Endpoint Protection

 View Only
  • 1.  Malewarebytes & Endpoint Protection ?

    Posted Aug 12, 2013 09:36 AM

    Our company's policy has been to install Enpoint Protection, Anti-Virus/Spyware and Proactive Threats, AND to install the freeware of Malewarebytes.  I don't want to run two antivirus programs.  It has to slow down the PC and use RAM.  And its hard to believe a freeware program could catch things that Symantec can't.  Any knowledgeable opinions on this?



  • 2.  RE: Malewarebytes & Endpoint Protection ?

    Trusted Advisor
    Posted Aug 12, 2013 09:39 AM

    Hello,

    Running more then one antivirus program on the same computer is not recommended. You may experience a false positive detection in one of the antivirus programs in this situation.

    Risks of using more than one antivirus program

    Antivirus and antispyware programs are generally written with the expectation that they will interrupt actions taken by other programs, in the interest of security. If more than one such program is running, there are a number of ways in which they can interfere with each other.

    To give a simple example, suppose that antivirus scanners A and B are installed on a computer. Program A copies a file to a temporary location for scanning. Program B notices the file activity, and copies the file from program A's temporary location to its own. Program A notices that file activity and makes another copy, and so an infinite loop forms. This could end with the computer running out of memory or hard drive space, hangs or crashes in the antivirus scanners, or other undesirable behaviors.

    Check this Article:

    Should you run more than one antivirus program at the same time?

    http://www.symantec.com/docs/TECH104806

    Hope that helps!!



  • 3.  RE: Malewarebytes & Endpoint Protection ?

    Posted Aug 12, 2013 09:42 AM

    Not recommeneded as it will be resourse hogg and file access issues.

    Should you run more than one antivirus program at the same time?



  • 4.  RE: Malewarebytes & Endpoint Protection ?

    Posted Aug 12, 2013 10:07 AM

    Malwarebytes is a second opinion malware scanner, it's not a true AV solution. It DOES NOT offer real time AV scanning protection. The paid version has a real time malicious IP blocker. Aside from that, it does not offer any real-time protection.

    Installing both SEP and Malwarebytes is generally OK to do since they don't conflict with one another. The only performance issue you may see is if you kick off a full scan in Malwarebytes and SEP is running a full scan as well.

    MBAM has a very low footprint so it won't be utilising CPU even during a scan. It is non-existent when it is not opened.

    As I said, since it is a second opinion scanner, installing side by side with SEP is fine. I've run both MBAM and SEP as well as Hitman Pro (another second opinion scanner) for years. As long as your cognizent of when your scans run, than you will be fine.



  • 5.  RE: Malewarebytes & Endpoint Protection ?

    Posted Aug 12, 2013 10:11 AM

    To be fair, the freeware version of Malware bytes (from what I recall) only ever runs an on-demand scan (doesn't do auto-protect or scheduled scans).  As such, you should be able to safely run the manual scan at times that do not clash with SEP's scheduled scans (although it may be a little slow as SEP's auto-protect will still be scanning each file called by MalwareBytes).

    While the others are correct in that you should not run more than one AV program at the same time, it is also true that no single product will catch everything (even Symantec.Cloud utilise multiple AV engines for their email scanning).

    I personally see no problem with using malwarebytes to scan and remove an infection if SEP happens to miss it (or as an additional scan if you think an infection exists).  But it should only be used in an reactive context, rather than a preventative one.  Plus, given the size of it, I'd be more inclined to only install it when needed, and remove it again afterwards.



  • 6.  RE: Malewarebytes & Endpoint Protection ?

    Posted Aug 12, 2013 10:29 AM

    Excellent point SMLatCST.

    I think another question here is how is the environment configured? There is a great article here:

    Security Response recommendations for Symantec Endpoint Protection 12.1 settings

    Article:TECH173752  |  Created: 2011-11-07  |  Updated: 2011-11-21  |  Article URL http://www.symantec.com/docs/TECH173752

     

    If running out of the box settings than trouble will be a brewing...