Home · Maps · About

Home > OTChat

[ Post a New Response | Return to the Index ]

(942844)

view threaded

Tech stuff: anyone here using Avira Antivirus?

Posted by Chris R16/R2730 on Fri May 18 17:14:26 2012

fiogf49gjkf0d
What a disaster, and here's how you can salvage your PC:

http://www.pcmag.com/article2/0,2817,2404483,00.asp



Post a New Response

(942869)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Fri May 18 18:37:25 2012, in response to Tech stuff: anyone here using Avira Antivirus?, posted by Chris R16/R2730 on Fri May 18 17:14:26 2012.

fiogf49gjkf0d
Every AV company has done that, and to the same degree. Since so many viruses embed themselves into system files, often the lab guys make the mistake of generating their signature from the wrong part of the file, causing a match with legitimate parts of the sample. Whoops! :)

Where they fell down is failing to TEST their new definitions before shipping them. This is what always happens when there's too much pressure on the labs to get out the defs before they're properly cooked.

I am *so* glad that I no longer need windows or fruits. :)

Post a New Response

(942870)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by Chris R16/R2730 on Fri May 18 18:39:51 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Fri May 18 18:37:25 2012.

fiogf49gjkf0d
I honestly thought my PC was fried, because it froze whenever Avira attempted to activate. Every file scanned led to disaster. I was able to boot in safe mode, do a restore and remove the malicious update. Problem solved.

Post a New Response

(942873)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Fri May 18 19:05:49 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by Chris R16/R2730 on Fri May 18 18:39:51 2012.

fiogf49gjkf0d
Ah ... this happens all the time with AV's ... and for a few weeks afterward they actually check their signature updates before shipping. Then they stop, rinse, repeat. :(

But as bad as this one was for Avira, Symantec still holds the record for maximum destruction and frequency. :)

Chinese analysts aren't the best, same for Romanian analysts. When I was with COMODO, got to see what a piss poor job they did but I wasn't allowed to tell them how to be more careful. Throughput is more important than accuracy which is why this happens. :(

Post a New Response

(942874)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by Chris R16/R2730 on Fri May 18 19:06:35 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Fri May 18 19:05:49 2012.

fiogf49gjkf0d
I'm gonna do manual updates for a while.

Post a New Response

(942876)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Fri May 18 19:25:12 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by Chris R16/R2730 on Fri May 18 19:06:35 2012.

fiogf49gjkf0d
You'll end up with the same results if there's a bad signature in the database. What happens here is that instead of selecting a unique bit of code from the virus sample, they mistakenly code up part of the compiler's code that will match numerous programs that compiler generates. In other words, the signature matches a key part of many files. Each gets nailed on the match. That's what happened here.

I'd say you're safe on autoupdate for a while now while their asses are still sore. The next event will be when management insists on greater "productivity" and that's when the shortcuts will be back in effect that cause this. Determining a proper signature for a virus sometimes is fast and easy and obvious, other times it takes a lot of work (and time) to identify it.

It's comparable to surgery. Sometimes all you need to do is stab it and it's gone, other times you have to carefully cut around brain cells. Management types that fail to understand this will force the surgeons to use a hatchet. That's what happened here and happens often with antivirus labs. It wasn't just the undetected viruses that romp for years that caused me to do KNOS, it was also THIS. :(

Post a New Response

(942883)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by Chris R16/R2730 on Fri May 18 19:43:33 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Fri May 18 19:25:12 2012.

fiogf49gjkf0d
Yes, but it an update is reported as bad before I update, I don't have to deal with the problem at all.

Post a New Response

(942888)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by cortelyounext on Fri May 18 19:49:11 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Fri May 18 19:25:12 2012.

fiogf49gjkf0d
What happens here is that instead of selecting a unique bit of code from the virus sample, they mistakenly code up part of the compiler's code that will match numerous programs that compiler generates. In other words, the signature matches a key part of many files.

Exactly.

Post a New Response

(942889)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Fri May 18 19:49:49 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by Chris R16/R2730 on Fri May 18 19:43:33 2012.

fiogf49gjkf0d
Good point. But having seen so many AV companies do this, once they drop the bomb they're afraid of their own shadow for a while. But yes, that's a prudent thing to do no matter what AV you're using. Downside though is that anything that isn't already in the definitions database won't be detected. So either way, it's really up to the AV company to ALWAYS test their shit before letting it escape. I'd pitch a bitch at them over it anyway - the more bitchslapping they get, the longer management won't try to push the labs to get it out regardless ...

Post a New Response

(942890)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by Chris R16/R2730 on Fri May 18 19:50:34 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by cortelyounext on Fri May 18 19:49:11 2012.

fiogf49gjkf0d
Avira is known for being oversensitive and indicating false positives. I just deal with it.

Post a New Response

(942892)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by cortelyounext on Fri May 18 19:50:52 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by cortelyounext on Fri May 18 19:49:11 2012.

fiogf49gjkf0d
I will be posting in the Old Music for the Soul thread momentarily. Please standby...

