since my subcription to Norton AV it's going to expire next month. I wonder if there's anything better, or more secure, not to mention better price,or should i stay put with the one I have now? any ideas? I'll apreciate any comment. thanx in advance
God hates us all, you know it's true, God hates this place. - Slayer 1726 Posts 10/03
Posted - Feb 23 2005 : 12:54AM
Panda is pretty good, but from what I have read NOD32 is the best.
Now if you are on broadband, and don't have a firewall, I would suggest getting one of those too. I honestly think those are not hyped enough. For safety on the net I say its a 50/50 tie between a decent firewall and decent A/V.
At this point, one can guarantee that a Windows PC that does not have a firewall and is connected to the Internet via broadband will get infected inside of 5 minutes.
For the better price, try http://free.grisoft.com . You can't beat free!
They do have a subscription version too, but it is not necessary to buy it at some point - you can use the free version forever.
Updates come out regularly for the free version. Varies. Rare to be only one per week. More like every other day.
Program can update itself - you don't have to manually download the update files and install.
Security? I found a review once that said this program - it is named AVG - didn't rate quite as high as the big names. But it was close. Considering that it is free, thats not bad. To get the most security, you probably want to use more than one anyway.
I don't know what a realistic average would be. But at work, a colleague setup a Windows XP test machine. He connected to a special network outside our company firewall, and 30 seconds (I kid you not) after he had connected to Google to test the connection, it started acting up, and one minute later it shut down.
It was no big deal. He just cleaned the hard drive and reinstalled XP and SP2 before going online again. No problems since then. Still, it was kinda funny in a geeky sort of way. I'd never seen a PC getting infected that fast before.
God hates us all, you know it's true, God hates this place. - Slayer 1726 Posts 10/03
Posted - Feb 23 2005 : 9:30AM
Correct me if I'm wrong, but is http://free.grisoft.com, AVG A/V ? If they make a F/W I didn't know it. I will say their software is pretty good as well, even for being free, however al the tests I have seen say NOD32 is the only one to NOT miss a Virus in like 3 years. (if I remember correctly)
if it doesn't have to be free, i'd go with nod32 or kav(kapersky). either of them will detect "in the wild" viruses that haven't been identified yet better than anything else, and scan faster with less resources than other stuff. nod32 is probably a little friendlier, i'm with pl on this one.
assuming stuff is set up right, isp's block enough trojan ports that the average person has a lot longer than the discredited, security co.-funded pr study said they would. windows ships with sp2, if you close up the holes and services that you should i'd think you can go weeks without worrying. not that you should, but a random 60-minute section of my firebox's log shows nothing infectious tried to get in, just lots of pinging-maybe i'll disable it and the ap and look at some packets with ethereal sometime later-but if you're not doing something idiotic with open ports and netbios shit the claims of infection within seconds are madness.
Minutes, not seconds, and 'something idiotic' is Windows out of the box. Betting on your ISP protecting you from hackers is my idea of madness, and your average joe has no idea what services to turn off in Windows.
That lot of pinging your firebox logged was probably hacker programs looking for PC's to attack.
I use the Norton Internet Security package (combined firewall and anti-virus package). Works well for me but did cost around £40 (the equivalent of about $76, though you'd probably find it a lot cheaper - as with most things - in the States) :)
I am happy with AVG, and have been for two years or better. Another decent free antivirus program is Avast from avast.com
I got a homepage hijacker that adaware and spybot and none of the others would touch. After googling and reading forums for two days I came up with someone recommending avast in combination with "adaware" and "hijack this". I downloaded and installed it and it cleaned up the problem. I uninstalled AVG before the install. I left avast running for a week or so after but it appeared to use more resources than AVG, so I switched back.
A free firewall is zonealarm- it's low overhead and seems effective. It can be set as verbose or as unobtrusive as you want it. I do not recommend it for email protection. Use one of the above for that.
I haven't kept myself up-to-date and in the know. I see a chance here to ask some questions. :)
A few years ago, the way it was, was that to have your machine infected by a virus, you had to do something stupid - i.e. download and executable and then run it. Same for a trojan.
Then, along came MS, with the ability to run scripts within its email program, right? ( this is about the time I didn't keep up to date ) As I seem to recall, the thing to do then was to set one's email client to not auto-open anything with a script in it - which in essence is the same as before - - don't run unknown stuff. In this case it is now a script, not a .exe or .com.
Apparently something has changed, from the way you folks in-the-know comment. You're saying that doing nothing - just sitting there connected to the internet - a machine can become infected? Without having to go into minute detail, can you tell me how that can happen? cite some examples maybe? Thanks.
Also, can you recommend some good places on the web - hopefully not full of hype - that would be good to read, to get caught up on this? Thanks again.
Me neither. I'm not responsible for IT security at work, and I haven't run Windows at home since the 90s.
Still, I'll take a stab at a couple of your Qs. Anyone should feel free to correct any wrong info.
Yes. However Outlook Express could still be fooled into running scripts when you read the mail, even if you specifically set it up not to. IIRC, the first exploit was called "BubbleBoy".
Don't use Outlook Express if you don't have to. There are several alternatives. Back in the day, I was quite fond of Eudora's free version. Find one that works for you.
