MSE 4

Discussion in 'other anti-virus software' started by stratoc, Apr 24, 2012.

  1. er34

    er34 Guest

    I do not find my words offensive and I did not mean to be offensive - apologies if you interpreted them that way. I was just listing some facts.
     
  2. er34

    er34 Guest

    Lodore, I am not working @ MS and I can't say from first party but I suppose the reasons are: WD/WI/MSE/FEP/SCEP are not meant for the absolute 0-day / 0-minute protection - there are other technologies for that. By updating just once in 24 hours users are better protected against potential false positive alarms (despite the in-depth testing performed by MMPC) - users are less likely to reach a false positive. And should a FP appears, MMPC will have more time to fix it and not to affect many users worldwide. If you are interested, you can notice that MMPC releases updates for home user first and slightly later for business users - for example MSE gets newer updates (update version) - SCEP latest update is slightly older - this is another indirect precautionary step to make guarantee no false positive.

    Advanced users can configure more often updates but if someone is that advanced, they will for sure know how to deal with false positive by themselves
     
  3. atomomega

    atomomega Registered Member

    Joined:
    Jul 27, 2010
    Posts:
    1,290
    I don't know, I've always thought that definitions from 4 hours ago will protect me the same as definitions from 5 minutes ago.
    I mean 0-day malware is 0-day malware anyway, if you have defs for it, then it's not 0-day anymore.

    Now, if your AV relies only on definitions... oh well...
     
  4. RejZoR

    RejZoR Lurker

    Joined:
    May 31, 2004
    Posts:
    6,426
    MSE mostly uses signatures anyway and signatures 24 hours ago and signatures 5 minutes ago aren't the same either...
     
  5. Macstorm

    Macstorm Registered Member

    Joined:
    Mar 7, 2005
    Posts:
    2,642
    Location:
    Sneffels volcano
    Thank you buddy :thumb:
     
  6. Fox Mulder

    Fox Mulder Registered Member

    Joined:
    Jun 2, 2011
    Posts:
    204
    I use MSE on one of my computers, Avast on the other. Frankly, I think that a good HIPS will trump an AV any day of the week. So AV choice is far less important than it used to be.
     
  7. jo3blac1

    jo3blac1 Registered Member

    Joined:
    Sep 15, 2012
    Posts:
    739
    Location:
    U.S.
    Depends on the user. I can't stand clicking agree 20x times a day, 140x times a week, 560x times a month and ~6,000x times a year.
    I have my HIPS recognize only most critical breaches while allowing most by default.
     
  8. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,065
    You can prevent over 80% of malware by keeping all software up to date.

    I would say all my customers that have been infected have had at least one outdated vulnerable third party product. The amount of computers that have java 6 installed from hp, dell etc and the older versions where never removed if a newer version was installed. I know that alot of people install windows updates but dont know about updating third party programs. If you could update all programs with one system like on linux,phones and tablets we would have less issues.
     
  9. SouthPark

    SouthPark Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    753
    Location:
    South Park, CO
    That's been my observation from watching the MSE support forum. The great majority of users asking for malware help there report using very old versions of Flash, Java, etc., even if they keep Windows up to date.
     
  10. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    A truly effective AV is the one that protects you when you visit the risky areas of the Internet.
    If you do Not visit the risky areas of the Internet, then you can keep MSE...:rolleyes:
     
  11. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    No AV is perfect though. Just using a bit of common sense can stop 80% of infections, whichever AV you're running.
     
  12. silverfox99

    silverfox99 Registered Member

    Joined:
    Jul 14, 2006
    Posts:
    204
    Some AVs also have 'Vulnerability' scanner eg BullGuard i believe licences from Secunia that would pick up the old versions of Java, Flash etc- most AV that have it require it be run manually though which many users won't do or know it's even there. It would be helpful for vendors to incorporate the 'vulnerability scan' as part of the regular AV scan unless the user ops out of that scan.
     
  13. jo3blac1

    jo3blac1 Registered Member

    Joined:
    Sep 15, 2012
    Posts:
    739
    Location:
    U.S.
    100% agree. For those that just go on the internet to check email, read news and do occasional google search, MSE is just perfect.
    For others, you can still use MSE, just beef it up with extra HIPS, AM, and FW. I used Outpost and MBAM Pro.
     