Post a New Response

(942897)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Fri May 18 19:57:26 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by Chris R16/R2730 on Fri May 18 19:50:34 2012.

fiogf49gjkf0d
And again, that comes down to very poor lab work and not taking the time to find a propr unique for a signature. It's not all that hard to do quality detections, but it does take a little bit of time to choose the right one. :(

Post a New Response

(942898)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by Chris R16/R2730 on Fri May 18 19:58:24 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Fri May 18 19:49:49 2012.

fiogf49gjkf0d
Given that I use the free versions of all my AV programs (Ad-Aware, Avira, MWB) I think I do fine. I have not had a "visible" infection in 2.5 years.

Post a New Response

(942902)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Fri May 18 20:01:10 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by cortelyounext on Fri May 18 19:50:52 2012.

fiogf49gjkf0d


Post a New Response

(942905)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Fri May 18 20:05:11 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by Chris R16/R2730 on Fri May 18 19:58:24 2012.

fiogf49gjkf0d
Thought you got nailed more recently. Maybe it was the other Chris.

"Free" was one of the biggest mistakes the industry ever made - no offense there ... but many programs can be given away for free, no problem. Once you create them, you're done and can move on. Programs that require serious maintenance like operating systems and security software where you have to maintain it every day cost a fuckload of money.

The "competition" in the security industry completely emaciated the revenue required to do the job properly. That's why you have what passes for labs these days with heavily underpaid and overworked entry level types who make these kind of mistakes. :(

Post a New Response

(942977)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by Henry R32 #3730 on Sat May 19 02:03:25 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Fri May 18 18:37:25 2012.

fiogf49gjkf0d
Yup, happened with our virus scanner on our Linux servers... it up and decided all of the Windows binaries (like syslinux.exe) were a virus for a couple of days. As a result, we changed the scan so that it warns only (and emails us the number of found bad files so we can check the logs...).

Post a New Response

(942978)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by Henry R32 #3730 on Sat May 19 02:05:50 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by Chris R16/R2730 on Fri May 18 19:58:24 2012.

fiogf49gjkf0d
I'm not sure if Avira has the option but you could allow it to auto-update but disallow it from auto-quarantine/clean/whatever... Symantec and McAfee allow this and at least with the former, you can ignore the window pretty easily.

Post a New Response

(942979)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Sat May 19 02:07:36 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by Henry R32 #3730 on Sat May 19 02:03:25 2012.

fiogf49gjkf0d
Heh. Been there, done that. :)

Post a New Response

(942980)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Sat May 19 02:08:20 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by Henry R32 #3730 on Sat May 19 02:05:50 2012.

fiogf49gjkf0d
The "free" versions are rather limited. And Avira goes off like fire alarms in dorms. :)

Post a New Response

(942991)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by G1Ravage on Sat May 19 03:28:16 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Fri May 18 18:37:25 2012.

fiogf49gjkf0d
The Internet now scares me. I'm burning my computer.

Post a New Response

(942994)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Sat May 19 03:44:08 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by G1Ravage on Sat May 19 03:28:16 2012.

fiogf49gjkf0d
Nah ... burn a KNOS DVD ... you won't need any of that crap any longer. You can just surf and nobody will know that you don't forgive, don't forget and will forget to expect you. :)

Post a New Response

(943105)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by orange blossom special on Sat May 19 17:01:22 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Fri May 18 18:37:25 2012.

fiogf49gjkf0d
I forget the AV that killed the VAIO sitting on the floor. And now I don't know what happened to the HD as I can no longer even try to install various OS's on it. I wanted to try win8 on that thing, but now it's completely unsalvagable.

Post a New Response

(943128)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Sat May 19 18:46:24 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by orange blossom special on Sat May 19 17:01:22 2012.

fiogf49gjkf0d
SONY always shipped McAfee as part of the install. Do you hear that drive even trying to spin up when you apply power? Unless it's not twirling, you can usually bring them back.

Post a New Response

(943308)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by orange blossom special on Sun May 20 17:23:30 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Sat May 19 18:46:24 2012.

fiogf49gjkf0d
Not sure, last i messed with it, it would pretend the drive was there, then it didn't. I formatted and right after it likes to tell me the HD doesn't even exist anymore.

Post a New Response

(943328)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by SelkirkTMO on Sun May 20 18:09:37 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by orange blossom special on Sun May 20 17:23:30 2012.

fiogf49gjkf0d
Fire it up one of these days ... give me some specific messages if you want to bring it back from the dead ...

Post a New Response

(944881)

view threaded

Re: Tech stuff: anyone here using Avira Antivirus?

Posted by Dan Lawrence on Sun May 27 09:59:13 2012, in response to Re: Tech stuff: anyone here using Avira Antivirus?, posted by SelkirkTMO on Sun May 20 18:09:37 2012.

fiogf49gjkf0d
How do you feel about Bitdefender Antivirus Plus? My wife is looking at it to replace McAfee.

Post a New Response


[ Return to the Message Index ]