Yes. It's got to do with a software interface layer that enables applications to communicate with each other. Microsoft, like any large company, rolled their own technology to do this called COM. For a user, this feature can be quite useful. As a programmer I hate COM. It's utter shite. *Ahem* small sidestep. Later MS enabled COM to be used across a network. They called it DCOM, and they said that it was good. Amen. Like most large bits of software, DCOM has some bugs. Some of them quite severe. Enabling remote infection. I think "Blaster" has been the most famous exploit of those bugs so far.
Here is a short history of DCOM my Microsoft. GRC.com has another view.
GRC.com is a pretty good place to check out for info about Windows security holes. Do keep in mind when browsing there, that Steve at GRC is not Microsoft friendly. Even I think he goes over the top at times, but at least that means he points out every little flaw he can come up with. Just don't panic about everything he goes on about.
If you're unsure about your firewall, you should check out GRC's ShieldsUP port scanner. Look for it on their main page.
Looks like it is concerned with adware and spyware, as you said. I was thinking more about viruses.
Quite a bit of that is beyond me, but I think that the first thing mentioned there, that allowed the problem, was javascipt. Wouldn't that make the simple solution to just disable in the browser?
>>As I seem to recall, the thing to do then was to set one's >>email client to not auto-open anything with a script in it
>Yes. However Outlook Express could still be fooled into >running scripts when you read the mail, even if you >specifically set it up not to.
It could? I didn't know that. Tnx.
>IIRC, the first exploit was called "BubbleBoy".
>Don't use Outlook Express if you don't have to.
I remembered this one! :)
>There are several alternatives. Back in the day, I was >quite fond of Eudora's free version. Find one that works >for you.
Me too. Eudora. It has been a while though. If I recall, it has some sort of floating ad box, that manages to get itself *exactly* just where you don't want it.
>>You're saying that doing nothing - just sitting there >>connected to the internet - a machine can become >infected?
>Yes. >It's got to do with a software interface layer that enables >applications to communicate with each other. >Microsoft, like any large company, rolled their own >technology to do this called COM. >For a user, this feature can be quite useful. As a >programmer I hate COM. It's utter shite. >*Ahem* small sidestep. >Later MS enabled COM to be used across a network. They >called it DCOM, and they said that it was good. Amen. >Like most large bits of software, DCOM has some bugs. Some >of them quite severe. Enabling remote infection. >I think "Blaster" has been the most famous exploit of those >bugs so far.
>Here >is a short history of DCOM my Microsoft. >GRC.com has another view.
>GRC.com is a pretty good place to check out for info about >Windows security holes. >Do keep in mind when browsing there, that Steve at GRC is >not Microsoft friendly. Even I think he goes over >the top at times, but at least that means he points out >every little flaw he can come up with. >Just don't panic about everything he goes on about.
>If you're unsure about your firewall, you should check out >GRC's ShieldsUP port scanner. Look for it on their main >page.
>Hope this wasn't too off-topic.
Thank you for the info and websites. Have not been there yet. Will do soon. Probably be back with questions - :)
Sadly, it's not an exaggeration, at least for NT5.
A friend of mine who is a design engineer at a major PC company tests all new boards with NT4, NT5, etc, as well as current operating systems. He has found, by experiment, that it is no longer possible to install NT5 with a system connected to the corporate net, never mind the Internet itself, because the mean time to infection is shorter than the best case time to download current patches after installing Windows. He has to burn patches onto CD and apply them that way before connecting Ethernet.
A more recent OS & patchlevel would likely survive longer. But without a real firewall you're just putting up a "honeypot".
Probably the best site for general security, virus and all Internet usage issues is http://www.broadbandreports.com/
For AV software I'm using KAV (Kaspersky). It's really not clear which AV software is best and you'll find at least a few votes for almost anything. The key point is that no one program solves everything - the general assumption seems to be that even the best AV software has no more than 30% coverage.
Best practice is probably:
Use a hardware "stateful" (aka SPI) firewall. I use ZyXel.
Use good real-time AV software (not just Panda's free on-demand scan).
Don't use Internet Explorer.
Don't use Outlook or Outlook Express.
Don't log in as Administrator for normal activity. Create a non-privileged account and use that for day-to-day things. This limits the damage malware can do if it does get in.
Don't give the kids Administrator-level accounts. They don't need to install neat games their friends send them.
Don't open an attachment just because it came from dear old Grandma Ethel - she didn't know if it was safe when she sent it.
If you haven't seen a really convincing phish e-mail then you need to be more suspicious.
If you use Yahoo, Google or any other web e-mail, never use the same password there as at any other web site.
that may have been true, but sp2's firewall along with most isp's filtering or blocking ports 135-9 should give you a hell of a lot longer than 5 minutes. even pre-sp2, there was an experiment done on broadbandreports that put the figure around 11 hours.
Kaspersky is at http://www.kaspersky.com/index.html
A US company that sells licenses is at http://www.useice.com/ (Kaspersky is Russian)
Free trials are available from Kaspersky.
A Kaspersky-specific forum is at http://forums.useice.com/cgi-bin/ikonboard.cgi
BroadbandReport's security forum is at http://www.broadbandreports.com/forum/security and is highly recommended before spending money on any particular package, or for security information in general.
Kaspersky has a very good reputation for finding viruses, but sometimes is a bit more of a problem child than more user-experience-oriented packages such as Norton. After posting my message above I discovered that one of my notebooks won't do it's scheduled full scans, won't uninstall and won't upgrade. I'll have to ask KAV support for the special uninstaller.