Page 2 of 2 [ 24 posts ]  Go to page Previous  1, 2

lau
Veteran
Veteran

User avatar

Joined: 17 Jun 2006
Age: 77
Gender: Male
Posts: 9,798
Location: Somerset UK

27 Dec 2007, 11:52 am

Grimfaire wrote:
Part of my job is to keep our PCs clean.

(From which I would assume that your experience is primarily in a business environment, where the cost of a commercial product is not so important, plus the commercial versions usually have extra facilities that are more useful in such an environment, plus it would not be legal to use the free AV products in such cases.)

Grimfaire wrote:
My thumb drive has the following tools on it (most have been mentioned here)

HijackThis (which can be found at TrendMicro.com)
StartupList (this shows you want starts up with your PC)
Spybot S&D (make sure it's correct site as mentioned above. (Direct Download from Download.com)
Adaware from Lavasoft (note: a lot of pretenders with this just like Spybot; that is why I always put the company name with this)

I'm surprised that you have give a link to c|net's Download.com for SpyBot, as I always ensure that I go directly through http://www.safer-networking.org. Admittedly, the links from there for downloading the main program do include Download.com as an option.
I also wonder what "StartupList" does that SpyBot doesn't? Maybe I'll check it out, when next I have occasion to use Windows.

Grimfaire wrote:
Then never ever ever skimp on your AV scanners. The free ones are fine for quick and dirty but they all have flaws and are just not supported or updated like the good ones. They also rarely protect as well.

You base this statement on what?
Grimfaire wrote:
Symantec's End Point Protection is now the big dog on the block. It takes up less memory than any other product on the market, has more features including a rules based firewall(a must) and root kit detection. This used to be a big system hog but the new version is amazing.

After that - Kaspersky is your best choice.

There are other fine scanners out there but grisoft is not one of them. It has a detection rate of under 80% which puts it down there with McAfee. *ouch*


I'd be interested to know where you get your "80%" from. From an independent site, I see Grisoft with 97.75% for this August. Symantec get 98.80%, but are beaten by Avira at 99.45%, second only to AEC TrustPort at 99.64%. http://www.av-comparatives.org

I certainly would concede that Symantec, for instance, exhibits a higher detection rate. Unfortunately, that comes with a cost, in my experience. That cost being of losing your entire system due to a "hiccup" in Symantec's far too clever/extensive operation (something that happens all to often, in my opinion). I have spent quite some time working on sorting out normal, home user's systems. I have seen many that had been reduced to un-usability due to Norton(Symantec) misbehaving. At least Symantec provide a tool on their website for total removal of all their products - very handy, when it works, after you run it a few times, because the tool itself crashes.


_________________
"Striking up conversations with strangers is an autistic person's version of extreme sports." Kamran Nazeer


gbollard
Veteran
Veteran

User avatar

Joined: 5 Oct 2007
Age: 59
Gender: Male
Posts: 4,009
Location: Sydney, Australia

27 Dec 2007, 4:00 pm

Quote:
There are other fine scanners out there but grisoft is not one of them. It has a detection rate of under 80% which puts it down there with McAfee. *ouch*


We use McAfee at work plus a hardware firewall. I used to use Symantec but found their updates and methods to be pretty flaky. One of the risks of doing things the symantec way is that they can actually cause harm to the PC configuration.

I lost a few PCs trying to upgrade Symantec a couple of years ago and had to rebuild them. At the same time they were giving us lousy support on the firewall and their email scanner product was badly affecting our domino server. I abandoned the brand and have been much better for it.

No... McAfee isn't the best scanner out, but it's reliable enough for me, particularly with all the other protection I have in place.



Grimfaire
Deinonychus
Deinonychus

User avatar

Joined: 5 Aug 2007
Age: 56
Gender: Male
Posts: 307
Location: Michigan

27 Dec 2007, 5:08 pm

Bah! Hit a mouse button and lost what I was typing.

So I'll be a bit more conscise.

1) McAfee has more than it's share of problems as well as a much lower detection rate. In the past uninstalling has formated your hard drive for you.

2) Symantecs non AV engine applications in the past have been dreadful. I'd never have reccomended them to anyone.

3) Their new product is a quantam leap forward and just plains works.

4) Startup list is an entirely different beast than either hijackthis or spybot. Hijackthis lists everything that hooks into your web browser. Spybot is an application that scans based on signatures for malware on your system. Startup list gives a dump of everything that your system loads at startup. In conjunction with everything else; it helps tracking down those last vestiges of some malware that wants to sit around.

5) I base my numbers on keeping track of about 5 or 6 different sites that test AV programs and keep a spreadsheet at work. I also do my own testing with about 10 different apps every quarter.

6) Yes, I currently run a large network but I cut my teeth as a home consultant for years. I have a series of articles written, that I'll post someday, that are meant to help those sys-admins in small and medium businesses get the most bang for their buck. Most everything is marketed towards large enterprises that have $$$ to throw around; not us little guys who have limited funds and time.

7) If all you're using is McAfee and a hardware firewall; you're in for a world of hurt. I know I'm paranoid but it's kept us clean for a couple of years now. I use a hardware firewall backed by a software firewall before getting to the outer network. On top of that; all email is scanned 4 different times by 3 different AV scanners before it gets to the user. In a business, you have to assume everyone is a moron and will open everything. At a home, you can base it on the user.

8) I used the download.com link because it's a bit more familar to people. I agree that going directly is normally the best case. And personally only go to safer-networking.org myself.

