Anti Virus ponder...

Associate
Joined
18 Sep 2008
Posts
985
I've used different types of AV before, from Norton, Kaspersky, NOD32, McAfee, AVG etc...
Now I wonder, if one PC has Norton and finds a virus on a USB key or external HDD for argument sake, and another PC has Kaspersky or another product didnt report it when it was plugged into the other PC, would you say that its a false positive from Norton's perspective, or a negative from Kaspersky's point of view.

Products aside (because I know people have different opinions on brand), would the general consensus be that if an AV product doesnt alerts for a long while then we assume its doing its job and that it will warn us when it does, or would you rather receive alerts to know something is really working?
I've also seen files that have been living happily on a hard disk for over a year, only to be alerted perhaps as a result of a new definition in the past few weeks. Therefore, would you think why it didnt alert it earlier, or even get an alert when it was plugged into a different PC running a different product?
Ponder over.
 
I'd say even a false positive is a good thing. Although I think they should all provide an option to permantely ignore a possible "false positive" though as it can get in the way. I use Symantec Endpoint Protection and I hardly ever get any messages from Auto Protect. Most of the time it gives me an option to Ignore but a lot of the time it can be a bit pushy.
 
Assuming both AV's were bang up to date you'd have to look into anything it flagged up, even if it did turn out to be a false positive. That's just the way it goes. Sometimes the warning flag will disappear on the next definitions update. It's the nature of the beast.

False positives are annoying though. I've wiped a system clean on the basis of what turned out to be a false positive. However anti virus is just one tool in the battle against malware and when you understand how it works, you just accept it for what it is.
 
Back
Top Bottom