Virus Scanners and Process Authentication for Windows?
cavedwler asks: "Like alot of people, for one reason or another, I still have Windows running on one of my PC's and have the standard virus scanner and wondered if that is enough. I ran across this site and found a program that seems to work well in conjunction with any virus scanner. It blocks any executable or script from running on your PC without your approval. It is not a virus scanner as it does not search for viruses but just does not allow them to run. It also has the ability to monitor files and restore them in real time if they have been modified. I have been running it for a while now and am thinking of recommend it to my boss for use at work. I was wondering if anyone else out there had tried this, or other programs similar to it, in a real world environment and had any problems or successes."
Sounds a lot like SecureEXE.
while this sounds great in theory, if your virus software is as up to date as it should be on an important box, then how would these scripts be a problem? i've had outlood running on my desktop for YEARS and have received at least one email that contained all of the "famous" virus/scripts, and i've never had a problem. if you have your software set to NOT OPEN ANYTHING you dont tell it to, you dont have a problem. save your IT department some moeny and implement policies or some other such feature. just my 2 cents. . .
-
AVG AntiVirus
- ZoneAlarm and
-
Ad-aware
will keep your Windows box free of all sorts of nasty things for FREE.but do you really need them? Stuff like that tends to confuse the non-technical user types.
I find it far more effective to make sure that people aren't running as privileged users under NT. If they aren't running as a privileged user and you have a decent virus scanner that has up to date definitions you'll take care of 99.9% of the threats out there. Worst case scenario... some virus/worm wipes out the user's documents folder.
It really isn't that hard to properly secure NT/2000/XP... I just rarely see the IT staff of most companies bothering to do it.
What if this software recorded a category and you could choose what category of software you wanted to run? No more clicking on the should this run dialog.
What an idea? Maybe something could be put into a permissions file. Oh wait...
The message on the other side of this sig is false.
... it always prompts me it i REALLY want to run SexDialer.exe Of course I do! This bug needs to be fixed!
and only if the ppl at your work know what they are doing. I used to work in a company where some employess saw the "Download the magical executable and see her ride" ,and they would (the employees i am talking about are programmers actually, or so called, i am sad to say). So it might be good for you, or your boss, who know what your are doing, but dont assume every one is as smart my pal. God created stupidty to haunt us.... FOREVER..:)
The lunatic is in my head
Some viruses (actually, most) do not come in the directly executable flavor any more, I think.
I found that one of my biggest beefs with ZoneAlarm is the sheer lag it impeded upon my connections. Not that it's a bad product, I found it extremely useful for locking certain apps from internet access (non-infected apps that liked to "call home") - but when I switched to using an old PC as a routing server things become much faster.
Of course, back then I didn't know IPtables... but there are other solutions that do just as well. 486's with dual-NICS can run as these... but hell an older P1 will handle it very nicely and you can find peopel giving them away now.
Of course, ad-aware will always be my friend... and I'm using Norton (just the AV, not the drain-your-resources-suite) so I can't comment on AVG until I try it out later (when my norton subscription runs out, most likely).
Link.
Ant(Dude) @ Quality Foraged Links (AQFL.net) & The Ant Farm (antfarm.ma.cx / antfarm.home.dhs.org).
Australian made and amazingly comprehensive, especially under the hood.
Got time? Spend some of it coding or testing
Like alarge number of people, for along time there's been one
particular mistake by others at the top of alist of things
that annoy me. Why can't people be alittle more careful with
their grammar? One has to draw aline somewhere, don't be aloser.
YAW.
Your head of state is a corrupt weasel, I hope you're happy.