464 04.07.2005 no virus found
|
| NOD32v2 1.1049 04.06.2005 Win32/TrojanDownloader.Agent.EX
| Norman 5.70.10 04.06.2005 no virus found
| Panda 8.02.00 04.07.2005 Trj/CWinning.A
| Sybari 7.5.1314 04.07.2005 no virus found
| Symantec 8.0 04.07.2005 no virus found
|
| So, the above example shows that having the biggest library doesn't *always*
| help...
|
| At the end of the day, Kaspersky has the best detection rate but it's all
| about having a layered approach to security.
|
| Note:
| Jotti Virusscan:
http://virusscan.jotti.org/
| VirusTotal:
http://www.virustotal.com/xhtml/index_en.html
You'd be surprised how many of the FORM or NYB (TRUE viruses) I have seen well after I
thought they were lond since dead.
a) Email is NOT the only way to receive an infector
b) I won't use Jotti because he keeps the infectors for personal reasons and only has a
handful of scanners. Virus Total on the other hand has 17 AV vendor scanners on board
/*_and more importantly_*/, the samples provided to Virus Total are subsequently provided to
the 17 virus vendor participants. To add to it, I have submitted samples to Virus Total
where Clam AV did catch it. For example on 11/12/04 I submitted "wburgm.exe" to Virus Total
that was a SDbot variant. ClamAv failed to flag itwhile BirtDefender, Kaspersky, NOD32,
Norman and Sybari did. There there was a "bla.exe" sample that was a "w32/Dowloader.small"
type Trojan. Again, ClamAV failed. Then there was the "drvstat16.exe" submitted on Jan 2,
05 which was a "W32/Backdoor" variant that ClamAv failed to flag.
Humm, I see the Jotti web site just /*CHANGED*/ the wording on the web page ! He must have
read my thread in a.c.a-v and then reworded the web page accordingly.