Welcome, Guest. Please login or register.
March 19, 2010, 09:33:16 AM

Login with username, password and session length

372811 Posts
41346 Topics
94006 Members

Latest Member: claude.boulade

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  Over 1.1 Million Signatures and Comodo's Database continues to grow rapidly!
« previous next »
Pages: 1 [2] 3 Go Down Print
Author Topic: Over 1.1 Million Signatures and Comodo's Database continues to grow rapidly!  (Read 8154 times)
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6888


Why not ? The choice is yours !


« Reply #15 on: January 26, 2009, 04:23:37 AM »

a lot of FP's have been corrected in the last beta and I'm sure they will even work further to make sure these come as close to 0 as possible...

Xan
Logged

Yaraslau
Comodo Member
**
Offline Offline

Posts: 36


« Reply #16 on: January 26, 2009, 03:06:06 PM »

Hm... Every crack-patcher is defined as malware-patcher. Is it really malware? Of cause, no! FP? Probably, so.

From the previous post: as close to 0 as possible...  DREAM!!!!!!!!!!!!!!!!!!!

P.S. please, don't say crack is malware...
Logged

Let people be happy!
RejZoR
Comodo's Hero
*****
Offline Offline

Posts: 602



WWW
« Reply #17 on: January 26, 2009, 03:11:38 PM »

Even though cracks are illegal, they aren't malware and every antivirus thats detecting it and not willing to fix the false positive is bad in my eyes. If their excuse is the fact that they are cracks, well thats a bad one. Anyone could just add it to exclusions. What's worse is that some are indeed infected or just a replica of real malware and so users can't know for sure. And we all know we'll never prevent users from downloading cracks, keygens and patches...
Logged

darcjrt
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 476



« Reply #18 on: January 26, 2009, 03:45:33 PM »

Hm... Every crack-patcher is defined as malware-patcher. Is it really malware? Of cause, no! FP? Probably, so.

From the previous post: as close to 0 as possible...  DREAM!!!!!!!!!!!!!!!!!!!

P.S. please, don't say crack is malware...

A generic signature based AV will rate most patches as susp or flag it as malware because they have a line or multiple lines of code similar as a malware family. that is way most AVs rate patches as Trojan.Generic or something like that. For the AV they are malware as they open and inject code to another file.
Logged

Best Regards,

J
icecube1010
Comodo Family Member
***
Offline Offline

Posts: 84


« Reply #19 on: January 26, 2009, 03:50:34 PM »

Even though cracks are illegal, they aren't malware and every antivirus thats detecting it and not willing to fix the false positive is bad in my eyes. If their excuse is the fact that they are cracks, well thats a bad one. Anyone could just add it to exclusions. What's worse is that some are indeed infected or just a replica of real malware and so users can't know for sure. And we all know we'll never prevent users from downloading cracks, keygens and patches...

This is very true.  Especially when you just bought a game and want to get a nocd or nodvd patch for it.  This is very common.  I remember using Avira a while back and it detected about 5 games I had with this nocd crack or patch.  I had to check these executables to virustotal to feel safe that they were FP.  When I used Avast, I never had these types of FP's.

Ice
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6888


Why not ? The choice is yours !


« Reply #20 on: January 26, 2009, 03:58:37 PM »

Please do not forget that some keygens are created by anticrackers and they are malicious...

Xan
Logged

commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1401


^^^^


« Reply #21 on: January 26, 2009, 04:12:14 PM »

I doubt comodo has any interest to label any cracked software as a malware, we will probably get less and less FP with time, Right now I think the focus will be detection mostly, but the latest beta showed some major progress in the False Positive field, Lets see how the RC does later on..
 Love Love
Logged
Yaraslau
Comodo Member
**
Offline Offline

Posts: 36


« Reply #22 on: January 26, 2009, 05:06:49 PM »

I doubt comodo has any interest to label any cracked software as a malware

Smiley Malwarebytes Anti-Malware identifies MBAM cracks as trojans. Sure, team CRUDE only cracks, but not infects their own cracks. Wink
Logged

Let people be happy!
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6888


Why not ? The choice is yours !


« Reply #23 on: January 27, 2009, 04:21:08 AM »

Guys, this is the last post about it please do not talk anymore about cracks as it is illegal and so against the forum policy  Police

Quote
Illegal or inappropriate content. Comodo is focused on building trust on the internet. Members discussing or inciting illegal activity, posting or requesting anything illegal or inappropriate will be warned or banned as appropriate.


Thanks,

Xan
Logged

3xist
Guest
« Reply #24 on: January 27, 2009, 04:41:36 AM »

Guys, this is the last post about it please do not talk anymore about cracks as it is illegal and so against the forum policy  Police
 

Thanks,

Xan

And if so, Melih and myself won't be creating new threads and Melih will stop updating sigs number on these threads. Smiley

Cheers,
Josh
Logged
RejZoR
Comodo's Hero
*****
Offline Offline

Posts: 602



WWW
« Reply #25 on: January 27, 2009, 04:52:07 AM »

eXPerience, we are not talking about anything specific and we aren't posting any links or actual cracks so i see no reason to censor it. I'm just pointing iout the most common problem. For example ALWIL guys fix no-cd patches, however AVIRA refuses no matter even if detection is completelly off. No-cd patches are in grey area anyway, however i don't support cracks either but false detections are false and not fixing them will just make to generate more false positives on other files.
Logged

commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1401


^^^^


« Reply #26 on: January 27, 2009, 05:47:02 AM »

Iam with RejZoR on this one, many sites tests the amount of FP these days, not just detection so I hope it will kick some ass in this field as well! Submit all FP and help make comodo kick ass! =)

http://forums.comodo.com/beta_corner_cis/comodo_internet_security_beta_3861948459_av_false_positives_reports-t33536.0.html
Logged
icecube1010
Comodo Family Member
***
Offline Offline

Posts: 84


« Reply #27 on: January 27, 2009, 12:17:46 PM »

eXPerience, we are not talking about anything specific and we aren't posting any links or actual cracks so i see no reason to censor it. I'm just pointing iout the most common problem. For example ALWIL guys fix no-cd patches, however AVIRA refuses no matter even if detection is completelly off. No-cd patches are in grey area anyway, however i don't support cracks either but false detections are false and not fixing them will just make to generate more false positives on other files.

Not to get off topic here, but if gaming companies made their games to not use the cd or dvd in the drive, there would be less people looking for nocd or nodvd patches.  Hopefully, Comodo will not flag these .exe's as such.

Ice
Logged
Breen
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 324



« Reply #28 on: January 30, 2009, 05:11:35 PM »

I've got quite big package of new (2008/2009) malware. I've tested it with CAVS and it couldn't detect lots of it, every undetected file I'm uploading to Comodo reaserch. How long it takes to analize and add these samples to database? I hope not too long, because these files are nasty  Kewl.
Logged

100% organic software
.FaZio93.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2290



« Reply #29 on: January 30, 2009, 05:22:01 PM »

I've got quite big package of new (2008/2009) malware. I've tested it with CAVS and it couldn't detect lots of it, every undetected file I'm uploading to Comodo reaserch. How long it takes to analize and add these samples to database? I hope not too long, because these files are nasty  Kewl.

It depends on how much malware the analyzers are currently receiving. As you can see from this thread, they are working as fast as they can.  Wink 
Logged

Vista Home Prem x32 SP2
CIS 3.14.130099.587
Please remember to follow the Forum Policy.
Tags:
Pages: 1 [2] 3 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.175 seconds with 21 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com