AV or no AV

Discussion in 'other anti-virus software' started by computer geek, Feb 5, 2008.

Thread Status:
Not open for further replies.
  1. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    I understand but like a lot use pop3 and want my emailed scanned.
     
  2. Cerxes

    Cerxes Registered Member

    Joined:
    Sep 6, 2005
    Posts:
    581
    Location:
    Northern Europe
    With the exception of Win 3.x/DOS, I´ve always used an AV with all the Win versions so by psychological reasons I wont get rid of my AV.

    /C.
     
  3. MitchE323

    MitchE323 Registered Member

    Joined:
    Nov 22, 2007
    Posts:
    156
    That's cool I can understand that. At least it's not a physcho case thing. lol
     
  4. MitchE323

    MitchE323 Registered Member

    Joined:
    Nov 22, 2007
    Posts:
    156
    But in reality what I do is forward all of my mail over to a Gmail account which always opens in a sandboxed browser. I know that some will say Gmail is not secure but I don't think that's been proven out yet. I use it like a filing cabinet for email attachments. But we are talking about 'lowering' risk here, not an expectation of 'zero' risk. And then that risk (whatever it is) is measured against the wear and tear of an A/V on an OS.
     
  5. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Even downloads are not that big a deal. Okay I download a media file and extract it from the sandbox to the desktop. Oops, is it really what I think it is. Easy, right click it and run it sandboxed, and see if it just does what it's supposed to. IF sandbox acquires a host of new files, then it's bye bye.
     
  6. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    That is an issue, and I haven't yet solved the Sandboxie issue with Outlook, so, I run Outlook with lowered rights, to keep anything in the emails from causing problems.

    Scanning with an AV is no more of a sure shot in my mind, and I can't help wondering if everyone is so secure in their AV scan, why on earth all the debate about which is the best AV. If there is such a difference in them, then a lot of people using the "inferior" ones, whichever they might be, might be worse off then what I do.
     
  7. Sjoeii

    Sjoeii Registered Member

    Joined:
    Aug 26, 2006
    Posts:
    1,240
    Location:
    52?18'51.59"N + 4?56'32.13"O
    Wow
    Trjam Norton now? Why Norton?
     
  8. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Don't start down this off topic road.

    Pete
     
  9. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,126
    Location:
    U.S.A. (South)
    Looks good, however you failed to mention but we can assume all that is run within an FD-ISR snapshot also? :)

    On the note of AV, i haven't used them since before the first introduction of System Safety Monitor, only Online Scans with the small exception of NOD32 On-Demand that keeps identification of my ongoing malware inventory.

    I don't even bother testing malware with an AV, and why? With a simple combination of SandboxIE + HIPS, EQS in my case, all positioned on my FD-ISR snapshots with archives to fall back on, completely eliminates the need for such heavy resource hogs like AV's, not to mention AV's are the most targeted security programs running and likely always will be.

    Also i "CAN" use SuRun and sometime enjoy doing so, but a sandbox does just fine thank you and the HIPS is the middle-man or gate, they must request permission first before passage. :D
     
  10. innerpeace

    innerpeace Registered Member

    Joined:
    Jan 15, 2007
    Posts:
    2,121
    Location:
    Mountaineer Country
    :thumb: What a great concept and it is something everyone needs to take a bit more seriously. I do scan everything that I download with 3 scanners and if possible, upload it to be scanned. I am however lacking in the research department though.

    As far as running without a real-time AV, I've been toying with the idea for a while now. Sandboxie and Returnil are best friends with Sandboxie set to block access to my non-system partitions and Returnil protects my C: or system partition. Anything I want to save I can recover it to my desktop, scan it and then move it to my other 2 data partitions if it's clean. I also have Online Armor 2 on-board which keeps getting better and better.

    I do think AV's will evolve to include other features that will be necessary to protect against malware. Blacklisting isn't perfect and I found evidence of this when asked to clean a relative's computer. It was sort of an eye-opener for me ;).
     
  11. Sjoeii

    Sjoeii Registered Member

    Joined:
    Aug 26, 2006
    Posts:
    1,240
    Location:
    52?18'51.59"N + 4?56'32.13"O
    Sorry Pete you right.

    I would always advice a good AV
     
  12. jrmhng

    jrmhng Registered Member

    Joined:
    Nov 4, 2007
    Posts:
    1,268
    Location:
    Australia
    Blacklisting is still useful. If it is a signature detection, it gives positive assurance that a file is bad.
     
  13. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    But of course.
     
  14. Stijnson

    Stijnson Registered Member

    Joined:
    Nov 7, 2007
    Posts:
    533
    Location:
    Paranoia Heaven
    Will Sandboxie work with a program like Newsleecher? I download movies and those rars are mostly 50Megs each, so how would I cope with those going through Sandboxie?
     
  15. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    I guess you mean real-time AVs. I've stopped using real-time AVs long time ago, even without sandboxes and virtualization tools.
    There are reports of malware authors starting to write code targeting Sandboxie
     
  16. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    good post, hopefully Tzuk will be ready as always.
     
  17. computer geek

    computer geek Registered Member

    Joined:
    Oct 6, 2007
    Posts:
    776
    Oh yes, scan it with virustotal before using it in sandbox because you don't know it is a virus, and then since a virus cannot be activated without the user doing something.
     
  18. computer geek

    computer geek Registered Member

    Joined:
    Oct 6, 2007
    Posts:
    776
    What products do you guys use along with sandbox?
     
  19. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,616
    Location:
    Milan and Seoul
    I stopped using an AV 4 months ago, and I'm never going to have one ever again paid or free. My statement is not a direct criticism to AVs, but within the context of this thread.

    A sandbox/virtual environment can be defeated of course, but there isn't enough malware around written to target such applications. I doubt that there ever will be for the simple reason that it isn't worth the trouble due to the the low number of sandboxes.

    Now if you add any HIPS that can stop executables (they all do basically), I don't see what an AV could add to your security except for identifying malware for the record (if detected) at a great cost in terms of computer resources and speed (that is a fact for any machine - a fast computer will run faster).

    For somebody who never bothers about computer security, an AV + a FW are certainly the simplest way to protect their computer without any knowledge of anything.
     
  20. Osaban

    Osaban Registered Member

    Joined:
    Apr 11, 2005
    Posts:
    5,616
    Location:
    Milan and Seoul
    Registry protection + antiexecutable
     
  21. computer geek

    computer geek Registered Member

    Joined:
    Oct 6, 2007
    Posts:
    776
    thats what comodo pf does, and safespace. So do you guys think its enough having sandbox+hips or add an av? I have to take into account that my computer was using masses (masses and masses) of memory with all three installed and was going a bit chugga chugga. :D
     
  22. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    lucas1985 summed it up best. You can go totally virtualized if you want, but malware writers will up their effort at penetrating those products to.

    Blue said best last week that the AV and virtual route go well to protect what the other doesnt.
     
  23. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    GeSWall free + Jetico 1 in real-time. Carefully studying the move to LUA+SRP.
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I don't bother. I can run it the sandbox and even if is a virus it won't hurt me. But the results will give big clues.
     
  25. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I am running Sandboxie,OA,SSM and ShadowDefender/Returnil on demand.

    SSM is optional.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.