Forum Moderators: phranque
So my question is, do I really need anti-virus software? Maybe I'm naive, but I can't picture doing anything myself to get a virus.
The reason I ask is that I just had to do an unexpected reinstall of Windows 2000 on my computer this afternoon, and now it's really running snappy and nice. Every time I add AV software, including AVG, I get terrible system slowdowns and I kind of hate to do it if my brain can take the place of anti-virus software anyway! ;)
Or am I just being stupid for even considering not installing some AV stuff?
But I did go to check out a site I shouldn't have recently, to see how bad MSIE was, and if I hadn't had av and software firewalls I'd have lost the box probably.
Normally though I never see any signs of viruses anymore, especially after switching to thunderbird and using its email view as plain text option, that basically shuts down all virus activation completely.
avg shouldn't give you system slow downs like that, go into the configurations and turn off the scan every file on opening option, I think that's it, that will speed up the box a lot, or just use an even lower impact av product.
And I have had clients forward me emails with attachments which they said they couldn't open, viruses of course that opened fine, installed themselves on their boxes, just didn't do anything the user could see.
Oh, and this one: a friend of mine's dad came to visit him, the computer was on, his dad went to hotmail, opened up an email, machine got several viruses and spywares instantly, the av protection was out of date by a few weeks.
Friend didn't realize his dad had done that til next day, you can't always watch everything every minute, that's what av protection is for. [Mac and Linux users, feel free to snicker by the way...]
Fixing that one took me about 6 hours, sometimes it's a drag being the guy who can fix it, I popped on avg and no more problems like that. Just tweak avg, it is pretty light.
Oh yeah I Used to install AVG but it was getting more and resource hungry thats why I changed to AntiVir.
Same comments as you, you should have broadband to run it. But actually, avg is the same, it just doesn't update the whole thing as often, but it does update all of itself every once in a while, I don't know how often, not as often as antivir though.
But to be accurate, it doesn't download that big file every update, it just downloads it maybe once a month or so, every time the main program jumps up a version that is.
The family PC is a different matter; I have that loaded with Avast, MAS, ZoneAlarm etc. I can't stand over my family 24/7 to stop them doing something stupid.
Whilst a firewall is nigh-on essential nowadays, and an IDS is desirable if you're running as root (Administrator account), personally, I think you'd be fine without permanent AV protection... provided that you take steps to protect yourself against the usual vectors -- email, ActiveX and dodgy downloads.
Leaving a Windows machine connected to the net without an anti-virus program is simply not safe, even behind a firewall. Using Firefox is not in itself enough protection - that browser has a significant enough market share to start attracting the interest of virus-writers. Also any programs or scripts that you might download could contain malware.
But now, one of my business acquaintances retails a less well-known AV software ($30-$40). I have been using it for almost a year and never had a virus. It is very light, runs 24x7, updates automatically every day.
As far as I know, firewalls alone will not protect against viruses like email attachments. About two months ago, I tried to open a virus, it was from one of my supplier’s in South Korea. I thought it was information that I would need. But luckily my virus checker caught it.
I have Windows XP SP2 on two machines and 2000 on another. Does XP have an AV checker now and is it any good? Is it free?
So, next question: What's a good, light AV software that will do its job but have a minimal impact on system performance? AVG with "check-every-file" turned off has been recommended, as well as AntiVir. Are there any others I should consider before committing myself? (Norton and McAfee are out, I'll never use them again, same for PC-cillin.) I'd love to find a good open-source application for this; I looked at ClamWin, which looks good, except that it doesn't have realtime monitoring. Of course, it's probably the realtime monitoring of other AV's that causes the performance hit in the first place.
I'd like to be particularly careful this time around, since every AV software I've ever tried has slowed the system (any system) way down and it never really recovers, not even by uninstalling the AV application. So I want to be sure to make the right choice. I'm willing to pay for software if necessary. Realtime monitoring would be nice, but I guess it wouldn't be a requirement.
In all these years I have never had a virus and I actually trade on the net so I get a lot of emails.
I do not open emails with unrequested attachments and delete anything unread which does not look pertinent.
I do have a firewall and I do not visit sites I that I would rather people not know I have looked at.
The above has kept me trouble free for many years
The problem with not running any av is if you hit unexpected/unanticipated circumstances, other users, who are all pretty much by definition clueless, tricky sites, things like a client emailing you a document that you expect but which has been contaminated by a virus, downloading some piece of software that installs something bad, whatever.
Linux guys though, don't be totally confident, it was only very recently that a buffer overflow thing was fixed that allowed escalation of privileges, can't remember what it was, but it's very easy to exploit, worms can carry that payload.
Don't be positive you have no viruses by the way, if you run 4 different av products on your machine, each will find a different type or group of viruses, so if you've done one scan, it doesn't mean you don't have a trojan/backdoor/virus in waiting on your box, it just means you think you don't.
