"Security experts have long maintained that running two different anti-virus products on the same Windows machine is asking for trouble, because the programs inevitably will compete for resources and slow down or even crash the host PC.
... But an upstart anti-virus company called Immunet Protect is hoping Windows users shrug off this conventional wisdom and embrace the dual anti-virus approach. Indeed, the company’s free product works largely by sharing data about virus detections from other anti-virus products already resident on the PCs of the Immunet user community.
... I’ve been running Immunet in tandem with Kaspersky Internet Security 2010 for the past three months, and have haven’t noticed any impact on system resources or stability issues. Immunet’s creators are especially proud of that last aspect of the program, and say it’s due to the fact that the program does most of its scanning and operations “in-the-cloud,” – that is, not on the user’s system. "
I'm not sure I can answer your question about validation, Michael. False positives continue to be a problem with every AV (some more than others).
But as I understand it, Immunet gathers data from all its users, who use a variety of AVs. As you know, some AVs respond to new threats with updates quicker than others.
Thanks Dale for that feedback. It encourages me to give Immunet a trial. I've been a "crash test dummy" myself for years, but have never considered a 2nd AV, except as a standalone on-demand scanner, with real-time protection disabled.
Using Outpost Firewall Pro on XP Pro here, I always put it temporarily into "Auto-Learn" mode when installing new programs, to avoid alerts. (It automatically reverts to "Rules Wizard" after one hour, if I forget to do so manually).
I believe DC is going offline shortly to correct some problems (hopefully the log-in cookie retention issue, but I'm not holding my breath).
I think the question should be, "Does Immunet do anything useful?" Doing no harm is not the same as doing something good.
You ask the $60,000 question, Michael, to which I have no answer.
Immunet has not been subjected to independent testing as to its effectiveness. But I find its concept intriguing.
I do know that in medical studies on potentially therapeutic new drugs, studies on safety take precedence over studies on effectiveness.
All I know is that this program installed quickly and easily, with no conflicts while running with my resident AV that I could detect. It does add "iptray" to my startup list, and "Immunet Protect" as a service. It does not slow down my PC or browsers, as far as I can see. It runs a scan in about 30 seconds, and like all my scanners, detects nothing. It says I am protected from 12 million threats.
Which is to say, I too have found no problems with Immunet. No more, no less. It seems safe, and may offer some benefits, yet to be proven.
It's now been about one month since I installed Immunet Protect (IP). I should point out that this version 1.0.26 is a beta version, and after looking it over and running a scan, decided I didn't want a beta AV running in tandem with my NOD32 AV. I exited the program with a right-click on its tray icon. Or so I thought!
Today I opened my Control Panel> Security Center>Virus Protection, and was surprised to see the following: "Immunet Protect reports that it is up to date and virus scanning is on." (!)
Belarc Advisor confirmed this, as did Secunia PSI.
So it turns out IP has been running along with NOD32 for almost 4 weeks, with nary a problem or conflict. (I can of course prevent this by blocking its startup with WinPatrol). And nary a single alert or detection over all that time. Now that's a quiet AV.
When I open the program, I'm informed that some 186,000 folks are in the Immunet Cloud, and I'm protected from some 12 million threats.
As far as resources goes, Task Manager shows its service (agent.exe) using about 1/3 the memory that NOD32 does.
IP's on-demand scan of running processes and loadpoint processes (2082 files for me) takes about 30 seconds. This is not a replacement for your conventional AV on-demand scan, but is a quick supplement.
One feature I like is the History and Summary tabs. The resident IP was monitoring all executable files (literally hundreds, most of them in tmp folders) I downloaded in the last month, and declared them all as "known legitimate programs".
There are no "Help" files per se; clicking on "Help" takes you to Immunet's support forum.
Summary:
IP proved to be a 2nd resident AV that ran along side my own AV with no problems for one month. It was so unobtrusive I didn't even know it was resident (and that's embarrassing!). And no false positive detections.
Its version of cloud security is a promising and unique concept, an additional layer of security, and this is a program worth keeping track of. However, I cannot recommend a beta program, and in fact have disabled it properly this time. Its effectiveness at blocking/removing malware has yet to be independently evaluated.
Immunet states it will be releasing a new version shortly, and I will eagerly await it.
Whether this support addresses the issue you raise is moot.
I forgot to say my NOD32 is not listed as as a supported AV, which is another reason why I disabled Immunet.
The eicar testfile isn't much of a robust test, but it was detected by my AV. If I disabled my resident AV, it was detected by Windows Defender. When I disabled WD, it was detected by IE8. Never did get to Immunet detection. The point being there were no conflicts among these programs for this one simple test, in my particular environment.
It will take more than an eicar test to satisfy my reservations however, and I'll leave the real testing to the experts. Meanwhile, despite my (inadvertant) positive experiences to date, Immunet beta returns to disabled status on my system, for precisely the concern you express.
My only question is (being a bit confused, is), did you compare a) avast! (alone) vs. Immunet (alone), or did you compare b) avast! (alone) vs. avast!+Immunet (both running resident)?
I guess what I'm asking is, did Immunet augment or degrade avasts's protection in your testing. No need for any quick reply.
AFAIK, the Flash Scan looks for malware by scanning your system registry and running processes only. Obviously not a substitute for a full AV on-demand scan. -----------------------------------
1972vet:
Thanks for your input also. Until I read Kreb's article, it was gospel for me also to only use one resident AV (and indeed I still follow and recommend this practice). It's my nature to explore new ideas, so I follow this one with interest.
But I really appreciate all the expert input from all here.
For the record, I do not run Immunet in real-time alongside my resident AV. It's an interesting concept, which is why I raised the question. My experience is that it is "do-able". Whether it is wise is a different question. I follow your posts with great interest.
I read the link. Theis paragraph make absolutely no sernse to me
"But what makes Immunet different from other anti-virus products is that it also incorporates detections for malware from other anti-virus products that may be resident on users’ machines. For example, each time someone’s PC in the Immunet user base encounters a virus, that threat is logged and flagged on a centralized server so that all Immunet users can be protected from that newly identified malware."
Lets assume I am running Norton AV, and it finds a virus, how will signature aumotatically be created for Immunet, who will vaidated it? Lastly I want a AV company to be pro-active, searching for viruses in the wild and building a defense, rather reactive, waiting for some other AV company to find the problem means they will always be one step behind.
Just a quote from WinPatrol's BillP: "I’m also intrigued by new free software called Immunet but I’m still evaluating its effectiveness. I can confirm it works well when paired with WinPatrol PLUS."
joe53
5 Journeyman
•
5772 Posts
•
17269 Points
2111
0
Posted April 18th, 2010 21:00
I'm not sure I can answer your question about validation, Michael. False positives continue to be a problem with every AV (some more than others).
But as I understand it, Immunet gathers data from all its users, who use a variety of AVs. As you know, some AVs respond to new threats with updates quicker than others.
It *seems* like a good idea.