Recommended Posts

I'm using Firefox, with AdBlockPlus blocking malcious ads and annoying ads, NoScript blocking 0-day JavaScript vulnerabilities, and WOT so I know if I am on a safe site. Is there a possibility to get a virus if there is no route of entry through the browser or through USB flash drives (I only put drives that are my own that I know are not infected into my computer)?

Link to comment
https://www.neowin.net/forum/topic/1238996-do-i-really-need-antivirus/
Share on other sites

Just my own personal experience that I wouldn't recommend to everyone, haven't used a resident suite in over a decade, got tired of the inane amount of false positives/nags, performance drag, compatibility issues, etc.. personally if you're waiting for that "This program is malware" warning, you already made a mistake by letting it on your system to begin with.  Barring OS exploits that any OS gets and exploitable services (web servers, etc, again on any OS), 99.9% of the time malware on a desktop typically comes from user error or bad habits.. it doesn't appear out of thin air like catching a cold.  If you have internet facing services though you may want to reconsider.. that sort of stuff gets hammered all the time on any OS you can think of.

 

My neighbors for example (rank them in the "clueless user" category) have had multiple problems in the past, always due to dumbassery.  No you don't need that codec to view the video, no it's not safe because the guy said so, no you don't want to run that Shipping Label.docx.exe that got mailed to you.  With a bit of corrective training (and hardening of their browser) I haven't had to work on their system in over two years now.. but they still run resident protection just because.  

 

Obviously regular drive images are a good idea, that safety net never hurts.  An on-demand scanner is handy to have if you tend to grab stuff from random places, never mind a sandbox to run them in. If you don't have a sandbox, get a VM.  If you don't trust where the file came from, you don't run it without some sort of barrier to protect the system, period.

 

Whichever way you go though.. backups are always front and center.  Only takes one mistake to let malware in. It's entirely on you if you want to run without it, and it's certainly not for everyone.

I also agree with Max Norris. If a site provides some sort of checksum like MD5 or SHA1, or CRC, then that can provide a means of a good chance the file in question, is the real thing. imo WOT is not needed as if a site has been deemed safe but at the same time, the site/page could be compromised and that is another addon that if it were bad, it could do anything it wants. Also anything that can hold information such as USB/DVD/etc.. can be suspect and if your not sure, then run a VM/sandbox or a seperate testing PC. Also there are plenty of sites like virustotal/etc.. that you can upload files to or check websites and see if they are malicious or not. Also like Max Norris said, use images as they can save you.

I would install at least MSE. It is not the world greatest AV suite, but it helps amd is free. I also recommend frequent images so that you can easily backpaddle.

 

I run most of my web activities thru a virtual Linux Mint Mate system. That is the best protection you can get.

  • Like 2

I'm using Firefox, with AdBlockPlus blocking malcious ads and annoying ads, NoScript blocking 0-day JavaScript vulnerabilities, and WOT so I know if I am on a safe site. Is there a possibility to get a virus if there is no route of entry through the browser or through USB flash drives (I only put drives that are my own that I know are not infected into my computer)?

That certainly helps a lot. Whenever I load Windows, I use virtually the same configuration of FF + ABP + NoScript + CookieMonster. However, it's not a silver bullet when it comes to Windows unfortunately. It minimizes your exposure, and you could probably get away with it if you only download programs from reputable sources / scan them online, but it won't eliminate the threat entirely.

 

GNU/Linux is the only desktop OS I recommend for a completely secure malware-free experience. I would never do any sensitive work on Windows, nor would I store any important files there. The risk is too great.

I'm using Firefox, with AdBlockPlus blocking malcious ads and annoying ads, NoScript blocking 0-day JavaScript vulnerabilities, and WOT so I know if I am on a safe site. Is there a possibility to get a virus if there is no route of entry through the browser or through USB flash drives (I only put drives that are my own that I know are not infected into my computer)?

 

if your asking the question, then yes

  • Like 2

One question. Where would viruses come from? Neowin? Nope! so similarly, All reputed sites are safe. Except; Warez, Porn, Cracked Software. Don't tell me that cracked Photoshop is safe and clean..Just saying and neither is cracked/ toolkit Office 2013, no matter how many scans you run! and use worlds "best" AV/IS. If you invite Viruses yourself, you'll have them for sure.

One question. Where would viruses come from? Neowin? Nope! so similarly, All reputed sites are safe. Except; Warez, Porn, Cracked Software. Don't tell me that cracked Photoshop is safe and clean..Just saying and neither is cracked/ toolkit Office 2013, no matter how many scans you run! and use worlds "best" AV/IS. If you invite Viruses yourself, you'll have them for sure.

