The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Can I get a virus if I do sane things ? Possible scenarios ..

    Discussion in 'Security and Anti-Virus Software' started by wearetheborg, Nov 10, 2009.

  1. wearetheborg

    wearetheborg Notebook Virtuoso

    Reputations:
    1,282
    Messages:
    3,122
    Likes Received:
    0
    Trophy Points:
    105
    Can you get a virus if running in user mode in XP64bit ?

    I dont run anivirus programs, (but I use windows sparingly). I am wondering if its necessary.
     
  2. DetlevCM

    DetlevCM Notebook Nobel Laureate

    Reputations:
    4,843
    Messages:
    8,389
    Likes Received:
    1
    Trophy Points:
    205
    If you can get one?
    Definitely.

    How much harm does it do? No idea - also XP 64Bit was more s test OS.
     
  3. wearetheborg

    wearetheborg Notebook Virtuoso

    Reputations:
    1,282
    Messages:
    3,122
    Likes Received:
    0
    Trophy Points:
    105
    This is for XP 64 bit

    Can I get a virus if I browse in a sane fashion, eg., say:
    I am in user mode.
    Autorun,autoplay are disabled.
    I plug in a thumb drive, full of mp3s, some of which contain viruses.
    I open winamp/windows media player, and from there try to play some of the infected mp3s.


    Or say I try to open infected JPG images from firefox or any other picture browsing program.

    Can I get a virus in these cases ? How ? Why would malicious code in an infected mp3 get executed if a player is just rtying to play the file, or if a program is tryign to display an image ?
     
  4. Sahugani

    Sahugani Notebook Consultant

    Reputations:
    22
    Messages:
    210
    Likes Received:
    0
    Trophy Points:
    30
    if you are deliberatly doing this then you just might get a virus. granted i know next to nothing about code executing and what not.
     
  5. arjunned

    arjunned Notebook Deity

    Reputations:
    288
    Messages:
    766
    Likes Received:
    0
    Trophy Points:
    30
    The simple answer is - yes. You can get infected if u open an infected jpeg or mp3. Simplest way to avoid this is to have your AV updated so it will detect if any virus runs from you infected file. Or run media files sandboxed.
     
  6. wearetheborg

    wearetheborg Notebook Virtuoso

    Reputations:
    1,282
    Messages:
    3,122
    Likes Received:
    0
    Trophy Points:
    105
    I've been looking at
    http://en.wikipedia.org/wiki/Computer_virus
    And from there I gather, its improbable I'l get a virus by opening an mp3/jpeg if I set the execute disable bit... by open I mean using a program like winamp etc to open the file, and not double clicking it directly.

    Now, documents that contain macros like MS office document are another matter.
     
  7. pipspeak

    pipspeak Notebook Deity

    Reputations:
    94
    Messages:
    1,041
    Likes Received:
    55
    Trophy Points:
    66
    I'm no code expert, but it seems to me that trying to "beat" a virus at its own game is asking for trouble, especially with the rate at which viruses evolve. I'd rather leave it to an AV scanner that is updated daily or a sandbox.
     
  8. wearetheborg

    wearetheborg Notebook Virtuoso

    Reputations:
    1,282
    Messages:
    3,122
    Likes Received:
    0
    Trophy Points:
    105
    I'm just trying to operate in the safest possible way --- if I can prevent the virus from ever executing, all the better.
    Any recommendations for a sandbox ?
     
  9. swarmer

    swarmer beep beep

    Reputations:
    2,071
    Messages:
    5,234
    Likes Received:
    0
    Trophy Points:
    205
    To greatly reduce your chances of infection, you can play/view the media file in a relatively uncommon program. iTunes or WMP may be exploited... who's going to bother developing an exploit for foobar2000?

    The sandbox thing is another option, and maybe a better one, but I don't know much about that.
     
  10. pipspeak

    pipspeak Notebook Deity

    Reputations:
    94
    Messages:
    1,041
    Likes Received:
    55
    Trophy Points:
    66
    Sandboxie seems to be popular but is only for 32-bit systems. I did read somewhere that 64-bit OS have some sort of sandbox built-in but I don't run x64 so have no idea if or how it might work. Best bet might be to ask on a security-related forum like Wilderssecurity.com
     
  11. graycolor

    graycolor Notebook Evangelist

    Reputations:
    30
    Messages:
    459
    Likes Received:
    0
    Trophy Points:
    30
    If you have mcafee you should be fine. I'm not sure about other antivirus, but I never got a virus ever using mcafee.
     
  12. arjunned

    arjunned Notebook Deity

    Reputations:
    288
    Messages:
    766
    Likes Received:
    0
    Trophy Points:
    30
    Hmm. This is the first time i'm hearing that. I dont think x64 has a built-in sandbox; but do u have a link?

    Cheers.
     
  13. wearetheborg

    wearetheborg Notebook Virtuoso

    Reputations:
    1,282
    Messages:
    3,122
    Likes Received:
    0
    Trophy Points:
    105
    Yeah, I'm 100% sure 64bit OS doesnt have that built in, at least XP64 bit.
     
  14. arjunned

    arjunned Notebook Deity

    Reputations:
    288
    Messages:
    766
    Likes Received:
    0
    Trophy Points:
    30
    And neither does Vista or 7.
     
  15. DetlevCM

    DetlevCM Notebook Nobel Laureate

    Reputations:
    4,843
    Messages:
    8,389
    Likes Received:
    1
    Trophy Points:
    205
    I think what you are looking for s "Data Execution Prevention" - and drivers need to be siged in the 64Bit OS.
    There is some Kernel protection built into it, but that doesn't mean its virus safe.

    If you check my 32vs64 Bit thread (sig) - I've got a couple of links at the very bottom of the post - that may help :)
     
  16. Th3_uN1Qu3

    Th3_uN1Qu3 Notebook Deity

    Reputations:
    214
    Messages:
    1,192
    Likes Received:
    0
    Trophy Points:
    55
    To answer the OP's questions, if you do "sane things", use an alternative internet browser and an ad blocker, you will not get viruses. Oh and disable AutoPlay to protect you from those pesky USB stick worms.