Welcome, Guest. Please login or register.
December 19, 2009, 07:26:47 AM

Login with username, password and session length

343599 Posts
37980 Topics
86206 Members

Latest Member: cobra

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Feedback/Comments/Announcements/News - CIS
| | | |-+  Comodo are now generating Generics Signatures... :) Check it out :-)
« previous next »
Pages: [1] Go Down Print
Author Topic: Comodo are now generating Generics Signatures... :) Check it out :-)  (Read 673 times)
3xist
Guest
« on: July 04, 2009, 08:49:31 PM »

I talked to Umesh (Head of the AV Labs).

CIS 3.10 is now out. Comodo have now started generating very powerful generic signatures, which catch many many other malware (thousands).

You can tell these signatures look different from before, Because each signature now has Numbers or letters after it (Example: Before in Virus Section it was just Virus.Win32.Virut being added (Only added for one variant of Virut) Now you all see this...


(DB 1539)

Which represents Generic Signatures. You cannot differentiate however between Generic Signatures and Normal Signatures, But the AV Labs are generating as much Generic Signatures as possible now, Next week the database size will start going down, Because Comodo won't need so many signatures being added now and the format has obviously changed to suite this, and create a higher detection. Smiley

Cheers,
Josh

« Last Edit: July 05, 2009, 06:18:36 AM by 3xist » Logged
Petit
Comodo's Hero
*****
Offline Offline

Posts: 398


I'll grow up to be a "Real Dragon" !!


WWW
« Reply #1 on: July 04, 2009, 08:55:06 PM »

Nice.
But did it will increase download size ?

And also I wish Comodo can be Repair a file infection virus ASAP.
By not deleting file.  Angel
Logged



OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1641


The only thing i ask for are eggs.


WWW
« Reply #2 on: July 04, 2009, 09:53:42 PM »

Alright TrojWare is full of them.

Just a Question.

Generic? (yes or no)
TrojWare.Win32.Vapsup.INT (Yes)
TrojWare.Win32.TrojanDownloader.Tibs.31 (Yes)
TrojWare.Win32.TrojanDownloader.CodecPack.e (Maybe?)

Not Generic?
TrojWare.Win32.TrojanDownloader.Banload.~AB 

Note the ~ it used to be used in the database before 3.10 came out.
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
devenroy
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 410



« Reply #3 on: July 04, 2009, 11:21:38 PM »

Nice to see Generic Signatures are in use now with 3.10 which will result in better detection & lesser database size.
thanks 3xist for this thread.
Logged

Thanks,
Deven
3xist
Guest
« Reply #4 on: July 05, 2009, 03:38:18 AM »

Ive seen first detections using Generic Signatures today. Only one signature to catch all these variants of the Magania Family!

TrojWare.Win32.Magania.~awds[at]25568546 signature Caught 60 Variants (Limited in picture, and I only collected a handful of these variants so more would be detected)



Awesome!

Cheers,
Josh

« Last Edit: July 05, 2009, 03:49:17 AM by 3xist » Logged
Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 3233



WWW
« Reply #5 on: July 05, 2009, 03:53:52 AM »

High 5
Logged

E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM.  500gb. HDD


~~~
Trying to see if I can completely switch to linux Cheesy
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.037 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com