Recommended Posts

no, it's not necessary, the VM is completely isolated from the host as long as you don't have shared folders turned on (even then it's highly unlikely that any virus would know to make use of that)

That very much depends on what you are using the VM for. The VM can definitely still get a virus. And the VM isn't completely isolated from the host if it's on the same network. You could easily spread the virus back to the host over that network, just like any other two computers on the same network. If it's just a temporary VM that you are going to tear down, or can afford to wipe out and replace if it does get a virus, then maybe you don't care. If it's a VM that's going to stay running and is daily use, you'll probably want to put AV on it. AV on your host has nothing to do with your VM, so treat it as if it is it's own machine.

^ i was talking completely isolated as in file system wise, the fact that it's still using the same network should (i at least hope) be a given

though i definitely agree with you that it also depends on how the VM is being used

^ i was talking completely isolated as in file system wise, the fact that it's still using the same network should (i at least hope) be a given

though i definitely agree with you that it also depends on how the VM is being used

Oh, right, it won't spread from the VM's HDD to the host's HDD. But it can still propagate over the network.

Well actually, if you're using VirtualBox there's an exploit for that... ;)

:laugh: Really? I'm really not that surprised. If the files are on the same hard drive, I suppose there's always the possibility. You could say that's what you get for using a free VM. Any issues like that on more trusted VMs?

:laugh: Really? I'm really not that surprised. If the files are on the same hard drive, I suppose there's always the possibility. You could say that's what you get for using a free VM. Any issues like that on more trusted VMs?

Most hypervisors are free. vmware, microsoft hyperv, for example are free.

Most hypervisors are free. vmware, microsoft hyperv, for example are free.

From what I remember of the intel advisory that remixedcat posted, it effects hyperV, virtualbox and nearly every other VM system except vmware.

I actually meant to say open source, not free, but either way, that exploit is obviously much more complex than I originally thought. Judging from what I read, it looks like everyone has it patched by now though.

It really depends what your host's AV can do. I know at a vmware class I was at last week, they have antivirus plugins (vSphere 5.1) at the hypervisor level which scan and monitor the VMs instead of clients on each VM. Why? To prevent scan storms... you know, when all your VMs suddenly decide to run antivirus scans at the same time and murder your storage and performance... yea.

From what I remember of the intel advisory that remixedcat posted, it effects hyperV, virtualbox and nearly every other VM system except vmware.

VMWare isn't immune from host->VM viruses, however: https://blogs.vmware.com/workstation/2012/08/crisis-virus-attempts-to-infect-vmware-workstation-or-player-virtual-machines-on-windows.html

Hello,

Yes. You could download a file over a connection the host OS doesn't scan (SSL) and then would be unable to scan the guest OS for malware from the host OS. It would essentially be a "black box" in terms of the host OS not being able to scan inside of it for threats.

Regards,

Aryeh Goretsky

More or less proper system and network configuration, firewall, access control and safe browsing practices over antivirus cascade every day.

Antiviruses are reactive measures - a virus must already be inside the system to be detected by one. If there is such a hole, however, anything else can get in, given time.

I upgraded from ESXi 5.0 to 5.1 yesterday and ironically there's an interesting section in the upgrade guide about some modular AV for guests and the host machine, not sure if you need the paid version or just free but it might do exactly as you want, http://www.vmware.com/files/pdf/products/vsphere/vmware-what-is-new-vsphere51.pdf

? VMware vShield EndpointTM ? Delivers a proven endpoint security solution to any workload with an approach that is simplified, efficient, and cloud-aware. vShield Endpoint enables 3rd party endpoint security solutions to eliminate the agent footprint from the virtual machines, offload intelligence to a security virtual appliance, and run scans with minimal impact.

Remixedcat will know more about it.

^ you can run endpoint shield vm on esxi - but you can not do it for free. In a nutshell the guest vms hand off the work of scanning and such to a different VM. A central point for all your vms antivirus/malware scanning.

You then only need to update 1 location for new signatures/dats - and work is done on 1 vm vs every vm having to use resources to scan, etc.

post-14624-0-93543300-1351525213.jpg

This is not something you would normally have available in a "home" lab sort of setup. But if you have budget, and you have enough vms then it does make sense to go this route.

But I do believe that the agent is now part of 5.1 (free) so I guess if you had a FREE dedicated VM appliance that would do the scanning you could do it for free? I would also assume you need vcenter, the few companies I looked at that supply appliances, etc. State you need vcenter - which is not free again.

Sandbox ,which protect your host from virus.A sandbox is use for separating two programs , so that one cannot affect the other. It's a form of security for when there is uncertainty of one program's effect on the other. :)

NO! People assume a sandbox protects them well NO! IT DOES NOT!

Sandbox traps calls and emulates functions, but if someone wants to bypass it then they can and will.

