3 ms·
> Then they must find a copy of the virus, examine it and add it to the list of virus definitions used by their software. Strictly speaking, this isn't true.
by CanSpice 12y ago
> Then they must find a copy of the virus, examine it and add it to the list of virus definitions used by their software.
Strictly speaking, this isn't true. The major AV companies use file behaviours to try to stop viruses as a first line of defense, something like "if a file is an executable and it tries to run some manner of encryption on files in the My Documents folder, its likelihood of being a virus is high". AV companies use file checksums as a last-ditch effort because most viruses out there are polymorphic (they have some unused data section at the end that randomly changes, which busts checksum detection).
A lot of AV companies also offer virus cleanup services, so if you do happen to get hit by a virus that snuck by, they can help reduce the damage.
Nobody's saying "use AV and you don't have to ever worry again". AV is just another piece of the defense puzzle, along with user vigilance (don't click that link in that email from "eBay"), operating system restrictions, network restrictions (to help prevent data egress), and so on.