Showing posts with label AntiVirus. Show all posts
Showing posts with label AntiVirus. Show all posts

Tuesday, 6 November 2012

Independent AntiVirus Vendor Product Review Resources

We need some independent voices when it comes to the plethora of AntiVirus products out there.

In our search we have come up with the following resources that provide some insight into the various AntiVirus products out there and how affective they are.

virus BULLETIN

So far the best one we have come up with is:

Their Magic Quadrant is an awesome at-a-glance view of current product:

image

The above chart is a great comparison of a great many AntiVirus vendor’s products.

AV-comparatives

This site has some great charts with a number of important factors that should be a part of our A/V product analysis.

There are a number of different reports available on this site.

image

image

The above charts give us some inclination on how the product protects the endpoint but also how it impacts the performance of the endpoint machine.

It used to be that A/V products could greatly hinder a user’s day-to-day duties. With today’s PCs that is not so much a problem anymore but one should still be mindful of any possible impact especially for power users.

AV-Test

This site has a limited product list with a few informative charts based on the host operating system being protected.

The link above is to their corporate products list:

image

Note the lack of AVG listed anywhere on this chart.

Based on the Virus Bulletin results and the A-V Comparatives results we are confident that AVG can be a viable alternative to Symantec’s EndPoint Protection.

We will be looking at deploying the AVG product here and as a pilot at one of our more active accounting firms to get some real-world experience with it.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

Windows Live Writer

Tuesday, 23 October 2012

Some Malware Tools

Here is a short list of some malware tools:

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

Windows Live Writer

Wednesday, 17 October 2012

AVG CloudCare - Whatcha Think?

While at the SMB Nation Fall Conference we saw a demonstration of AVG's new Cloud managed antivirus product and it looks very promising.

Please post a comment or use the Blog Questions e-mail link in the blog's column with your thoughts on AVG's corporate A/V product.

Whatcha think? Worth a look or not?

Thanks for reading!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

Windows Live Writer

Wednesday, 8 August 2012

Quick Links to MalwareBytes Program and Definitions Download

We sometimes need to use the MalwareBytes product to verify that a system is clean.

That site has links to both the program download on a third party site as well as the definition update file that can be important if a malware infection is afoot.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Thursday, 21 July 2011

Microsoft Security Essentials–False Positive on Adware: Win32/Hotbar

A number of our machines have been throwing the following warning from MSE:

image

Adware: Win32/Hotbar

Category: Adware

Description: This program has potentially unwanted behavior.

Recommended action: Review the alert details to see why the software was detected. If you do not like how the software operates or if you do not recognize and trust the publisher, consider blocking or removing the software.

Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.

Items:

file:C:\Windows\Temp\7E04B5FB-F941-4DE0-ACA3-C0C397211F5F-Sigs\643683E7-6213-45C6-B3D0-151E26E31C81mpasdlta.vdm.new.temp

file:C:\Windows\Temp\7E04B5FB-F941-4DE0-ACA3-C0C397211F5F-Sigs\643683E7-6213-45C6-B3D0-151E26E31C81mpasdlta.vdm.old.temp

We sent out an e-mail to find out what was up.

It turns out that the flag is a false positive on MSE’s own update files with a fix in the works.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Tuesday, 10 May 2011

Via Phone: Hi, We are the National Internet Service and You are Sending Our Systems a Virus!

One of our client’s users had the presence of mind to pause for a moment when they were called at home this morning and heard the line:

Hi, we are the National Internet Service and your computer is sending our systems a virus! Please sit down at your computer and . . .

They interrupted the speaker and told them that they would be calling their IT support folks ASAP and hung up.

When things like this happen it is important to get in touch with the authorities that handle fraud cases such as this:

Contact for the Canadian Anti-Fraud Centre:

It's not always easy to spot a scam, and new ones are invented every day.

If you suspect that you may be a target of fraud, or if you have already sent funds, don't be embarrassed - you're not alone.

If you want to report a fraud, or if you need more information, contact The Canadian Anti- Fraud Centre:

Toll Free: 1-888-495-8501

Toll Free Fax: 1-888-654-9426
Email: info@antifraudcentre.ca

To report economic crime on-line please click here

One can only imagine how one can be fooled into providing all sorts of information to a caller like this.

A pearl of wisdom from my Dad: Never volunteer _anything_ in the way of information. Be specific, to the point, and KISS.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 2 May 2011

WindowsRecovery Malware – Who To Trust For Removal?

One of our client’s users picked up this lovely nasty:

image

image

Note the lack of Task Manager button in the above or below screenshots.

image

  • WindowsRecovery Malware

Now, we went to this site to download Malwarebytes and its updates:

image

Once we downloaded the two we dropped them onto a USB flash drive and plugged it into the infected machine.

When we managed to navigate to the USB flash drive the MB file was missing?!? We ended up needing to reveal hidden files in Windows Explorer as WindowsRecovery had managed to set the MB install file as hidden!

Okay, we have MB and its update installed. We were able to use the Start –> Run command to get to the mbam.exe file (Windows XP SP3 is where the infection is) but it would not update.

Once we started the MB scan and it began to pick up the infected files the malware rebooted the machine.

When we slaved up the infected machine’s hardware Microsoft Security Essentials picked up one infected file while MB found a few more. We dropped the drive back into the machine and WindowsRecovery was still there. :(

Do a Bing search for Remove WindowsRecovery and the following happens:

image

If we can’t get the machine clean using the “traditional” product in Malwarebytes then it is looking like the only option for us is to wipe and reload. There is no way we are going to trust many if not all of the sites that are in the results above. Especially all of the ones offering a “free removal tool”.

If this is a sign of the way things are going with malware infections we are going to stop wasting both our client’s time and ours and advise that we would image the machine, wipe it, and then reload it.

Now, here we are a little later on and what do we find but:

After reading through the above instructions, we will still recommend a wipe and reload. Our policy is to make this recommendation whenever a Trojan or Rootkit are involved. Once a system is owned in this manner there is virtually no way to guarantee ownership after “cleaning”.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Thursday, 3 February 2011

Symantec LiveUpdate Certificate Expiring Soon

On certain versions of Symantec’s LiveUpdate product the Symantec root certificate will be expiring on April 30, 2011.

A grid of products impacted by this problem:

image

The updates look to be had from Symantec’s support portal which may require an up to date product license.

Note that the impact of the certificate expiration for products impacted by this situation is no more A/V updates!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 26 February 2010

Excellent Virus Information Site Along With Links To Free Tools

This link comes by way of Harry Waldron (blog link).

image

The resources on this site are absolutely amazing! The links to free tools that can be used to detect and clean almost any type of virus or malware infection are priceless.

This is one site to bookmark and it even has an RSS link for the reader!

Thanks Harry! :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Thursday, 17 September 2009

Why We Use ExchangeDefender

A while back we had a client that had booked a series of flights online.

A few minutes later, an e-mail with an attachment happened to arrive in his inbox with the airline’s “itinerary”. Without even thinking about it he opened the e-mail and the attachment and that was the point of no return.

The A/V, Trend, did not stop it.

So, we ended up in a bad situation that got worse when we discovered that the local laptop backups were not being done.

We had tried the cloud A/V and spam filtering that Trend had but we ended up having way too much grief with their service.

In comes Own Web Now’s ExchangeDefender.

The analogy we use when explaining why we prefer having the filtering done in the cloud before e-mail enters the corporate network works quite well.

The Anti-Virus program is like a 6’6” 275Lb bouncer that sits close to the front door. They can move about the place with relative ease and have access to all entry points in the place.

For the most part, the bouncer – name him/her whatever – catches any baddies that try to get in through the doors or the windows.

But, every once in a while a slim and short baddie does get by the bouncer because baddie is just too quick and new.

It then takes a bit of training for the bouncer to pick up on the new baddie and squash them at the point of entry. That delay can cause a big problem if the biddies' siblings happen to try and get in too.

With that imagery in mind, we can explain how Vlad’s service is set up to do just that long before the baddie even reaches the door. They get squashed out on the street! ;)

And, because the service is dedicated to this task alone, the filtering that is done will be that much better than anything the Anti-Virus vendors can do in real-time.

This morning, this was in an Inbox:

image

The file was culled before it reached the corporate network. A file culled out there is a file not clicked on by a user. Leaving that file to some form of Exchange based filtering or the endpoint workstation is a dangerous game we are no longer willing to play.

Given the fact that the cost of the ExchangeDefender service is very minimal relative to the level of services received it is not a difficult sell. We also include the ExchangeDefender service in our Hybrid Managed Services plans to add value to them too.

And, once our clients are onboard with our services and ExchangeDefender they do notice a big difference in the amount of time they no longer spend processing all of the junk e-mail.

