Advertisement
Promo

Security threats Toolkit

Is your anti-virus program still working?

Robert Vamosi

Published: 15 Jun 2004

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A friend of mine works for a university-based medical research facility, and she recently wondered why their network was experiencing a dramatic increase in virus traffic. Their Internet-facing servers, she told me, were all protected with the latest release of a major anti-virus software product. The product, like its popular home version, features automatic live updates of the latest signature files, yet they were getting hit with several variations of the Bagle virus, plus some other new viruses.

This may sound familiar. You have a desktop anti-virus program installed now, and you know the signature file subscription is current with the vendor, but still you're seeing virus-like symptoms, or perhaps you actually know that you have a virus. Since the first of this year, many new viruses have been shutting down anti-virus and firewall programs, or, in other cases, disabling the software's automatic update feature, leaving your system vulnerable to future attack.

It's actually an old trick. The virus MTX, for example, released in 2000, blocks access to anti-virus software Web sites. But these recent anti-virus-disabling attacks are more effective because of their sheer volume: with some 30-odd variations of Bagle appearing within a 10-week period, each one better than the last, you might have been hit and not even realised it.

Time to check your protection
At one time, you needed to manually update your anti-virus program monthly, weekly, then every couple of days. Problem was, with a big email outbreak such as I Love You, you were often infected before you got around to updating your signature files. So the software vendors opted for automatic downloads of signature file updates. This method has its pros and cons.

First, the pros. I like the set-it-and-forget-it anti-virus protection available on most products today. I think it's made protecting your PC much easier for casual Internet users.

But, unfortunately, convenience breeds a false sense of security. I once knew someone who felt all cars should have standard transmissions so that the driver would at all times remain in touch with the road's conditions and be better able react to danger. In the same way, it might be good for us to have to pay more attention to our anti-virus and firewall software. I'm not suggesting we give up the ease-of-use features we now enjoy, but rather these products should now integrate with each other more than they currently do and provide some kind of checks and balances for each other.

Help on the way
I expect to see some major changes coming later this year. Currently, the new ZoneAlarm Security Suite works with your existing third-party anti-virus programs and reports whether the signature files are out-of-date or if the software is even working. And the new Microsoft Security Center, one component of Windows XP SP2 (to be released late summer or early fall 2004), will also warn if your anti-virus protection is compromised. Whenever the anti-virus program becomes disabled, a dialogue box informs you of the change. Also, whenever you check the ZoneAlarm Security Suite or Microsoft Security Center main screen, you'll see a warning that your anti-virus protection is not enabled.

Until these products become widely available, you will still need to check your anti-virus programs from time to time to see that they are still working.

A happy ending
My friend has taken to doing just that, and in the process, found the anti-virus software update feature on one of the servers had been disabled in early April. By reactivating that server's protection, her research facility has significantly reduced their latent virus problem. I suspect some of you may experience the same result with your home computers.

Related articles

ZoneAlarm Security Suite

Review ZoneAlarm Security Suite puts Norton Internet Security and McAfee Internet Security to shame with its easy-to-use features. [07 Jun 2004]


Windows XP Service Pack 2: a first look

Preview The forthcoming Service Pack 2 for Windows XP is actually a significant upgrade for Microsoft's OS, delivering much-needed security enhancements. We highlight the key changes. [24 Mar 2004]

24 Talkbacks


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
21 out of 63 people found this useful


New Products

System Center Essentials 2010 Beta 1

System Center Essentials 2010 Beta 1

If you spend more time fighting fires than adding business value through IT, it's time to look at Microsoft's comprehensive management solution for medium-sized businesses.

Chrome OS: a first look

Chrome OS: a first look

Google has released source code for a preliminary version of its Linux-based operating system. Is it destined to dominate the netbook market? Here are our first impressions.

Office 2010 Beta: a first look

Office 2010 Beta: a first look

How does the first public beta of Microsoft's next productivity suite differ from the Technical Preview? We have a hands-on evaluation.

Microsoft Security Essentials

Microsoft Security Essentials

Security Essentials is recommended if you want 'set and forget' security. If you need more robust configuration choices, or don't want to contribute to the cloud, then look elsewhere.

View all Previews

Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters