Jump to content

Recommended Posts

Posted

For performance which do people think is the best anti virus? I see antivirus as a necessary evil, i hate how most of them kill the performance of Windows, so i'm after opinions on which kills the pc least.

 

We run Symantec Anti Virus Corporate, and have since 2003, its only our latest PC's that we do not notice the AV killing the PC and it would make PIII PC's die.

 

We may be getting some Netbooks soon, and since the speed of these is less, i'm wondering which AV will not kill them. The version of Symantec we have does not support Vista or 7 , so were going to have to change it at some point. What i do like is the way symantec updates silently, which i think is important on managed stations.

 

Any recommendations?

Posted

I'd wager symantec corporate being lighter than most network based AV solutions around, the only one that's similar is Sophos. The former being the only real choice for CC3 based networks though, if you're RM'd up.

 

Otherwise nod32 is very good but takes a LOT of work. It works on guilty until proven innocent theory, i.e. absolutely everything is a threat unless you say otherwise. I've grown rather fond of Avast! personally, it's light and fairly unobtrusive, works on all the system's I've got around the building from everything from XP up to 7/2008 without issue and is free too.

Posted
For performance which do people think is the best anti virus? I see antivirus as a necessary evil, i hate how most of them kill the performance of Windows, so i'm after opinions on which kills the pc least.

 

We run Symantec Anti Virus Corporate, and have since 2003, its only our latest PC's that we do not notice the AV killing the PC and it would make PIII PC's die.

 

We may be getting some Netbooks soon, and since the speed of these is less, i'm wondering which AV will not kill them. The version of Symantec we have does not support Vista or 7 , so were going to have to change it at some point. What i do like is the way symantec updates silently, which i think is important on managed stations.

 

Any recommendations?

 

When our network was CC3 we used Sophos and it was great. We controlled it through the Enterprise Management software on our servers and we had no real issues.

 

We are now with the LEA and they have central servers running Symantec Anti-Virus Corporate. However I do believe they have updated their installation to support Vista (I may be wrong). We have noticed no issues with performance - but by that I mean nobody has complained LOL.

 

Not much help - but both seem to be excellent products.

 

GJE

Posted
Just moved to Kaspersky here from Symantec Corp - and absolutely love it, whatever Symantec does, Kaspersky does it better. NOD32 came in a close 2nd when we evaluated them all.
Posted
Not seen a Kaspersky installation as yet (managed on a network) - what's the general opinion on it? I quite like it (in fact it's the only paid AV solution I'd consider going near if there were not better free solutions available) on standalone machines.
Posted
Well i've put the home edition 30 day trial of nod32 on this netbook and it seems ok performance wise. Cannot tell its on really which is what i like. I've not tried our current Symantec on it yet will do on monday, but newer vesions have a habbit of getting worse as they add more unwanted gunk. Like AVG 7 use to just work and be fast, now AVG 8 seems really bloated.
Posted

Quakers -

 

I am still in the Eval stage of NOD32 - but I just got a quote from my sales rep and the pricing for NOD32 in education if fabulous. I have been on TrendMicro for several years - it has been a very good product that scales great.

 

I have just been looking at a different solution that I hope will handle protection better. It has been a battle lately with Trend for me - especially with malware - it seems to be getting in way to easy and then successfully pulling down Tojans. I get alerts but my NOD32 has picked up a number of things that Trend has missed in the last two weeks of eval.

 

Scott

Posted

Sophos in use here but it's going in Summer, too bloated and doesn't like to tell you what's going on, apparently visiting each PC to find out whether it's cleaned or deleted a virus is an acceptable behaviour for an Enterprise level product :rolleyes:

 

Testing Kaspersky at the moment to replace Sophos, heard lots about NOD but a bit concerned at the detection rates being mentioned at the moment. AVG8 is a bit lumpy now and really see it as a home product rather than business personally.

 

Symantec too resource heavy for me at the mo, might change my mind if the engine gets upgraded to the same as the new Norton home products that are meant to be light as a feather from what I've read :D

Posted

Make sure you have the latest Symantec corporate version, early versions did indeed bring computers to a stop because they had an automatically generated system scan run each time the computer turned on.

