It depends on what you want to use it for.
In my opinion most people do not use CW for the purpose it was created for.
The most important thing to remember is that CW provides no real time protection. You should always have another Active/RealTime antivirus protection running at all times. Period. No exceptions. I will not debate this
Secondly, Is not a system checker. It does not check the registry or do clean up or repair. If you run it on your system and allow it to delete a file that you don't know anything about your system can get hosed
Third, it is not a cleaner. It identifies and can delete or quarantine files it finds suspicious.
The only proper way to use ClamWin is to scan a file as soon as you get it, BEFORE you run it.
Now to the question, How good is it?
I would say fair at best.
You have to realize that ClamAV updates several times a day.
There is no way they can throughly test their defs when they update that often. They have a very high false positive rate.
So, is this bad, well not really.
Worst case scenario, if you use ClamW as I have indicated, is that a good file triggers a false alarm! Well, what do you do? First, you do NOT run or open the file!!! You ask yourself, where did I get this file from. Do I trust, REALLY TRUST the source? Based on my use of CW in the past is this the sort of alarm I've seen before? At this point you run your OTHER antivirus program, you know the one I said you should ALWAYS have, and see what it says. Now, if your Other checker says clean and CW says dirty what do you do? As I mentioned ClamAV updates several times a day. It might have the latest baddie in it's database that your Other doesn't.
and see what they say.
Based on the results you make a decision.
I myself would always download another copy of the file from another source if possible, and would wait at least 24 hrs from when I uploaded samples to the 2 sites mentioned above.
You should also upload a sample to the folks at ClamAV and ask them to confirm if you REALLY believe it is a false positive. http://cgi.clamav.net/sendvirus.cgi
For most people, you don't really believe it's a false positive, you HOPE it is, because you really want to run that program that you just downloaded
So, I hope that this does Not answer your question, because there is No answer.
ClamWin should be used as a secondary backup checker to your standard high quality Namebrand Antivirus/Antimalware program{s}.
No file should be run if CW flags it.
No file should be deleted Just because CW flags it.
If the file is worth having, it's worth double checking it and even waiting a day or 2.
So, as a first line of defense it sucks.
As a backup it's good, and I use it all the time
Hope all this makes sense,
Tim
ps. and if for some strange reason someone thinks I'm being harsh, I am the biggest supporter, tester, and user of CWP at this site
Things have got to get better, they can't get worse, or can they?
It is a decent AV. maybe not the best but as a portable scanner that still works on ME and has the backing of the *nix people it is the best OSS AV out there. so far the other OSS AV's have poor scanning or their database is not updated to par with the bigger companies. Because ClamAV is used on many linux machines it has a large community that keeps the Database up to date. it is updated about 3-4 times a day. the downside is you have to manualy update the database.
I use it to scan indivigual files. i dont use it to scan the whole computer.
Good question, anyone know?
That's true. I want to try in 2 pc clamwin & other one which is the best i've tried & compare the logs
It depends on what you want to use it for.
In my opinion most people do not use CW for the purpose it was created for.
The most important thing to remember is that CW provides no real time protection. You should always have another Active/RealTime antivirus protection running at all times. Period. No exceptions. I will not debate this
Secondly, Is not a system checker. It does not check the registry or do clean up or repair. If you run it on your system and allow it to delete a file that you don't know anything about your system can get hosed
Third, it is not a cleaner. It identifies and can delete or quarantine files it finds suspicious.
The only proper way to use ClamWin is to scan a file as soon as you get it, BEFORE you run it.
Now to the question, How good is it?
I would say fair at best.
You have to realize that ClamAV updates several times a day.
There is no way they can throughly test their defs when they update that often. They have a very high false positive rate.
So, is this bad, well not really.
Worst case scenario, if you use ClamW as I have indicated, is that a good file triggers a false alarm! Well, what do you do? First, you do NOT run or open the file!!! You ask yourself, where did I get this file from. Do I trust, REALLY TRUST the source? Based on my use of CW in the past is this the sort of alarm I've seen before? At this point you run your OTHER antivirus program, you know the one I said you should ALWAYS have, and see what it says. Now, if your Other checker says clean and CW says dirty what do you do? As I mentioned ClamAV updates several times a day. It might have the latest baddie in it's database that your Other doesn't.
At this point you upload the file to a site which uses multiple Antivirus checkers like:
http://www.virustotal.com/en/indexx.html
or
http://virusscan.jotti.org/
and see what they say.
Based on the results you make a decision.
I myself would always download another copy of the file from another source if possible, and would wait at least 24 hrs from when I uploaded samples to the 2 sites mentioned above.
You should also upload a sample to the folks at ClamAV and ask them to confirm if you REALLY believe it is a false positive.
http://cgi.clamav.net/sendvirus.cgi
For most people, you don't really believe it's a false positive, you HOPE it is, because you really want to run that program that you just downloaded
So, I hope that this does Not answer your question, because there is No answer.
ClamWin should be used as a secondary backup checker to your standard high quality Namebrand Antivirus/Antimalware program{s}.
No file should be run if CW flags it.
No file should be deleted Just because CW flags it.
If the file is worth having, it's worth double checking it and even waiting a day or 2.
So, as a first line of defense it sucks.
As a backup it's good, and I use it all the time
Hope all this makes sense,
Tim
ps. and if for some strange reason someone thinks I'm being harsh, I am the biggest supporter, tester, and user of CWP at this site
Things have got to get better, they can't get worse, or can they?
It is a decent AV. maybe not the best but as a portable scanner that still works on ME and has the backing of the *nix people it is the best OSS AV out there. so far the other OSS AV's have poor scanning or their database is not updated to par with the bigger companies. Because ClamAV is used on many linux machines it has a large community that keeps the Database up to date. it is updated about 3-4 times a day. the downside is you have to manualy update the database.
I use it to scan indivigual files. i dont use it to scan the whole computer.
Mir