![]() |
| New Clamav based antivirus with nice GUI and on-exec shield |
|
GuitarBob
|
It needs some work. It failed to detect my 3 EICAR test files and also 4 new viruses for which I was preparing Clam AV signatures. The scan shields were active, too. It uses the Clam AV signatures, and I do not think it has any heuristics. Relying only upon the Clam AV signatures does not give much protection against new viruses.
On the other hand, the Clam Sentinel program, which scans in real-time with ClamWin but also has its own heuristic engine, detected the 4 new viruses and quarantined them as "suspicious" with its heuristics when they were dropped into the %Appdata% folder, and it detected 2 of them when they were dropped into a C:\Test folder. The majority of viruses will be in the %Appdata% or Windows folders. Regards, |
||||||||||||
|
|
|||||||||||||
|
xqrzd
|
My thoughts:
A dated approach. You should use a filter driver instead of PsSetCreateProcessNotifyRoutine / global events. You should at least use PsSetCreateProcessNotifyRoutineEx so you don't need to hack around limitations. It doesn't scan files with unicode characters. Renaming the clam test file bypasses your process block. Your named pipe implementation isn't correct, it continuously uses a lot of I/O. |
||||||||||||
|
|
|||||||||||||
|
Lipper
|
Thanks for testing and the heads up, GuitarBob. I'll stick with ClamWin and Clam Sentinel.
|
||||||||||||
|
|
|||||||||||||
|
GuitarBob
|
Neither ClamWin nor Clam Sentinel use filter drivers, but I have hopes... Clam Sentinel does use exclusive control when scanning, but I fear that is still not good enough for fast-acting malware.
Regards, |
||||||||||||
|
|
|||||||||||||
| Amiti Antivirus |
|
freefighter
|
Hello,
I have checked this Antivirus, too. It installs up to Win 7 64 Bit, but does not work with Windows 8. It uses a lot of hard disk space as well as memory (200 MB). Cpu load is three times higher then with MSE. I think they still have to do a lot of work on it. But I am glad that someone is using Clamav as a basis for a Windows antivirus again since Spyware terminator has abandoned its Clamwin plugin. Let's keep an eye on it. Have a nice weekend! Tom |
||||||||||||
|
|
|||||||||||||
| New Clamav based antivirus with nice GUI and on-exec shield |
|
||
|
Powered by phpBB © phpBB Group
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.
Design by phpBBStyles.com | Styles Database.
Content © ClamWin Free Antivirus GNU GPL Free Software Open Source Virus Scanner. Free Windows Antivirus. Stay Virus Free with Free Software.