 

This was fixed about 2 years with a patch and ever since then I've hardly even noticed it running, even on older pcs.

Posted

Hi All,

 

Can the users of NOD, Kaspersky, McAfee, Symantec, Trend, Avast, AVG, etc. post the memory footprint of an average client (main scanner process name, peak memory, etc)?

 

The main headache for SAV users seems to be memory usage and I would like to gather a bit of intelligence from users of other products. From reading the different threads on here it seems as though Symantec is quite heavy too but all the rest seem OK or there are other nagging problems that override the footprint issue.

 

 

Regards,

 

Sophos Technical Support

Posted
Sophos in use here but it's going in Summer, too bloated and doesn't like to tell you what's going on, apparently visiting each PC to find out whether it's cleaned or deleted a virus is an acceptable behaviour for an Enterprise level product :rolleyes:

 

Not sure how you had Sophos set up but I've found it to be a little too vocal at times! I receive email notifications of detected threats and keep an eye on the other 'problems' using the Enterprise Console. It just works!

Posted
Well after trying our current Symatec Corporate 8 on on the little netbook today i promptly put NOD32 back on, the performance hit was noticable with symantec.
Posted

@sophos support

 

nod32krn.exe is at the moment 32mb. But its not just the memory footprint but also the slowing down of the machine as a whole we've found with sophos.

 

IVe been running some comparisons, and some of our older laptops can take up to 3 - 4 mins longer from startup and logon when sophos is installed compared to some others. (which for teachers is a nuicance)

Posted

I have just installed NOD32 on my network and am in the process of removing Sophos.

 

Very different and slightly harder to get your head round than Sophos but it works and the speed is excellent.

 

I paid about the same for NOD as I did for Sophos but I fancied a change.

 

I installed version 4 of the client and am having problems with it not updating but install is pretty easy using MSI or push clients.

 

Much more stressful than I imagined but isn't all new software.

 

I have downgraded my opinion of the remote admin stuff from terrible to above average.

Posted
Can the users of NOD, Kaspersky, McAfee, Symantec, Trend, Avast, AVG, etc. post the memory footprint of an average client (main scanner process name, peak memory, etc)?

Will do, when I get a chance to sit down and stress test our Avast installs properly.

 

The main headache for SAV users seems to be memory usage and I would like to gather a bit of intelligence from users of other products.

Yes, for workstations this is true... For situations where there's a wireless network and as a result the potential for packet loss or connection drop Sophos is much more worrying in its inability to recover or report an error.

 

It shouldn't be taking over as the primary process that must be dealt with over the WZC client which needs to get enough resources to be able to reconnect... Catch22 springs to mind.

 

Bit moot now though as I've moved my schools away... and frankly there's still far too many issues regarding remote cleaning, scanning, etc... so I'm not going to be interested in returning.

Posted
Quakers -

 

I am still in the Eval stage of NOD32 - but I just got a quote from my sales rep and the pricing for NOD32 in education if fabulous. I have been on TrendMicro for several years - it has been a very good product that scales great.

 

I have just been looking at a different solution that I hope will handle protection better. It has been a battle lately with Trend for me - especially with malware - it seems to be getting in way to easy and then successfully pulling down Tojans. I get alerts but my NOD32 has picked up a number of things that Trend has missed in the last two weeks of eval.

 

Scott

 

I just received a quote too and it is 4 1/2 times what we are currently paying for McAfee!!:eek:

Posted (edited)
Not sure how you had Sophos set up but I've found it to be a little too vocal at times! I receive email notifications of detected threats and keep an eye on the other 'problems' using the Enterprise Console. It just works!

 

It usually shouts a lot in the Enterprise console but then when you want some useful info like what file was infected, what action was taken, what user was logged on we get... nada!

 

Get loads of SAV errors but even when acknowledging not all go away - and that's not because they're warnings as Sophos support told me. It's just the acknowledgement function doesn't work properly all of the time!