 

Totally wrong. Neowin could totally serve up a virus if they were hacked and bad code was put on the website or a malicious ad provider stuck in an Ad with an exploit on it. Happens all the time to other legit sites, heck I think Yahoo had a bad ad and infected 200,000 machines. or was it 2 million?

  • Like 5

One question. Where would viruses come from? Neowin? Nope! so similarly, All reputed sites are safe. Except; Warez, Porn, Cracked Software. Don't tell me that cracked Photoshop is safe and clean..Just saying and neither is cracked/ toolkit Office 2013, no matter how many scans you run! and use worlds "best" AV/IS. If you invite Viruses yourself, you'll have them for sure.

Even so called reputable sites can contain malware. Youtube was briefly infected recently if I remember correctly. Servers can be compromised to spread it, etc. Point being, there's no single thing you can do besides completely disconnecting from the internet. For most of us, that's not an option.

 

And who hasn't clicked on a link from a search result to find it's not what you expected? It's easy to run across dodgy/less reputable sites by accident. So to suggest that the only way to be safe is to avoid them entirely is impractical.

Pretty much what Max Norris said. When your using Windows, you are targeted and so you need to address that. I wouldn't install an anti-virus suite because they're not worth the hassle. To be honest, I consider it *too late* by the time your anti-virus solution has actually found something. Instead I would:

  • Ensure that Windows Update is switched on
  • Uninstall Java
  • Either keep Flash up to date or use IE or Chrome's built-in version of Flash
  • Consider a sandbox technology (I use Sandboxie personally) for the times when you don't fully trust software

Think about this: When was the last time you heard of a major Windows virus / worm and any of the anti-virus companies said "Yes!  We caught that before it affected our customers!"

Uninstall Java

You may as well uninstall dotNET while you're at it. Every piece of software on a system is a potential security threat if it isn't kept up-to-date. Take a look at your next Windows update and note how many vulnerability fixes there are for dotNET.That will give you an idea of the risks of out-of-date software. This is why a good package manager is essential to system security.

I'd also add that running a VM is an option but I think it's more important to have an environment that you can discard trivially. I used to use a VM solution that had the option to essentially commit or discard changes at the end of a session and I would always choose discard.

 

Sandboxie offers a separation facility but runs in the same run of Windows so it's more convenient for me. I run Java inside it so that my main installation of Windows does not have any Java functionality visible to the browsers. You can also set it up so that your browser always runs in a sandbox that gets discarded when you close it, meaning that whatever changes are made do not persist. You get the option to keep downloads, obviously.

You may as well uninstall dotNET while you're at it. Every piece of software on a system is a potential security threat if it isn't kept up-to-date. Take a look at your next Windows update and note how many vulnerability fixes there are for dotNET.That will give you an idea of the risks of out-of-date software. This is why a good package manager is essential to system security.

 

Just about every time I've witnessed a successful malware attack, Java has been the attack vector. Seriously, practically nobody needs Java on a Windows machine. It's been a sorry tale of vulnerabilities, fragile update agents and extreme software engineering incompetence.

 

I don't recall ever wondering if my version of .NET was out of date. I haven't used Silverlight for a long time so it's not really relevant to drive-by attacks from the web.

and when using windows explorer, turn on the "show known extension" setting, that would enable you to immediately discern any app/program trying to look like a (fake) folder or documents files.

Any apps that doing that almost positively have malicious intent behind it.

  • Like 2

Just about every time I've witnessed a successful malware attack, Java has been the attack vector. Seriously, practically nobody needs Java on a Windows machine browser.It's been a sorry tale of vulnerabilities, fragile update agents and extreme software engineering incompetence.

 

I don't recall ever wondering if my version of .NET was out of date. I haven't used Silverlight for a long time so it's not really relevant to drive-by attacks from the web.

FTFY.

 

There are quite a few reasons to have it otherwise.

You dont download any files?

What about exploits in sites that attack the OS?

I only download files from trusted sources, and I do not run stupid things.

How can I get stuff onto my computer that attacks the OS?

 

 

My neighbors have had multiple problems in the past, always due to dumbassery

My point exactly.

 

 

I would install at least MSE

I am using Windows 8's Windows Defender, which is MSE. It annoys me because it seems to suddenly hog CPU and memory at random times.

 

 

Totally wrong. Neowin could totally serve up a virus if they were hacked and bad code was put on the website or a malicious ad provider stuck in an Ad with an exploit on it. Happens all the time to other legit sites, heck I think Yahoo had a bad ad and infected 200,000 machines. or was it 2 million?

