« ‘Welcome to Bulgaria’ site infected…
Adult Site with wp gets hacked »

How good is MSE?

October 19th, 2009

There have been a lot of talks about Microsoft Security Essentials. A lot of criticism too.

Well, as far as I’m concerned, I find that it beats a lot of the paid AV products.

Take this pretty common Trojan from fastdor.ru/video/preview_tube.mpeg.exe

vt

Well, only a handful of AV vendors are detecting it. A lot of the big guys don’t detect anything at all!

Microsoft picks it up without a problem:

mse

Note that I downloaded this file several times from that site, and the binary constantly changed its MD5. Despite that, MSE continued to detect the file.

MSE’s main install only takes 11 MB out of your hard drive

mseins

While it’s DB remains small as well:

nsedb

There are 2 main files for the full DB. mpasbase.vdm (anti-spyware) and mpavbase.vdm (anti-virus) which are respectively 9 and 29 MB.

What is Microsoft’s secret recipe for being so good? What kind of detection are they using that they can maintain such small Databases? I wanna know ;-)

Jerome Segura

Malware ID: 81d216b763f6de31fd7fa1508c50c03c.zip

    This entry was posted on Monday, October 19th, 2009 at 10:07 am and is filed under Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.