  14. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Unless one is a malware tester, why would anyone in his/her perfect mind go to the darkside of the Internet? o_O

    (I'm excluding redirects to domains spreading malicious content, such as what happens with drive-by downloads.)

    By simply checking e-mail, reading news, Google search, etc., users can be redirected to malicious domains/phishing domains. Therefore, I'd say there's always a risk, so either MSE is great enough to protect them or it isn't. There's no middle term. The same applies to any other such product. The naked truth is none is perfect, and will always failt at any given time, and when it fails it may mean ABC user saw his/her bank account compromised, etc.

    I'm a believer of a layered security approach, and MSE fits just fine. Plus, I'm pretty confident that none of my relatives will ever complain about totally ruined systems, because the previous antimalware with bad definitions deleted a system file.

    But, most of the security comes from the browser itself, the application they use the most.

    I agree to an extent. There are some easy ways to pretty much automatically detect something as being dubious, and this is where common sense plays. But, at times it won't be enough to have common sense. One could argue what common sense means within computer security, though. For instance, my common sense says only to allow my web browser to connect to specified domain names. :D
     
  15. er34

    er34 Guest

    The "issue" is that you do not recommend 1st party solutions but 3rd party ones - Microsoft has many 1st party technologies already available to be combined with their antivirus.
     
  16. er34

    er34 Guest

    For those who say MSE is not effective against zero-day malware.
    I came across supposedly fresh malware sample. AVIRA on the machine did not detect the problem. The obvious problem was BSOD. The hidden one was Trojan Necurs.

    When I picked the sample - you can see that very small amount of the vendors could find it according to the popular service (9/44). Even 5 hours ago -> 13/44. When I noticed Microsoft detects this, I cleared the problem with Microsoft Safety Scanner.

    N.B.! VT is not always a reliable service to compare vendors and detection - just an example.
     
  17. DBone

    DBone Registered Member

    Joined:
    Nov 24, 2010
    Posts:
    1,041
    Location:
    SoCal USA
    You obviously are a big MSE fan.
     
  18. jo3blac1

    jo3blac1 Registered Member

    Joined:
    Sep 15, 2012
    Posts:
    739
    Location:
    U.S.
    Why is it an issue? Not everybody likes to use IE10, has windows 7 ultimate with applocker and UAC doesn't protect as well as fully featured HIPS.
    But by all means, I am not implying that people must use my set up.
     
  19. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    I see your point, & in the main I agree. When I was thinking of common sense, I was thinking of not surfing Russian porn sites (or any dodgy sites renown for malware), bit torrenting, clicking on spam email links or clicking on anything that moves on your monitor etc.
     
  20. Fox Mulder

    Fox Mulder Registered Member

    Joined:
    Jun 2, 2011
    Posts:
    204
    To me, common sense means avoiding any place on the Internet where people have a motivation to be sleazy.
     
  21. jo3blac1

    jo3blac1 Registered Member

    Joined:
    Sep 15, 2012
    Posts:
    739
    Location:
    U.S.
    Sure. But sometimes you have to go to those places then what?
     
  22. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    If you really need to visit sites which almost certainly contain malware, apart from the fact that you are not now using any common sense, I doubt if any single AV program would protect you completely.
     
  23. Fox Mulder

    Fox Mulder Registered Member

    Joined:
    Jun 2, 2011
    Posts:
    204
    I don't know why those places are necessary except for, perhaps, malware testing. In which case, use a VM. :p
     
  24. atomomega

    atomomega Registered Member

    Joined:
    Jul 27, 2010
    Posts:
    1,290
    Gee... so much fuzz about MSE. I mean, it's your average AV. So are all the other AV's.
    I remember when I first came in to Wilders, my computer had loooong booting times because of all the security I was running.
    Experience showed me that I can rely on ANY free av, and all I need to add is some extra measures like browser extensions (Chrome) and DNS filtering. That's all I use now and I've never been infected for 748 days and counting...
     
  25. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    Does MSE4 still requires to have Windows Update service enabled in order to update definitions?


    Haven't you figured it by now? It's not about the AV, it's about a hobby and contagious paranoia. I 've been over a year without any AV. As soon as i returned to Wilders, i started trying AVs again. It's contageous. If you put a poll "when was the last time your AV saved you", the majority will come out "i don't remember".
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice