Stopping Fake Antivirus - Antivirus, Endpoint, Disk Encryption
AntiVirus Solutions Review and Discussion February 19 th, 2013.
-
Upload
louisa-shaw -
Category
Documents
-
view
215 -
download
1
Transcript of AntiVirus Solutions Review and Discussion February 19 th, 2013.
![Page 1: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/1.jpg)
AntiVirus Solutions Review and Discussion
February 19th, 2013
![Page 2: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/2.jpg)
Outline
• What do you use?• Vendors• Comparisons Effectiveness/Features• SEP 12.X Demo• Web Filtering• Post Infection Tools• Questions
![Page 3: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/3.jpg)
What Do You Use?
• Strengths/Weaknesses• Ease of Use (Management)• Reliability (Rate of Infections)• Resource Intensive• False Positives• Overall Experience Good or Bad
![Page 4: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/4.jpg)
Vendors
• Trend Micro• Symantec• McAfee• Microsoft Security Essentials• Kaspersky• ClamAV• AVG• Webroot
![Page 5: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/5.jpg)
Comparisons Effectiveness/Features
• http://chart.av-comparatives.org/chart1.php
![Page 6: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/6.jpg)
SEP 12.X Demo
• Symantec Endpoint Protection 12.x• Demo
![Page 7: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/7.jpg)
Cloud vs. Traditional Comparison
• May not protect while disconnected from the internet
• Malware may cripple internet connection rendering Cloud AV useless
• Light weight• Small disk footprint• http://www.webroot.com/shared/pdf/Webro
ot_SecureAnywhere_vs_antivirus_competitors_19Sep2012.pdf
![Page 8: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/8.jpg)
Web/Email Filtering
• Barracuda • McAfee SaaS• Symantec Security.Cloud• Cisco IronPort• Cisco IPS• Untangle
![Page 9: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/9.jpg)
Post Infection Tools
• Malwarebytes• Symantec Power Eraser• Norton Power Eraser• McAfee Stinger• McAfee Rootkit• Combofix• Kaspersky TDSSKiller• UBCD/Ubuntu
![Page 10: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/10.jpg)
RKL Tips and Tricks
• MalwareBytes• netstat –ano• Stop system restore• kill Explorer History• kill temp files• hosts• Regedit
• hklm/sw/ms/win/current/run• hklm/sw/ms/winnt/current/winlogon/userinit• hkcu/sw/ms/win/current/run• hkcu/sw/ms/Win/Current/policies/Explorer/NoDriveTypeAutorun
Value: FF• hku/[sid]/sw/ms/win/cv/run
![Page 11: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/11.jpg)
RKL Tips and Tricks
• Hijackthis• Dates in windows and system32 and drivers (right click and clean
with MB)•
• discache.sys in drivers directory• atapi.sys in drivers directory – verify there is a version number
• other copies available in backup directory• updates• Symantec• combofix (will disconnect you twice if remote)• Temp file cleaner - This may disconnect you• Tweaking.com (ReimageRepair.exe on fob)
![Page 12: AntiVirus Solutions Review and Discussion February 19 th, 2013.](https://reader030.fdocuments.in/reader030/viewer/2022032415/56649f005503460f94c15d54/html5/thumbnails/12.jpg)
Questions?