Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old July 30th, 2009, 10:39 AM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,552
Default Re: Microsoft beta AV

Quote:
Originally Posted by Toby75
Can someone post some screen shots of the HIPS component? I would like to compare it to Windows Defender.

Thanks,
Toby

There's no HIPS functionality in MSE, and HIPS functionality of WD is taken out in Windows 7 version. MSE's proactive defense is based on Dynamic Signatures (search for it), which typically delivers the same "prompts" as a regular detection, thus continuing unmatched simplicity.
  #27  
Old July 30th, 2009, 03:24 PM
Toby75's Avatar
Toby75 Toby75 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 461
Default Re: Microsoft beta AV

Quote:
Originally Posted by raven211
There's no HIPS functionality in MSE, and HIPS functionality of WD is taken out in Windows 7 version. MSE's proactive defense is based on Dynamic Signatures (search for it), which typically delivers the same "prompts" as a regular detection, thus continuing unmatched simplicity.

OK - Thank You Raven

Are there any other ways MSE checks if the file is valid? MD5, etc.?

Last edited by Toby75 : July 30th, 2009 at 03:30 PM.
  #28  
Old July 30th, 2009, 03:27 PM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,552
Default Re: Microsoft beta AV

Quote:
Originally Posted by Toby75
OK - Thank You Raven

Are there any other ways MSE checks if the file is valid? MD5, etc.?

No problem. Sorry, but I don't have that technical information, though I'm sure someone else here knows.
  #29  
Old July 30th, 2009, 04:21 PM
trjam's Avatar
trjam trjam is offline
Incredibly Massive Poster
 
Join Date: Aug 2006
Location: North Carolina
Posts: 8,620
Default Re: Microsoft beta AV

MSE does start to slooow things down after a couple of days, but it is still beta.
__________________
Webroot SecureAnywhere
  #30  
Old July 31st, 2009, 07:31 AM
Smiggy's Avatar
Smiggy Smiggy is offline
Regular Poster
 
Join Date: May 2007
Location: The Angel Isle
Posts: 173
Default Re: Microsoft beta AV

No problems here, been testing on 20 PC's of varying speeds, memory.

Killed the Rustok SpamBot that was plaguing one PC and showed no slowdown on even the PC with least memory/CPU power.
Initial download of signatures was slow on all but after setting up scheduler on daily 4hr intervals it updates quick as a flash now.

Thumbs up from me, and it's only a Beta!!

__________________
Win 8/Avast 8/Common Sense 8
  #31  
Old July 31st, 2009, 09:52 AM
Edward_Stream's Avatar
Edward_Stream Edward_Stream is offline
Infrequent Poster
 
Join Date: Jul 2009
Posts: 18
Default Re: Microsoft beta AV

anyone tested it? how does it work? how about the balance between resource consumption and detection rate?
  #32  
Old July 31st, 2009, 09:59 AM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,552
Default Re: Microsoft beta AV

Quote:
Originally Posted by Edward_Stream
anyone tested it? how does it work? how about the balance between resource consumption and detection rate?

http://www.wilderssecurity.com/showt...ity+essentials
  #33  
Old July 31st, 2009, 10:45 AM
Eliot's Avatar
Eliot Eliot is offline
Frequent Poster
 
Join Date: Aug 2003
Location: Arkansas, USA
Posts: 854
Default Re: Microsoft beta AV

I am not sure how it detects. I am beginning to think it is not scanning for malware but rather scanning files for them. I can't think of another way to describe it.
__________________
Asus P5Q PRO, Intel Q9650 Quad Core 3.0 Ghz
GeForce 9800 GTX+, 4GB OCZ DDR 1200

Running Windows 7 x64
  #34  
Old July 31st, 2009, 11:06 AM
funkydude's Avatar
funkydude funkydude is online now
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Microsoft beta AV

You don't need to describe it, Microsoft describes it very well, it's based on heuristics/generic signatures/dynamic signatures, whatever you want to call it.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #35  
Old August 4th, 2009, 10:05 PM
Toby75's Avatar
Toby75 Toby75 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 461
Default Re: Microsoft beta AV

On the Microsoft forums they say that using WD will not be necessary when using MSE...that it covers the same things and then some.

However, WD has HIPS, MSE does not. So you can bypass MSE!
  #36  
Old August 5th, 2009, 02:48 AM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,552
Default Re: Microsoft beta AV

Quote:
Originally Posted by Toby75
On the Microsoft forums they say that using WD will not be necessary when using MSE...that it covers the same things and then some.

However, WD has HIPS, MSE does not. So you can bypass MSE!

Yep, they're making a big mistake. If checking the built-in Windows Defender of Windows 7 you'll get what I mean...
  #37  
Old August 6th, 2009, 03:12 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Microsoft beta AV

Quote:
Originally Posted by raven211
Yep, they're making a big mistake. If checking the built-in Windows Defender of Windows 7 you'll get what I mean...

When you look at the I/O of MSE, it must be using the same intrusion detection agents as Windows Defender, only you can not control them. So the option to be warned when joining as an experienced member in the community is lost.

For Windows 7/Vista Users the UAC protection will cover that ground, so only the XP users are worse off in practise (well at least the 95% of them which run as admin).

Regards Kees
  #38  
Old August 6th, 2009, 03:52 AM
raven211's Avatar
raven211 raven211 is offline
Very Frequent Poster
 
Join Date: May 2005
Posts: 2,552
Default Re: Microsoft beta AV

Quote:
Originally Posted by Kees1958
When you look at the I/O of MSE, it must be using the same intrusion detection agents as Windows Defender, only you can not control them. So the option to be warned when joining as an experienced member in the community is lost.

For Windows 7/Vista Users the UAC protection will cover that ground, so only the XP users are worse off in practise (well at least the 95% of them which run as admin).

Regards Kees

So what you're saying is that MSE is handling all the data which was HIPS "automatically" by itself instead, and that the same goes for the later WD?
  #39  
Old August 6th, 2009, 04:03 AM
Kees1958's Avatar
Kees1958 Kees1958 is offline
Massive Poster
 
Join Date: Jul 2006
Posts: 5,857
Default Re: Microsoft beta AV

Sorry, yes and no

MSE offers the same protection as WD at basic user level, using all standard settings. It performs the actions you defined (automatically) when a known malware touches a point protected by an intrusion agent,

Only as advanced user (spynet community) of WD you would get a warining. UAC covers these grounds, so that is problably why MS removed the WD options. As a basic user of WD, you can control/select the agents, MSE does not offer this option. But I guess 99% of the users did not change these WD settings anyway.

Cheers
  #40  
Old August 6th, 2009, 05:05 PM
Toby75's Avatar
Toby75 Toby75 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 461
Default Re: Microsoft beta AV

Quote:
Originally Posted by Kees1958
Sorry, yes and no

MSE offers the same protection as WD at basic user level, using all standard settings. It performs the actions you defined (automatically) when a known malware touches a point protected by an intrusion agent,

Only as advanced user (spynet community) of WD you would get a warining. UAC covers these grounds, so that is problably why MS removed the WD options. As a basic user of WD, you can control/select the agents, MSE does not offer this option. But I guess 99% of the users did not change these WD settings anyway.

Cheers


I used to use WD as an advanced member. Now I'm using MSE with UAC active. When I'm testing malware which try to load drivers...I'm not prompted by UAC...am I supposed to be prompted? I thought UAC only controls the execution of exe's.


Edit: I forgot to mention I'm using Vista.
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:50 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums