Re: How effective is any antivirus program?



Pete Zahut wrote:
Speaking as a reasonably computer-savvy "end-user", I reckon that many years ago viruses were just an annoyance and antivirus programs worked well. Unfortunately, viruses, trojans, keyloggers, spyware etc., etc., etc., have become much more malignant and sinister. They are harder to remove, hell, they can even hide themselves from attempts to get rid of them.

So, once infected, can a system _really_ ever be cleaned, disinfected, and healed to the point where you could use it for online shopping or internet banking again?

The reason I ask is that a friend of mine is antivirus-ed, antispyware-ed, antitrojan-ed to the hilt but, if any "anti" program triggers and says that something is wrong, he doesn't rely on the program to do its job and clean the infection - he takes it as a warning that something's wrong and he then deletes the partition, recreates the partition, reformats and reinstalls an earlier drive image using Acronis. He thinks that that is the only way to be sure he can use his bank or credit card details safely.

Is he paranoid or does he have a point?

TIA



Paranoia is a good defense. ;-

At present, most infections can be cleaned, but that is slowly changing. I think he's overdoing it, but not by much.

FWIW, I run MBAM, SuperAntiSpyware, S&D, and a rootkit sniffer/deleter about once a week. Every other week or so the first one I run finds and cleans out a baddie. The others then report a clean machine. Avira runs from boot.

Herewith a tale that explains my paranoia:

About 8 months ago I had a _severe_ infection on this machine. It deleted all the operating files for the software, blocked anti-malware programs, disabled several control applets, and blocked downloading and of anti-malware (AMW). I didn't have a drive image, so I couldn't just reformat and reinstall. Fortunately, I have an older machine running W2000, which I used to get more anti-malware. I was able to run one off a floppy disk. I also had Portable Apps, which includes AMW and runs off a USB stick, ran that too. I was then able to d/l more AMW and run it. It took me the better part of two days to clean the machine, repair XP, and reinstall the software. A couple of glitches remain, e.g. there is no Shutdown/Log Off/etc button on the welcome screen (I think there's a registry key to reset, but I haven't bothered to find it.)

Since then my paranoia has gone up a couple of notches, and continues to rise, but not yet as high as your friend's. But it's getting there. Next on my agenda is a external drive (but not NAS - networks can be compromised too)) dedicated to store drive images for all the computers in our house.

Cheers,
wolf k.
.


Loading