[情報] Virus.gr 2009年9月防毒軟體評測

看板AntiVirus作者 (老鼠貓)時間14年前 (2009/09/24 03:06), 編輯推噓31(31047)
留言78則, 24人參與, 最新討論串1/2 (看更多)
The test was made on 10 August-05 September 2009, using Windows XP Professional SP3 on a Pentium Dual Core 2Ghz, 2048MB DDRAM-2. All programs tested had the latest versions, upgrades and updates and they were tested using their full scanning capabilities e.g. heuristics, full scan etc. The default settings of each program were not used, in order for each program to achieve its maximum detection rate. Because of this, there is a possibility for the tested programs to detect a few false positives. All programs were updated on August 10th 2009, between 03.00AM and 07.00AM GMT. The 562086 virus samples were chosen using Kaspersky, F-Prot, Nod32, Dr.Web, BitDefender and McAfee antivirus programs’ reports. Each virus sample was unique by virus name, meaning that AT LEAST 1 antivirus program detected it as a new virus. MS-DOS based virus samples were not used. ALL virus samples were unpacked and the only samples that were kept were the ones that were packed using external-dos-packers (that means not winzip, winrar, winace etc). The virus samples had the correct file extension using a special program (Renexts) and were unique, according to checksum32 filesize. Most "fake" virus samples were removed, as well as "garbage" files. The programs MKS_VIR , PER and IPArmor were not tested because there were no english demo versions available. The program Extendia AVK was not tested because there was no demo version available. Thorough mode was not used in VBA32 due to extremely slow scan process and heuristics were set to medium. The Cleaner’s heuristics were set to medium due to many false positives. The program F-Prot was tested using its command line scanner (options fpscan j:\avtest\trobo /adware /applications /output=fpscan_report.log /streams /maxdepth=4 /heurlevel=4) because its GUI kept crashing. The program ZondexGuard was not tested because it could not be updated. The programs Microsoft Security Essentials and A-Squared Anti-Malware crashed while scanning the samples. The program Avast Professional uses the same engine as Avast free edition. The program Steganos Antivirus uses the same engine as AVG free edition. The program Moon Secure uses the same engine as ClamWin. DOS-Based scanners were not tested. The following file types were used. SH, ELF, COM, EXE, PL, BAT, PRC, DOC, XLS, BIN, MDB, IMG, PPT, VBS, VBA, OLE, HTM, INI, SMM, TD0, REG, CLASS, HTA, JS, VI_, URL, PHP, WMF, HLP, XML, SCR, PIF, SHS, WBT, CSC, MAC, DAT, CLS, STI, INF, HQX, XMI, SIT. The virus samples were divided into these categories, according to the type of the virus : File = BeOS, FreeBSD, Linux, Mac, Palm, OS2, Unix, BinaryImage, BAS, MenuetOS viruses. Windows = Win.