Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


June 20, 2006

Windows Defender

New graphics, streamlined interface mark Beta 2 of Microsoft's antispyware tool
RSS
View this exclusive article with VIP access -- click here to join |
See More Security Articles Here | Reprints | Or sign up for our VIP Monthly Pass!

Windows Defender Beta 2 is Microsoft's second antispyware beta release, but it really feels more like a new program. New graphics, tighter integration into the OS, and a streamlined interface all set this release apart from its predecessor, Microsoft AntiSpyware Beta 1.

Like Microsoft AntiSpyware, Windows Defender doesn't include centralized management or reporting features, so this free tool is still targeted squarely at the consumer. Still, some companies and organizations might deploy it because it's a free Microsoft product. For the consumer, this new version is a great step toward protecting Windows computers. Let's walk through some of the features in Windows Defender.

A Service, Not an Application
Windows Defender is Microsoft's foray into antispyware, spearheaded by its acquisition of Giant Software in 2004. People are obviously excited about this program—according to the Microsoft Windows Defender Web site, the product has more than 25 million active users. You can download Defender free from Microsoft, and it will also be integrated into Windows Vista.

If you're familiar with Microsoft AntiSpyware, you'll immediately notice significant changes in Windows Defender. The program now runs as a service instead of an application, which ties it more closely to the OS. For example, you can close Windows Defender during an active scan and it will keep scanning in the background.

Also, the system tray icon appears only when there's a problem or notification, much like the Windows update icon. Upon discovery of a suspicious program, Windows Defender flashes a warning on the screen, as Figure 1, shows, and displays an icon in the system tray. After you address the warning, the icon disappears.

In the Vista version, Windows Defender is included in the new malware protection portion of the Windows Security Center Control Panel application, but as of Beta 2, the Windows XP version isn't yet integrated into this console. Several features from Microsoft AntiSpyware won't appear in Windows Defender because upcoming Microsoft programs make them redundant. For example, Microsoft Internet Explorer (IE) 7.0 lets you manage Browser Helper Objects and list and remove ActiveX controls, so those features have been removed from Windows Defender.

Streamlined Interface
You'll notice that Windows Defender has fewer features to tweak. Microsoft AntiSpyware boasted over 58 distinct checkpoints; these remain embedded in Defender, but you won't see them individually. Instead, in the new version, you'll see nine protection groups —including Auto Start, System Configuration, Internet Explorer Add-ons, Services and Drivers, and Windows Add-ons—that can be monitored. You can enable or disable the real-time protection of these groups but not of the individual checkpoints. Power users and administrators won't have as much control as they did with Microsoft AntiSpyware, but most users probably won't notice.

The operation of Windows Defender is simple. From its Vistaesque interface, you can choose to scan a computer, view a history of activity, or access tools that let you configure the program and peek into software running on your computer. You can select a quick scan or a full scan or customize your own scan by specifying the drives or folders you want Defender to check. The full scan checks your entire hard drive and all currently running programs. A quick scan checks areas likely to be infected with spyware.

Microsoft also simplified the scanning interface. Microsoft AntiSpyware delineated scanned objects such as memory processes, files, registry keys, and cookies, but Windows Defender lumps all of these object types together. In addition, Windows Defender permits you to schedule only one automatic scan—you must choose between a quick daily scan or a weekly full scan; you can't schedule both.

After you run a scan, Windows Defender shows a summary of suspicious items by alert level (Severe/High or Medium/Low, as Figure 2 shows).You can remove all the detected items or click Review items detected by scanning to get more details about individual items. Details about the discovered spyware include its category, description, removal advice, and the resource (registry key, file, folder) in which the spyware was discovered. You can specify whether to ignore, quarantine, remove, or always allow a detected item (see Figure 3). When you allow an item, it's added to a list of approved applications, so you won't be prompted time and again about a program you deem safe. If you make a mistake and accidentally allow a malicious item, you can navigate to the History pane and click the Allowed Items link to view and manage these items.

The SpyNet Option
If you want more protection and don't mind giving up a little privacy to get it, you can sign up as an advanced member of the Microsoft SpyNet community through Windows Defender. Then, if Defender finds on your computer a suspicious item for which it doesn't yet have a spyware definition, it sends information about that item to the SpyNet community and displays on your computer information about what other SpyNet members have said about that item. This service is free, but the information that Defender sends Microsoft about suspicious items found on your computer could contain potentially sensitive data such as the name of a file on your system—and this might violate some companies' policies.

Software Explorer
One of the most interesting (and most usable) features of the Windows Defender UI is the Software Explorer tool, which consists of a subset of the System Explorers in Microsoft Anti-Spyware. Software Explorer lets you view details about Startup Programs, Currently Running Programs, Network Connected Programs, and Winsock Service Providers.

Microsoft has improved the presentation of information about these programs in terms of both quantity and quality. The programs are sorted by publisher name and now include data such as when the program was installed, its version, and the user running the program. Network Connected Programs is new in Windows Defender; it shows the names of the actual executables and the network ports they're connected to, so you can easily see which programs are making external connections.

Overall, Windows Defender Beta 2 simplifies and improves the experience, for most users, of working with Microsoft's antispyware tool. Some administrators might miss the fine grained capabilities of the previous version. Windows Defender Beta 2 also omits the management capabilities that third-party enterprise antispyware scanners provide. Thus, Microsoft's antispyware tool is clearly targeted to and best suited for the consumer market. Of course, Microsoft could make Defender much more manageable by simply incorporating Group Policy support for configuring Windows Defender, as the company has done for Windows Firewall.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

How can I stop and start services from the command line?

...

Where is Microsoft NetMeeting in Windows XP?

...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Top 10 Email Security Challenges and Solutions

Introduction to Identity Lifecycle Manager "2"

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing