The only anti-virus measure that I take is to upload unknown executables to http://www.virustotal.com/
The only anti-virus measure that I take is to upload unknown executables to http://www.virustotal.com/
I hate this "I've been running without AV for ages, and I never saw any viruses" argument. Of course you didn't. Making you aware hasn't been the motive for a long, long time.
It's virtually impossible to run a Windows (or Linux, or Mac) installation with the usual suspects--Java, Flash, Adobe Reader, etc.--without being exposed to good old, non-targeted malware. Take into account that most of it is distributed from "good" sites, and "if I don't see it, it must mean there's nothing there" and "I never go to any risky sites" prove pretty silly.
I'm not saying that AV is the best solution, or even a good one--indeed it can even be what contains the vulnerabilities used to take over a machine--but there is a reason it exists. Let's not pretend that AV solves all ones problems, but let's also not pretend that it's completely ineffective. It's only ineffective if there really is no other (probable) way for things it detects to get through--which there is on most desktop operating systems unless you (manually) go to great lengths to isolate the different things you do. There are ways to make AV moot, but it rarely comes built-in or without user overhead/experience requirements. (Ironically, in Windows 8 anti-virus comes built-in.)
btw I have been running without AVG for ages on all kinds of systems. Once in a while I'm checking if my habits are still ok and run a bunch of standalone scans. They never find a single thing. Does that mean they all suck hard and that my machines are infected by newer and more invisble things than they can find? (note this is an honest question. I have no clue.)
And of course "absence of evidence is not evidence of absence," so either the scans suck hard, or you're clean; but barring a more specific (and probably not fully-automated) inspection, there's no way to tell.
We have syslogs going back 7 years. You want to come audit our network? I'll bet you all of the money in my bank account that you find nothing.
> with the usual suspects--Java, Flash, Adobe Reader, etc...
Nobody in my house runs those.
> It's all about staying on the machine, and staying silent.
They have to communicate over the network at some point though. Otherwise, it'd be useless.
So yeah - as far as I know - and that's pretty damn far.
I can imagine how to do it. But I also know that 99.9% of people don't.
> > with the usual suspects--Java, Flash, Adobe Reader, etc...
> Nobody in my house runs those.
That's very unusual, and you'll have to agree.
Let's assume that you are really doing so much that AV is completely moot. You're still being reckless by giving people the impression that they can just uninstall it and continue doing what they were doing (i.e. using Java, Flash, Adobe Reader, etc.), and everything will be exactly the same.
...if you know what you're doing.
Where did I imply anything remotely close to what you just said?
Literally anything could be possible "if you know what you're doing" if you leave it that ambiguous.
Do you have more information about this? I wasn't aware that malware was just "floating" out in the ether. I have been staunchly in the camp of, "If you know what you're doing you can remain safe." but you seem convinced otherwise. Why?
See "Compromised sites" at the bottom.
In my experience, compromised sites and insecure ad networks are by far the most common means of distributing malware through legitimate sites.
Even if you know what you are doing, you are very likely to come across sites running e.g. Wordpress, Drupal, etc. with shitty addons, e.g. timthumb, that have been compromised and are serving exploits through hidden iframes, redirecting you to bad pages, etc.
Very cool link though, thanks.
Tell me how the virus manages to stay out of Sysinternals Autoruns, and I will panic with you.
Otherwise, no antivirus is really necessary.
There's a whole category of malware that does just that: https://en.wikipedia.org/wiki/Rootkit
The most common (and basic) way is to run as a child process inside svchost.exe.
> Otherwise, no antivirus is really necessary.
You don't care what happens in all the time that elapses from you're infected with something until you realize you are, if you realize it?
It shows all services with their signature, all device drivers with their signature, etc. It validates the signatures too.
I'm sure I only run signed services and drivers.
Also, there's a rootkit detector Sysinternals utility. The page you linked describes how Mark Russinovich one of the writers of the Sysinternals utilities, discovered the Sony Rootkit.
> You don't care what happens in all the time that elapses from you're infected with something until you realize you are, if you realize it?
Of course I do, that's why I have the Sysinternals utilities at hand.
I actually miss the old versions of McAfee vscan and equivalents. Light weight, checked things over (yes, it wasn't active, might miss corrupting programs, etc...), but if you know what you are doing, like above mentions, you can be pretty safe on windows.
That said, I'm mostly a mac/'nix house hold these days.
Yes, but a basic one. You'd prevent something running on port X from being exploited directly. Doesn't do anything against other methods, like getting you to open a shady PDF or SWF file.
> That said, I'm mostly a mac/'nix house hold these days.
If you're running a window manager, there's virtually no difference between them and recent versions of Windows. If anything, Windows has the upper hand on the non-headless side.
It's nice to be able to say "At least I'm not on Windows anymore", but it is no reason whatsoever to not be as vigilant.
The primary reason why you're not targeted as much on OS X or Linux is not that they have a much smaller attack surface than Windows (anymore.) It's that it doesn't make economic sense for an attacker to target Linux users if they are less than 2% of the desktop computer market share, and they generally consist of tech-savvy (e.g. more likely to use NoScript, or spot shady processes than normals).