If it matters, antivir and avg are mentioned by crackers as decent av choices, whereas norton/mcafee just make them laugh.
So, next question: What's a good, light AV software that will do its job but have a minimal impact on system performance?
if you do not run antivirus, in my opinion you're asking for trouble. most viruses are not detectable by us regular ol humans, unless of course you can read every single line of code on your computer every day and - and have a job too. dont stick your head in the sand, get some antivirus software.
there are 2 types of people in this world:
- those who have had a virus on their computer, and those that will..
Norton software in general has a reputation for getting in the way (but I've never used it myself) and I've yet to meet a real computer professional that uses McAfee. I tried both McAfee and Kaspersky stuff many years ago and ditched both. The Kaspersky software was laughably slow but I believe it has improved somewhat since then.
Kaled.
Thanks again!
So recently I did complete system reinstall. My idea was to install:
1. Win2K
2. Win2K Service Pack on CD-ROM (no risk there)
3. Drivers not covered by the sys or service pack
4. Basic apps (everyday stuff)
5. fluff (DVD player, that sort of thing)
That meant that AV software and Firefox installs came right after drivers, all of which I thought were either in Win2K, the SP, or on CD. Unfortunately, I was missing one or two drivers. I visited just a dozen or so pages, I thought all on the manufacturers' sites. I figured, that wasn't that risky. WRONG! I picked up a host of spyware and one virus that would, among other things, not let me update my virus definition files. Since it didn't manifest itself until quite a bit later in the process, this resulted in a whole day's work down the drain.
I ended up reformatting the hard drive and starting over with this process
1. Win2K and SP from CD-ROM
2. AV and anti-spyware software from CD
3. Update AV and anti-spyware
4. Install Firefox in case I need to surf for something during the next phase.
5. Drivers
6. Everyday apps
7. Fluff
Lesson learned. No surfing without AV and with IE, no matter who runs the site and for how brief a time.
I also hated AV software because it slowed down the system, then I found Dr. Web and I loved it. It's only $40/year, but it's totally worth it. In total it takes 2MB of RAM and it stays on 0% CPU usage most of the time. It does background scans, but it's so polite, that you don't notice it. Every time I accidently downloaded something infected, it always poped up though, so it is not just slow because it's not working, it's just well written!
Downloading FF is pretty much the first thing I do after Windows is reinstalled
Actually, I should have mentioned, that I'm paranoid. So when I reinstalled, I switched the system to the slave drive, then reinstalled on the new master. When I got the virus problems, I rebooted on the slave drive, made sure I had all the missing downloads on CD, then reinstalled without having to go online until I had FF and all AV and anti-spyware stuff in place.
Then with the latest virus defs, I did a full scan of both drives and then started transferring data over.
I'm surprised you guys see a slowdown with Grisoft AVG! I don't see any performance drop at all, the only thing I notice is when mail is incoming it takes a few seconds more coming in as it scans it. I schedule the complete scans at 3:30AM (that slim avenue between OK-enough-hit-the-pillow and here-we-go-again) and the few times I've been up during a scan it's lags. But still workable.
So my question is, do I really need anti-virus software? Maybe I'm naive, but I can't picture doing anything myself to get a virus.
Never use it. Never a problem. Once in a blue moon, when I'm feeling less certain I run Tend Micro's Housecall online scanner, but it's never found anything.
I do use a hardware firewall though to keep the hackers out of the broadband connection which they seem to be constantly scanning.
Matt
Best thing is to have one for the net ( surfing and emails and downloads ) ..one for "dev" ..another for making your sites etc
Use regmons ..( the diamond one is good )..and worm hooks ..( they also make a good one )..both need adjusting depending on what you are doing and where you are going ...but are way way more effective than anything from norton , macafee or panda etc ..which are like putting photos of rotwiellers in the window of your house and hoping the burglars beleive they are real ..:))
Best of the major freebees are AVG and Anti vir ( be warned about anti vir in the free version the help is fora only ..but you need to understand German to login to the fora ) best of the old freebees was probably esafe from aladdin ( used to use file checksums on load each time the system started so it was very very difficult to get past it per session )..now commercial and tres tres cher ( around $1500.oo per user last time I looked ) ..( BTW their hasp is junk ..and easily diss'd and opened ) ....and esafe is only about as good as NOD 32 ..actually NOD 32 is probably better as its faster and as has been mentioned has more frequent updates of it's tables ..and is very very light foot print ..low CPU usage ..seriously if you think about it the price is centimes per day for 99% security ( 100 % security doesn't exist )..no one can protect you from your own "left click" on the " blondes do it ..." button ;))
Virii ( for simplicity we will call all virii , exploits , tojans ..etc ..virii ..Ok ..cute ..good :) infections come in 3 sorts ..
