View Full Version : free AntiVirus offers
mrbass
30th January 2004, 08:05
"I'll continue here tomorrow with more free offers in the Antivirus and Firewall area which is really a must for every Windows user." --doom9 (Jan 30th news).
here's my list of free for home user Virus Protection.
http://mrbass.org/antivirus/
Doom9
30th January 2004, 08:27
Why thank you.. you just made my job easier. I was only aware of AVG and Anti-Vir.
bond
30th January 2004, 11:06
great thanks :)
Sirber
30th January 2004, 13:07
the "microsoft AV offer" seems to only gather your personnal data, haven't got the mail to download it yet...
bond
30th January 2004, 13:10
does anyone know a good freeware firewall?
bit-wise
30th January 2004, 13:36
Believe it or not, ZoneAlarm version 2 (Not versions 3 or 4) is a fantastic firewall which is free for home users.
The first time an application accesses the internet (as a client or server), ZA prompts you if it should allow it, and if it should remember your answer each time the app starts.
I'm embarrassed to admit, but ZA has identified several stealthy trojans when it popped up the "connection" message unexpectedly. The most recent, a week ago, that no trojan or virus scanner except TDS-3 picked up, but no one can remove it as of yet. (The new self-modifying code and multiple copies running - kill one and it spawns another). Sent off the binaries of the trojan and reinstalled Windows. How this latest got on my machine is beyond me - I never open attachments or install apps over the web, I'm on SP4, and I have all security updates installed.
I use ZA in conjunction with a hardware firewall configured with your typical outbound-only rules but no stateful packet inspection. The real nice thing about the new generation of hardware firewalls is the fact you can bandwidth shape based on protocol. By default when a socket opens, it will attempt to consume 100% of your bandwidth until finished. You can throttle this down, to say, 40%, thus allowing other types of traffic such as HTTP to consume the rest.
Doom9
30th January 2004, 14:40
I use Kerio Personal Firewall myself.
windtrader
30th January 2004, 17:56
My internet connection is via DSL. I route through the DSL modem and into a Linksys cable/DSL router. I've assumed that it is acting as a hardware firewall providing adequate security. Have I been fooling myself and either have no protection or need to add software firewall and if so, does this have to be installed on all PCs in my home network?
bit-wise
30th January 2004, 18:38
@windtrader
The router will keep you should from hackers only. Your Linksys DSL router NATs down to private IP addresses (probably 192.168.0.x) so, unless you explicitly tell the router to forward traffic to one of your machines, no inbound connections from the router are allowed from the Internet.
This however does not prevent malicious code from being run on your machine. Prime example: Some Internet sites attempt install malicious applications posing as something innocent - like a search toolbar. Most children (and many adults) don't realize the consequences when things are installed. Next to email attachments, that is how most computers get infected these days (Trojans floating around on the peer-to-peer networks may now be #2)
windtrader
30th January 2004, 19:22
bit-wise,
Thanks. I feel better. :) For the stuff I let through, I have several software tools that inspect, reject, flag, etc. potential virus stuff. I have McAfee Virus Scan Pro on all the time, except in the rare occasion where I turn it off temporarily while doing a big FTP or download/upload of files. I have Ad-Aware Pro running all the time to manage popup stuff, use the Internet settings to block all cookies except those in my list (privacy=high, security=med), run Sybot Search and Destroy to clear other crap off the system. Email comes in/out via yahoo and two private servers that keep on top of applying server based spam and virus scanning. NEVER execute anything I am not sure of, except stuff I dl via usenet and that gets checked by McAfee (I hope, so far no problems). I feel covered; do you see I am missing anything else?
thx
Doom9
30th January 2004, 19:33
@windtrader: An example of what you're missing: HyperSnap DX phones home.. regardless of if you use a demo, cracked demo (god behave), or a fully registered version. Now I have paid my license fee and I don't think they have a right to phone home so all connection attempts from that software stop with Kerio.
It might not be to stop malicious software that allows other people to use your PC for stuff you'd not authorize.. even software that looks trustworthy can't be trusted. And MS software also has the nasty tendency to phone home. I'd rather rest easy knowing that I'm in charge of what goes out.
bond
30th January 2004, 19:33
hm is irc chatting known to be abused as a big potential securtiy hole?
i mean its an open connection through the firewall, anything which can be done to make it safer?
windtrader
30th January 2004, 19:41
HyperSnap DX phones home.. Does not compute... What do you mean "phone home", like ET. :sly: What is going on and how would that compromise security in my system? I do have Hypersnap DX5 but do not operate in a resident mode, I just load it when I need to snap something then shut it down.
I'd rather rest easy knowing that I'm in charge of what goes out. and what measure are you taking to ensure that?
thx
Doom9
30th January 2004, 20:26
What do you mean "phone homeIt contacts a server by the Hypersnap makers. I don't know what kind of data is transmitted.. but I don't want to send them a single byte.
and what measure are you taking to ensure that?
Software firewall and strict rules to what is allowed to connect outside. Obviously you can never be a 100% but that's life.
Deviant
30th January 2004, 21:41
Another good free firewall is Sygate personal firewall.
mrbass
30th January 2004, 22:05
A couple of free antivirus protection programs not to get IIRC.
-Bitdefender...doesn't have resident memory protection (in their free offering). You might as well run a free online scanner daily.
-RavAntivirus (which Microsoft bought btw)
they don't have resident memory either...how lame is that.
-Microsoft/ Computer Associates....asks for address, ph#, etc. I put all bogus but still it seems like it's only for certain pcs, etc. Didn't really like it though.
All of these are free for HOME use only. Just like lavasoft ad-aware. That's why we use spybot at work since it's free.
albertgasset
30th January 2004, 22:10
Yes, I use Sygate firewall and i'is quite good. As antivirus I have AntiVir Personal, which is free for personal use: http://www.free-av.com/.
r6d2
31st January 2004, 00:34
Originally posted by Doom9
And MS software also has the nasty tendency to phone home.
This might be related to Wolfman's theory of Bill Gates being an alien, as exposed on this funny response to nikthebak regarding this virus in a movie (http://forum.doom9.org/showthread.php?s=&postid=436585#post436585).
windtrader
31st January 2004, 07:50
It contacts a server by the Hypersnap makers. I don't know what kind of data is transmitted.. but I don't want to send them a single byte. It's kind of scary to think about all the programs one (geeks like us) usually has loaded and how many are probably doing all kinds of crap like this. As you state, who knows what the hell they are sending back "home".
Guess y'all have given me enough fright to get off my lazy ass and do some firewall tire kickin'. :) However, I remain resistant to loading only what MUST be loaded; It is amazing how much crap gets loaded no matter how hard you try to keep it down. need this.. need that......
bit-wise
31st January 2004, 22:59
I'm glad to see this topic has provoked conversation from at least a few people. 98% of the users out there are ignorant of how to lock down a Windows box and thus viruses and back doors abound...
I agree, it's a huge legal grey area on what can and can not be sent back to the product manufacturer - in my opinion, the less the better. (read: none).
@bond
IRC clients are pretty much safe, but there is a new wave of back doors that once "installed" IRC to the world your IP address and the root/admin password to your machine.
To add to your toolbox of weapons, I also use a freeware product called Starter from CodeStuff (http://codestuff.netfirms.com/news.shtml) which shows you a list of all applications that are loaded at start up and currently running processes. Note, there are zillions of services out there, so here (http://www.lafn.org/webconnect/mentor/startup/PENINDEX.HTM) is a site that list the service name, executable, what it is, and if its needed.
I have yet to find a good software firewall that really allows me to define rules in a manner similar to hardware firewalls such as Checkpoint. If anyone knows of one...
Doom9
31st January 2004, 23:03
I have yet to find a good software firewall that really allows me to define rules in a manner similar to hardware firewalls such as Checkpoint. If anyone knows of one...
Actually.. Kerio Personal Firewall allows you to create regular firewall rules (source/dest IP, source/dest port and protocol). That should get you pretty close to what you can do with a hardware based firewall.
bit-wise
31st January 2004, 23:14
In the flurry of replies, I forgot you windtrader...
I'd say your in pretty good shape, actually quite good. There is a third facet you might want to look into:
There are three main types of malicious software out there Viruses, Add based Programs, and Trojans. There are three different types of tools to root them out.
(Windrader, the following explanation is is just for public reference for the less informed - I know your on top of things)
Anti-virus programs excel at scanning active HTTP traffic and files for viruses and prevent them from getting installed.
Add based scanning programs (Ad Aware is one) looks for programs that are not viruses, but not necessarily what you want on your machine. You all are probably familiar with what happens when you install Kaaza, LimeWire, or BearShare. Data miners get installed everywhere.
The third is Trojans, which do overlap slightly with anti-virus, but there is enough of a difference to warrant investing some time in a Trojan scanner. I use TDS-3. On some test systems that I purposely infected, Norton only picked up about half the Trojans, but TDS-3 found them all.
For giggles, I would recommend downloading an eval of TDS-3 and giving your system a full scan... Let me know if you find anything!
windtrader
1st February 2004, 03:17
For giggles, I would recommend downloading an eval of TDS-3 and giving your system a full scan... Let me know if you find anything! Well, I guess I ain't gigglin..
I did a normal scan and got one hit. Should I just delete these off the system? Any way to determine when/how/who I got this thing?
Message: Positive identification, Adware.PurityScan c:winnt\system32\winservn.exe
I'll also run a full scan and see what else pops up.
thx
bit-wise
1st February 2004, 14:58
@doom9
Thanks! I'm off to check it out.
@windtrader
Any number of things could cause the install. It's categorized as a "potentially unwanted program", so it may not be picked up by all virus scanners. Symantec (http://sarc.com/avcenter/venc/data/adware.purityscan.html) has a entry for your newly identified system tool, although they are tailored to people who are running NAV.
Running a quick Google search with the keywords of "Adware.PurityScan" yielded many results. Drop me a note here if you need some assistance with removing it.
windtrader
1st February 2004, 18:05
bit-wise,
McAffe classifies this as non-threatning, although it has a scan setting to detect for "malicious" programs which would catch and clean this off. I have it set on now, will be interesting to see what else it may pick up in this category.
thx don
yuinfo
11th February 2004, 20:27
Anybody who uses DSL connection may find floppyfw (http://www.zelow.no/floppyfw/) usefull. You need a junk motherboard, two NICs and old floppy or CD (no HD, monitor, etc.). Works beutifully, and no pure software firewall can't compare to it.
goldirin
11th February 2004, 21:08
take a look here http://www.agnitum.com/products/outpost/
kblood
11th February 2004, 21:46
I used to have Norton Antivirus, and I have to say it's a fine antivirus program. Then my update registration expired, and I had to pay to keep updating it, so I decided to look around for free solutions.
I have tried Avast and AVG. Avast is nice, and I like the SMTP/POP3 protection, similar to what Norton does, but it consumes more resources than AVG (quite noticeable!). Also, it seemed to have performance problems when I start up Thunderbird and it checks 6 email accounts at once, all of them going through POPFile (bayesian filter proxy) for classification. AVG only has email scanning for Outlook Express 5 & 6, but besides that, I find it really good. I think Symantec lost a customer. Everything else about AVG I think is pretty good: heuristics, little resources, good resident scanner, frequent and small-sized updates... One firm vote for AVG.
When I want to double-check, I go to Trendmicro's Housecall online scanner, which was, the last time I checked, the only online scanner ICSA certified. Really good too. One vote for this one as well.
I tried Kerio 2.x and later 4.x betas, but then I started with some crashes (obviously, they were betas). So I looked around, hadn't heard much good about the later ZoneAlarm versions, and found Sygate Personal Firewall. It does a very good job, very much recommended. Also allows for Advanced Rules, which can give you very precise control. It shows the buttons for the Pro version, but they are disabled, to encourage you to upgrade, but I have never found a need to do so. The free version works really good. One vote for Sygate then!
Of course I also run SpyBot S&D. Wonderful program.
Is there any free specialized Trojan scanner? I think I am pretty safe, but just in case...
A couple of things I have found but have not been mentioned here, and are also not on mrbass's very nice page:
- F-Prot for DOS is also available for free, and it works perfectly fine in a DOS window, so it's also a nice alternative for double-checking. I have heard of people that were not able to clean some infected files with other antiviruses, and F-Prot for DOS saved them. Of course, no resident protection is included, but sometimes a DOS antivirus is useful...
- Kaspersky Labs also offer a free and really nice removal tool, quite complete, and under 200k in size. ftp://ftp1.avp.ch/utils/clrav.com
clrav.com [10.1.7., updated January-28-2004] Tool:
Free detection & cleaning tool for the following viruses:
I-Worm.BleBla.b,I-Worm.Navidad,I-Worm.Sircam,
I-Worm.Goner,I-Worm.Klez.a,e,f,g,h,Win32.Elkern.c
I-Worm.Lentin.a,b,c,d,e,f,g,h,i,j,k,l,m,n,o,p,I-Worm.Tanatos.a,b
Worm.Win32.Opasoft.a,b,c,d,e,f,g,h,I-Worm.Avron.a,b,c,d,e
I-Worm.LovGate.a,b,c,d,e,f,g,h,i,j,k,l,I-Worm.Fizzer
I-Worm.Magold.a,b,c,d,e,Worm.Win32.Lovesan
Worm.Win32.Welchia,I-Worm.Sobig.f
I-Worm.Dumaru.a-d,Trojan.Win32.SilentLog.a-b
Backdoor.Small.d,I-Worm.Swen,Backdoor.Afcore.l-r,I-Worm.Sober.a,.c, I-Worm.Mydoom/Novarg.
That's it from me. Useful thread!
r6d2
11th February 2004, 21:51
Originally posted by kblood
AVG only has email scanning for Outlook Express 5 & 6. [...]One firm vote for AVG.Me too, definetely. (Just a note: my version also scans Outlook XP).
I've also been using www.mailwasher.net for spam control. Good tool.
kblood
11th February 2004, 22:08
Yeah, I guess the plugin probably works with most versions of Outlook, but I wouldn't know... I fear too much the holes of that program to run it! :D
And for Spam control, POPFile is truly wonderful. The installation has also become much simpler in the later versions. And it can classify your email in many more ways than just Spam/Not Spam. Very highly recommended, but I have to say I haven't tried other options.
Note that Thunderbird also has now a built-in bayesian Spam filter.
(Bayesian means, in a very simplistic summary, that it "learns" as you use it, so it becomes more and more effective)
windtrader
12th February 2004, 07:05
For trojans I was referred to this software TDS-3 by Radius Systems. It seems to work well.
kblood
15th February 2004, 16:02
I found "a2 free" as a free option for Trojan scanner. Looks quite good.
http://www.emsisoft.com/en/
No resident protection, but then, I don't think a Trojan scanner should be resident, I already have an antivirus resident, and that would be overloading it too much, I think :)
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.