Windows Defender
Total Page:16
File Type:pdf, Size:1020Kb
Windows Defender Table of Contents Windows Defender -1 ..................................................................................................................... 2 Windows Defender -2 ..................................................................................................................... 5 Windows Defender Usage .............................................................................................................. 6 Windows Defender Interface -1 ..................................................................................................... 7 Windows Defender Interface -2 ..................................................................................................... 8 Windows Defender Scan Configuration .......................................................................................... 9 Windows Defender - Regular Scans .............................................................................................. 11 Additional Configurations ............................................................................................................. 12 Windows Defender Advantages -1 ............................................................................................... 13 Windows Defender Interface -1 ................................................................................................... 14 Windows Defender Interface -2 ................................................................................................... 15 Windows Defender Scan Configuration ........................................................................................ 16 Windows Defender Advantages -2 ............................................................................................... 17 Microsoft Malware Protection Center .......................................................................................... 18 Microsoft SpyNet .......................................................................................................................... 20 Windows Defender Disadvantages -1 ........................................................................................... 21 Windows Defender Disadvantages -2 ........................................................................................... 22 Windows Defender CLI ................................................................................................................. 24 Windows Defender PowerShell .................................................................................................... 25 Windows Defender PowerShell Automatic .................................................................................. 26 Windows Defender PowerShell Manual ....................................................................................... 27 Notices .......................................................................................................................................... 28 Page 1 of 28 Windows Defender -1 Windows Defender -1 Provides • Spyware • Malware detection and removal in real time • Built-in anti-virus (Windows 8 only) Formerly known as Microsoft Anti-Spyware 23 **023 Windows Defender, Windows defender, formerly known as-- the artist formerly known as Microsoft Anti-Spyware. I guess they changed the name because it's a little bit more than just anti-spyware. It's anti- malware, does malware detection and removal, as well. And then if you're running Windows Defender in a Windows 8 environment, it is a built in antivirus functionality. For Windows 7-- give me one second. Student: Hey, Mark. Mark Williams: Yes sir. Page 2 of 28 Student: I noticed that when I put Kaspersky's in. I run ESET, Avast and Kaspersky's in different boxes-- see how they work with-- Kaspersky wanted you to disable Microsoft stuff. Mark Williams: Sure. Student: I wasn't so sure about that. Mark Williams: I think many vendors will recommend, oh you have another firewall running, or you have another antivirus running, or you have another vendor's product running, you should go ahead and disable that. And sometimes that is a good idea because there are contention type of issues you have to worry about. They sometimes compete for the same resources. Sometimes they do interfere with each other. On the other hand, there is this term it's called diversity of defense. Diversity of defense is a good thing because this vendor might catch-- notice and catch x and not y, whereas this one might notice and catch y but not x. So, if they work together in a complementary fashion, that's probably better for us the end users. Oh, it is. I just wanted to check. In your notes, I believe it does-- the notes we provided for you, it does say if you want antivirus protection with Windows 7 that you use something known as MSE, Microsoft security essentials. So, Windows Page 3 of 28 Defender has antivirus coded into it. But if you want anti-virus capability, then basically you turn on-- in Windows 7, Microsoft security essentials. And defender, it now goes away and security essentials is going to do the anti-malware, anti-spyware type of thing. Microsoft security essentials for Windows 7, it is a free download for you. It does not come with the install, but it is a free download that you can add on if you need. Student: Won't that give you some problems because every day they have an update? So, if you're set-- if you set your security so that you say download and notify me when, you're going to get that every day. Mark Williams: Every day. Sure. Page 4 of 28 Windows Defender -2 Windows Defender -2 Offers improved Internet browsing safety Protection against the latest threats through updated signatures 24 **024 It can be annoying. So, this is one of the things I think is nice. Not only is it looking at your system for malware and spyware and such, it's also looking at your browsing. So, when you're using Internet Explorer or another web browser, it's trying to help identify when you're going to sites that might be considered less than safe, sites that might have malware associated with them and such. And so, it also will help you if you're downloading anything in an email attachment or something. Before it actually opens or as it's opening, it would do a scan of it and if it says Page 5 of 28 that this is malicious or bad stuff it would stop the application, the attachment from opening. So, the Defender real time protection is a nice little feature that they've added in. Windows Defender Usage Windows Defender Usage Periodically scans the computer for potential malware To protect against emerging threats, an up-to-date signature file is necessary Defender automatically updates 25 **025 Periodically, how do we use it? It periodically is going to scan, as you mentioned, it has to-- in order for it to scan for malware it has to have the latest and greatest updates. So, it has to go out and do an update and then scan. It is always recommended that you try to have your antivirus, your anti- Page 6 of 28 malware, your spyware protection, have them scan when your system is idle. Often times these scans do take up a lot of resources. I know specifically when I am trying to accomplish a task, if it's in the middle of the day and that scan kicks off, then I can usually see a performance hit. So, three o' clock in the morning might be a good idea, when you're definitely not going to be using that machine. So, it does automatically update and you can schedule your scans for a later point in time. Windows Defender Interface -1 Windows Defender Interface -1 Windows 7 provides a button / menu driven GUI for configuration options. 26 **026 So, there is a difference in the way Defender looks in Windows 7 Page 7 of 28 compared to the way Defender looks in Windows 8. In Windows 7, they have, in Defender, these buttons, the home button, the scan button with the drop down menus and so forth. And I guess that's nice. But they-- they decided they wanted to change it in Windows 8. Windows Defender Interface -2 Windows Defender Interface -2 GUI provides 4 clean tabs for viewing, configuring, and controlling Defender in Windows 8. 27 **027 So, when you bring up Windows Defender in 8, instead of having those iconic buttons at the top, you have a tabular type of interface to select, so the home, update and history, and then settings, tomatoes, tomatoes. They effectively both-- both the devices, both the applications, Page 8 of 28 effectively do the same thing, just a different interface. Mike? Student: It's easier for the programmer to add a tab then it is to go mess with a navigation bar. Mark Williams: Okay, that's a good logic for why they did it that way. Add another tab, just another little module of code. That makes sense. Windows Defender Scan Configuration Windows Defender Scan Configuration Regular scans should be run according to local policy. 28 **028 Here they're showing you under the home tab, we have the ability to schedule our scans and set our scan options, I should say, what type of scan do we want to do, quick scan, full scan, or customized. You Page 9 of 28 might want to do-- when you initially install the system and run the scan for the very first time, do a full complete scan of the system. Obviously, the full scan's going to take a little bit longer. But then, on a recurring basis, maybe on a day-to-day basis, you do a quick scan. It does not look at everything, certainly not going to look at the files that have not changed. It'll go this is your Windows directory, there have been no changes in your Windows directory. We don't