Naked Win 7 still vulnerable to most viruses
User Account Control easily bypassed
Ensure Ease of Recovery with Asigra’s Agentless Software
Out-of-the-box Windows 7 machines are still vulnerable to eight out of ten viruses, according to a test by security firm Sophos.
The experiment proves that the improved User Account Control (UAC) features built into Windows 7 are not enough and that additional anti-virus protection is still required. In fairness to Redmond, Microsoft crystal clear that anti-virus remains a necessary add-on to Windows PCs.
As well as paid-for products a number of free-of-charge products from AVG, Comodo, Avast and Avira are available, along with Microsoft's home-grown Microsoft Security Essentials freeware anti-malware scanner.
In the Sophos experiment, Windows 7 with User Account Control in default configuration and no-anti-malware installed was tested against ten malware samples that arrived in Sophos's labs on 22 October. Seven of these badware packages ran while two failed to work on Win 7 machines irrespective of whether UAC protection was in place or not.
UAC stopped only one example of malware that would otherwise have infected the PC, a strain of autorun malware (called Autorun-ATK by Sophos).
Two Trojans - a variant of Bredo and a banking trojan - failed to work on Win 7 machines. However, a variant of the notorious Zbot Trojan as well as a scareware package slipped through the net infecting Win 7 machines used in the test, irrespective of whether or not Windows UAC was running.
UAC debuted in Windows Vista as a technology designed to prompt users for permission before allowing applications to run. Widely criticised as annoying, Microsoft released a less intrusive version of the software with Windows 7.
"User Account Control did block one sample; however, its failure to block anything else just reinforces my warning prior to the Windows 7 launch that UAC's default configuration is not effective at protecting a PC from modern malware," writes Sophos security researcher Chester Wisniewski.
"Lesson learned? You still need to run anti-virus on Windows 7."
Wisniewski notes that Vista fared better then other flavours of Windows in a security report by Microsoft released on Monday. The infection rate of Windows Vista SP1 was 61.9 percent less than that of Windows XP SP3.
That, according to Wisniewski, means Vista is the "least ugly baby in its family" and ought not to confer any bragging rights. "You can be sure the next report will highlight its even less ugly younger sibling, Windows 7," he adds. ®
Bootnote
During a presentation on The Balance of Browser Security and Settings at the RSA Conference in London last month, Microsoft's Ed Gibson referred to the version of UAC that came with Vista as "User Annoyance Control". The terminology by Microsoft’s chief security advisor in the UK was clearly deliberate, and a sign that Redmond acknowledges that the constant pop-ups generated by the technology on Vista boxes were counterproductive. ®
COMMENTS
8 of 10 viruses?
Maybe I've lost count of how many viruses target the OS, but I thought that the VAST majority of viruses target specific applications like Office. I have no doubt that there's a large number that still apply, but not 80% applying to a fresh OS install.
This really smacks of searching for a stat to justify a POV rather than developing a POV based on overwhelming statistical data.
When people will get this: UAC is not for admin accounts!!!
UAC is for running as a normal user and been properly prompted to "Sudo" whenever an admin-permission requiring operation is executed.
This article is misleading!!!
You don't need an antivirus if you do not run as admin!!!
AND THE MORAL HAZARD IS: And if you run as admin, an anti-virus is always too late when a truly efficient worm emerges!
But the constant marketing message is that Antivirus == total protection!
@magnetik
OSX and Windows have several things in common, one of which is that they allow most users to run executable applications.
If a user insists on running some piece of malware, just how exactly will OS X stop him from doing that?
Maybe OSX have no way to let a particular application start every time the user logs on. If that is the case, then yes, it is probably more secure. It would also be a helluva less convenient! I don't think that is the case, do you?
So... A piece of malware is ran by the user, it sets itself to start every time the user logs in... Damage done. No difference between OSX and Windows so far, right?
UAC is designed to only question the user in case an application request admin priviligies. It is not designed to secondguess the user in case the user simply runs a normal user-level application (or piece of malware).
What the morons over at Sophos have shown, is that a user can screw with his own setup. If they had also shown that other users of the same machine were infected, then they would have bragging rights. As it stands now, an admin of that computer simply have to wipe the infected user profile and create a new one. (or simply clean it manually -- whatever is easiest)
That does not change much, no matter what OS you're using. PS: I've not used resident AV products at home for twenty+ years -- no infections so far. Of course I patch security holes often, but I would do that with other operating systems too. (except OSX where updates are often running quite late)

IT infrastructure monitoring strategies
Agentless Backup is Not a Myth
Top 10 SIEM implementer’s checklist
Steps to Take Before Choosing a Business Continuity Partner
Enabling efficient data center monitoring