I soon managed to get the machine horribly infected, to the point where I could not open any programme without a barrage of pop-ups and errors. I then tried to install and clean the system using a variety of anti-virus programmes. I measured the time each took to scan, and the amount of infections removed.
In the anti-virus section, I compared NOD32 and its replacement ESS anti-virus with the most popular free systems, AVG, Avast and Avira Antivir, and the often recommended commercial systems Kaspersky, Trend Micro and CA (Computer Associates). The virtual machine was reloaded after each test, so the products were tested under exactly the same circumstances.
Kaspersky and Avast would not install on the test system, and Trend Micro could not complete a scan, crashing before cleaning the system. This does not imply that they are bad products or would not protect a system under usual circumstances.
| Product | Infections cleaned | Time of first scan |
| NOD32 V2.7 | 49 | 2.43 |
| Eset V3 | 46 | 3.49 |
| Kaspersky | Could not install | |
| AVG Free | 31 | 15.35 |
| Avast | Could not install | |
| Avira Antivir Free | 47 | 8.06 |
| CA | 40 | >10* |
| Trend Micro | Could not complete scan |
Notes on testing procedure:
Time of first scan utilized a quick or smart scan where this was available.CA needed help to finish the first scan – I had to kill processes manually. Hence the time is not accurate. I could not do the same with Trend Micro as the computer completely froze each time a scan was attempted.
The free AVG product deserves a special mention, as it is trusted by many users. Note that it had the worst detection rate and longest scanning time of any product tested. This product should be avoided.
I found a better result using NOD32 V2.7 compared to its successor, Eset Anti-Virus V3. I hope this result will shift as the new product matures, but at the time being recommend the older version which is still updated hourly.
These tests were conducted using the Anti-Virus only programmes. Most vendors supply more comprehensive security suites, however these have a greater impact on system performance, and I prefer to use a mixture of other hardware and software to achieve protection, as discussed below.
In most cases the machines required a reboot and second scan, plus one or more anti-malware scans before being anywhere near completely clean. Should you find your computer in such a state I recommend professional technical support.
Conclusions
Any Windows user connected to the Internet absolutely needs an up to date anti-virus programme, however this is only one line of defense.This article has not discussed firewalls, as that is another topic that warrants its own article. You should always access the Internet from behind a NAT router whenever possible, and have the operating system firewall turned on.
Consider a content filtering DNS service like the free OpenDNS and have it setup to prevent access to malicious sites. You will need a static IP to take advantage of content filtering.
Use the NOD32, V2.7 anti-virus system. It proved not only the lightest on system resources, but had the fastest scan time and the best result.
Home users with a tight budget could choose Avira Antivir, which supplies a free version for home use only. It came a close second to NOD32. It does however display advertising at least once per day.
Use at least one anti-malware system as well. In testing, the free version of Malware Bytes proved very effective. It does not provide real-time protection so needs to be run when required. Super Anti-Spyware also gave a very good result.
Consider using Mozilla Firefox with the No-Script plugin. This prevents web sites from running any active content on your computer without your explicit permission.
Perhaps the most important defense is to educate your users. Ensure they are not clicking on sensationalistic Internet advertising (if it sounds too good to be true, avoid it!). Particularly common at the moment are ads claiming to clean your computer that are actually fronts for malicious software. Ensure they do not open attachments from an untrusted source, or without knowing exactly what they are.
Recommended products
All these security products are free with the exception of NOD32 anti-virus.DNS Protection:
OpenDNS http://opendns.com/
Setup with a static IP to not allow connection to dangerous sites.
Anti-Virus:
NOD32 V2.7 http://nod32.com.au/ (or available from Mobile Computing)
Avira Antivir Free http://free-av.com/
Anti-Malware:
Malware Bytes http://malwarebytes.org/
Super Anti-Spyware http://superantispyware.com/
Safe Web Browsing:
Mozilla Firefox http://firefox.com/ with the No-Script plugin http://noscript.net/