<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: and I say we are detecting between 400,000 and 10,000,000 malware!</title>
	<atom:link href="http://blogs.mcafee.com/mcafee-labs/2008/06/19/i-say-we-are-detecting-between-400-000-and-10-000-000-malware/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.mcafee.com/mcafee-labs/i-say-we-are-detecting-between-400-000-and-10-000-000-malware</link>
	<description></description>
	<lastBuildDate>Tue, 29 Nov 2011 07:51:20 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Hake Binder</title>
		<link>http://blogs.mcafee.com/mcafee-labs/i-say-we-are-detecting-between-400-000-and-10-000-000-malware/comment-page-1#comment-18024</link>
		<dc:creator>Hake Binder</dc:creator>
		<pubDate>Thu, 26 Jun 2008 12:50:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=675#comment-18024</guid>
		<description>We use McAfee in the Enterprise and our average detection rate this year has been 60% McAfee versus 40% detected using IDS signatures. In the last month that&#039;s down to 35% detection rate for McAfee. To be fair that&#039;s pretty typical of what we&#039;ve seen from all of the vendors but it doesn&#039;t bode well for anyone who deploys antivirus as the solution for malware.</description>
		<content:encoded><![CDATA[<p>We use McAfee in the Enterprise and our average detection rate this year has been 60% McAfee versus 40% detected using IDS signatures. In the last month that&#8217;s down to 35% detection rate for McAfee. To be fair that&#8217;s pretty typical of what we&#8217;ve seen from all of the vendors but it doesn&#8217;t bode well for anyone who deploys antivirus as the solution for malware.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Seyed H. Mohtasebi</title>
		<link>http://blogs.mcafee.com/mcafee-labs/i-say-we-are-detecting-between-400-000-and-10-000-000-malware/comment-page-1#comment-18023</link>
		<dc:creator>Seyed H. Mohtasebi</dc:creator>
		<pubDate>Sun, 22 Jun 2008 10:38:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=675#comment-18023</guid>
		<description>Itâ€™s up to McAfee to decide assign a new name for a new virus or categorize in old virus. All experienced experts know these huge numbers that new anti-virus products declare what means!



But the unacceptable thing is McAfee delay with new threats.



Some days ago I found an unknown virus that copies itself in each folder with the same name as the folder and makes all folders hidden. I submitted it to WebImmune. I expected that WebImmune would respond me after doing some tests. I waited for almost three days but no solution was provided by McAfee. Finally I decided to send an email to McAfee and asked them to provide me a solution or better still an EXTRA.DAT. Their answer that was full of questions that McAfee is supposed to answer me (like why do you suspect this file?) disappointed me. After replying the email and answering all questions, they asked me some log files. I have provided all of them but unfortunately nothing was provided by McAfee. Meanwhile, our network was going done under this new virus. I have traced all other anti-virus reactions for this threat in VirusTotal (www.virustotal.com). For first day there was no anti-virus that can detect this threat. But this number was going up. After almost 10 days finally I could find an EXTRA in WebImmune.



Although, the description of viruses are too old and for many new viruses there isnâ€™t any description on NAI.com.



Many people around the world are proud that they use McAfee products. They believe McAfee is an experienced company in dealing with viruses.



You, your colleagues and also we as customers can improve it.</description>
		<content:encoded><![CDATA[<p>Itâ€™s up to McAfee to decide assign a new name for a new virus or categorize in old virus. All experienced experts know these huge numbers that new anti-virus products declare what means!</p>
<p>But the unacceptable thing is McAfee delay with new threats.</p>
<p>Some days ago I found an unknown virus that copies itself in each folder with the same name as the folder and makes all folders hidden. I submitted it to WebImmune. I expected that WebImmune would respond me after doing some tests. I waited for almost three days but no solution was provided by McAfee. Finally I decided to send an email to McAfee and asked them to provide me a solution or better still an EXTRA.DAT. Their answer that was full of questions that McAfee is supposed to answer me (like why do you suspect this file?) disappointed me. After replying the email and answering all questions, they asked me some log files. I have provided all of them but unfortunately nothing was provided by McAfee. Meanwhile, our network was going done under this new virus. I have traced all other anti-virus reactions for this threat in VirusTotal (www.virustotal.com). For first day there was no anti-virus that can detect this threat. But this number was going up. After almost 10 days finally I could find an EXTRA in WebImmune.</p>
<p>Although, the description of viruses are too old and for many new viruses there isnâ€™t any description on NAI.com.</p>
<p>Many people around the world are proud that they use McAfee products. They believe McAfee is an experienced company in dealing with viruses.</p>
<p>You, your colleagues and also we as customers can improve it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andres</title>
		<link>http://blogs.mcafee.com/mcafee-labs/i-say-we-are-detecting-between-400-000-and-10-000-000-malware/comment-page-1#comment-18022</link>
		<dc:creator>Andres</dc:creator>
		<pubDate>Sun, 22 Jun 2008 03:19:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=675#comment-18022</guid>
		<description>I dont think so... just this year, we find a lot of kind o viruses that McAfee didnt detect, and others like karspersky did.</description>
		<content:encoded><![CDATA[<p>I dont think so&#8230; just this year, we find a lot of kind o viruses that McAfee didnt detect, and others like karspersky did.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Huey Chang</title>
		<link>http://blogs.mcafee.com/mcafee-labs/i-say-we-are-detecting-between-400-000-and-10-000-000-malware/comment-page-1#comment-18021</link>
		<dc:creator>Huey Chang</dc:creator>
		<pubDate>Sat, 21 Jun 2008 00:26:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=675#comment-18021</guid>
		<description>Lots of Chinaâ€™s Trojans cannot be detected.

Add more detections about them.

Analysis and analysis malwares....</description>
		<content:encoded><![CDATA[<p>Lots of Chinaâ€™s Trojans cannot be detected.</p>
<p>Add more detections about them.</p>
<p>Analysis and analysis malwares&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Craig Hughes</title>
		<link>http://blogs.mcafee.com/mcafee-labs/i-say-we-are-detecting-between-400-000-and-10-000-000-malware/comment-page-1#comment-18020</link>
		<dc:creator>Craig Hughes</dc:creator>
		<pubDate>Fri, 20 Jun 2008 17:29:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.labs.com/research/blog/?p=675#comment-18020</guid>
		<description>Wouldn&#039;t it be better to write a security system which prevented the threats which have not yet occurred, rather than those which you already know about?  If there are 760k new samples in a month, how many of those were detected a-priori, that is before the detector was modified to include them?</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t it be better to write a security system which prevented the threats which have not yet occurred, rather than those which you already know about?  If there are 760k new samples in a month, how many of those were detected a-priori, that is before the detector was modified to include them?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

