Security Basics mailing list archives

RE: Different AV Prouducts


From: "Murda Mcloud" <murdamcloud () bigpond com>
Date: Fri, 15 Aug 2008 10:20:56 +1000

Not sure if someone else has said this already but you may need to look at
scripting nonav from Symantec to be sure you got rid of the frighteningly
huge thing that NAV is.

I have found eset to be great for admin and detection rates. It can be a
weird thing to setup initially though-especially regular scans. After that
though it is plain sailing.


-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Isaac Perez Moncho
Sent: Friday, August 15, 2008 6:50 AM
To: pthroumoulos () rochester rr com; 'Security Basics Forum'
Subject: Re: Different AV Prouducts

I would suggest nod32 or smart security from eset.
The performance is really good, it detects a lot of virus. You can check
it's detection rate at :
http://www.av-comparatives.org/

The centralized management console is powerful and easy to use. I found
really easy to install and configure the clients from the console or off
line.

The only problem is that smart security has the firewall and the
antispyware, as other firewall software it takes a bit of time to
configure it and get it working properly. And maybe some users don't
have the knowledge to do it.

We moved out from sophos for some reasons, as the detection rate for
nod32 is higher, we were not using centralized management with it, eset
has antispyware and firewall in a single product and it was less than
half the price (not the most important thing, but you have a better
product for less money, which can be invested in other security
measures).
Definitively eset products will detect more than symantec.

And if choose this one, be careful implementing a host firewall in the
servers. You can loose remote access after the installation.

Hope that helps

En/na pthroumoulos () rochester rr com ha escrit:
Hello,



I was wondering if anybody could provide me with any positive
information about switching from Symantec Corporate Edition (10.1.4.4000)
to any other AV products. I have looked at a couple different solutions
but am by no means a security guru and would appreciate any feedback I
could get that would help persuade me to switch to a different solution.
The two other products that I am considering are Kaspersky or Sophos.
Reason I picked these two is that I have seen quite a few emails bounced
back and forth about the quality of both of these products compared to
Symantec. Obviously all AV products are going to be better at certain
things than others such as detection and removal. All I am looking for is
a product that I can implement on about 180+ clients and about 30 servers
that will be easily managed and not have too large of a foot print and I
do not want to have to visit every client to remove the old AV before
deploying the new solution.
One of the reasons I would like to switch from Symantec to another
product is that just recently I had to deal with their tech support for
an issue we were experiencing on our clients. My experience with tech
support has left me very jaded as it took them almost three weeks to
figure out the problem.
The issue we were experiencing was when a user would log into their
desktop explorer.exe would not load and they would only see their
wallpaper (All dell machines) The solution to the issue was to turn of
"tamper protection"
on all the clients, though this did solve the issue I am still a little
concerned about the fact that you need to turn off any component of any
AV product. I also feel like Symantec does not do the best job at
detection of other types of malware besides viruses. Several times this
year I had several infected clients that I had to rebuild because
Symantec did not detect the issues till it was too late to do anything.
If anybody could point me in the right direction to getting more info on
a better AV solution than Symantec I would greatly appreciate it.







Current thread: