<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html" />
  <link rel="self" type="application/atom+xml" href="http://ask-leo.com/atom.xml" />
  <id>tag:ask-leo.com,2012://3/tag:ask-leo.com,2009://3.3911-</id>
  <updated>2012-01-29T18:47:42Z</updated>
  <title>Comments for Does running Windows in a virtual machine protect me from viruses?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.32-en</generator>

  <entry>
    <id>tag:ask-leo.com,2009://3.3911-comment:60191</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3911" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html#c60191" />
    <title>Comment from Alec on 2011-09-28</title>
    <author>
      <name>Alec</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Actually, there have been instances of virtual machine escape, which is when malware is able to get out of the virtual environment and run directly in the host environment.  Most, as you allude, use defects in the network interface between the virtual machine and the host.  However, I know of at least one that got out using a defect in the virtual machine's display driver.<br />
<p><br />
To mitigate this, for the internet I use virtual machine software that is regularly maintained (i.e. VMWare and not QEMU), use Linux as the host and Windows as the guest in the virtual machine, run all virtual machines that access the internet under a regular Linux user account (i.e. not root), use host only networking under VMWare for all virtual machines that access the internet and tell the host Linux firewall to block all services for that VMWare host only network except for file sharing (Samba) and the web server (Apache).  Then, I use a Windows 95 virtual machine to do my regular internet access, the reason being that, for the last several years, every instance of malware that has invaded my Windows 95 virtual machine has caused it to promptly crash, thereby stopping the malware in its tracks before it can do worse damage and also immediately making me aware that I just came across malware.  So far, I have yet to be able to duplicate this type of protection in later versions of Windows.<br />
</p></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html">Does running Windows in a virtual machine protect me from viruses?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2011</a>.</p>
    </content>
    <published>2011-09-28T17:33:31Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3911-comment:40838</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3911" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html#c40838" />
    <title>Comment from Peter on 2009-12-08</title>
    <author>
      <name>Peter</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>I second the question above from Glenn P.<br />
<b>PLEASE</b> let me know by email if you respond to this question</p>

<p>(copied response)<br />
<i><br />
Seems to me you could greatly mitigate the networking issue of VM's by shutting down the networking feature, at least temporarily. If it is possible, for example, to bar the VM from sending any data to the physical machine, but only to certain peripherals (particularly the monitor and printer), you could then, while this state lasts, safely use the VM for web browsing, knowing that all downloads, cookies, malware, etc., is being written EXCLUSIVELY to the VM, and NOT to the physical computer. Toss the VM session down the drain, and all malware, etc., vanishes with it.</i></p>

<p><i>But now for the BIG Question: Is this scenario even possible?</i></p>

<p></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html">Does running Windows in a virtual machine protect me from viruses?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-12-08T08:46:44Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3911-comment:39683</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3911" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html#c39683" />
    <title>Comment from Glenn P. on 2009-11-06</title>
    <author>
      <name>Glenn P.</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Seems to me you could greatly mitigate the networking issue of VM's by shutting down the networking feature, at least temporarily. If it is possible, for example, to bar the VM from sending any data to the physical machine, but only to certain peripherals (particularly the monitor and printer), you could then, while this state lasts, safely use the VM for web browsing, knowing that all downloads, cookies, malware, etc., is being written EXCLUSIVELY to the VM, and <u><i><b>NOT</b></i></u> to the physical computer. Toss the VM session down the drain, and all malware, etc., vanishes with it.</p>

<p>But now for the <b><u>BIG</u></b> Question: <i>Is this scenario even possible</i>?</p>

<p>Please expand on your article and answer this, Leo!!! It's <u><i><b>IMPORTANT</b></i></u>!!!</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html">Does running Windows in a virtual machine protect me from viruses?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-11-06T21:32:24Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3911-comment:39647</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3911" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html#c39647" />
    <title>Comment from J. E. Schmidt on 2009-11-05</title>
    <author>
      <name>J. E. Schmidt</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>In order to help out other people and keep them away from Windows: I'd like to learn a great deal about Ubuntu (Linux) and how to set up a VM in there to run XP.  As I use Kingwin drive racks, would plug in a new HDD, install Linux and go from there.  I do have a boxed set of Linux distro which came from them--is this the same as Ubuntu?</p>

<p>To reach the goal of "a computer for every kid" in our school system, Linux is the only way to go.  Kids need to learn from their start they can do all sorts in Linux without that M$$$ stuff.</p>

<p>I'm especially angry with M$$$$ over their peremptory discontinuance of XP.  I'm the decision maker for 200 computers in our various businesses and it's XP forever, and friends who are IT guys in large companies tell me they aren't scrapping all their computers for new ones just to pay M$$$ for a new operating system they don't need anyway, either.</p>

<p>M$$$$$ is a stupid greedy company caring only for itself and not the world "out there" which wants to keep using XP.  That Ballmer person ought to be  "whacked upside the head," a phrase used by Judge Jackson in the anti-trust case.  There's no excuse for not continuing to sell it, expand site licenses, etc. particularly since support will continue until 2016.  XP+SP4 could be very profitably sold in huge quantities @$50 per copy on hooks in stores; and it would be appropriate to charge existing users something for SP4 if there were to be such a thing.</p>

<p>Greed leads to piracy and ultimately will be its own comeuppance for M$$$$.  It's history.</p>

<p>j</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html">Does running Windows in a virtual machine protect me from viruses?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-11-05T15:45:32Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3911-comment:39593</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3911" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html#c39593" />
    <title>Comment from David on 2009-11-03</title>
    <author>
      <name>David</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Firstly, I am one who believes VMs are one of the most incredible tools available. Even among 'cool' IT geeks, we almost gush over what we can achieve using a VM. For what it's worth, I use Virtual Box from SUN - its simplicity to setup and use puts it in the category of 'worth checking just to see what it does'.<br />
I use Ubuntu for day-to-day work for all the typical Linux reasons, performance, reliability, security, support, etc. Now, due to the usability work done on the major distros such as Ubuntu, it's also an easy environment to work within.</p>

<p>Anyway, back to the topic, I have many reasons to keep a lot of alternative OS's in my computer all available in a VM. Customers and friends often ask me to show them how something is meant to work or whether it works properly in a certain environment. I have every Windows release(except ME which I could but don't use) from 2000 up to Win 7). Being able to jump in and out without rebooting is just so useful.</p>

<p>As Leo states, all the connectivity, shares, etc. are as difficult or easy to setup as they are in a traditional environment. I therefore treat a VM as  an easily infected environment and so keep all my anti-virus software up-to-date (something that needs to be understood BTW, is that although Linux is virtually 'virus or germ proof', passing on or sharing infected files onto an unprotected Windows machine is the same as passing that same dirty file onto a normal unprotected Windows computer - the germ simply 'wakes up'.</p>

<p>WINE in Linux is pretty cool - I use it occasionally for MYOB simply because in WINE it runs almost natively. In Virtual machines, there is nothing that doesn't work in my experience. In fact, with the caveat that you do need modern quantities of memory, VM performance feels identical to working in a sole environment.</p>

<p>To Selinap and Gabe, I need to point out that using a VM for banking is a complete waste of time in 99.9% of cases. In banking, all your work is done behind a fortified encryption SSH screen (shown by a Padlock somewhere in your Window). A VM is no safer than your normal session.</p>

<p>The exception might be (because I haven't tested it) that a VM provides you with a layer of protection against a key-logger if you share your computer or if it's been accessible to someone malicious enough to install a key-logger application. A VM might protect you due to the fact that you've crossed over into a clean environment as you enter the VM. I'm open to correction on that though.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html">Does running Windows in a virtual machine protect me from viruses?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-11-03T21:53:57Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3911-comment:39566</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3911" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html#c39566" />
    <title>Comment from Gabe on 2009-11-03</title>
    <author>
      <name>Gabe</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Selinap.</p>

<p>Leo discusses the pros and cons of that <a href="http://ask-leo.com/does_a_sandbox_or_virtual_machine_help_protect_your_privacy.html" rel="nofollow">here</a>.  It sounds like you've got a good suggestion for the "complexity" drawback he mentions at the very end of that article.  While it does add complexity to a users daily computing, I could see having a dedicated VM that I ONLY use to:<br />
1) Open Internet Explorer<br />
2) Browse to BankA, BankB, or BankC to handle all of my personal banking needs<br />
3) Close the browsers and then close the VM</p>

<p>I like it!</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html">Does running Windows in a virtual machine protect me from viruses?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-11-03T14:39:46Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3911-comment:39419</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3911" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html#c39419" />
    <title>Comment from Selinap on 2009-10-28</title>
    <author>
      <name>Selinap</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>I would suggest that we use different VM for different purposes. For example, one VM for critical activities only (like banking), and the rest would be for general purposes. </p>

<p>That way, we have created an isolated environment for critical activities.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/does_running_windows_in_a_virtual_machine_protect_me_from_viruses.html">Does running Windows in a virtual machine protect me from viruses?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-10-29T01:19:31Z</published>
  </entry>

</feed>

