Pages

Showing posts with label microsoft. Show all posts
Showing posts with label microsoft. Show all posts

Microsoft launches free antivirus software

Microsoft launches free antivirus software

Microsoft has released a trial version of its new antivirus program, Microsoft Security Essentials.


Microsoft has launched a free anti-virus suite, called Microsoft Security Essentials.
Microsoft has launched a free anti-virus suite, called MicrosoftSecurity Essentials.

The security software, which is currently only available in the United States, China, Brazil and Israel, aims to provide computer users with basic protection against viruses, trojans and malware.

“Cost and performance barriers prevent many consumers from using up-to-date security software to protect their PCs,” said Microsoft in a statement. It said Microsoft Security Essentials was “a no-cost anti-malware solution that provides consumers with quality protection from threats including viruses, spyware, rootkits and trojans.”


Microsoft Security Essentials is available in http://www.microsoft.com/security_essentials/market.aspx and is Microsoft’s second attempt at creating an antivirus product after its first package, Windows One LiveCare, failed to resonate with consumers.

But some computer experts have questioned whether Microsoft Security Essentials provides PCs with an adequate level of protection.

“Early reviews of the beta are showing that it underperforms when compared to existing freeware products, and well below paid solutions,” said Symantec, a rival security firm, in a statement. “Referring to Microsoft’s basic antivirus and anti-spyware product as an essential security solution is misleading. Consumers need firewall protection, web protection, anti-spam and identity safeguards.”

Microsoft said it would make the antivirus package available in other countries later this year. Windows 7, its next-generation operating system, hits shops on Oct 22.


Microsoft antivirus starts public testing next week

Microsoft antivirus starts public testing next week:

Microsoft will start the public beta-test of its free antivirus software, codenamed Morro, next week at http://www.microsoft.com/security_essentials. However, you may not get the chance to try it then, if you even want to. According to ZD Net's Ed Bott: "The public beta will be limited to 75,000 downloads."

Morro is not as comprehensive as the paid-for OneCare (which included a Managed Firewall, PC Performance Tuning, Data Backup and Restore, Multi-PC Management, and Printer Sharing) but offers more protection than the free Windows Defender.

Bott has been testing what we can now call Microsoft Security Essentials, and says that:


"Contrary to some recent reports, this isn't a cloud-based service. Instead, it offers a dynamic signature service that pushes signatures on a daily basis, but adds the ability to query the signature service when need to reduce the window of exposure to new malware. By monitoring for suspicious behavior, the service can query for a sample when necessary. Rootkit detection features target kernel-mode malware and can detect the sort of tampering in the kernel that is typical of rootkits."

The service is similar to the antivirus part of the discontinued One Care, which tested well in May 2009, when "the independent AV-Comparatives group" gave it its highest (Advanced+) rating. Bott says:

"Only 3 of the 16 products in the test earned that rating. Microsoft's technology scored second in the accuracy ratings, behind AVIRA but ahead of AVG, Symantec, McAfee, and a dozen other products. And on the crucial measure of delivering the fewest false positives, Microsoft stood far ahead of the pack, delivering the fewest false positives of any program tested."

Sadly, the better it works then the more bananas Symantec and McAfee are going to get, and Symantec is taking an early lead. In a press release, Lee Sharrocks, Symantec's Vice President Consumer Sales EMEA says:

"Microsoft isn't going to change the dynamics of the consumer security industry. The reality is that shareware and freeware vendors have been in the market for 20-plus years. The freeware space is crowded and Microsoft is just joining the fray. In addition, early reviews of the beta are showing that it underperforms when compared to existing freeware products, and well below paid solutions such as Norton AntiVirus."

In that case, Mr Sharrocks, we can assume that Symantec (which pays PC manufacturers to install its own suite as crapware) won't need to go bleating to its friends in the European Commission. It's a pretty good bet that that's exactly what Symantec will do. But if not, damage is already being done.

There was an interesting paragraph in Ars Technica's report:

"One last thing Ars discussed with Burch was the "Essentials" branding. We've seen it before with Windows Live Essentials, but Burch says MSE will not be included in this suite, even though non-Windows Live applications like Silverlight are included. Microsoft is likely aiming to release MSE in time for Windows 7, but unlike Windows Live Essentials, Burch says there will be no download link for MSE included in the final version."

Ars describes this as "a curious decision" because it doesn't make any sense. "Nevertheless, it can be quite easily explained: Microsoft wants to avoid antitrust issues."

In fact, what's really happening is that Microsoft is doing its best to keep away from the European Commission's idiot clutches even though this means not doing what would be best for users. It's an example of the fear of irrational EC action damaging the interests not just of European consumers, but of the rest of the world's, too.

Critical Windows vulnerability under attack, Microsoft warns

Microsoft has warned of a critical security bug in older versions of its Windows operating system that is already being exploited in the wild to remotely execute malware on vulnerable machines.

The vulnerability in a Windows component known as DirectX is being targeted using booby-trapped QuickTime files, which when parsed can allow attackers to gain complete control of a computer. Because many browsers are designed to automatically play video, people can be compromised simply by visiting a site serving malicious files. Vista, Windows Server 2008 and the beta version of Windows 7 are not affected, and neither is Apple's QuickTime player, Microsoft said.





Microsoft has offered several work-arounds until a patch is available. The most straight-forward of them involves visiting this link and clicking on the "Fix it" icon. (We got an error when using Firefox, but it worked fine with Internet Explorer.) Several additional fixes are available on the work-arounds section here. The installation of QuickTime doesn't protect Windows users from being compromised.

The vulnerability exists in the way a DirectX application programming interface known as DirectShow handles supported QuickTime files. By manipulating the format, attackers can gain the same system privileges assigned to the logged-in user. Since Microsoft doesn't make it easy on users who log in to limited accounts, the vulnerability means most people using 2000, XP and Server 2003 versions of Windows are at risk of losing complete control of their machines.

Vista and later versions of Windows aren't affected because the vulnerable QuickTime parser filter was removed from them.

Microsoft was vague about the real-world attacks targeting the flaw except to say it "is aware of limited, active attacks that use this exploit code." It said it is sharing additional details with company partners through its Microsoft Active Protections Program, which was announced in August.

Microsoft says-

We’ve just released Microsoft Security Advisory 971778 today. This discusses a new vulnerability in Microsoft DirectShow affecting Windows 2000, Windows XP and Windows Server 2003 that is under limited attack. The advisory outlines information about the vulnerability and steps customers can take to protect themselves while we’re working on a security update to address the issue.

Our investigation has shown that the vulnerable code was removed as part of our work building Windows Vista. This means that Windows Vista and versions of Windows since Windows Vista (Windows Server 2008, Windows 7) are not vulnerable.

The vulnerability is in the QuickTime parser in Microsoft DirectShow. An attacker would try and exploit the vulnerability by crafting a specially formed video file and then posting it on a website or sending it as an attachment in e-mail.

Our investigation has found three workarounds that you can implement to protect yourself and we’ve documented these in the security advisory.

We’re also sharing information about this vulnerability and the limited attacks that we’ve seen with partners in our Microsoft Active Protections Program (MAPP) and our Microsoft Security Response Alliance (MSRA) program to provide information that they can use to provide broader protections to customers.

As always, we’ll continue monitoring the situation and providing more information through the security advisory and the MSRC weblog.