*.* viruses. Macro = Macro and Formula viruses. Malware = Adware, DoS, Constructors, Exploit, Flooders, Nukers, Sniffers, SpamTools, Spoofers, Virus Construction Tools, Droppers, PolyEngines, Rootkits, Packed. Script = ABAP, BAT, Corel, HTML, Java, Scripts, MSH, VBS, WBS, Worms, PHP, Perl, Ruby, Python, WHS, TSQL, ASP, SAP, QNX, Matlab viruses. Trojans-Backdoors = Trojan and Backdoor viruses. Rank 1. G DATA 2009 20.0.2.1 - 98,89% 2. F-Secure 2009 9.00.148 - 98,72% 3. Kaspersky 2010 9.0.0.463 - 98,67% 4. AntiVir 9.0.0.381 Premium - 98,64% 5. ZoneAlarm Antivirus 8.0.400.020 - 98,62% 6. AntiVir 9.0.0.407 Personal - 98,56% 7. Ashampoo 1.61 - 98,48% 8. MultiCore 2.001.00036 - 98,36% 9. Paretologic 6.1.1 - 98,11% 10. TrustPort 2.8.0.2255 - 98,03% 11. eScan 10.0.977.4091 - 97,82% 12. The Shield 2009 12.0.12 - 97,72% 13. BitDefender 2010 11.0.15.297 - 97,61% 14. Ikarus 1.0.97 - 97,15% 15. AVG 8.5.392 Free - 97% 16. BitDefender 2009 12.0.12.0 Free - 96,37% 17. Nod32 4.0.437.0 - 95,97% 18. Avast 4.8.1335 Free - 95,87% 19. Comodo 3.9.95478.509 - 95,57% 20. Trend Micro Antivirus 17.1.1250 - 95,36% 21. F-Prot 6.0.9.1 - 93,03% 22. McAfee Enterpise 8.7.0i - 92,35% 23. McAfee 13.11.102 - 92,32% 24. Norman Security Suite 7.10.0.1 - 90,76% 25. Blink Personal 4.3.2 - 90,17% 26. Vba32 3.12.10.9 - 89,91% 27. K7 Antivirus 7.7.0568 - 89,02% 28. Norton 16.5.0.134 - 87,37% 29. ArcaVir 2009 - 85,09% 30. Outpost 6.7.2957.446.0711 - 83,59% 31. Dr. Web 5.00.4.06300 - 82,89% 32. Rising AV 21.51 - 80,92% 33. Vipre 3.1.2775 - 79,69% 34. Kingsoft 2009.08.05.16 - 79,59% 35. V3 Internet Security 2009.08.10.02 - 79,24% 36. ViRobot Desktop 5.5 - 79,05% 37. Antiy Ghostbusters 6.1.6 - 77,14% 38. Panda 2009 9.00.00 - 70,8% 39. Twister 7.3.3.9983 - 67,14% 40. Virus Chaser 5.0a - 66,54% 41. Quick Heal 10.00 - 65,97% 42. PC Tools 6.0.0.19 - 59,77% 43. ClamWin 0.95.2 - 52,48% 44. Sophos Sweep 7.6.8 - 42,84% 45. Iolo 1.5.3 - 40,14% 46. Net Protector 2009 - 34,34% 47. The Cleaner 2010 Free 6.1.0.2007 - 34,11% 48. Digital Patrol 5.10.102 - 27,29% 49. Trojan Hunter 5.1.875 - 24% 50. Protector Plus 8.0.E02 - 21,61% 51. Solo 8.0 - 11,3% 52. Trojan Remover 6.8.1 - 11,16% 53. VirIT 6.4.71 - 9,01% 54. IOBit Security 360 beta 3.1 - 8,92% 55. PCClear 1.0.8.6 - 8,08% 資料來源: http://www.virus.gr/portal/en/content/2009-08%2C-10-august-05-september -- ※ 發信站: 批踢踢實業坊(ptt.cc) ◆ From: 61.64.160.236

