Monday, November 15, 2010

Microsoft vs. McAfee: How free antivirus outperformed paid

Ed Bott has experiment
How effective is free antivirus software? Ed Bott had a chance to see a real, in-the-wild example just this month, and the results were, to put it mildly, unexpected. The bottom line? Microsoft’s free antivirus solution found and removed a threat that two well-known paid products missed. Here are the details.
Ed Bott’ve had Microsoft Security Essentials (MSE) installed on my main working PC for most of the past year. Mostly, he use it for real-time protection. He typically disable the scheduled virus scans on PCs and instead occasionally do a manual scan just to confirm that nothing out of the ordinary has snuck through. Last month he decided to perform a scan using the Full option.
MSE had detected several files that it considered malicious. One was a rigged PDF file. The other was a single file in the Java cache folder on this system that contained three separate exploits. Using the information in the MSE history pane, he found the file and uploaded it to Virustotal.com, which is a free service that allows you to scan a suspicious file using 43 separate antivirus engines. The file, identified by a unique hash, had already been analyzed:
Only 17 of 43 antivirus products detected this as a threat. The full results page showed the identification, if any, for each product on the list. Microsoft, Symantec, Avast, and F-Secure were among the engines that flagged the file. But the majority didn’t. That means one of two things. Either the file was a false positive, or he was about to delete something harmless and perhaps even necessary. Or it was real, and most AV programs were missing it.
To get to the bottom of the issue, he sent e-mail messages to contacts at three companies. He asked Microsoft to reanalyze the file and confirm that it was indeed malicious. He also asked McAfee and Sunbelt to look at the file; both of them had reported the file as clean, according to VirusTotal.
Microsoft had two analysts review the file. Here’s a portion of their response:
We have confirmed that the threat detection you received from Microsoft Security Essentials is indeed valid. There were more than 3.5 million reported CVE-2008-5353 attacks in Q3 2010, and Java vulnerability exploitations like these, while once a rare occurrence, have spiked this year. … [T]his exact file is something we have seen in the wild more than 40,000 times in the past six months.
This October 18 post by Holly Stewart on the Microsoft Malware Protection Center blog provides useful additional detail on why these types of attacks can be challenging for IDS/IPS vendors, as well as the steps customers should take to ensure that they are protected.
According to the scan results, this threat was first identified in definition 1.85.1774.0, which was released by Microsoft on July 9, 2010.
McAfee responded quickly to my e-mail as well. A spokesperson sent this reply:
Our Labs team took a look at the file you referenced and it is malicious. We are in the process of developing new heuristics to combat the effects from a stream of recent malicious JAR files more proactively, the file corresponding with the hash you mentioned is in the queue.
Sunbelt’s Malware Response Manager, Dodi Glenn, reported that this file was in the company’s repository and submitted it for detailed analysis. Here are the results:
This file contains a malicious java.class … that exploits the CVE-2008-5353 vulnerability. … We are currently testing our updated detection for this exploit and expect to release it shortly.
The good news is that my system wasn’t compromised in any way. The exploit in question was blocked by a Java update that I had installed last year. Likewise, the booby-trapped PDF file (which all of the antivirus programs detected) relied on the user having a very outdated version of Adobe Reader installed, and mine was fully up-to-date.
Last week, when I wrote about Microsoft’s decision to expand its distribution of Microsoft Security Essentials via Microsoft Update, McAfee complained that free software simply isn’t as good as its paid protection. Here’s what a spokesperson told me:
McAfee wants consumers to be safe online. Options that provide an elementary level of security are free products including Microsoft Security Essentials, however these mostly rely on traditional protection mechanisms. McAfee products offer not only more features but most importantly, McAfee products offer real-time protection using cloud-based Global Threat Intelligence to combat even the most sophisticated threats thus ensuring complete protection and peace of mind.
In this case, at least, that protection wasn’t as complete as the free Microsoft product it was comparing itself to.
As an aside, it’s worth noting that criticizing Microsoft Security Essentials because it’s free misses an important point. MSE uses the same scanning engine and definitions as its enterprise-grade Forefront product, which is most assuredly not free.
One certainly shouldn’t draw definitive conclusions from a single anecdotal example, but as this case shows, the gap between antivirus products isn’t as simple as free versus paid, and even the best and brightest researchers can miss a threat.

Resource:http://www.zdnet.com/blog/bott/microsoft-vs-mcafee-how-free-antivirus-outperformed-paid/2614

Monday, October 18, 2010

McAfee Launches Digital Information Security Initiative

McAfee announced it has unveiled its "Security Connected" initiative, enabling partners, developers and customers to apply a sustainable approach to securing digital information.
McAfee has announced the first two of four new connected security platforms.
1. McAfee Endpoint Security 9
2. McAfee Security Management 5


Security often is being driven from different silos within businesses, from mobile devices, PCs, and tablets, to mission-critical networks, hosted applications, servers, cloud services, virtual machines, and databases, bringing dozens or hundreds of different security technologies and disparate management paradigms with them.

McAfee said its Security Connected components include: -Proactive security through built-in integration and intelligence -Global Threat Intelligence: Threat research and content capability to deliver predictive threat analysis, reputational scoring, cloud delivery and intelligence in depth to power connected security technologies.

-Broad portfolio of countermeasures: Integrated security for PCs, Mac, smartphones, tablets, storage, embedded, silicon, network perimeter, datacenter, web gateways, mail security, content, and so on with a choice of on premise, SaaS, or hybrid delivery models.

-McAfee Connected: program is aimed at helping partners worldwide ensure product and service compatibility with McAfee solutions. The program's testing process ensures that the third-party hardware, software and services that customers choose perform well, and are compatible with, McAfee technology.

Monday, October 4, 2010

How to Remove Antimalware Doctor Virus ?

End Infected Processes

Step 1

Press "Ctrl" + "Alt" + "Delete."

Step 2

Click on the "Task Manager."

Step 3

Click on the "Processes" tab.

Step 4

Right click on "Antimalware Doctor.exe," and select "End Process."

Delete Infected Registry Values

Step 1

Click on the "Start" menu.

Step 2

Click on "Run."

Step 3

Type "regedit" (without the quotation marks) and click "OK." The Registry Editor will open.

Step 4

Locate the following registry values in the left pane of the Registry Editor and delete them. To delete a registry value, right click on it and select "Delete."

"HKEY_CURRENT_USER\Software\Antimalware Doctor Inc\Antimalware Doctor"
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor"
"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run Antimalware Doctor.exe"

Delete Infected Files

Step 1

Click on the "Start" menu.

Step 2

Click on "Search Files and Folders."

Step 3

Search for and delete the following files. To delete a file, right click on it and select "Delete."

"enemies-names.txt"
"Antimalware Doctor.exe"

Sunday, September 19, 2010

Trend Micro Titanium Maximum Security 2011

Trend Micro's Titanium initiative aims to offers consumers maximum security with minimal aggravation. When you download Trend Micro Titanium Maximum Security 2011you immediately how different it looks from the 2010 model.
Features:
SPAM-BLOCKER
Detects and blocks annoying and dangerous junk email and image spams. The real-time spam detection provides immediate protection from outbreaks.

REAL-TIME UPDATES
Safeguard your computer from the latest on-line threats today and in the future. Titanium Maximum Security leverages Trend Micro%27s Smart Protection NetworkT plus real-time antivirus scanning to provide always-on-guard protection keeping you safe from latest, ever-evolving malware threats.

PARENTAL CONTROLS
Protect your children from inappropriate websites, limit their time on the Internet, and see detailed reports about what they do online, without having to look over their shoulders.

DATA THEFT PREVENTION
Prevent hackers and spyware from stealing credit card numbers, passwords, email addresses, and other sensitive data.


TREND MICRO VAULT
A password protected folder that can safeguard your sensitive files. If your computer is lost or stolen, you can remotely lock this vault to keep these files safe.

SECURE ERASE
Deleting a file just removes the directory information used to find it, but not the actual data. Secure Erase overwrites deleted files with random data, so that the contents can%27t be retrieved.

SYSTEM TUNER
Recover disk space, make Microsoft Windows start faster, clean out your instant messaging history, and optimise your computer%27s performance. Schedule automatic tune-ups to keep your PC running smoothly.

LIGHT ON SYSTEM RESOURCES
Titanium is powered by Trend MicroT Smart Protection NetworkT which gathers and analyses threat data, blocking viruses and other malware BEFORE they can reach your PC. Because the processing is done "in the cloud", Titanium uses less of your PC%27s memory and disk space, so it won%27t slow you down.

DETAILED SECURITY REPORTS
Easy to read graphic reports provide you with all the details about the threats that attack your computer. You can drill down into detailed logs with just one click.

FREE TOOLS
The Titanium Maximum Tool Centre displays a page of shortcuts so you can easily access and manage features such as Parental Controls, System Tuner, Secure Erase and more. From the Tool Center you can turn features ON or OFF for a solution tailored to your individual internet security needs.

Wednesday, September 8, 2010

Norton Releases 2011 Security Products


Norton announced its 2011 versions of its Norton Internet Security suite and Norton Antivirus software, a new application--Norton Power Eraser--that is produced to remove the increasingly common fake antivirus malware.
New features for Norton's 2011 product lineup include new "reputation-based" detection technology, bolstered behavioral malware detection (detecting malware based on how it acts on your PC), and new system performance monitoring tools.
Norton Power Eraser is a new freebie tool designed to identify so-called fake antivirus malware--malware that looks like garden variety antivirus software and tried to coerce you into paying for "full" versions of the software that do nothing at all.
Another new tool is Norton's Bootable Recovery Tool, a tool of last resort for when your PC is so hosed by malware that it won't start up, or your antivirus software won't even work properly. The Bootable Recovery Tool is a free download, but you need to enter a Norton product key in order to use it.
As for detection, the company declares that the new Norton products lead the security pack. We'll be the final judge of that, though, when we have a chance to thoroughly test the new Norton products. To see how Norton Internet Security 2010 performed, be sure to check out our review from earlier this year.
The new Norton products are available for purchase now from Norton.com; Norton Internet Security 2011 costs $70 (for use on 3 PCs), and Norton Antivirus 2010 costs $40.

Wednesday, July 14, 2010

Kaspersky Lab welcomes greater online Facebook protection

Kaspersky Lab has welcomed latest moves by Facebook and CEOP (the Child Exploitation and Online Protection Service) to provide users of the social networking site a panic button app.
The app, which is designed to protect children who use the Facebook social networking site, is a good move says the IT security vendor, but there needs to be more education and vigilance in order to keep young people safe online.

Ram Herkanaidu, a member of Kaspersky's global research and analysis team, says that having a panic button is an important step, but it needs to be part of a wider education for both adults and children on how to keep them safe online. "It can be difficult for anyone, child or teenager, to know who online strangers really are, so it is important to understand the techniques used to attract young people and how to combat them", he said.

Against this backdrop, Kaspersky suggests all online users have a good internet security suite installed on their computer, with parental controls that can monitor youngsters' social networking interactions. And, says the IT security vendor, if need be, users should block messaging to certain users, as well as confidential information like the home address, phone numbers and other sensitive private data.

Parents, says Kaspersky, should always be attentive of how much your children use the internet and to whom they are speaking to and when. And parents, the IT security firm adds, should always investigate any new contacts, if they approach your child first.
Finally, says Herkanaidu, if your internet security has parental controls, you should make full use of them to examine your children's online activity and stop them from being groomed into giving personal information that could potentially put them in danger. Social networking websites, he says, are a modern cultural phenomenon. Facebook alone, for example, currently has over 300 million active users, 150 million of which log-on at least once a day

Monday, July 5, 2010

Kaspersky Lab Predicts Malware Epidemics

Kaspersky Lab, a leading developer of secure content management solutions, has successfully patented technology in the USA that allocates the potential scale of malware epidemics to be accurately predicted in order to prevent them from spreading.
"The patented technology works by examining statistical data about threats received from a global monitoring network.
Emerging epidemics can be recognized by the number of incidents occurring during a specific period in one location or another. It makes it possible to pinpoint the source of an epidemic and forecast its likely propagation pattern.
Protective measures can then be implemented by countries in the path of the epidemic. This slows the proliferation rate considerably and offers effective damage limitation, according to chief intellectual property counsel Kaspersky Lab.
The technology has a number of advantages over other similar systems, including the ability to trace the source of the threat, generate protective measure and simulate the spread of an epidemic, she said.
Today's malware has the capacity to spread in millions of computers infected in an instant as an epidemic sweeps across the Internet. This can take down huge swathes of infrastructure, bringing information highways to a standstill and leaving systems vulnerable to data leakage which in turn opens the door to large scale fraud. Detecting malware on computer that is infected during an epidemic has little or no effect. What is needed is a reliable method for estimating the potential scale and direction of an epidemic, an early warning system, and that is exactly what the new technology developed by Kaspersky Lab's Yury Mashevsky, Yury Namestnikov, Nikolay Denishchenko and Pavel Zelensky, is capable of doing. The technology was granted Patent No. 7743419 by the US Patent and Trademark Office on 22 June, 2010.
Kaspersky Lab currently has more than 50 patent applications pending in the USA, Russia, China and Europe. These relate to a unique information security technologies developed by the Company's personnel.