<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>EWF as an Antivirus solution</title><link>http://blogs.msdn.com/embedded/archive/2005/03/23/401377.aspx</link><description>Over the years, the product team is periodically contacted by different internal Technical Account Managers for some of our premier customers and the conversation goes something like this: TAM: I’ve got this customer and they have this cool device and</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: EWF as an Antivirus solution</title><link>http://blogs.msdn.com/embedded/archive/2005/03/23/401377.aspx#402599</link><pubDate>Sun, 27 Mar 2005 02:47:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:402599</guid><dc:creator>Anthony Spina</dc:creator><description>When you stated that &amp;quot;Many have tried and many have failed and learned their lesson the hard way&amp;quot;:&lt;br&gt;&lt;br&gt;Where they commiting changes after the box had been up for days or on a fresh boot ?&lt;br&gt;Where they SP2 installs with Firewall on/No Exceptions ?&lt;br&gt;Was the IE policy locked down ?&lt;br&gt;&lt;br&gt;Conceptually it would sound like a no-brainer that EWF would solve everyones virus issues, being able to start fresh everytime you hit the reset button. That entire post seemed like a lead in to the Computer Associates plug on the bottom.&lt;br&gt;&lt;br&gt;When hackers learn to circumvent EWF, thats when people will have problems, No ?&lt;br&gt;&lt;br&gt;</description></item><item><title>re: EWF as an Antivirus solution</title><link>http://blogs.msdn.com/embedded/archive/2005/03/23/401377.aspx#402613</link><pubDate>Sun, 27 Mar 2005 05:33:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:402613</guid><dc:creator>Andy Allred</dc:creator><description>Hi Anthony, thanks for the feedback. &lt;br&gt;&lt;br&gt;This isn't a plug, it's the only componentized AV solution for XPe today. Actually, you can install any AV software designed for XP Pro, perhaps i should have emphasized that as an alternative, but the CA version is the one componentized which is more helpful for smaller footprint devices. &lt;br&gt;&lt;br&gt;I've componentized FPROT for my own experiments and it worked fine, so you're not limited to the one listed in the post, but CA's is the only one publicly available. I've also installed from the desktop Symantec and Panda on XPe runtimes, but those weren't componentized and required a lot more dependencies just to get the AV *installer* to work. For small footprint devices restricted in disk space a componentized version is preferable.&lt;br&gt;&lt;br&gt;I highly recommend you don't use EWF for the reasons i mentioned regarding commiting to disk and the fact that, even though the disk is protected, the device can still continue to infect other machines. If there's no person sitting in front of the device how do you know you need to press that reset button in order to &amp;quot;fix&amp;quot; the problem, for instance if the device is headless or in a remote location? &lt;br&gt;&lt;br&gt;Using EWF as an AV solution is not a &amp;quot;best practice&amp;quot;. If you decide to do it anyways, at least having the servicing infrastructure, firewall and security of SP2 will help.&lt;br&gt;&lt;br&gt;SP2 for embedded was only just released a few months ago, it was the Gold and SP1 versions that have been infected, all the incidents i'm aware of did not have a firewall. To date i haven't heard of any SP2 infected embedded devices yet.&lt;br&gt;&lt;br&gt;This raises the issue that for devices like a thin client or a cash register that have a user sitting in front of it most of the day, user education comes into play as well. Another issue are the devices that allow everyone to run as Administrator, but as you mentioned, IE being locked down is a good idea as well.&lt;br&gt;&lt;br&gt;To answer some of your other questions, i don't know about the IE settings of the infected machines. These were mostly SP1 devices and some were not being serviced properly if at all. &lt;br&gt;&lt;br&gt;For most embedded devices, a firewall is going to protect you due to very few open ports. Having AV on the box is additional insurance. &lt;br&gt;&lt;br&gt;One issue i did not raise is that you need the ability to update the virus definition files, something you'll need to consider as part of your servicing scenario perhaps.&lt;br&gt;&lt;br&gt;A lesson learned is that security in general needs to be a consideration early on in the design phase of your device. EWF was not designed to act as an AV feature, if you choose to use it in this manner please at least use a firewall, service the device and use SP2.&lt;br&gt;&lt;br&gt;Lastly, security of EWF is a concern and is considered in the design and test of the feature. I worry about *any* of our features being attacked by hackers &amp;lt;grin&amp;gt;&lt;br&gt;&lt;br&gt;Thanks again Anthony. Do you have any requests for topics?&lt;br&gt;</description></item><item><title>re: EWF as an Antivirus solution</title><link>http://blogs.msdn.com/embedded/archive/2005/03/23/401377.aspx#9653092</link><pubDate>Fri, 29 May 2009 16:56:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9653092</guid><dc:creator>Mohammed Nusrath</dc:creator><description>&lt;p&gt;We are facing issues with thin clients running Mcafee and if we are disabling the EWF option, then the performance is good. We are running mcafee on our wyse thin clients. &lt;/p&gt;
&lt;p&gt;What is your take on disabling EWF completely. I understand that disabling EWF will allow users to write files to the disk but we will educate them not to save anything on the box.&lt;/p&gt;
&lt;p&gt;Apart from that,will there be any impact.?&lt;/p&gt;
&lt;p&gt;thanks&lt;/p&gt;
</description></item><item><title>re: EWF as an Antivirus solution</title><link>http://blogs.msdn.com/embedded/archive/2005/03/23/401377.aspx#9653353</link><pubDate>Fri, 29 May 2009 18:14:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9653353</guid><dc:creator>MattKell (MSFT)</dc:creator><description>&lt;p&gt;Mohammed: Generally speaking, if you are running an actual anti-virus program, you will probably not want to use EWF, as any changes, cleanup, quarantines, etc. performed by the AV program will be lost once the EWF overlay is discarded. &amp;nbsp;The intent behind this post was to show how EWF could be considered an anti-virus solution by enabling it to &amp;quot;lock down&amp;quot; the hard drive - you can just throw out any changes that a virus may have made to your system. &amp;nbsp;But as Andy pointed out in an earlier reply, as long as the virus is active on the computer, it can infect other machines as well, so a real AV solution is in fact better.&lt;/p&gt;
&lt;p&gt;The only major impact of disabling EWF completely would be that you don't get the benefits of EWF's write filtering. &amp;nbsp;At that point, if protecting your hard drive from unauthorized writes is a concern, there are a number of other ways to lock the system down for security that are supported in XP Pro (and therefore in XPe). &amp;nbsp;Your mileage may vary.&lt;/p&gt;
&lt;p&gt;Hope this helps!&lt;/p&gt;
</description></item><item><title> Windows Embedded Standard NT4e XPe and beyond EWF as an Antivirus | debt solutions</title><link>http://blogs.msdn.com/embedded/archive/2005/03/23/401377.aspx#9790326</link><pubDate>Fri, 19 Jun 2009 19:36:49 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9790326</guid><dc:creator> Windows Embedded Standard NT4e XPe and beyond EWF as an Antivirus | debt solutions</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://debtsolutionsnow.info/story.php?id=1996"&gt;http://debtsolutionsnow.info/story.php?id=1996&lt;/a&gt;&lt;/p&gt;
</description></item></channel></rss>