PDA

View Full Version : may be paranoid but... (Windows Defender)


jes
11-10-2007, 06:40 PM
I recently decided to disable Windows Defender (I run Vista) to download, install, update and scan with Adaware to see if Defender was missing much. Adaware found 160 instances of spyware. I didn't remove anything in the case that I might do more harm than good. Has anyone else done this? Should I be concerned?

pop pop
11-11-2007, 01:00 AM
May be Vista related, I don't know. Maybe Defender is not updating...

I tested my system after seeing your post and came up almost totally clean. Then again, my configuration is different:

XP Pro totally updated
Kaspersky 7 AV with antispyware components
Sygate Firewall
SpywareBlaster
Spybot S&D
Adaware SE Plus
Windows Defender

I ran scans with Adaware and Spybot. Adaware was clean. Spybot found one item: FunWebProducts, Trackin Cookie---My wife <smile>

Budfred
11-11-2007, 01:24 AM
I would run other antispyware scans, but stay away from Ad-Aware... They have gone downhill faster than anyone thought possible...

AVG Anti-Spyware, Spybot and others can be good... However, only run one in resident mode... Defended is probably fine, both because Ad-Aware is not really reliable and because no single antispyware is going to catch all problems...

jes
11-11-2007, 01:34 AM
I suppose that part of my concern is also that several weeks ago I had a PC running XP pro and spybot was finding 3-5 spyware every few weeks but since it crashed and I got this one running Vista, Defender has found nothing that I know of.


...Spybot found "41 problems". Every one of them was a tracking cookie so there is really not much to worry about, right? I suppose this means that Windows Defender doesn't bother with tracking cookies. Why would Adaware report 160 when Spybot found only 41?

pop pop
11-11-2007, 02:02 AM
IMHO Defender is pretty good. After all, M$ bought it from Giant software and put their name on it after some mods. In general, I'm not an M$ fan, but I'm pleased with Defender.

Sylvander
11-11-2007, 04:45 AM
Just recently, TrojanHunter 5 (http://www.misec.net/) found and eliminated a Trojan [Adware.BSPlay.100] that none of the other scans [AVG, a-squared, Spybot, HJT] had found.

Budfred
11-11-2007, 08:48 AM
Of the programs Sylvander mentioned, only a-squared is really designed to find trojans, so it makes sense that Trojan Hunter found something the others didn't... However, that is starting with the assumption that it wasn't a false positive...

As I earlier, no single antispyware will detect everything, there are just too many things out there and there are different definitions of what is malware... Defender is a bit more careful about what it designates malware because MS doesn't want more lawsuits... That said, it may be that you need to tell it to look at things like tracking cookies... I don't use it, so I am not sure about the details of how it works...

The other thing is that Vista is somewhat more secure out of the box... This means that infections are less likely to begin with... Some off this is because the criminals haven't figured out all of the ways to get through the security yet and some of it is because they intended it to be more secure...

I am much more suspicious about Ad-Aware finding false positives these days than any of the other possible explanations...

jes
11-11-2007, 12:59 PM
Alright, thanks.

I would like to hear more about Adaware going down hill. Did you find that out through trial and error?

Fruss Tray Ted
11-11-2007, 03:10 PM
Before you condemn AdAware for reading false positives, take those cookies it found and put copies in a folder. Then do some online scans of that folder to see if they are problem files or not.

I would assume that AdAware still works OK for the malware it was updated to until the demise of the company. So it is probably not even seeing the newer threats and only reporting any older ones that it finds. It's the LACK of seeing new baddies that worries me about using it, esp if you are not using any other one in conjunction with it.

Budfred
11-11-2007, 11:24 PM
I am not saying those are false positives... I am saying that I don't trust the results of Ad-Aware scans at this point...

I can't reveal details of the reports I have heard since they were in confidential forums, but it appears that Ad-Aware is in another self-destruct pattern and that they may not recover from it this time... If you are using the old version of it, what FTT said may be true... If you are using the new version, I suggest dumping it... Since you are on Vista, I am guessing it is the 2007 version...

dragush
11-25-2007, 05:21 PM
interesting i am using CCleaner, spybot, and bitdefender just uninstalled adaware and was wondering if this should be sufficient or if i should get another one and which it should be

Budfred
11-25-2007, 08:20 PM
If you are not running a firewall, you need to add that... Read the article linked in my signature for more ideas...