9) The biggest problem with av-comparatives is that they only ever test the commercial home user versions of everything. The enterprise apps are an entirely different beast more often than not. Also, if you trend their results; you'll see that Kaspersky and Symantec score near the top in every report while others are a bit more hit or miss. I'll take a .5% drop one month to stay at the top month after month. :)

10) As for grisoft and other free scanners; I state this from personal experience in that I setup a small farm in my apartment and installed grisoft, mcafee and symantec (sorry, I did 3 more but forgot which they were). Left them open to the internet and then logged what happened. (all were virtuals so I could control the baseline to make sure everything was the same and reload them to base if crap happened). The old saying, you get what you pay for is quite often true at least with AV Scanners.


_________________
When in trouble or in doubt; run in circles scream and shout.


gbollard
Veteran
Veteran

User avatar

Joined: 5 Oct 2007
Age: 59
Gender: Male
Posts: 4,009
Location: Sydney, Australia

27 Dec 2007, 5:35 pm

Quote:
7) If all you're using is McAfee and a hardware firewall; you're in for a world of hurt. I know I'm paranoid but it's kept us clean for a couple of years now. I use a hardware firewall backed by a software firewall before getting to the outer network. On top of that; all email is scanned 4 different times by 3 different AV scanners before it gets to the user. In a business, you have to assume everyone is a moron and will open everything. At a home, you can base it on the user.


We use a hardware firewall on the network - it's fairly aggressively configured.
We have software Firewalls and AV.

All our inbound/outbound mail is scanned by a battery of different scanners.

We don't use outlook or exchange (yay --- that gets rid of half the viruses anyway) - we use Lotus Notes/Domino which doesn't permit the same level of viral interaction.

How do you get time to test all those scanners... do you have a large IT department? I'm basically the IT department, though I now have a 2 day per week helper. We only have about 28 internal people to support but we also look after 1200 externals and a couple of hundred databases. (and I do a bit of development too).

No time to get things perfect. :(



Grimfaire
Deinonychus
Deinonychus

User avatar

Joined: 5 Aug 2007
Age: 56
Gender: Male
Posts: 307
Location: Michigan

27 Dec 2007, 5:46 pm

It's my life. :)

We have a full time developer and I've a full time helper who does vertical application support which leaves me pretty free to handle everything else. I'm normally working 10+ hour days and go home to more testing and research. I've an internal support burden of about 80 people with 1000+ externals. I only have 30 or so DBs but it encompasses multiple terabytes of information. (last I checked I had over 40 TB of storage being used)

Remember --> Aspie. :) Computers have been one of my "things" since I switched over from dinosaurs at age 6. hehe

The greatest thing though for testing is Virtual Servers. I can't say enough about them. Get a VHD file with your OS... make copies of it and load up a bunch of different virtuals; install what you want on each and let them go.

Now; I'll probably say this a hundred different ways in a hundred different posts but it needs to be said.

It doesn't matter one little bit one OS/Mail/Server/etc that you run. The principles and operation are the same. The screws needed to screw in the nuts may be slightly different but you still need to attack each process in the same manner. You can never assume just because such and such OS hasn't had a virus this month that it's safe. Mac fanboi's are the worst of the lot. "I don't need an AV scanner because I have a Mac." (or insert your favorite Linux/BSD/UNIX/etc OS into that same line) Remember, the very first in the wild Virus was for UNIX. There are POC virus against every OS all the time.

The developers get all the glory because people see what they do. Security folks are only ever noticed when they fail.

:)


_________________
When in trouble or in doubt; run in circles scream and shout.


lau
Veteran
Veteran

User avatar

Joined: 17 Jun 2006
Age: 77
Gender: Male
Posts: 9,798
Location: Somerset UK

27 Dec 2007, 5:57 pm

Grimfaire wrote:
...
4) Startup list is an entirely different beast than either hijackthis or spybot. Hijackthis lists everything that hooks into your web browser. Spybot is an application that scans based on signatures for malware on your system. Startup list gives a dump of everything that your system loads at startup. In conjunction with everything else; it helps tracking down those last vestiges of some malware that wants to sit around.

Does this means you are not familiar with "Expert Mode" in SpyBot?


_________________
"Striking up conversations with strangers is an autistic person's version of extreme sports." Kamran Nazeer


TheZ
Tufted Titmouse
Tufted Titmouse

User avatar

Joined: 21 Dec 2007
Gender: Male
Posts: 32

27 Dec 2007, 6:13 pm

The safest thing would be to unplug your computer, but thats no fun is it.

When I used to work with a school districts IT unit spyware was our biggest issue becase of all these OMGFREEGAMESWOOT crap sites that included other free things. It got to the point that we ended up booting from an image for all the computer labs.



Dokken
Veteran
Veteran

User avatar

Joined: 11 Oct 2007
Age: 46
Gender: Male
Posts: 998
Location: DeeSee/Merryland Area

29 Dec 2007, 12:46 am

If you're using windows, for firewall, best bet is Comodo or online Armor (both are free) http://www.matousec.com/projects/window ... esults.php

for anti-virus: Kaspersky, NOD32, or BitDefender2008 (not free, but there is always a way) and Avira AntiVir PersonalEdition (free)

anti-spyware: AVG Anti-Spyware Plus (free), Sunbelt CounterSpy, Spyware Doctor, or Spy Sweeper (last 3 aren't free, but there is always a way). I personally don't use any of these in real-time. Just On-Demand scanners, but may be best for you to use them in real time

anti-trojans: aSquared(free) or AVG Anti-Spyware Plus (free)


_________________
I hereby accuse the North American empire of being the biggest menace to our planet.