type #1. PRON CLICK ..your problem ..you new it was dangerous ..you didn't go in covered ..it's like STD's ..call the doc ..and hope he or she is discreet ..and all the cover your tracks stuff doesn't work..i dont care what it says it does ..if one day your significant other learns enough they will find what you click on ..so ..assume it or dont do it ..;)
80% of what I clean up is this ..normally we dont discuss pron here ( good reasons we have young veiwers ..how young we do not know ) but it is a fact that most drive by malware sites are adult ..or warez ..usually both ..
the next ..around 15% is
type #2. EMAIL ..preview pane in outlook is the biggest culprit ..( been there ..done that ..only the once tho :)..got a 2 kb crypted javascript destruct script in a header ..straight into the preveiw pane ( which I had relaxed 'cos on 9x doze it was running under the same restrictions /permissions as the IE 5.5..so I lost all the sys back up files and sysfiles beginning with the letter "L" ( upper or lower case 'doze doesn't discriminate ..creamed is creamed ..heh heh :)
this attack was however aimed at me directly ..so after decrypting the js ..I had to admire the design ( GFO ) ..( and also thanks to vkaryl ..come back ..it's tooo quiet here v ..who sent me the .dlls needed to replace what was tossed ..
Nevertheless "outlook" has never been allowed to stay on any box of mine that uses "doze since ..you can remove outlook altogether from anything ..removing IE is trickier ..and can kill your system if you get it wrong as it can be considered to be the alter ego of all redmonds OS's ..but it can be done ..( actually you need to keep it on at least one machine ..just to see how you designed pages look,in it and what the pages of others are actually doing ..just dont go into anywhere in anything other than source mode and even better use lynx for the first look ..opera for the second ( with all options to "off" ) ..you can always read what someones java script include is gong to do without actually letting it run rampant on your box while it surprises you ..java script can make destructive x sit up and do handstands ..whatever the permissions are set to ..and whatever SP2 says ..so unless you are Mr marx or Mr tribble ..dont :). ( maybe also kaled and some others whom I forgot ..I beg your pardons :)
Last ..
type #3. This is where it gets exotic ..we had this conversation last year ( or maybe it was the year before ..flashback and old age are ruining my timesense ..worth every moment of it tho ;))..'bout the "Lan guy" ..
now most lan guys or girls have waaay more paper than me that says they know what they are doing ..but usually their systems can be adjusted by people like me ( in a previous life only ..'onest 'guv' ) ..because they lack the curiosity ( or if you will the perversity of ..what if I did this ) ..here we are not discussing protecting your servers from "MANU" from RIO and his friends or even from Sony and the rootkit ninjas see [webmasterworld.com...] ..he hee hee :)
just your own box ..so ..
Rule #1. dont use the same box for the web as for the rest ..( actually I use 9811 for the web box and now XP pro for another etc and 9811 for another ..and ubuntu for another ..and 2k on the 1st lap top Xp pro on the 2nd and probably will move 80% all things to linux soon anyway ) ..
Nothing gets from the web box to the others except via USB key and is checked down to the last cluster tip and byte even files which are "protected" there are many small apps ..some of them free which will let you do this ( even with 'doze files which are running and therefore "protected " ..I recommend going to [sysinternals.com...] to begin looking into such things ..It's not the only place out there but it will do for a beginning ..
You could also begin by reading right here too [webmasterworld.com...] ..about how to catch nasties via your choice of CD music or DVD ..( a reg mon would have saved you had you been unlucky enough to have bought one of these )..reg mon is your friend ..learn the "mantra"
REGMON IS MY FRIEND :))
Rule #2.no one 'cept YOU gets to touch your boxes ..buy another one for each family member ..no one gets to put so much as a USB key or a camera near your box without you know it's a clean whatever ..
Rule #3. you can get infected by just about anything that can hold data and quite a few things that you think can't hold data and just 'cos the ripped DVD of harry potter that your kid downloaded from kazza or limewire ..( ROTFALOL ) or whatever they are using to exchange virii these days ..played in your home DVD player doesnt mean it's not loaded with "OWN youz" from "manu" or his friends ..same applies to your mobile phones and anything that can store data ..flash memory or otherwise ..
Rule #4.If you are in doubt ..run a regmon and a worm hook and an AV ..from those suggested ... there are quite a few members, admins , owners and mods here ...( and I know more than a few lurkers ) who can tell even more specifically than I have done ..what you should be aware of ..this post could be much longer ..but as discussed in another thread previously also this is not a subject that one can do too much detail in on open fora without it turning in to a script kiddies kindergarten ..if you are truly curious you will learn security and associated subjects ( go look in other fora here such as JDMorgans for some gems ) ..If you were to ask about malicious code postable on web pages ..for example ..or why some code is unpostable here on these fora ..