Being a partner with Own Web Now is an important part of our business model (previous blog post). As we build up our client’s usage of the OWN services, the more confident we are going forward.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Friday, 10 July 2009

Rogue Infection: WARNING! YOUR’RE IN DANGER!

One of our clients received a link via an e-mail from a friend saying that they needed to purchase, download, and install a product to help keep their system running great!

Now, the machine is virtually unusable due to constant battering by pop ups from a product called System Security 2009 (also a Rogue AntiSpyware blog link). The rogue also prevents any .EXE from running on the system except an IE window that takes us to the “online activation system”.

We are going to flatten this system, extract their data from an earlier ShadowProtect image, and start fresh.

Since much of the infections legitimately found on the system are Trojan related, there can be no guarantees that removing them does not leave a backdoor of some sort into the system.

The desktop as it is now:

Security-Warning

And:

Security-Warning-2

Our client new something was well out of sorts due to the misspelling of “YOUR’RE” when the background started showing up.

Note the constant fight between the malware and AVG Free.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Friday, 6 March 2009

SBS 2008 – Disable or Remove A/V Prior to Running the SBS Connect Wizard

When it comes time to add a new workstation or laptop to the SBS 2008 domain, keep in mind that the SBS Connect Wizard makes a number of critical changes to the system.

These changes happen in the way of software additions such as the new SBS Vista Gadget, local profile configuration, registry changes, and the domain configuration to mention a few.

Because of the nature of these changes, it is a good idea to not have any third party AntiVirus (A/V) products installed or active at the time the SBS Connect Wizard will be used.

Since it is our preference to run a server managed A/V product such as Symantec’s EndPoint Protection MR4 on our SBS 2008 domains, we install the software after the system has been connected to the domain.

If there is an A/V product already installed on the system either remove it in preparation for the SBS domain join, or at least disable it prior to running the SBS Connect Wizard.

We have seen instances where third party A/V products have put up a barrier when the SBS Connect Wizard has been used and thus caused the domain join, local profile configuration, and SBS configuration changes to fail.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer

Thursday, 12 February 2009

ExchangeDefender is a huge time and money saver for our clients and us!

We moved our domains over to the ExchangeDefender E-mail Hygiene and Reputation Services Provider not quite three weeks ago now.

One of the first things that got noticed was the drastic reduction of junk showing up in our Junk Mail folders. By drastic reduction, we mean maybe 1 piece of spam for every couple of days!

Another change is the elimination of illicit SMTP connections to our SBS (previous blog post) based Exchange server as ISA now only allows SMTP connections from the ExchangeDefender servers.

The ExchangeDefender reports are amazing. They show how much e-mail is spam, and how much is not. They give our clients and us a pretty good idea of how much time we are saving by not having to deal with spam!

Ultimately, we no longer need to deal with all of that spam which is a huge time waster when we look at the amount of time spent sifting through the garbage everyday!

The other aspect to having our outbound e-mail passing through the ExchangeDefender servers is no longer needing to monitor black lists for our IP address or IP subnet on all of the blacklists that are out there. That in turn means that we no longer need to jump through all of the hoops required to take our IP off of a blacklist.

The big time waster when it comes to having our IP address blacklisted is the inability to send e-mail to any domain that subscribes to that blacklist. We would then end up waiting hours, days even, before our IP was considered “safe” by the recipient’s e-mail servers once we found the blacklist site and its Remove IP feature.

The ExchangeDefender service is worth it for both our clients and us. That is why we signed up with OWN as a Service Provider!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer

Wednesday, 11 February 2009

Symantec Endpoint Protection MR4 Memory Footprint and CPU Usage

A while back, we blogged about Symantec Endpoint Protection (SEP) and how much of a memory hog it was: SBS on dual Xeon E5345 Quad vs. 5130 Dual Core + Symantec EndPoint Memory Costs.

We just finished our first site A/V migration off of Trend’s Worry Free Business Security back to Symantec’s Endpoint Protection in its MR4 version. In this case, as well as it will be at the other Trend sites we have, we paid for a 1 year gold maintenance SEP agreement for the client’s site, removed the Trend product, and installed SEP at no cost to our clients.

Our Trend odyssey can be read here:

Given our past experience with SEP RTM, the one main concern we had was with memory usage.

We were fortunate that in this case, we had a second server with Windows Server 2008 Standard x64 installed running a number of different roles on the SBS 2003 domain. The box has 16GB of RAM installed, so memory should not be an issue.