09/24 05:11, , 1F
我只想問他們是怎麼統計偵測數的 哈
09/24 05:11, 1F

09/24 08:51, , 2F
NOD32果然很慘, 看來明年真的可以考慮換卡巴了....XD
09/24 08:51, 2F

09/24 08:52, , 3F
說慘仔細看%好像也還好?? 話說這個Outpost明明只是防火
09/24 08:52, 3F

09/24 08:53, , 4F
牆不是嗎??連這個都有8x%啊?? 那版號應該是firewall吧@@
09/24 08:53, 4F

09/24 09:42, , 5F
第一名的沒聽過XD 話說小紅傘怎麼會簡寫成AntiVir ~"~
09/24 09:42, 5F

09/24 09:53, , 6F
洗髮精變那麼厲害 大驚
09/24 09:53, 6F

09/24 09:53, , 7F
G-Data是德國有明網路安全公司
09/24 09:53, 7F

09/24 09:56, , 8F
G-Data 是用兩個其他廠的掃描引擎作核心,第一不意外 O.O
09/24 09:56, 8F

09/24 10:57, , 9F
小紅傘原名就是 AntiVir 啊...
09/24 10:57, 9F

09/24 11:12, , 10F
free得還是小紅傘最強 另外兩個有中文的不知道排到哪=3=
09/24 11:12, 10F

09/24 11:13, , 11F
PANDA更慘...
09/24 11:13, 11F

09/24 11:13, , 12F
小紅傘中文快點做出來吧....
09/24 11:13, 12F

09/24 11:20, , 13F
看看就好
09/24 11:20, 13F

09/24 11:29, , 14F
Avira GmbH是公司名稱,Avira AntiVir Personal是產品名稱
09/24 11:29, 14F

09/24 11:29, , 15F
沒公佈樣本,隨他說得
09/24 11:29, 15F

09/24 12:02, , 16F
江民呢?
09/24 12:02, 16F

09/24 12:23, , 17F
洗髮精好像是小紅傘的OEM 其實前幾名都有卡巴和紅傘的影子
09/24 12:23, 17F

09/24 13:18, , 18F
NOD還贏一些>"<,看起來還不是最慘的
09/24 13:18, 18F

09/24 13:25, , 19F
有個大問題是,它把所有有人報殼的都當作一個樣本 = ="
09/24 13:25, 19F

09/24 14:06, , 20F
不知道有沒有人想過偵測率不等於解毒率啊= =?
09/24 14:06, 20F

09/24 14:07, , 21F
解毒率很難測吧 XDrz 那麼多樣本
09/24 14:07, 21F

09/24 14:10, , 22F
不過在中毒以前先偵測攔截,就沒有解毒的問提了XD
09/24 14:10, 22F

09/24 14:11, , 23F
不過希望他能公佈樣本,這樣我也可以來一起測試
09/24 14:11, 23F

09/24 14:12, , 24F
病毒都是先寫出來才有防毒廠商做病毒碼出來啊= ="
09/24 14:12, 24F

09/24 14:14, , 25F
基本上有病毒碼以後用救援光碟掃描就沒有解毒率的問題了
09/24 14:14, 25F

09/24 14:14, , 26F
只是系統還能不能用就是未知數了 ..╮(﹋﹏﹌)╭..
09/24 14:14, 26F

09/24 14:57, , 27F
我覺得因為win的系統檔案有ms的版權問題 如果真要解毒的話通常
09/24 14:57, 27F

09/24 14:58, , 28F
可行的方式就是把原始沒問題的版本覆蓋回去 但是這樣要付ms多
09/24 14:58, 28F

09/24 15:00, , 29F
少版權費?XD 所以我覺得解毒率這種事情不該是Antivirus的責任
09/24 15:00, 29F

09/24 15:02, , 30F
把"是malware"的檔案正確判斷出來才是防毒軟體的責任 其他請右
09/24 15:02, 30F

09/24 15:02, , 31F
轉向ghost或重灌...
09/24 15:02, 31F

09/24 15:04, , 32F
原始沒問題的版本覆蓋回去 → sfc /scannow
09/24 15:04, 32F

09/24 15:05, , 33F
他指的解毒應該是指惡意程式存在的情況 刪除它的能力吧
09/24 15:05, 33F

09/24 15:07, , 34F
修復感染檔案的能力我認為是不重要...因為這種東西本來
09/24 15:07, 34F

09/24 15:07, , 35F
就是你發現檔案被感染了 對方接收到樣本之後才處理的(?
09/24 15:07, 35F

09/24 15:09, , 36F
不過我要說這測試看看就好 全開的Sophos不可能比蛤蜊低
09/24 15:09, 36F

09/24 16:00, , 37F
Norton................
09/24 16:00, 37F

09/24 16:04, , 38F
我指的解毒不單單刪除,包括防毒軟體自我保護和解殼能力
09/24 16:04, 38F

09/24 16:06, , 39F
很多防毒軟體自我保護爛到爆,像某傘又常常報殼不報毒
09/24 16:06, 39F

09/24 16:06, , 40F
開戰的人要負責整理全部推文唷- -!
09/24 16:06, 40F