But I use AdBlockPlus to block malicious ads.

 

You forgot one addon/plugins called "Ghostery"

Ghostery is proprietary. I use Disconnect. The addons I did not list are: request policy, httpseverywhere, httpsfinder, privacy badger, beef taco, betterprivacy, refcontrol, and youtube all html5 (so I don't need flash).

 

 

And who hasn't clicked on a link from a search result to find it's not what you expected? It's easy to run across dodgy/less reputable sites by accident. So to suggest that the only way to be safe is to avoid them entirely is impractical.

But I use WOT, so I know if a link is trustable.

 

 

Just about every time I've witnessed a successful malware attack, Java has been the attack vector. Seriously, practically nobody needs Java on a Windows machine. It's been a sorry tale of vulnerabilities, fragile update agents and extreme software engineering incompetence.

 

I don't recall ever wondering if my version of .NET was out of date. I haven't used Silverlight for a long time so it's not really relevant to drive-by attacks from the web.

I'm not going to uninstall Java because I develop using Java. There are no vulnerabilities in Java itself, it is just when it is used in the browser is when it is unsafe. That's why I disabled it in the browser and why I decompile Java programs and check them before running them.

 

 

and when using windows explorer, turn on the "show known extension" setting, that would enable you to immediately discern any app/program trying to look like a (fake) folder or documents files.

Any apps that doing that almost positively have malicious intent behind it.

Already do that.

 

 

OP, what OS are you running?

I use Windows for gaming, Arch Linux for everything else.

This topic is now closed to further replies.
  • Posts

    • agenda pushing is... hiring women? you are insane. also low iq.
    • AIMP 5.40 Build 2721 by Razvan Serea AIMP is a powerful audio player that allows you to listen to your favorite music with an outstanding sound quality. Its appearance resembles that of another classical audio player (Winamp). The program includes a 20-band equalizer, a visualization window to display rhythmic visual effects and a playlist editor to organize your audio files. A nice fading effect makes your list of songs look like an endless music loop and a handy volume normalizing feature avoids drastic volume changes between tracks. Also, the players main functions can be conveniently controlled by global hotkeys. Besides playing music, AIMP features three extra utilities which also enable you to record any sound on your computer, convert audio files from one format to another and view or edit tags. AIMP is based on the well-known audio engine BASS, so its easy to connect new plug-ins (from the plug-in library included in the program) and expand the players functionality. Main Features and Functions: Multi-Format Playback: Supports numerous audio formats, including CDA, AAC, AC3, APE, DTS, FLAC, IT, MIDI, MO3, MOD, M4A, M4B, MP1, MP2, MP3, MPC, MTM, OFR, OGG, OPUS, RMI, S3M, SPX, TAK, TTA, UMX, WAV, WMA, WV, XM, DSF, DFF, MKA, AA3, AT3, OMA, WebM, MDZ, ITZ, S3Z, XMZ, AIFF, and MPEG-DASH (YouTube). CUE Sheet Support: Enables the use of CUE sheets for managing audio tracks. Output Support: Compatible with DirectSound, ASIO, WASAPI, and WASAPI Exclusive output methods. 32-Bit Audio Processing: Utilizes 32-bit audio processing for optimal sound quality. Internet Radio: Allows listening to internet radio stations in OGG, WAV, MP3, AAC, and AAC+ formats, with the capability to capture streams in various formats. Bookmarks and Playback Queue: Facilitates creating bookmarks and managing a playback queue. Rating and Auto-Marks: Collects statistics on track listening and automatically calculates ratings and marks for listened tracks. Plugin Support: Allows the addition of new utilities or extensions to existing features through plugins. Built-in Scrobbler: Supports Last.fm, Libre.fm, and ListenBrainz services for scrobbling. Cloud Integration: Supports OneDrive, Google Drive, DropBox, Облако@mail.ru, Яндекс.Диск, and custom WebDAV clouds. Podcasts: Offers podcast support for subscribing and listening. Hotkeys: Allows configuration of local and global hotkeys. Multi-User Mode Support: Supports multiple users working on one computer. Multi-Language Interface: Provides a multi-language interface. 4K and High DPI Support: Supports scale factors of 125%, 150%, 175%, and 200% for high-resolution displays. Flexible Program Options: Offers customizable program settings. Flexible UI: Charm UI: A modern flat-style skin with 4K and High DPI support. Bliss 4K: A skin-transformer from AIMP4 included in the installation package. Pandemic: The classic skin from AIMP3 included in the installation package. User Skins: Access to a catalog of user-created skins. Sound Effects: 20-Band Equalizer and Built-in Sound Effects: Includes Reverb, Flanger, Chorus, Pitch, Tempo, Echo, Speed, Bass, Enhancer, and Voice Remover effects with flexible settings. Volume Normalization: Features peak-based normalization and Replay Gain, along with logarithmic and loudness-compensated volume control. Mixing Options: Offers Fade In/Fade Out, cross-mixing, and pause between tracks. Silence Remover: Removes silence from tracks for a seamless listening experience. Music Library: Music Library: Organizes music files, allows setting marks for listened tracks, and keeps playback statistics. Smart Playlist: Creates playlists based on content from the Music Library database, with filtering and grouping capabilities. Playlists: Multiple Playlists: Supports working with multiple playlists simultaneously. Powerful View Settings: Allows data display customization, track grouping, and separate settings for each playlist. Content Protection: Provides the ability to block content from changes. File Search: Enables searching files across all opened playlists. AIMP 5.40 Build 2721 changelog: Audio converter: WavPack - support for 32-bit float samples format General: localizations has been updated General: WavPack codec has been updated to v5.9 Plugins: scrobbler - Last.fm - in case of an access denied error, the Track Info dialog displays links to web-version of the catalog Fixed: General - error creating a file in a folder created by template if the folder name ends with a dot Fixed: general - menu cannot be scrolled via mouse wheel if the "scroll inactive windows when I hover over them" option is switched off Fixed: General - port number is not extracted from URL if there is no "/" after the port token (regression 5.40) Fixed: audio converter - statistics are not taken into account if the "delete sources files" option is switched on and target folder equals to source Fixed: audio converter - dither does not switched off when processing files in 24-to-24-bit format Fixed: Sound engine - VST - changing the sample rate leads to certain plugins to hanging up Fixed: player - does not read disc numbers for CUE that specified as custom tag fields stored in the audio file Fixed: player - manual invoking the jump to next track action does not work if the next file is not exists and the "track repeat" option is switched on Fixed: plugins - BASS_AAC - does not play certain files to the end Fixed: plugins - CDDA - MusicBrainz - wrong artist name is extracted for certain releases Fixed: issues from incoming crash-reports Download: AIMP 64-bit | Standalone | ~20.0 MB (Freeware) Download: AIMP 32-bit | Standalone View: AIMP Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Notion is shutting down its email client one year after launch by David Uzondu In April 2025, Notion launched Notion Mail, an AI-powered email client that acted as a customizable overlay for your existing accounts. Instead of replacing Gmail entirely, it reimagined how users interacted with their inboxes by offering features like intelligent auto-labeling alongside automated calendar scheduling. Now, a little over a year later, Notion has announced that it is shutting it all down on September 22. Since Notion Mail is a frontend client, most of your Gmail data will remain safe inside your Google account, but the company said that you must export stuff specific to Notion Mail, like snippets, custom auto-label instructions, email drafts, and scheduled drafts, before the deadline. Starting today, June 25, you can export that data directly from the app or the web interface, and this grace period will last all the way until September 21. Once September 22 arrives, Notion will permanently delete all unsaved local assets, including files you attached to snippets. Your existing database syncs and mail blocks will persist, though they will stop receiving new messages after the shutdown. Notion advises that if you or your company operate within a regulated environment, you must transition off earlier than the general shutdown date to maintain compliance. Companies that rely on HIPAA coverage face an even tighter timeline and must transition away from the platform by June 30th. Notion, in its X announcement post, basically said that it doesn't see the point of maintaining a standalone email client, especially when users have shifted their habits toward automation. The platform pointed to its Notion agents, which it claims "more than half of Notion Mail users" already employ to manage emails without ever opening an actual inbox, so it is "going all in" on using these agents to run your inbox. Notion introduced Notion Agents last September at the "Make With Notion" conference, giving users AI-powered digital assistants that can do stuff like run in the background on specific schedules (e.g., summarizing your daily open tasks every morning at 8 AM).
    • OK, but isn't nvidia still planning to cut off win10 support this year?
  • Recent Achievements

    • One Month Later
      The_Focal_Point earned a badge
      One Month Later
    • One Year In
      Vistor earned a badge
      One Year In
    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
  • Popular Contributors

    1. 1
      +primortal
      404
    2. 2
      +Edouard
      168
    3. 3
      PsYcHoKiLLa
      131
    4. 4
      Xenon
      72
    5. 5
      neufuse
      69
  • Tell a friend

    Love Neowin? Tell a friend!