Here are a couple of screenshots of SEP up and running on the Win2K8 x64 box:

09-02-11 Symantec - Program Footprints

Symantec Endpoint Protection MR4 x64 Memory Footprint (SEP Client and SEP Management Server): ~200MB

The above screenshot was taken after about 3 days of the server being in production. The memory footprint out of the box was not a whole lot less than that.

Wow! What a huge step down in memory consumption versus the previous versions of the product.

Symantec utilizes SQL Anywhere for their database structures:

09-02-11 Symantec - Db SQL Anywhere footprint

SEP MR4 SQL Anywhere Memory Footprint: ~82MB

The combined total RAM usage of the product on the management server is less than 250MB! That is an awesome achievement. Especially since that number includes both the client and management components.

The SEP client on the workstations has also taken a huge step down in its memory consumption:

09-02-11 Symantec SEP MR4 on Windows Vista

SEP MR4 Windows Vista Enterprise Client Memory Footprint: ~30MB

 09-02-11 Symantec SEP MR4 on Windows XP Pro

SEP MR4 Windows XP Professional Client Memory Footprint: ~15MB

It looks as though both the server and workstation versions were slimmed right down.

Besides the memory footprint reduction, the CPU resources that the server A/V and client workstation A/V uses has been drastically reduced. In our workstation VMs, the client would run around 3-5% of the CPU cycles during intensive usage while on physical laptops and workstations that number would barely approach 1-3% during intensive usage.

On the server side, Live Update is set up to run update checks hourly, and it does seem to be pulling a good number of updates down for each SEP component during those update sessions. So, it looks as though Symantec is also keen on having the product as up to date as possible.

Now, whether our SEP clients remain virus free will be another thing to see yet.

But, given the fact that none of our clients had a virus problem while on Symantec’s previous generation corporate products, we are counting on SEP to keep that virus free legacy alive.

NOTE: We do not install third party firewall components on servers or workstations. We only install the A/V and malware components.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer

Wednesday, 14 January 2009

AntiVirus 2009 on Google's Home Page?!? WinSystems.dll

This is probably one of the more interesting things to see on any given day:


Google has detected unregistered (sic) AntiVirus 2009 copy on your computer.

Now, besides the bad grammar, it is a little surprising that Google would be supporting any kind of A/V product.

If one is careful enough, the so-called IE Information Bar actually hides a bit of bad code that shows itself.

BleepingComputer.com has some great articles on removing the malware.

The articles point to a MalwareByte's A/V freeware product that actually does the removal: Malwarebytes' Anti-Malware.

In the above screenshot, the malware shows in the tray. The user knew that there was something up on the initial window, but did not realize that the only way to get rid of that window was via the Task Manager. So, clicking on the red X only served to give A/V 2009 a foothold into the system.

So, we downloaded the tool and ran it through. It cleaned out the system, but missed something. After the clean we were still getting the A/V 2009 hook on the Google Web page.

So, back to BleepingComputer.com: Antivirus 2009 Hijacks The Google Web Site. But, the winsrc.dll file mentioned in the article did not exist on this system.

Run IE with no add-ons and Google was clean.

So, a look into the Add-Ons manager in IE turned up:

IE Add-On for Research? winsystems.dll

Disable that add-on, and sure enough there was no more A/V 2009 on Google's home page.

A quick search for the file and a SHIFT+DEL and the file was gone.

The lesson here is quite simple: MalwareBytes is a great tool, but like any other malware fighting tool, it may miss on its searches once in a while. It managed to scan through and find a whole bunch of different stuff like the original A/V 2009 programs, search bars and the like, but it missed the winsystems.dll.

For users with Windows Vista, the UAC lesson is very simple: Cancel.

For users of Windows XP: Do Not Touch. Bring up the Task Manager and kill the software there.

The process in the Processes tab was AntiVirus2009.exe, so it was not too difficult to kill so we could get to the MalwareBytes site and download the cleaner tool as A/V 2009 always redirected to a "Get our product now or else you are doomed" type message page.

We really need to keep on top of training our users! In this case, we are dealing with a new client. So, in time, and with some Internet "Street Smarts" training, our new client's users will be more prone to avoid any malware infections.

Working against malware is one area where our experience, that is our working with the same settings and Internet Explorer Add-Ons, and knowing which Windows processes are the right ones to be there, can pay dividends in finding the source of the problem quickly and efficiently.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists

*All Mac on SBS posts are posted on our in-house iMac via the Safari Web browser.