Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Product Lifecycle
  3. Running a Business
  4. Suitable Anti-Virus for those who ship software

Suitable Anti-Virus for those who ship software

Scheduled Pinned Locked Moved Running a Business
helpquestionsysadminsecuritysales
4 Posts 3 Posters 7 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K Offline
    K Offline
    kmoorevs
    wrote on last edited by
    #1

    Simple question...Is Microsoft Security Essentials sufficient AV protection on development workstaions used to compile and sign executables? One of my biggest fears has always been that a system gets compromised and we unwittingly send out a batch of infected updates. :omg: I am currently in a situation where a customer's AV identified 5 of our executables as being infected and quarantined them. In trying to resolve the situation, their network administrator asked for those files as a zipped email attachment which I sent. She promptly replied that the attachment had been stripped due to detection of a virus! I have checked these files with both MSE and AVG with no problem. I have applied for an evaluation of the AV the customer is using (lightspeed) both to replicate the issue, and to find out if the claim is legitimate but am still waiting. BTW, any executable we ship is digitally signed.

    "Go forth into the source" - Neal Morse

    L V 2 Replies Last reply
    0
    • K kmoorevs

      Simple question...Is Microsoft Security Essentials sufficient AV protection on development workstaions used to compile and sign executables? One of my biggest fears has always been that a system gets compromised and we unwittingly send out a batch of infected updates. :omg: I am currently in a situation where a customer's AV identified 5 of our executables as being infected and quarantined them. In trying to resolve the situation, their network administrator asked for those files as a zipped email attachment which I sent. She promptly replied that the attachment had been stripped due to detection of a virus! I have checked these files with both MSE and AVG with no problem. I have applied for an evaluation of the AV the customer is using (lightspeed) both to replicate the issue, and to find out if the claim is legitimate but am still waiting. BTW, any executable we ship is digitally signed.

      "Go forth into the source" - Neal Morse

      L Offline
      L Offline
      Lost User
      wrote on last edited by
      #2

      kmoorevs wrote:

      Simple question...Is Microsoft Security Essentials sufficient AV protection on development workstaions used to compile and sign executables?

      Simple answer; nothing will be sufficient to give guarantees. Install 10+ AV's, and you'll still receive "updates" of virus-definitions. There's no way to eliminate the threat completely. FWIW, using Avast! Antivirus, nothing more. The thing that protects it best, is to be paranoid on who touches your build-server. If it's really a big issue, then install a second build-server in a remote area. Upload the sources bij FTP, generate a hashcode of the binaries and compare them with a hash of the local binaries. If they stop matching, "something" changed.

      Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^]

      K 1 Reply Last reply
      0
      • L Lost User

        kmoorevs wrote:

        Simple question...Is Microsoft Security Essentials sufficient AV protection on development workstaions used to compile and sign executables?

        Simple answer; nothing will be sufficient to give guarantees. Install 10+ AV's, and you'll still receive "updates" of virus-definitions. There's no way to eliminate the threat completely. FWIW, using Avast! Antivirus, nothing more. The thing that protects it best, is to be paranoid on who touches your build-server. If it's really a big issue, then install a second build-server in a remote area. Upload the sources bij FTP, generate a hashcode of the binaries and compare them with a hash of the local binaries. If they stop matching, "something" changed.

        Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^]

        K Offline
        K Offline
        kmoorevs
        wrote on last edited by
        #3

        Thanks! :)

        "Go forth into the source" - Neal Morse

        1 Reply Last reply
        0
        • K kmoorevs

          Simple question...Is Microsoft Security Essentials sufficient AV protection on development workstaions used to compile and sign executables? One of my biggest fears has always been that a system gets compromised and we unwittingly send out a batch of infected updates. :omg: I am currently in a situation where a customer's AV identified 5 of our executables as being infected and quarantined them. In trying to resolve the situation, their network administrator asked for those files as a zipped email attachment which I sent. She promptly replied that the attachment had been stripped due to detection of a virus! I have checked these files with both MSE and AVG with no problem. I have applied for an evaluation of the AV the customer is using (lightspeed) both to replicate the issue, and to find out if the claim is legitimate but am still waiting. BTW, any executable we ship is digitally signed.

          "Go forth into the source" - Neal Morse

          V Offline
          V Offline
          Vasudevan Deepak Kumar
          wrote on last edited by
          #4

          Try uploading a small executable to https://www.virustotal.com/[^] and you can see the output from a host of antivirus engines they support.

          Vasudevan Deepak Kumar Personal Homepage You can not step into the same river twice.

          1 Reply Last reply
          0
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • World
          • Users
          • Groups