
My biggest gripe for all Anti-Virus solutions is the amount of false positives. One recent incident I posted about prompted me to completely change AV products.
I’ve had to stop using Angry IP Scanner since it gets caught by almost all AV as some kind of Hack Tool. Though, they have a petition to AV vendors to have it removed, but it hasn’t helped. I’ve found a better IP scanner with the all the same functionality (SoftPerfect Network Scanner), but it gets a free pass from all AV products I’ve run across so far. This level of hypocrisy isn’t helping the vendors.
I have to keep my suite of utilities from NirSoft in a zipped folder to keep it from being deleted off my USB thumb-drive. NirSoft has a page devoted to all the different False Positives for its utilities…. they eventually had to stop updating it due the sheer volume of all the reports. Its a major problem for many developers… heres a post from NirSoft: Antivirus companies cause a big headache to small developers
Unfortunately, most Antivirus companies goes too far with their Virus/Trojan protection, and in many times they classify completely legit software as Virus/Trojan infection. One good example for that is my own password recovery tools: Most people need these tools to recover their own lost password. These password tools, like many other utilities out there, can also be used by hackers for bad purposes.
Its a shame… NirSoft is really a good suite of products. But the bigger shame is how hit and miss some AV vendors are… and that some decided to flag all of his products. And though they all claim to have a process to handle false positives, none really follow though…. Unless you get bought out by Microsoft…
One good example is SysInternals. In the past, their psexec.exe tool that can be used to execute code on remote machine, was detected as Virus by some Antivirus programs, but today, when SysInternals is a part of Microsoft, All Antiviruses show it’s clean.
It used to be the only big name products… eg Norton and McAfee… but almost all vendors now do it. I guess the little guys didn’t want to look like they were missing anything.
False positives and misdiagnoses of viruses is so wide spread, its almost a joke. What seems to be more worrisome is their inability to do anything about the actual viruses while hampering the ability of users and sysadmins to remove them. I recently ran across this while researching this post: False Positives Is A Common Problem In Todays Antivirus Software
One of my work place is frequently being infected by Brontok virus even when every computer has Symantec Antivirus Corporate Edition installed. The joke is the antivirus cannot prevent Brontok virus from infecting the computer BUT it can block and auto delete Brontok Washer which I use to disable Brontok virus. So Symantec Antivirus CE can’t remove Brontok virus from the computer and doesn’t allow me to use third party tools that CAN clean the virus. Seems like a pretty useless antivirus to me.
Its made me question the value of Anti-Virus in today’s world. Nothing seems to stop some of the Malware that’s running rampant on social networking sites these days. However, MalwareBytes (not an anti-virus, but simply a Anti-Malware product) is actually what we use to remove most viruses, spyware and malware we see come in to the shop. And oddly enough, I don’t think its seen a false positive yet (for me at least).