You are here

How good is Clamwin

5 posts / 0 new
Last post
silentcon
silentcon's picture
Offline
Last seen: 12 years 7 months ago
Joined: 2008-05-31 05:37
How good is Clamwin

How good is Clamwin vs virus,malware,spyware,trojans and any other things.

truthseeker
truthseeker's picture
Offline
Last seen: 12 years 5 months ago
Joined: 2008-07-30 20:32
Good question, anyone know?

Good question, anyone know?

EspaÑaks (not verified)
Yay

That's true. I want to try in 2 pc clamwin & other one which is the best i've tried & compare the logs

Tim Clark
Tim Clark's picture
Offline
Last seen: 13 years 7 months ago
Joined: 2006-06-18 13:55
It depends on what you want

It depends on what you want to use it for.
In my opinion most people do not use CW for the purpose it was created for.

The most important thing to remember is that CW provides no real time protection. You should always have another Active/RealTime antivirus protection running at all times. Period. No exceptions. I will not debate this Blum

Secondly, Is not a system checker. It does not check the registry or do clean up or repair. If you run it on your system and allow it to delete a file that you don't know anything about your system can get hosed Sad

Third, it is not a cleaner. It identifies and can delete or quarantine files it finds suspicious.

The only proper way to use ClamWin is to scan a file as soon as you get it, BEFORE you run it.

Now to the question, How good is it?
I would say fair at best.

You have to realize that ClamAV updates several times a day.
There is no way they can throughly test their defs when they update that often. They have a very high false positive rate.

So, is this bad, well not really.
Worst case scenario, if you use ClamW as I have indicated, is that a good file triggers a false alarm! Well, what do you do? First, you do NOT run or open the file!!! You ask yourself, where did I get this file from. Do I trust, REALLY TRUST the source? Based on my use of CW in the past is this the sort of alarm I've seen before? At this point you run your OTHER antivirus program, you know the one I said you should ALWAYS have, and see what it says. Now, if your Other checker says clean and CW says dirty what do you do? As I mentioned ClamAV updates several times a day. It might have the latest baddie in it's database that your Other doesn't.

At this point you upload the file to a site which uses multiple Antivirus checkers like:
http://www.virustotal.com/en/indexx.html
or
http://virusscan.jotti.org/

and see what they say.
Based on the results you make a decision.
I myself would always download another copy of the file from another source if possible, and would wait at least 24 hrs from when I uploaded samples to the 2 sites mentioned above.

You should also upload a sample to the folks at ClamAV and ask them to confirm if you REALLY believe it is a false positive.
http://cgi.clamav.net/sendvirus.cgi
For most people, you don't really believe it's a false positive, you HOPE it is, because you really want to run that program that you just downloaded Blum

So, I hope that this does Not answer your question, because there is No answer.
ClamWin should be used as a secondary backup checker to your standard high quality Namebrand Antivirus/Antimalware program{s}.

No file should be run if CW flags it.
No file should be deleted Just because CW flags it.

If the file is worth having, it's worth double checking it and even waiting a day or 2.

So, as a first line of defense it sucks.
As a backup it's good, and I use it all the time Biggrin

Hope all this makes sense,

Tim

ps. and if for some strange reason someone thinks I'm being harsh, I am the biggest supporter, tester, and user of CWP at this site Blum

Things have got to get better, they can't get worse, or can they?

Mir
Mir's picture
Offline
Last seen: 12 years 4 months ago
Joined: 2007-12-03 16:07
It is a decent AV. maybe not

It is a decent AV. maybe not the best but as a portable scanner that still works on ME and has the backing of the *nix people it is the best OSS AV out there. so far the other OSS AV's have poor scanning or their database is not updated to par with the bigger companies. Because ClamAV is used on many linux machines it has a large community that keeps the Database up to date. it is updated about 3-4 times a day. the downside is you have to manualy update the database.

I use it to scan indivigual files. i dont use it to scan the whole computer.

Mir

Log in or register to post comments