AntiVirus Solutions Review and Discussion February 19 th, 2013.

12
AntiVirus Solutions Review and Discussion February 19 th , 2013

Transcript of AntiVirus Solutions Review and Discussion February 19 th, 2013.

Page 1: AntiVirus Solutions Review and Discussion February 19 th, 2013.

AntiVirus Solutions Review and Discussion

February 19th, 2013

Page 2: AntiVirus Solutions Review and Discussion February 19 th, 2013.

Outline

• What do you use?• Vendors• Comparisons Effectiveness/Features• SEP 12.X Demo• Web Filtering• Post Infection Tools• Questions

Page 3: AntiVirus Solutions Review and Discussion February 19 th, 2013.

What Do You Use?

• Strengths/Weaknesses• Ease of Use (Management)• Reliability (Rate of Infections)• Resource Intensive• False Positives• Overall Experience Good or Bad

Page 4: AntiVirus Solutions Review and Discussion February 19 th, 2013.

Vendors

• Trend Micro• Symantec• McAfee• Microsoft Security Essentials• Kaspersky• ClamAV• AVG• Webroot

Page 6: AntiVirus Solutions Review and Discussion February 19 th, 2013.

SEP 12.X Demo

• Symantec Endpoint Protection 12.x• Demo

Page 7: AntiVirus Solutions Review and Discussion February 19 th, 2013.

Cloud vs. Traditional Comparison

• May not protect while disconnected from the internet

• Malware may cripple internet connection rendering Cloud AV useless

• Light weight• Small disk footprint• http://www.webroot.com/shared/pdf/Webro

ot_SecureAnywhere_vs_antivirus_competitors_19Sep2012.pdf

Page 8: AntiVirus Solutions Review and Discussion February 19 th, 2013.

Web/Email Filtering

• Barracuda • McAfee SaaS• Symantec Security.Cloud• Cisco IronPort• Cisco IPS• Untangle

Page 9: AntiVirus Solutions Review and Discussion February 19 th, 2013.

Post Infection Tools

• Malwarebytes• Symantec Power Eraser• Norton Power Eraser• McAfee Stinger• McAfee Rootkit• Combofix• Kaspersky TDSSKiller• UBCD/Ubuntu

Page 10: AntiVirus Solutions Review and Discussion February 19 th, 2013.

RKL Tips and Tricks

• MalwareBytes• netstat –ano• Stop system restore• kill Explorer History• kill temp files• hosts• Regedit

• hklm/sw/ms/win/current/run• hklm/sw/ms/winnt/current/winlogon/userinit• hkcu/sw/ms/win/current/run• hkcu/sw/ms/Win/Current/policies/Explorer/NoDriveTypeAutorun

Value: FF• hku/[sid]/sw/ms/win/cv/run

Page 11: AntiVirus Solutions Review and Discussion February 19 th, 2013.

RKL Tips and Tricks

• Hijackthis• Dates in windows and system32 and drivers (right click and clean

with MB)•  

• discache.sys in drivers directory• atapi.sys in drivers directory – verify there is a version number

• other copies available in backup directory• updates• Symantec• combofix (will disconnect you twice if remote)• Temp file cleaner - This may disconnect you• Tweaking.com (ReimageRepair.exe on fob)

Page 12: AntiVirus Solutions Review and Discussion February 19 th, 2013.

Questions?