Virus and Malware
Posted 23/01/2011 - 14:54
Link
Amoringello - your comment on Ms Security essentials got me thinking. I said above that I had a Trojan that Ms SE missed and Norton stopped. Of course that might not quite be the case. What I do not know is whether Ms SE ran first and missed it or had Norton not caught it, whether Ms SE would have caught it.
Any thoughts?
Any thoughts?
Posted 23/01/2011 - 15:18
Link
Not much on thoughts. It seems each has their own set of pluses and minuses. For a free product it holds up pretty darned well.
For the paid products... well, lets just say that a few years ago I had done tests against popular malware toolkits created five (5) years earlier (things that script kiddies find abundantly and probably don't even use any more because their antiquated). The top of the line paid programs caught less than half of them. More sophisticated developed malware applications installed and hid silently against all paid and free malware detection software I tested (about two dozen different applications - e.g. Kaspersky, Sophos, McAffee, Norton, TrendMicro).
This was about three or four years ago. Things have gotten better - on both sides.
My suggestions...
1. Keep your OS up to date with latest patches.
2. Have some sort of malware detection, if only to give that little extra protection in case you fat-finger a web address and go to "faceboob.com" by mistake. (or if your favorite website gets hacked).
I've only gotten a virus twice in 20+ years. One I installed myself. The other I got because I mis-typed a web page URL.
3. Never run more than one anti-malware program at once.
Sadly, none are perfect and none are equal to another. Roll the dice and pick one.
4. Avoid software firewalls unless you have the patience and knowledge to use them properly.
Software Firewalls are great, as they can keep unwanted programs from calling out!
Sadly, they become so overly annoying that they tend to train the user into accepting every message just so that they can get their work done. I mean how many people know if SVCHOST should or should not allow the current unknown connection??? So they end up being counter productive, and damned near useless.
For the paid products... well, lets just say that a few years ago I had done tests against popular malware toolkits created five (5) years earlier (things that script kiddies find abundantly and probably don't even use any more because their antiquated). The top of the line paid programs caught less than half of them. More sophisticated developed malware applications installed and hid silently against all paid and free malware detection software I tested (about two dozen different applications - e.g. Kaspersky, Sophos, McAffee, Norton, TrendMicro).
This was about three or four years ago. Things have gotten better - on both sides.
My suggestions...
1. Keep your OS up to date with latest patches.
2. Have some sort of malware detection, if only to give that little extra protection in case you fat-finger a web address and go to "faceboob.com" by mistake. (or if your favorite website gets hacked).
I've only gotten a virus twice in 20+ years. One I installed myself. The other I got because I mis-typed a web page URL.
3. Never run more than one anti-malware program at once.
Sadly, none are perfect and none are equal to another. Roll the dice and pick one.
4. Avoid software firewalls unless you have the patience and knowledge to use them properly.
Software Firewalls are great, as they can keep unwanted programs from calling out!
Sadly, they become so overly annoying that they tend to train the user into accepting every message just so that they can get their work done. I mean how many people know if SVCHOST should or should not allow the current unknown connection??? So they end up being counter productive, and damned near useless.
Posted 23/01/2011 - 16:38
Link
... which is why the best software also asks "only if unsure". And then if your new PDF 'sploit tries to call home, you get a warning and *only then*. So you take warnings more seriously as they come up rarely.
Behavioural analysis is the way forward, along with cloud capability and better UIs to inform users - they are getting into a lot of technology they don't understand and need their hands holding.
Bret
Behavioural analysis is the way forward, along with cloud capability and better UIs to inform users - they are getting into a lot of technology they don't understand and need their hands holding.
Bret
my pics: link
my kit: K3, K5, K-01, DA 18-55, D-FA50 macro, Siggy 30/1.4, 100-300/f4, 70-200/2.8, Samsung 12-24/f4, Tamron 17-50, and lots of other bits.
my kit: K3, K5, K-01, DA 18-55, D-FA50 macro, Siggy 30/1.4, 100-300/f4, 70-200/2.8, Samsung 12-24/f4, Tamron 17-50, and lots of other bits.
Add Comment
To leave a comment - Log in to Pentax User or create a new account.


967 posts
20 years
Virginia,
USA
When it was detected I was also prompted to install/run a virus scanner which I think was part of the Malware/virus. declined as it didnt seem to be anything to do with AVG.
After re-reading your comments, if this file was detected upon initial installation, it is probably safe to say that your machine is safe. This is assuming the description I read on it is correct and that it simply configures your registry to run further software on startup. If the file was cleaned before you rebooted, you are likely OK. (hopefully the registry is fixed upon detection and cleaning)
Most of the fake virus alerts are not actually capable of doing anything as long as you do not click to allow them to install. (again, smart decision!!) Although without knowing exactly which malware was reporting the notice it is hard to say. (it is possible to be infected without actively running an executable).
My comments above still stand, and if you're paranoid I'd wipe the machine... but I'd suspect you're *probably* OK on this one.