Is CA EZ Antivirus any good?

B

Bob

Actually, that's likely planned, to reduce the overhead of scanning
compressed files. You might want to review this writeup from Virus
Bulletin (see section on near misses). It describes the issue:

There should be an option like there was in McAfee. In fact McAfee
gove the user 2 options: executables only, with zip and all files with
exceptions.


--

Map of the Vast Right Wing Conspiracy
http://home.houston.rr.com/rkba/vrwc.html

If you can read this, thank a teacher.
If you are reading it in English, thank an American soldier.
 
B

Bob

Huh? Could you be more specific how it's a rebranded Mac OS? You
perked my curiosity.

Unfortunately it did not perk your humor.

Nevermind - this is not an issue that lends itself to attempts at
subtle humor.


--

Map of the Vast Right Wing Conspiracy
http://home.houston.rr.com/rkba/vrwc.html

If you can read this, thank a teacher.
If you are reading it in English, thank an American soldier.
 
H

Heather

What's in a Name? said:
lol@bob+heather
I am going to have to write those down.
lmao

(VBG).....btw, I had a good look at your website and I am impressed with it.
And that's no joke.....:cool:)

I have been away from news groups for a while, so trying to catch up. But I
will say, without reservation.....any Symantec product screws up WinME, yet
they still sell it saying it is compatible with it......NOT!!

XX Heather (Figgs)
 
R

Roger Wilco

Bob said:
Did you perform all the tests?

I did all of them and eTrust missed some on download. Here are the
results I got.

* eicar.com - detected before downloading.

* eicar.com.text - not detected but loaded into browser.

* eicar.com.zip - not detected but downloaded. Detected when manually
scanned unzipped.

* eicarcom2.zip - not detected but downloaded. Detected when manually
scanned unzipped.

That's not so good, is it.

Actually that "is" good. Other results could be termed false positives
for EICAR. :))
 
B

Bob

Actually that "is" good. Other results could be termed false positives
for EICAR. :))

I am disappointed in CA AV for not at least trying to imitate McAfee,
which allows the user to select which kinds of files to scan
automatically.

With a 2.4 GHz machine and ATA133 drives, I can afford a little
"overhead" in scanning *everything* (except the pagefile).

Maybe eTrust users need to bring this glaring defect to the attention
of CA.


--

Map of the Vast Right Wing Conspiracy
http://home.houston.rr.com/rkba/vrwc.html

If you can read this, thank a teacher.
If you are reading it in English, thank an American soldier.
 
D

DaVinci

Bob said:
I am disappointed in CA AV for not at least trying to imitate McAfee,
which allows the user to select which kinds of files to scan
automatically.

With a 2.4 GHz machine and ATA133 drives, I can afford a little
"overhead" in scanning *everything* (except the pagefile).

Maybe eTrust users need to bring this glaring defect to the attention
of CA.

It's possible to configure an exclusions list with both the real-time
and on-demand scanners. It may take a bit more effort to exclude what
not to scan than to include what to scan, but it is an option if you
need or want selective scanning.
 
B

Bob

It's possible to configure an exclusions list with both the real-time
and on-demand scanners. It may take a bit more effort to exclude what
not to scan than to include what to scan, but it is an option if you
need or want selective scanning.

Yes, I saw that and set it to exclude "pagefile.sys", although I do
not know if it would scan that if I did not exclude it.

But I want to make it scan *everything* except excluded files, which
includes non-executables which includes ZIP and other archive files. I
want that rule to be applied to real time and manual scans.

How do I do that?

--

Map of the Vast Right Wing Conspiracy
http://home.houston.rr.com/rkba/vrwc.html

If you can read this, thank a teacher.
If you are reading it in English, thank an American soldier.
 
D

DaVinci

Bob said:
Yes, I saw that and set it to exclude "pagefile.sys", although I do
not know if it would scan that if I did not exclude it.

But I want to make it scan *everything* except excluded files, which
includes non-executables which includes ZIP and other archive files. I
want that rule to be applied to real time and manual scans.

How do I do that?

It's necessary to create separate exclusion rules for the real-time and
on-demand scanners. Go into Scan Settings and under Exclusions, click
Modify for each scanner. Click Add, and if for example you want to
exclude all zip files, add the entry *.zip. Do the same for cab files
with *.cab, etc. As you've already seen with adding pagefile.sys to the
excludes list, you can also browse and add specific files, folders, or
partitions.
 
B

Bob

It's necessary to create separate exclusion rules for the real-time and
on-demand scanners. Go into Scan Settings and under Exclusions, click
Modify for each scanner. Click Add, and if for example you want to
exclude all zip files, add the entry *.zip. Do the same for cab files
with *.cab, etc. As you've already seen with adding pagefile.sys to the
excludes list, you can also browse and add specific files, folders, or
partitions.

I did that.

Now how do I make CA AV scan *everything* but exclusions?

As it is now, it won't scan ZIP files automatically.


--

Map of the Vast Right Wing Conspiracy
http://home.houston.rr.com/rkba/vrwc.html

If you can read this, thank a teacher.
If you are reading it in English, thank an American soldier.
 
D

DaVinci

Bob said:
I did that.

Now how do I make CA AV scan *everything* but exclusions?

As it is now, it won't scan ZIP files automatically.

AFAICT, the on-demand scanner scans everything, including zip files, and
excludes only what's in the excludes list. It appears that the
real-time scanner scans zip files when you attempt to extract the
contents. I downloaded the eicar zip files, which it allowed, but then
it flagged the contents (eicar.com) when I attempted to extract it. Why
do you think it doesn't scan zip files?
 
B

Bob

AFAICT, the on-demand scanner scans everything, including zip files, and
excludes only what's in the excludes list. It appears that the
real-time scanner scans zip files when you attempt to extract the
contents. I downloaded the eicar zip files, which it allowed, but then
it flagged the contents (eicar.com) when I attempted to extract it. Why
do you think it doesn't scan zip files?

I was expecting it to scan the zip file just like the executable,
namely, before I downloaded it. It is good to know that it will catch
it when I extract.

I like eTrust and I hope it works out. Thanks for your support.
 
B

Bob

How is it a defect if the scanner is designed to function this way?

I expect it to catch the virus even if it is zipped up. However, it
looks like I will have to settle with catch the virus when I unzip.

Most people have their browser set to automatically perform the unzip
on download, but I don't for safety reasons. I make Mozilla ask
permission to save to disk and not open anything.
 
D

DaVinci

Bob said:
I was expecting it to scan the zip file just like the executable,
namely, before I downloaded it. It is good to know that it will catch
it when I extract.

I like eTrust and I hope it works out. Thanks for your support.

Okay, I see now. Keep in mind that you always have the option to scan
the zip file before you extract the contents using the on-demand
scanner. For example, using the on-demand scanner, eTrust identifies
that the double zipped eicar is infected.

I'm glad to hear the information was helpful. Good luck.
 
B

Bob

Okay, I see now. Keep in mind that you always have the option to scan
the zip file before you extract the contents using the on-demand
scanner. For example, using the on-demand scanner, eTrust identifies
that the double zipped eicar is infected.

Yes, but I still would like to have the option of getting CA AV to
scan automatically before I download - like I had with McAfee.

But all this is academic. I sent the eicar.com file to myself and I
did not receive it. I used 2 ISPs - one for my POP3 server and the
other for my SMYP server. One of them caught it - most likely Road
Runner.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top