Microsoft Security Essentials

Discussion in 'other anti-virus software' started by Kees1958, Aug 9, 2009.

Thread Status:
Not open for further replies.
  1. Zimzi

    Zimzi Registered Member

    Joined:
    Jul 10, 2005
    Posts:
    289
    In my opinion the lack of web scanner is the bigest flaw for the MSE. MSE scans only those files that are downloaded to disk. It is risky because in case of, for example, drive-by exploit MSE detects exploit when it is downloaded. Unfortunately, very often it is too late.

    I would rather choose an antivirus that has web scanner and that can detect malware coming from the web before data actualy reache to disk. Many times I was in situation when Avira Free (which has no web scanner) detected malware too late. In the identical situation Avira Premium, thanks to the web scanner, protected pc without difficulty.

    I would really like to see MSE with web scanner and capability for blocking dangerous IPs / URLs. I think that MSE then really would be probably the best choice among antiviruses.
     
  2. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076

    Incorrect, for the script to take advantage of the exploit it needs to be saved to cache, in most cases, this download to cache is suspended before the exploit script can even finish downloading and it's detected by MSE during download. In cases where the whole file needs to be scanned, newly created files are always suspended for scanning and are harmless.
     
  3. Morro

    Morro Registered Member

    Joined:
    Jul 11, 2009
    Posts:
    355
    Location:
    Netherlands
    Besides if you use a program like Sandboxie it will/Should be contained already.
     
  4. Fajo

    Fajo Registered Member

    Joined:
    Jun 13, 2008
    Posts:
    1,814
    Sandboxie was not even brought up. Lets try not to RE Hijack a thread as it just got back on track in the first place. We don't need to start going down the same path we just got off in the first place, Nor do you want this thread closed due to A vs B which it will eventuality turn into if this keeps up ;(
     
  5. ratchet

    ratchet Registered Member

    Joined:
    Feb 20, 2006
    Posts:
    1,988
    Vista Home Premium SP1 question! I've always had Windows Updates set to inform me but not download and install. Do I need to have it set to download and install to keep MSE's strictures updated? Thank You!
     
  6. jmc777

    jmc777 Registered Member

    Joined:
    Aug 6, 2004
    Posts:
    244
    No, you don't.
     
  7. Zimzi

    Zimzi Registered Member

    Joined:
    Jul 10, 2005
    Posts:
    289
    I ask for an explanation and will be glad to learn something from you.

    If I understood well, you claim one of these things:

    a) MSE has some special features (detecting and removal technics or whatever to be called), which enables to MSE to be as effective (in detecting and removing exploits and other malware coming from the web) as antiviruses that have a web scanner?

    b) There are no big differences between antiviruses that have web scanner and antiviruses that do not have a web scanner, that both of them, under some circumstances, can be equally effective and that the whole story about the importance of web scanners is just a snake oil?

    @ Fajo

    You're so funny (in a positive sense). :D
    Will you write something about MSE finally?
     
  8. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    The main useful thing behind web scanners is URL blocking which is what browsers do, the actual scanning of files in transit is about as useful as POP3 scanning (not very useful, but some people really like these features). Everything eventually ends up on your drive where it can be suspended and removed before it is even run.

    But you need to be careful, some AV's will keep detection of scripts/etc in a separate module (MSE does not do this, MSE has detection for everything in 1 module so you're safe) and disabling the web module in those AV's can potentially reduce your protection. I believe this is where the main belief that having a web scanner increases your protection comes from, especially if the AV company wants to have slightly increased heuristics on their web module (which can be argued to create more FPs from downloaded files), rather than their standard scanning module. With MSE, the heuristics are the same throughout the program (and we already know from tests they are really good), so again, it does not need detection of scripts/etc in a separate module.
     
    Last edited: Oct 27, 2009
  9. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Hello, if you hit the update now button it will delay the auto udate, I suggest you leave it alone for a few days and you should start noticing it updating itself.
     
  10. nanana1

    nanana1 Frequent Poster

    Joined:
    Jun 22, 2007
    Posts:
    947
    Anyone o_O?
     
  11. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Vista/7 = ProgramData\Microsoft\Microsoft Antimalware
     
  12. Zimzi

    Zimzi Registered Member

    Joined:
    Jul 10, 2005
    Posts:
    289
    I can not agree with your claim because I know that everything comes from the Internet may not be saved in the browser's cache before, eventually, it is used. But, since I do not take my opinion on this matter for particularly relevant, I put here the link to very interesting explanation posted on this forum by Vlk (Vlk is antimalware expert and member of the Avast's team).

    Vlk's post best explains why the web scanner is very useful addition to any anti-virus which aims to provide not only basic antimalware protection.
     
  13. Fly

    Fly Registered Member

    Joined:
    Nov 1, 2007
    Posts:
    2,201
    A question, not just specifically related to MSE. Without a web shield, does MSE (or other AVs) scan files only after they are written to disk? Not when code/malware just resides in memory (RAM) ?
     
  14. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    You seem to misunderstand again, I wasn't explaining the use of a cache, but for you to see something on your screen, it NEEDS to be downloaded, where it is scanned before it is run, it's not a mater of "agreeing" with me it's a matter of FACT, it does NOT matter where it is downloaded, it WILL be downloaded so your computer can run it and you see the effect. You cannot escape having a file scanned.
     
  15. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    bottom line, MSE is the best AV out there. Time will tell but they are going to sink vast resources into making it stay that way. Or at least that is what a little birdie out west told me.;)
     
  16. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Not really a fact as much of a hope I'd assume :)
     
  17. trjam

    trjam Registered Member

    Joined:
    Aug 18, 2006
    Posts:
    9,102
    Location:
    North Carolina USA
    will be in time for next round of testing, take my word on that. Detection is the key that resources are being aimed at.
     
  18. JohnnyDollar

    JohnnyDollar Guest

    Did anyone else get an email yesterday from MS about beta testing the new build?
     
  19. IceCube1010

    IceCube1010 Registered Member

    Joined:
    Apr 26, 2008
    Posts:
    963
    Location:
    Earth
    Yes. I did about 4 days ago.

    Ice
     
  20. guest

    guest Guest

    What's new in the beta?
     
  21. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Nope, how does one get it?
     
  22. JohnnyDollar

    JohnnyDollar Guest

  23. jmc777

    jmc777 Registered Member

    Joined:
    Aug 6, 2004
    Posts:
    244
    Just thought I'd point something out in case some MSE users missed it: If you log in with your Windows Live ID before submitting malware samples at the Microsoft Malware Protection Center, the site will keep track of your submissions.
     
  24. Zimzi

    Zimzi Registered Member

    Joined:
    Jul 10, 2005
    Posts:
    289
    I think the Vlk presented slightly different facts (here is the source):

    Would you be so kind to comment Vlk's explanation, because, if I understood it well, there is malware that can compromize pc security completely independent of whether the malicious file is written to the browser's cache (or anywhere else on the hard disk) and intercepted by the AV file system scanner.

    This is the main reason why web scanners are invented. Why would antiviruses have web scanners at all if they could be equally effective without them?

    I think that it is very important question for understanding the comprehension of protection provided by MSE.
     
  25. Kerodo

    Kerodo Registered Member

    Joined:
    Oct 5, 2004
    Posts:
    8,014
    Yeah, got one on the 23rd, but I think I'm going to pass on any further beta testing and just stick to the releases.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.