09/24 16:07, , 41F
更別說那些裝了防毒軟體找到毒卻刪不掉還要使用者自救的
09/24 16:07, 41F

09/24 16:10, , 42F
感染形病毒注射PE如果只殺特徵碼那就全殺光了連解都不用解
09/24 16:10, 42F

09/24 16:11, , 43F
不過還是推薦使用開放作業系統...連防毒軟體都不用安裝
09/24 16:11, 43F

09/24 16:18, , 44F
還是有病毒啦,比較少而已
09/24 16:18, 44F

09/24 16:21, , 45F
這個測試的 File 類就是其他平台的病毒啊 :D
09/24 16:21, 45F

09/24 18:01, , 46F
防毒軟體還原系統檔理論上應該不用考慮版權問題吧?? 只
09/24 18:01, 46F

09/24 18:02, , 47F
要請user放原版光碟, 然後下參數幫它restore回來就好XD
09/24 18:02, 47F

09/24 18:02, , 48F
解毒有用的啦~~正妹: 怎麼辦, 我電腦/隨身碟中毒了....
09/24 18:02, 48F

09/24 18:03, , 49F
強者: (把硬碟/隨身碟拿回來裝自己電腦用防毒軟體解毒)
09/24 18:03, 49F

09/24 18:03, , 50F
不用怕, 我已經幫妳解完毒了.... 然後請樓下接XD
09/24 18:03, 50F

09/24 18:05, , 51F
正妹:那我繼續玩facebook了不送,公車從巷子走出去20分鐘.
09/24 18:05, 51F

09/24 18:14, , 52F
j大~~你真是個好人(指) 然後00:00就變地獄junorn了嗎XD
09/24 18:14, 52F

09/24 18:17, , 53F
あなたのウイルス、晴らします。
09/24 18:17, 53F

09/24 21:13, , 54F
比較驚訝的是洗髮精功力大增!!
09/24 21:13, 54F

09/24 21:16, , 55F
引擎好像是別人的...
09/24 21:16, 55F

09/24 22:42, , 56F
前十名都98%以上 大家都好強...
09/24 22:42, 56F

09/24 23:46, , 57F
洗髮精容易自己死當的情況還在嗎O_Q
09/24 23:46, 57F

09/25 01:09, , 58F
其實我被ZoneAlarm給驚訝到了...
09/25 01:09, 58F

09/25 09:45, , 59F
G-DATA 在第一名,洗髮精、COMODO 大躍進。(驚悚
09/25 09:45, 59F

09/25 09:47, , 60F
其實 NOD32 表現的也不錯,Panda 這個才叫做有慘(淚
09/25 09:47, 60F

09/25 09:49, , 61F
其實這排名雖然很有趣,也有使用、購買抉擇的參考價值。
09/25 09:49, 61F

09/25 09:49, , 62F
我比較驚訝Sophos, 這家應該本業就是做含防毒的安全軟體
09/25 09:49, 62F

09/25 09:50, , 63F
的不是嗎@_@" 話說原本主要做防火牆的幾家怎麼現在都變
09/25 09:50, 63F

09/25 09:50, , 64F
但是在挑選防毒軟體的時候,也不要忘了「技術支援」這一塊
09/25 09:50, 64F

09/25 09:50, , 65F
得突飛猛進啊....@_@"
09/25 09:50, 65F

09/25 09:51, , 66F
畢竟防毒軟體賣的不只是軟體,更是授權期間的「服務」。
09/25 09:51, 66F

09/25 09:51, , 67F
支援啊, 以前當兵時反應給Kav與紅傘, 反應速度真的沒話
09/25 09:51, 67F

09/25 09:52, , 68F
說, 一天內就回應了, 其中一家還幾個小時內就回了; 反
09/25 09:52, 68F

09/25 09:52, , 69F
觀當時小弟用的NOD32~~週末還放假沒回應的勒....~_~
09/25 09:52, 69F

09/25 09:53, , 70F
Panda 跟 Dr.Web 的技術支援也真的很快。
09/25 09:53, 70F

09/25 10:07, , 71F
技術支援的反應速度...(看著目前用的 GGreat ZAV)
09/25 10:07, 71F

09/25 10:07, , 72F
有上下班時間,還有周休二日、國定假日、年假...。
09/25 10:07, 72F

09/25 10:08, , 73F
需要時絕對找不到人XD...(不過我居然還可以用了好幾年)
09/25 10:08, 73F

09/25 10:56, , 74F
古早以前還叫 Zlock 的時候我有用過... 更新版還寄磁片的
09/25 10:56, 74F

09/25 22:32, , 75F
江民是不是太差了,不是還跟M$的W7合作了 = =
09/25 22:32, 75F

09/26 00:02, , 76F
K大字爆年齡了@@!
09/26 00:02, 76F

09/26 02:40, , 77F
ZLOCK不是還在嗎?
09/26 02:40, 77F

09/26 08:23, , 78F
改名叫 ZAV 了... 官網有說改名的原因 XD
09/26 08:23, 78F
文章代碼(AID): #1Akd6ydB (AntiVirus)
文章代碼(AID): #1Akd6ydB (AntiVirus)