Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 30, 2009, 10:23:14 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
346223
Posts
38256
Topics
86883
Members
Latest Member:
barkerrd1
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
General Category
Melih's Corner - CEO Talk/Discussions/Blog
Eighty percent of new malware defeats antivirus????!!!!
« previous
next »
Poll
Question:
OT posts splitted
who removed my posts from this thread
0 (0%)
https://forums.comodo.com/empty-t28058.0.html
0 (0%)
Total Voters: 0
Pages:
[
1
]
2
Author
Topic: Eighty percent of new malware defeats antivirus????!!!! (Read 18773 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8374
Eighty percent of new malware defeats antivirus????!!!!
«
on:
July 23, 2006, 06:10:11 PM »
http://www.zdnet.com.au/news/security/soa/Eighty_percent_of_new_malware_defeats_antivirus/0,2000061744,39263949,00.htm
Interesting reading.
The point that is being raised in this news article is that people use AV mostly and anti spyware is yet to penetrate the market.
One of the major reasons why Anti-Spyware products come as a seperate product is because vendors are looking for ways to charge extra for this. At Comodo we decided to turn our AV engine to also catch spyware hence we called it CAVS (Comodo Anti Virus/Spyware). Hence I believe our strategy is right and our strategy will help fight malware better, cos majority of people still think just AV will be enough and don't bother with Anti spyware.
Read the article and let me know your thoughts please.
Thanks
Melih
«
Last Edit: November 25, 2007, 11:24:58 AM by Melih
»
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5325
I'm not a complete idiot, some bits are missing.
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #1 on:
July 23, 2006, 08:42:47 PM »
Based on that article, I think we should keep CAVS very quiet & not tell any more people about it.
Hmm.. I believe there's a slight flaw in that thinking. :
Seriously, I think your strategy is correct & certainly is best for the user.
But, the article does make a valid point. The more popular any product becomes, then there more likely it will be that virus/trojan/malware writers test their latest thing against that product. That is, as the article indicates, indeed a worrying trend.
Logged
Vista Business x32+SP2 with CIS 3.12 & Firefox 3.5 & Becky! 2.52
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
Laurence
Comodo Member
Offline
Posts: 40
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #2 on:
July 23, 2006, 08:55:50 PM »
Hi Melih,
It certainly sounds to be a wise course of action alright, to integrate antispyware and antivirus together; and scanning in such a way, so as 1) first and foremost, as much as possible, prevent same from entering one's system, 2) should it enter, catch same before it does harm, and 3) preferably clean/disinfect/eradicate it once found; barring that, at least quarantine suspicious files.
And from what I read on
rootkits
it sounds like they remain a real problem and growing concern. I am hopeful that CAVS, combined with a successful firewall (such as CPF), eventually proves itself to be up to the task of protecting those who use computers and traverse the Internet, providing end users with that warm and fuzzy feeling which can come from truly knowing that one is being protected by the best.
So, continue to press on, making our CAVS (and other Comodo products of course) the very best there is, and then we won't have to be numbered among that 80 %. ;-)
Laurence
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8374
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #3 on:
July 23, 2006, 09:04:23 PM »
Quote from: kail on July 23, 2006, 08:42:47 PM
Based on that article, I think we should keep CAVS very quiet & not tell any more people about it.
Hmm.. I believe there's a slight flaw in that thinking. :
Seriously, I think your strategy is correct & certainly is best for the user.
But, the article does make a valid point. The more popular any product becomes, then there more likely it will be that virus/trojan/malware writers test their latest thing against that product. That is, as the article indicates, indeed a worrying trend.
Yes worrying indeed!
Blacklisting technologies that work on signatures and algorithms that detect behaviour are always there to be broken. This is why at Comodo we supplement all these technologies with safelisting approaches which is not susceptible to what the author has described.
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
pandlouk
I love Comodo
Comodo's Hero
Offline
Posts: 2240
Retired Mod
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #4 on:
July 23, 2006, 09:25:23 PM »
That article has some truth but it makes me wonder why he don't give any information about the programs he used and/or at least a catalog of the malware that he used for the test. It sure lacks of credibility since it just throw some percentuals and nothing more (not a number of the malware, not types of malware, etc.)
ps. This information is not new. It reminds me of blaster ( I think it was him), 2 years ago, that the first thing he did when infected a system was to disable the AV engine of the most known antivirus (norton,mcafee,etc.) and the second was to mutate his signature. It gave a great headache at the AV companies for more than 8 months.
Logged
campart
Newbie
Offline
Posts: 9
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #5 on:
July 24, 2006, 03:05:58 AM »
80% sounds very high...like possible exageration. I have been using Spyware Blaster up until now. Can I safely switch this off with CAVS in use? I noticed that on my previous PC I had Spyware Blaster and Spybot both loaded. Spybot had fewer updates and since its scans never detected any intruders I assumed that Blaster stopped everything from even getting to me. I should add that I use ThunderBird and Firefox so I don't have the usual MS security holes.
CPF and CAVS both working perfectly for me. Thank you Melih (and team).
Thank you mOngOd for your comments, I will keep Spyware Blaster up and running while CAVS evolves.
«
Last Edit: July 30, 2006, 05:22:23 PM by campart
»
Logged
m0ng0d
I used to be indecisive, but now I'm not so sure.
Global Moderator
Comodo's Hero
Offline
Posts: 797
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #6 on:
July 26, 2006, 08:31:21 PM »
I has Spyware Blaster and Spyware Guardian (both by the same company) loaded. Spyware Guardian interferred with CAVS installing correctly (as it silently stops things), so I had to uninstall it.
I think Spyware Blaster is a wonderful companion product to keep installed as it is more about "training" IE / Firefox with regards to Ads, Restricted Sites, and ActiveX install control.... I only foresee CAVS possibly depricating Spyware Blaster's ActiveX controls... but there are 2 other function that Spyware Blaster can still perform for you (until COMODO makes new products that incorporate those functions).
Logged
OS:
Win7 Ultimate x64
Comodo:
CIS 3.12
,
Backup 2.0
,
CSC 2.0
Other Security:
Mailwasher Pro 6.1 LFE
Wish:
x64 iVault for FireFox
DoomScythe
Comodo's Hero
Offline
Posts: 396
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #7 on:
July 31, 2006, 11:23:19 AM »
I think it is possible for this (80% new malware defeats antivirus) to happen, considering most anti-virus softwares are using the blacklist approach. I think this will continue to be a trend until some geniuses came up with a new method on which the AV software could work on. Playing catchup is always on the losing side.
Erm Melih, I don't get you when you said you were using the whitelist approach. Do you refer to the CPF or CAVS? I certainly think that it is the CPF, right? No way you could create a whitelist for the CAVS.......
Yours truly,
DoomScythe
Logged
TheFireKnight
Comodo Family Member
Offline
Posts: 89
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #8 on:
July 31, 2006, 12:33:05 PM »
I used to use Kerio PF to help in catching some rootkits when they tried to connect to the internet. Mostly it was because I could see all the information of what comes in and goes out.
Guess what? I've had
MUCH
greater success with CPF when it come to doing the same thing.
Sure a good firewall like CPF doesn't get rid of the rootkits, and generally I haven't really seen any AV/AS program being able to remove them, but at least I can sure tell when one is installed.
Removal usually turns out to be a manually done job.... but oh well....
Hopefully CAVS will collaborate with CPF enough to have a better chance of removing these nuisances.
Besides that, you'd need a program that does thread tracing to be able to catch many/all rootkits (thread tracing=very time consuming - maybe do-able when AMD releases their 4x4 initiative).
Edward
Logged
_/|__|\_ This is Kitty. Copy and paste Kitty into your
(=*-*=) signature to help him gain world domination!
("")_("") And win the battle against all bunnies!
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8374
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #9 on:
July 31, 2006, 01:21:12 PM »
Quote from: DoomScythe on July 31, 2006, 11:23:19 AM
I think it is possible for this (80% new malware defeats antivirus) to happen, considering most anti-virus softwares are using the blacklist approach. I think this will continue to be a trend until some geniuses came up with a new method on which the AV software could work on. Playing catchup is always on the losing side.
Erm Melih, I don't get you when you said you were using the whitelist approach. Do you refer to the CPF or CAVS? I certainly think that it is the CPF, right? No way you could create a whitelist for the CAVS.......
Yours truly,
DoomScythe
Give me 2 months to show you what i mean :-)
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Júštiñ™
Global Moderator
Comodo's Hero
Offline
Posts: 2868
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #10 on:
July 31, 2006, 01:30:10 PM »
Quote from: Melih on July 31, 2006, 01:21:12 PM
Give me 2 months to show you what i mean :-)
Melih
Logged
When the power of love, overcomes the love of power, the world will know peace.
~Jimi Hendrix
DoomScythe
Comodo's Hero
Offline
Posts: 396
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #11 on:
August 01, 2006, 12:39:21 AM »
Quote from: Melih on July 31, 2006, 01:21:12 PM
Give me 2 months to show you what i mean :-)
Melih
Alright Melih, now you got me really curious. Hehe
Yours truly,
DoomScythe
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 1096
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #12 on:
August 16, 2006, 10:23:19 AM »
Quote from: TheFireKnight on July 31, 2006, 12:33:05 PM
I used to use Kerio PF to help in catching some rootkits when they tried to connect to the internet. Mostly it was because I could see all the information of what comes in and goes out.
Guess what? I've had
MUCH
greater success with CPF when it come to doing the same thing.
Sure a good firewall like CPF doesn't get rid of the rootkits, and generally I haven't really seen any AV/AS program being able to remove them, but at least I can sure tell when one is installed.
Removal usually turns out to be a manually done job.... but oh well....
Hopefully CAVS will collaborate with CPF enough to have a better chance of removing these nuisances.
Besides that, you'd need a program that does thread tracing to be able to catch many/all rootkits (thread tracing=very time consuming - maybe do-able when AMD releases their 4x4 initiative).
Edward
The only effective method for removing these threats is by a comparison scan between the windows environment and a BARTPE or similar ,based bootable cd scan.
Logged
-[NHATZ_JADE]-
Comodo's Hero
Offline
Posts: 286
2G/3G Rigger & Radio Access Field Officer [HUAWEI]
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #13 on:
August 20, 2008, 12:33:18 PM »
Quote from: Melih on July 23, 2006, 06:10:11 PM
http://www.zdnet.com.au/news/security/soa/Eighty_percent_of_new_malware_defeats_antivirus/0,2000061744,39263949,00.htm
Interesting reading.
The point that is being raised in this news article is that people use AV mostly and anti spyware is yet to penetrate the market.
One of the major reasons why Anti-Spyware products come as a seperate product is because vendors are looking for ways to charge extra for this. At Comodo we decided to turn our AV engine to also catch spyware hence we called it CAVS (Comodo Anti Virus/Spyware). Hence I believe our strategy is right and our strategy will help fight malware better, cos majority of people still think just AV will be enough and don't bother with Anti spyware.
Read the article and let me know your thoughts please.
Thanks
Melih
HE!!O MELIH
A combination of FIREWALL / AV / ANTISPYWARE in One package will be the best I think.
Logged
OS
- [XP PRO sp2]
PROCESSOR
- [CELERON-D single]
BROADBAND ANTENNA
- [Motorola Canopy with Surge & Lightning Arrester]
UPS
- [Liebert Emerson ItOn]
ON-DEMAND SCANNER
- [MBAM] [SAS] [SPYBOT] [A-SQUARED]
http://www.facebook.com/home.php?#/nhatz.jaja?ref=profile
3xist
Guest
Re: Eighty percent of new malware defeats antivirus????!!!!
«
Reply #14 on:
August 22, 2008, 12:45:11 AM »
Quote from: LEWIS HAMILTON on August 20, 2008, 12:33:18 PM
HE!!O MELIH
A combination of FIREWALL / AV / ANTISPYWARE in One package will be the best I think.
Hey Lewis,
It's in the making
Cheers,
Josh
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.055 seconds with 21 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com