Virus test for CAVS

Boys, it takes time to collect all the virus samples so you can compeed with the market leaders :slight_smile: I would not be surprised if it takes 1 or maybe 2 years more before they are there :wink:

Greetz, Red.

Want to bet?

LOL! The entire test suite relies on your system allowing STEP 1 to complete. While it’s true that if we allow step 1 to complete, then CAVS will fail at least one of the following tests. However, since, CFP V3 and CAVS, in combination, stopped step 1 completing, steps 2 to “whatever” simply don’t matter and my PC didn’t end up “infected”.

If the infection can’t get into your system in the first place, isn’t that achieving the same nett result as letting your system get infected and being able to successfully remove it (albeit without any introduced instabilities)?

Of course CAVS detection rate needs to improve and I believe that it will. It won’t happen overnight, but it won’t take 10 years either. :wink:

Ewen :slight_smile:

P.S. I love their “proof tests”. The functions they are performing are done by the primary executable, which we have already allowed to run. If it had started an additional process to do these tricks, CFP V3 or CAVS HIPS would have picked it up and let me block it. Of course it can produce the effects that it can - we let it. LOL!

Lets have a guess as to how long it will take for CAV to catch
1)70%
2)80%
3)90%
4)above 90%

of the virus zoo that the testers have (as you all know these percentage depend on the virus samples the testers have)…

so what do u think? (I am just curious :slight_smile: )

Melih

As my reputation is already dead from here :wink:

I would say 85.37473638472873843274832737% :slight_smile:

Your reputation isn’t dead. :wink: I wasn’t having a shot at you, just trying to explain why it failed (which it did, if you follow their testing methods).

This is exactly what Melih has been trying to stress for months. Traditional anti virus testing methods revolve around the assumption that your PC is already compromised, and have no means of testing whether anything prevented the intrusion in the first place.

Tradtional AVs are a reactive cure.

CAVS / CFP V3 is a proactive vaccination.

It will be interresting to see how CAVS performs when testing methods start to include prevention.

Cheers,
Ewen :slight_smile:

Unfortunately, I think it will take quite a long time before ordinary people will think in new terms, concerning protection, as even the large AV companies seems to be detection focused. And their firewalls score poorly in the Matousec test.

Comodo’s technology will be years ahead of the common people’s thinking. Good for Comodo and those who use their software, sad for the large mass, until they discover Comodo!

/LA

About what ? I do beleve Comodo eventualy will manage a score above the 90% , but I don’t beleve they will acomplish that within 1 year from now.

Greetz, Red.

Tradtional AVs are a reactive cure.

CAVS / CFP V3 is a proactive vaccination.


Yep yep, as I have red many times its what Melih says

  1. Prevention
  2. Detection
  3. Cure

But you need to try to explain the normal people :-\ they just don’t believe what you’re saying. (:AGY)
Then you install an antivirus and antispyware, check their computer and find over 1000 traces of 300 virusses/spyware/adaware :). (checked my brothers pc)
But then the cure part :(, because lots of that malware is stuck in the windows kernel itself it’s or destroying the pc or leaving it there :-. Long live the HIPS feature :D.
Wel yeah, said enough gonna try to delete that ■■■■

Xan

Time to live up this topic again :wink:

After sending a ticket, which I don’t really trust, i like to forums much much more 8). I’ve found a strange malware creation tool here http://vx.netlux.org/vx.php?id=tv07 if you search the site further to here http://vx.netlux.org/vx.php?id=tidx you get a lot more malware creation tools ! So guys, start creating and adding it to the database please (if that isn’t found before) ;).

Hope I could give you some work :slight_smile: lol. (well actually i hope you wont have any work that it’s already added :D)
Xan

EDIT : Ticket ID: XJO-922934

you are missing the point…

What is your question?
how many % this AV detects?
or
how many % it protects from?

They are not the same question!!!

Melih

you are missing the point...
True, I read it 5 min ago and I saw that I completely missed it :-\. But to answer detection let's say 75%, prevention 90% ;)

Xan

so you want to let in 10% of the malware and don’t care to detect 25% of them?

Let’s say that BoClean and the firewall takes care of 160% of the prevention, so that makes 150% prevention ;). euhm tis makes no sense :(.

  1. I do care about it, otherwise I wouldn’t send tickets (see previous posts) to you.

btw this forum is answered already the ticket isn’t :slight_smile:

Hope I don’t come out to complaining cous that is certainly not the meaning
(L)
Xan

Np Xan :slight_smile:

I understand :slight_smile:

Melih

Are the malware that are created by this tool actually in the database or not Melih?

In Hungary an online pc magazine wrote an article about Pinch. It’s a malware generator. The article writer tested it, and created a malware. Many antivirus program called it “pinch-variant”, and not “exactvirusname.xyz”. Probably the same with other generators.

I read this topic with interest. I did the same anti virus test! 3 times Avira AntiVir popeded-up and 1 time windows defender pop up! I did the test with Mozilla Firefox/ Maybe the results are different with Internet Explorer?

Come On Comodo! You can beat them all :smiley: (B)

hey guys

It’s been a while but I tested the CAVS 2 again. :P0l And it failed some again but caught the most :-TU. I’ve seen in this forums that there was a antivirus sending e-mail but I don’t know where
Anyone any idea?

Xan

And heum Melih (and others)

The virus creation tool, I just created a virus with it and a scanned on-demand the CAVS2 and he didn’t find anything. The post of the creation tool was like a month ago already !
He can be found easily just google : virus creation tool and it’s the first site !

Xan