Discussion:
What does ccapp.exe do?
(too old to reply)
Chuck
2003-08-23 02:10:55 UTC
Permalink
Today ZA asked if it was OK to allow ccapp.exe to access the internet. I knew
it was used by NAV (and maybe others) so I gritted my teeth and answered yes -
for this one time only. What is ccapp.exe doing? Did I open myself to
problems? Should I allow it to access the internet without asking?

Chuck
...
Chuck
2003-08-23 14:12:24 UTC
Permalink
Thanks for the reply. I think now that my problem is caused by ccevtmgr.exe
which is called by ccapp.exe. ccevtmgr.exe is the event manager for scheduling
scans and automatic updates. I don't have either of those functions checked.
I don't think that NAV should be contacting the internet on its own.

I don't like sceduling of anything. If you schedule an event, the computer
must be on at the scheduled time or the event doesn't happen. I do manual
scans when I think it should be done. Sometimes several times a day and always
last thing before shutting down. I do manual updates on Wednesdays, but not
always at the same time of day and occasionaly on other days.

Chuck
...
http://www.pacs-portal.co.uk/startup_pages/startup_full.htm
It is part of Norton AntiVirus 2003 . Auto-protect and E-mail check will not
function without this
Baz
cquirke
2003-08-24 18:48:56 UTC
Permalink
Post by Chuck
Thanks for the reply. I think now that my problem is caused by ccevtmgr.exe
which is called by ccapp.exe. ccevtmgr.exe is the event manager for scheduling
scans and automatic updates. I don't have either of those functions checked.
I don't think that NAV should be contacting the internet on its own.
Eg wetter gree.
Post by Chuck
I don't like sceduling of anything. If you schedule an event, the computer
must be on at the scheduled time or the event doesn't happen.
That's OK; means you rack up Tasks at times the PC's not on, and when
you want those Tasks done, you leave it on :-)
Post by Chuck
I do manual scans when I think it should be done. Sometimes several times
a day and always last thing before shutting down.
That's doooomed.

Windows-based AV is convenient, but is useless when breached.

Well, that's overstating it a bit; let's just say it cannot meet the
target required, even as imperfectly as an av ever does.

If you allow malware to go active, and then scan it from within the OS
it's already running in, there are these possible outcomes:

1) The av finds and kills it successfully and safely
2) The av doesn't find it
3) The av finds it, claims to clean it, but it's still active
4) The av is dead, because the malware killed it when it went active
5) The malware takes punitive action and you bleed++

If your risk management (of which your av is but one part) is working,
then there's no need to scan the whole system, and doing so adds no
value. When there's something to find, the fact that it is there in
spite of effective risk management reduces the likelyhood of best-case
outcome (1), tilting the risk/benefit balance towards (5).

If you think there's something to find, then do a formal virus scan.
If you swallowed MS's arrogant claims that "NTFS is soooo secure it
doesn't matter that it can't be formally scanned", then you have to
hope your faith was justified, else you may be ^&*%$ed.

http://usera.iafrica.com/c/cq/cquirke/virtest.htm refers.
Post by Chuck
I do manual updates on Wednesdays, but not always at the
same time of day and occasionaly on other days.
File-based malware spreads within a day, and direct worms such as
Slammer go global within minutes. So the notion that once a week (or
even real-time as av vendor hatches fixes) is enough to keep you 100%
safe is right up there with Santa Claus and other myths.

Resident av is useful; just don't ever mistake it for a 100% (or even
99%) effective total solution against malware - even if you consider
only "traditional" malware, accepting that most av will do zero to
protect you against commercial malware, which is a growth industry.
"Why do I keep open buckets of petrol next to all the
ashtrays in the lounge, when I don't even have a car?"
Post by Chuck
----------------------- ------ ---- --- -- - - - -
Loading...