PDA

View Full Version : "Morro" Microsoft Security Essentials.



Wiebelhaus
June 25th, 2009, 07:32 PM
I set up a Virtual box with a clean install of XP Pro with all updates , all service packs and IE8 and a fresh Install of Microsoft's Security Essentials or "Morro" (http://fileforum.betanews.com/detail/Microsoft-Security-Essentials-Morro/1245771017/1). Then I surfed with IE8 , contracted a few malicious processes on the way and then decided to plant a few Zlob droppers from this viral database. (http://vx.netlux.org/vl.php). I screenshotted the results and I'll attach them in order , Basically Morro didn't squawk one bit even while I was surfing and contracting and even when I started dropping them in the My Document location and the System32 local , All default settings were left as is so the real time protection was enabled.

Then I ran a scan with Morro on default settings which was quick , it detected some and crashed during the removal attempt. I restarted the system and it loaded properly and then I scanned again with a full scan , it detected some and removed them. As you'll see in the screen shots it did not remove all of them as AVG did in the last screen shot (Check the paths in screenie #4).

By the way , this is in no way meant to be a professional test , this is just for internal testing and thought you guys might find it interesting! So if the subject comes with friends or family you can say "Hey! that thing doesn't work , I don't care what PC Mag says!"

monsterstack
June 25th, 2009, 07:40 PM
Microsoft are probably ******* off a lot of AV vendors with this product. Perhaps making theirs a bit rubbish is Microsoft's way of being nice to them?

starcraft.man
June 25th, 2009, 07:44 PM
Gasp, Microsoft writing a garbage program. You don't say.... shocked I say, SHOCKED!

billgoldberg
June 25th, 2009, 07:51 PM
It's still in beta I think.

But yes, it seems a bit rubbish as one of you put it.

mr-woof
June 25th, 2009, 07:52 PM
Is it a beta?

Edit: Beaten by the above post :)

Even if it is a beta, it shouldn't crash when trying to remove stuff.

Wiebelhaus
June 25th, 2009, 07:56 PM
Is it a beta?

Edit: Beaten by the above post :)

Even if it is a beta, it shouldn't crash when trying to remove stuff.

Also , It's more or less "Windows Live One Care" That's being re-branded and given away! Beta? I don't know if I believe that. But with performance like this it's going to be hard to even give it away!

mr-woof
June 25th, 2009, 08:03 PM
I see what you mean, even in beta you'd expect it to remove 50% of the items

Giant Speck
June 25th, 2009, 08:10 PM
I see what you mean, even in beta you'd expect it to remove 50% of the items

I didn't know a beta had those requirements.

starcraft.man
June 25th, 2009, 08:13 PM
Also , It's more or less "Windows Live One Care" That's being re-branded and given away! Beta? I don't know if I believe that. But with performance like this it's going to be hard to even give it away!

Explains it. Garbage by any other name is still garbage. One Care was an awful AV through it's whole lifespan (from every metric I saw). Microsoft should just concentrate on the stuff they can actually eventually be good at.

Wiebelhaus
June 25th, 2009, 08:17 PM
I didn't know a beta had those requirements.



Microsoft describes Morro as being built on its existing protection engine and delivering the same defenses as its enterprise solutions without the "additional non-security features found in many consumer security suites."

Source: (http://opensource.sys-con.com/node/755097)

That hardly sounds like beta material as we know of it here , That engine has been sold for about two years.

philcamlin
June 25th, 2009, 08:18 PM
microsoft failed once again :popcorn:

rustafar
June 25th, 2009, 08:43 PM
I know it's hard to find objective/independant reviews on anti-virus software but this site seems to be pretty independent. Based on the reports they have it seems that OneCare didn't do so well when it first came out but has performed better in recent tests. Perhaps Morro will continue this trend. Look under Comparative/Reviews --> Main Tests and check out the reports.

http://www.av-comparatives.org/

Delever
June 25th, 2009, 08:51 PM
It kind of looks like those web pages which try to get malware into your system by disguising web pages as virus threats.

TheLions
June 25th, 2009, 10:11 PM
It is actually funny, Microsoft is created anti-virus program instead fixing security holes allowing to get infected.
Do they have some contract with security companies like Symantec or what?

Same goes for fragmentation and registry bloat.

Grant A.
June 25th, 2009, 10:21 PM
Morro will probably make my computer muerte. ;)

gnomeuser
June 25th, 2009, 10:35 PM
It is actually funny, Microsoft is created anti-virus program instead fixing security holes allowing to get infected.
Do they have some contract with security companies like Symantec or what?

Same goes for fragmentation and registry bloat.

Actually they didn't, Microsoft, say what you might have actually started taking security very seriously the past few years. Adding an anti-virus offering is a nice belts and suspenders option to deploy along side their regular updates.

Aside that being a proponent for a 100% bugfree scenerio instead of prevention and protection is dangerous Utopian thinking.

There is a reason distributions like Fedora that take security seriously do not take approach and instead pro-actively protect against attacks and contains them when they happen. What Microsoft is doing is no different, and I believe that it is wrong to chastise for trying to improve. Morro will benefit a great deal of people who would otherwise not run an antivirus tool or worst till run an expired one (for that all important false sense of security - we have all seen it happen). Now they have a perfectly acceptable option to add that extra bit of protection.

It isn't being forced on anyone so there isn't even an objection to be made on anti-trust grounds.

Even though I am a Linux user, I am very happy Microsoft are doing this, fact is that most desktops out there are Windows machines. These machines get infected and become bots or worse still. Such conditions make the Internet suck for everyone and having fewer is a good thing.

billgoldberg
June 25th, 2009, 10:39 PM
Even though I am a Linux user, I am very happy Microsoft are doing this, fact is that most desktops out there are Windows machines. These machines get infected and become bots or worse still. Such conditions make the Internet suck for everyone and having fewer is a good thing.

I feel the same way.

Windows Defender was a good move, this is too.

Wiebelhaus
June 26th, 2009, 05:49 AM
I feel the same way.

Windows Defender was a good move, this is too.

I'm not trying to bash only show real world results , it is good they are trying but should we not at least expect the best from them? I see Computers on a daily basis with Defender and One care running and reporting things are fine with obvious "Personal Antivirus" infections.

They should be able to do it well at the very least , this can't be to much to ask.