A forum for reverse engineering, OS internals and malware analysis 

All off-topic discussion goes here.

What is your home AV?

Kaspersky
26
13%
Symantec
2
1%
Dr.Web
3
2%
NOD32
20
10%
TrendMicro
2
1%
McAfee
2
1%
Sophos
5
3%
F-Secure
No votes
0%
None
61
31%
Other
73
38%
 #24966  by nul1ptr_
 Fri Jan 16, 2015 9:29 am
Probably this is worth noting in this thread.

Personally I don't use AV as a linux user but I still install one on my family PC. Up to this day it was Avast but not using it myself I have never really tested it. Oh, and also EMET in addition and maybe Malwarebytes Anti-Rootkit in the future.
 #25374  by Patrick
 Mon Mar 02, 2015 9:25 pm
jimmychen wrote:so it should be a good indicator for av.
If only this were the truth.

avast's kernel-mode drivers still have bugs like using a user-mode IRP field but the execution mode of the original requester is kernel-mode. Unsure if this will cause a real-world crash, but if you enable verifier with the proper flags it'll catch it.