 

Way I see it a management console should tell me everything that I could find out by visiting the machine. For me that means taking the log file off the machine and displaying it nearly formatted in the console e.g. how WSUS does it. Sophos seems to take a few bits of info, leave the rest then tells me to go to each individual machine and check it out fully there... that's not Enterprise level standard imo.

 

Edit: just tried to view one of the "Error" computers and it's crashed the console!

 

Checking out the Kaspersky console in a bit, hope that's at the level otherwise the decision might get complicated :bowl:

 

The version 7 client is a lot heavier than 6 used to be (don't remember 1/2 as many problems with that) and the difference in load times between a machine with and without Sophos is very noticeable, especially at startup. Got a reg hack to try to disable a DLL but even if that fixes the problem it's another pain that shouldn't need doing.

Edited by gshaw
Posted
Well after trying our current Symatec Corporate 8 on on the little netbook today i promptly put NOD32 back on, the performance hit was noticable with symantec.

 

I'm running version 10.1.6.600 and its not noticeable on a 1ghz tablet pc. Maybe try the latest version.

Posted
The version 7 client is a lot heavier than 6 used to be ... Got a reg hack to try to disable a DLL but even if that fixes the problem it's another pain that shouldn't need doing.

 

We've added a lot of features into version 7 and heads up on version 9 (~September 09) as we're adding even more in. You can strip SAV right down and see if things improve but modern virus attacks are becoming even more complex. Conficker has highlighted the usefulness of HIPs to prevent registry modifications and stop that particular virus adding its service key - we've even seen a new strain of Conficker targeting our cleanup tool because it's been so successful but we're combating that too!

 

I do remember the golden age of SAV "classic" (the lightening bolt). The product was simple because AV could be. Now we're all living in a world of master crackers and vast sums of money being poured into malware writing by international organised crime - not geeks in garages.

 

If you want the lightest SAV...

 

- disable HIPs

- disable buffer overflow (BOPs)

- on-access scanner settings...

-- just read

-- scanning level = normal

-- scanning options = all unchecked

-- extensions "allow me to control exactly what is scanned"

-- exclusions = remote files

-- cleanup = do nothing (i.e. just block)

- disable application control

- strip out the Sophos_detoured.dll (the registry hack you mentioned?)

- disable the SophosBHO that actively scans website for malware (it's still running to protect you if SAV isn't)

 

...that should mean SAV doesn't have to do too much checking on a file before releasing it.

 

- run a full scan on the computer regularly to include new files and modified files in SAVs decision caching technology

 

...that should mean SAV is only comparing checksums and not scanning the whole file before releasing it.

 

- set AutoUpdate to stop running as the user logs on and allow a quicker boot(Sophos Anti-Virus for Windows 2000+: disabling updates on power-up)

- set AutoUpdate schedule to a longer delay (one hour, two hours?) not great if you've just done the above point! There's no best practice and you can adjust it as required to suit your network.

- set EM Library to a fixed package (not "latest SAV+IDEs" in EM Library) so you don't get engine updates each month. Rather you keep using the current engine and "top-up" with identity files which are lighter to download.

- setup a simple webCID on a local IIS server and allow clients to update from there with tons more file locking tolerance that UNC "file and print sharing".

 

...that should shorten the time taken for clients to update.

 

- defrag the hard drive

- switch off system restore (if you're not using it). Or exclude C:\System Volume Information\

- run scandisk to identify bad areas

- purge the temp locations and recycle bin (exclude C:\Recycler?) regularly

 

It's a big list and I could go on. You obviously don't have to do all of these things. You can see which ones might help you and just implement those. SAV + EM Library + Enterprise Console are very flexible products. From reading the threads on this site I get the impression from the feedback of users that NOD32 is initially complex to learn compared to SAV. Perhaps it is not. Perhaps SAV looks easier than it is because of its interface and layout? Perhaps the learning curve is steeper for Sophos than you first think and maybe some people are making light of the effort they have put into configuring it? I don't honestly know. However the evidence I have suggested the vast majority of users really like it and those open to suggestions can get help from Support to tweak it for their needs.

 

Regards,

Sophos Technical Support

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...