antivirus software... how do you choose?
9 min read
The bad guys certainly have something to answer for.
It is a problem when a virus or bit of malicious code gets through your defences and I can understand why you are feeling sore about it.
Norton and McAfee are both well respected products, but of course this is no consolation if you are having problems.
There is lots of information on how to protect your-self on the forums here, but as a quick answer try the following:
1 Check to make sure you have the latest virus/malware definitions installed before you go online.
2 Make sure your firewall is fully operational before you go online
3 Don't use your administrator account routinely to go online
4 Ensure your Windows operating system is fully updated and all critical and Office updates are installed
5 Check your Java, be sure it's updated to v7 and previous versions are uninstalled.
6 Don't open attachments to email without thinking carefully and then reviewing your decision.
7 Consider using the immunise feature in Spybot-S&D…update it first!
8 Don't use the preview pane to auto-view emails in Outlook Express
9 View emails in plain text rather than html
10 Consider alternatives to Outlook Express and Internet Explorer and finally be conservative where you click, attractive looking and free software downloads often come with unsavoury little friends attached to them!
Hope this helps,
By the way, I use the free versions of AVG and Zone Alarm for anti-virus and firewall
Regards
Paws
The recommendations of both Paws and Gee1, are worthy responses to your question.
In a Forum setting like this one, it is impossible to offer specific product recommendations with anything more than a testimonial assurance. Such as: "I use it and it works for me." Not very scientific, but remember that these Forums are Read by dozens of experienced and expert Members, Moderators, and Administrators. So if someone posts a false or misleading recommendation, it will almost certainly be corrected.
I, too, use AVG (free), Ewido (free), Spybot S&D - with Immunize, but not tea-timer (free) and Zone Alarm (free). In addition, I use SpywareBlaster and MVPS Hosts File as "passive blockers" of known bad sites. I regularly install that combination on machines after repair and malware removal work, as well as on new "out of the box" purchases for customers.
Over the years, I've used a small handfull of paid products:
Anti-Virus
McAfee
TrendMicro PC-cillin
Norton
AntiSpyware
Spyware Doctor
Counter Spy
Spy Sweeper
Of the Paid AntiVirus products McAfee and PC-cillin have served me well, but Norton has consistently caused a variety of intermittent and unexpected problems. In fact, a major source of problem related customer business comes to me from users who are having difficulty uninstalling a Norton that has caused them problems.
Of the Paid AntiSpyware, all three that I've listed have served me very well, though I say again, I most frequently use the above cited (free) products and have not had any infections or problems for many years.
I also use common sense and safe surfing as Paws recommends.
Of Paws excellent recommendations, you inquire about one: Limited User Accounts v. Administrator Accounts.
Here's my response to you.
(exerpted from a reply I wrote to another user in another thread) It is important to understand the distinction between "Limited User Accounts" and "Administrative Privilege Accounts".
Limited User Accounts have the ability to use any application program that is already installed on the machine; such as Microsoft Office, Outlook or other email client, Internet Explorer or other web browser, photo, music, and media display and editing applications, games, etc. The "limit" is that a "Limited User Account" cannot install new application programs, install many downloaded updates (firewall, MS updates, AntiVirus updates, Javascript updates) modify many areas of the Registry, or gain access to the Operating System, unless allowed by the Administrator. The "Administrator" account can do all the above, but can also install programs, modify the Registry, and gain access to changing the Operating System.
As a general rule, each machine should have only one "Administrator Account" and all other accounts should be "Limited User Accounts".
As a General Rule, all of us should be running our machine from a "Limited User Account" most of the time, and all of the time that we are logged onto the Internet, except when intentionally updating security and operating system files. Why? Because, in the ordinary course of computer use, various hazards and risks occur. If the owner/user is running from a "limited User Account" any "damage incurred" will be limited by the overall "privilege" of the Limited User account and any damage/error will remain restricted to that limited account in most circumstances.
So for instance, if an owner/user is "surfing the Internet" while logged onto their machine in a Limited user account, and runs afoul of some spyware, trojan or virus (by downloading, viewing or clicking) then the spyware/trojan/virus will be limited in its ability to "install itself" into the Registry and Operating System, because the malware enjoys only the privileges that it has gained from the limited user account. Of course, a Limited User Account, can still get "infected", but the infection will be stopped from advancing in many cases, because the Limited User Account does not have privilege to modify the Registry or to change the Operating System. Therefore, the "malware" may get saved in Temporary Internet Files or remain attached to a downloaded song or picture, but will not be able to do its work of additionally embedding itself into the Registry or Operating System. Pretty Neat, huh? (greatly oversimplified, but still good stuff to know)
If however, the owner/user is "surfing the Internet" while logged into the machine as Administrator, and then they run afoul of spyware/trojan/virus by downloading, viewing or clicking on infectious content, that malware will enjoy the same "privilege" that the Administrator Account has (full privilege) to install itself into the Operating System or modify the Registry, activating its malicious function or payload. Not Good!
Are there downsides?
Yes. When installing updates to MS Operating System, or Zone Alarm, or some AntiVirus upgrades, the owner/user will have to log off the computer and log back in as Administrator to perform those functions, and then log off and back on as Limited User to continue running applications or browsing the internet. An annoyance maybe, but well worth the price of safety.
And another: Some poorly written application programs may not be "fully functional" when run under Limited User Account. This is a simple fact of life with some software companies. For me, it is an opportunity to realize that using such software may not be in my best interest, and that it's time to search for a new/better mainstream application. I've done exactly that in all cases of applications that I use and you will probably be able to do the same.
How to change status/set privileges of User Accounts:
To “change” the attributes of a “user account” you have to be logged on from the Administrator account.
Go to - Control Panel
Click - User Accounts
Select the (usual named account that your use.
If it is already a Limited User Account, leave it that way.
If it is an Administrator Account…
Click on “Change my Account Type
Select “Limited User Account”
If a “Guest” account exists, turn it off (optional)
Windows will always "demand" that you have at least one Administrator Account, so you may want to create an account for that specific purpose, and name it Machine Admin (or whatever you'd like)
Let us know how you are progressing and if you have other questions.
Best Regards
However, there is always "alot more" to be said on any particular topic.
And as usual, Microsoft has decided to jump on the bandwagon with their own solution.
Their program is called: "Drop My Rights"
It is an add-on utility routine that kinda/sorta automatically does what I described.
However, the Microsoft "fix" has not been without its own problems.
So you can read about it, download and decide for yourself, here:
http://cybercoyote.org/security/not-admin.shtml
and more directly, here:
http://msdn.microsoft.com/library/default….ure11152004.asp
Windows Vista will incorporate much of this "reduced privilege" concept into the new operating system.
Bottom line: The owner/user is much safer running as a "Limited User Account" and the Microsoft "fix" may create more problems than it's presently worth, so I generally go with my written recommendation above.
Doug
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI