Author Topic: Want to improve detection?  (Read 15748 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Want to improve detection?
« on: June 03, 2006, 04:33:19 PM »
Just a suggestion to improve detection...
Use a P2P program and download *stuffs* like keygens, cracks, keymakers... etc.
If avast does not detect them, run Ewido and see what you're missing  8)
The best things in life are free.

JerryM

  • Guest
Re: Want to improve detection?
« Reply #1 on: June 04, 2006, 01:59:09 AM »
I accept that Ewido and Avast together really improve detection.  That is the reason I have Ewido, and the reason I removed another good AV whose Support folks insisted I remove Ewido.
I conclude that Ewido plus Avast is better than X without an AT.

I think I will just forego the further tests of bad sites. ;D

Jerry

justin1278

  • Guest
Re: Want to improve detection?
« Reply #2 on: June 04, 2006, 02:24:57 AM »
Hi,

That is what I do to get virus samples and test them, because this is the way some of the newer viruses go around (of course I don't use the keygens). Also Melih and myself may be setting up a "honeypot" to help obtain samples of newer viruses.

JerryM

  • Guest
Re: Want to improve detection?
« Reply #3 on: June 04, 2006, 02:35:01 AM »
Just a suggestion to improve detection...
Use a P2P program and download *stuffs* like keygens, cracks, keymakers... etc.
If avast does not detect them, run Ewido and see what you're missing  8)

What is a "crack?" I have seen it mentioned, but have no idea what it means.

Thanks,
Jerry

justin1278

  • Guest
Re: Want to improve detection?
« Reply #4 on: June 04, 2006, 03:17:30 AM »
It is a fake product key for a program (i.e. the one you recieve for purchasing avast! Professional Edition) that will activate the program.

JerryM

  • Guest
Re: Want to improve detection?
« Reply #5 on: June 04, 2006, 03:33:29 AM »
It is a fake product key for a program (i.e. the one you recieve for purchasing avast! Professional Edition) that will activate the program.

Thanks, Justin. Now I know.

Jerry

JerryM

  • Guest
Re: Want to improve detection?
« Reply #6 on: June 04, 2006, 03:39:06 AM »
I wish there were tests that tested AVs with and without a AT application also running in real time.
I realize this tests the system instead of the AV, but the overall security is what I am most interested in.

Firefighter ran some tests in 04 that did such. It was enlightening to me, and showed the value of layering.
FWIW, here is the thread on Wilders.
http://www.wilderssecurity.com/showthread.php?t=58597

If you follow the thread to posts 17 and 19, and then compare with post 1 it is obvious that the addition of a good anti-trojan provides much more protection.

Jerry

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Want to improve detection?
« Reply #7 on: June 04, 2006, 07:51:20 PM »
A crack is actually an executable  file which when run defeats the registration process in a commercial program so that it will work without buying it. This is different from a key, which is simply an alpha-numeric code which will activate a program, and is normally sent to a legitimate purchaser in an email. Illegally copied or generated keys may be found on crack sites, but they are not dangerous like cracks, which are often Trojan horses.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Kunio

  • Guest
Re: Want to improve detection?
« Reply #8 on: June 06, 2006, 07:13:38 AM »
Yes. This is only the thing I don’t like about avast. Their virus detection is not "first come first serve" that makes virus submission is not a fun thing to do..

justin1278

  • Guest
Re: Want to improve detection?
« Reply #9 on: June 06, 2006, 07:16:41 AM »
Hi,

A lot of keygens have viruses inside. I have found most with trojans but a few of the really nasty ones with worms  :-\.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Want to improve detection?
« Reply #10 on: June 06, 2006, 10:07:13 AM »
Maybe they should start at adding virus definitions more often ::)
4 days since the last signature update and still nothing. Khm. WHy don't we wait for whole week? This thing still bothers me a lot. Other AVs add loads of signatures daily and avast! adds just some in few days here and there.
You don't make good detection this way...
Visit my webpage Angry Sheep Blog

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: Want to improve detection?
« Reply #11 on: June 06, 2006, 10:31:21 AM »
Quote
4 days since the last signature update and still nothing

Huh?

My last update 0623-0 was June 5th 2006.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Want to improve detection?
« Reply #12 on: June 06, 2006, 10:40:12 AM »
Probably just false positives fix as it's not listed on VPS history page...
Visit my webpage Angry Sheep Blog

TAP

  • Guest
Re: Want to improve detection?
« Reply #13 on: June 06, 2006, 11:08:02 AM »
I sent a malware sample to avast!, AVG, AntiVir and some other AV's on Saturday (6/3/06) and AVG updated and caught it on Monday (6/5/06), I've noticed that AVG is quite fast to adding new/non-urgent malware so I don't surprise if people say AVG find some malware that other AV's don't.
« Last Edit: June 06, 2006, 11:12:10 AM by TAP »

Offline alanrf

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3870
  • Just an avast user
Re: Want to improve detection?
« Reply #14 on: June 06, 2006, 11:22:17 AM »
Quote
Probably just false positives fix as it's not listed on VPS history page...

I guess we'll see ... I certainly hope that they give more priority to getting the VPS file up to date and delivered than updating the history file.