Here's one that targets sandboxie for example http://www.wilderssecurity.com/showthread.php?t=251456

It's good practise to use but do NOT assume it gives you 100% protection or any kind of protection.

This topic is now closed to further replies.
  • Posts

    • Price Drop: Save 86% on Microsoft Office 2021 Professional Plus lifetime digital license by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can save 86% on a lifetime license to Microsoft Office 2021 for Windows. This bundle is for families and small businesses who want classic Office apps and email. It includes Word, Excel, PowerPoint, Outlook, Teams, and OneNote. A one-time purchase installed on 1 Windows PC for use at home or work. Lifetime license for MS Word, Excel, PowerPoint, Outlook, Teams, & OneNote One-time purchase installed on 1 Windows PC for use at home or work Instant Delivery & Download – access your software license keys and download links instantly Free customer service – only the best support! Microsoft Office Professional 2021 (for Windows) includes: Microsoft Office Word Microsoft Office Excel Microsoft Office PowerPoint Microsoft Office Outlook Microsoft Office Teams Microsoft Office OneNote Microsoft Office Publisher Microsoft Office Access No faffing about with subscriptions, just classic apps that don't expire. Good to Know ONE-TIME PURCHASE INSTALLED ON 1 DEVICE Redemption deadline: redeem your code within 30 days of purchase Access options: desktop Full versions No subscriptions – no monthly/annual fees Version: 2021 Updates included* *Support for this version of Office ends on Oct 13, 2026 A lifetime subscription to Microsoft Office 2021 Professional normally costs $219.99, but this deal can be yours for just $29.97, that's a saving of $190. For full terms, specifications, and license info, click the link below. Get Microsoft Office Professional 2021 for just $29.97, or learn more Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • The only reason I want to know where you from is because if you are not from the U.K, then why should you care what we in the U.K do or don't do? Racist I am not, I am fed up with the amount coming over here and feel they can come over here and think we need to support them. Do you know how much it costs this country to support these people coming over here? Even when we give them a place to live it is not good enough. We had a barge that was being used to house immigrants, oh but that was not good enough. A mate said to me at the time, when he was homeless, he would have been happy to live on the barge, instead of ending up sleeping on a bench on the beach. I am not scared to say what my family heritage is, unlike you who is scared to say where they are from or where they live. Father side U.S, mother side Wales, still have family living in the U.S. A mate who sadly died a few years ago, had a load of people from different races recording in his studio, I got on with all of them. Skin colour don't bother me, where they are from don't bother me. Religion don't bother me as long as they don't push it onto me and it is not crazy stuff. I am not religious. But if you are not living in the U.K, then why should you care if we are in the E.U or not? This the problem, too many people poking their noses into where it don't belong. But you believe what you believe, if you think I am racist, then be it, I really do not care. Just grow a pair
    • If he hasn't been able to figure that out, then why is he obsessed with tariffs? Because that's one of the most prominent tools to level the playing field when you have high cost of labor.
    • Microsoft released Windows 11 KB5102558, KB5095615 Setup and Recovery updates by Sayan Sen This past week Microsoft released the newest preview update (C-release) under KB5095093. Alongside those, Microsoft also released new dynamic updates. For those who may not know, dynamic updates bring improvements to the Windows Recovery process in the form of Windows Recovery Environment (WinRE) updates, which are also called Safe OS updates. The dynamic updates also affect the Setup file binaries in the form of Setup updates. These Dynamic Update packages are meant to be applied to existing Windows images prior to their deployment. Dynamic Updates also help preserve Language Pack (LP) and Features on Demand (FODs) content during the upgrade process. VBScript, for example, is currently an FOD on Windows 11 24H2. This time both recovery and setup updates were released for Windows 11. The company writes: "KB5095186: Safe OS Dynamic Update for Windows 11, version 26H1: June 23, 2026 This update makes improvements to the Windows recovery environment (WinRE). After installing this update, the WinRE version installed on the device should be 10.0.28000.2335. KB5102558: Setup Dynamic Update for Windows 11, versions 24H2 and 25H2: June 23, 2026 This update makes improvements to Windows setup binaries or any files that setup uses for feature updates in Windows 11, version 24H2 and Windows 11, version 25H2. KB5095615: Safe OS Dynamic Update for Windows 11, versions 24H2 and 25H2: June 23, 2026 This update makes improvements to the Windows recovery environment (WinRE). After installing this update, the WinRE version installed on the device should be 10.0.26100.8737." Microsoft notes that both the Recovery and Setup updates will be downloaded and installed automatically via the Windows Update channel.
  • Recent Achievements

    • Conversation Starter
      jessse3334 earned a badge
      Conversation Starter
    • Reacting Well
      JuvenileDelinquent earned a badge
      Reacting Well
    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      201
    3. 3
      PsYcHoKiLLa
      151
    4. 4
      Steven P.
      73
    5. 5
      macoman
      62
  • Tell a friend

    Love Neowin? Tell a friend!