Live data from Hacker News

McAfee quarantines svchost.exe on millions of WinXP machines worldwide

andreyf.tumblr.com

81–90 of 113 posts

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#81
post #72

I don't have time to counter all the misinformation here. Just a couple quick points: - McAfee has been crap for a long time now; they're not much better than Norton's products from the last few years. - Corporate networks are running McAfee because McAfee (and TrendMicro, and other garbage a/v vendors) provide incentives to VARs, consultants, resellers, etc. - However, this is a far cry from "all antivirus is bad".…

"- There are plenty of good products available, some of them are free, ..." Care to list some please? I don't use Windows, but I'm sick of my dad's PC being infected by the "Windows Security" scam application every 4 months. Not to mention the set of other viruses I find when trying to clean it up...

AVG is good

http://free.avg.com/ww-en/free-antivirus-download

ClamAV for windows is ok too:

http://www.clamwin.com/

Hell, just running housecall once in a while manually can do wonders:

http://housecall.trendmicro.com

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#82

Just another nail in the coffin of the usefulness of AV systems. And good riddance. My work computer actually has McAfee on it, which I've disabled through the registry. Don't like how slow it makes my computer. Education, people! It's better than buying useless feel-good software.

I think it's interesting to consider computer viruses and biological pathogens in terms of "optimum harmfulness." A cold virus's best strategy, for example, is to keep you awake coughing so your immune system is weak, make you sneeze and cough and have a runny nose so you spread germs, etc. But it shouldn't kill you, especially not before you pass it on. I've heard (did I read it in Guns, Germs and Steel?) that syphi…

> McAfee has just demonstrated a computer autoimmune disease.

My goodness, what a fascinating idea. (And a search suggests the you are the first person in all of history to think of that.)

When will the biological parallels end? Will we someday get viral transmission of OS code snippets from one machine to another, leading to improved OSs? The mind boggles ....

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#83
post #56

I don't have time to counter all the misinformation here. Just a couple quick points: - McAfee has been crap for a long time now; they're not much better than Norton's products from the last few years. - Corporate networks are running McAfee because McAfee (and TrendMicro, and other garbage a/v vendors) provide incentives to VARs, consultants, resellers, etc. - However, this is a far cry from "all antivirus is bad".…

Speaking as someone who knows something about these things, it is clear that you are not as informed as you are making yourself out to be. There are two reasons why I say that. (1) Your knowledge of the AV industry is outdated. McAfee has actually been trending upwards in recent years. (2) A 97% detection rate is obviously bullshit. If any product achieved a detection rate anywhere close to that number, the false pos…

Not that I'm all that interested in getting into a pissing contest with Some Guy From The Internet, but:

1. I've been doing virus and malware cleanups for people since -- well, since 1995 or so, at least.

2. I've recently begun presenting seminars on basics for novice computer users.

3. I was among the first to clean up the rather nasty kbiwkm rootkit a while back. One of my clients was infected with it before there had been an a/v response, and before anything could be learned about it anywhere.

4. I've recently begun to get contacted internationally (well, from Canadian individuals, anyway) to clean up websites infected with various sorts of nasty bugs.

5. Most importantly, I follow the results and reports from av-comparatives.org religiously; they're not affiliated with any particular antivirus vendor, product, or group, their tests appear to be very thorough, their methods appear to be fairly rigorous, and they provide reasonable results for a number of different metrics related to antivirus products, all in a regularly-released report that's quite readable.

6. I started a company three years ago to address the various flaws that I saw in the I.T. industry, one of which was the number of people that got hit with viruses over and over again. I have a very, very low rate of repeat virus cleanups for my clients, many of whom are novices that are particularly susceptible to multiple computer virus vectors. You might feel like being snarky and saying that I never hear back from them because they don't care for the service, but then again, I'm currently experiencing my third straight year of 300% growth, and most of my "marketing" comes from word-of-mouth.

But, I don't have a blog, so of course I'm not an expert. Carry on.

edit: ohbtw, two of today's systems that were infected with rogue antivirus also had up-to-date and active McAfee installations, which isn't at all unusual. But, yeah, you're right, it's much better now than it used to be.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#84
post #72

I don't have time to counter all the misinformation here. Just a couple quick points: - McAfee has been crap for a long time now; they're not much better than Norton's products from the last few years. - Corporate networks are running McAfee because McAfee (and TrendMicro, and other garbage a/v vendors) provide incentives to VARs, consultants, resellers, etc. - However, this is a far cry from "all antivirus is bad".…

"- There are plenty of good products available, some of them are free, ..." Care to list some please? I don't use Windows, but I'm sick of my dad's PC being infected by the "Windows Security" scam application every 4 months. Not to mention the set of other viruses I find when trying to clean it up...

Microsoft Security Essentials. It's free and it's the fastest and most thorough AV solution.

http://www.cnet.com.au/microsoft-security-essentials-3392988...

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#85
post #53

Earlier quoted context omitted.

But that's totally meaningless! Think of it in another way, at any point in time you have x number of virus that you are likely to come across through whatever means. If all those viruses are in the 0.2%, then the catch rate isn't going to be 99.8% it's going to be 0%. So being able to catch 99.8% of 3 millions viruses when new ones are released all the time is a pointless comparison for efficiency.

20% is totally meaningless as well, but you posted it.

No, he didn't. But that doesn't change his point.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#86

If I were a trader, I'd short McAfee right now. This probably means lots of settlements. EDIT: This could actually be a profitable venture. Somewith with at least basic HN-type knowledge and a daytrading account could make serious money. Finance professionals most probably have no idea how important specific IT news are during the day. One should be able to trade ahead of consensus pretty easily.

Finance professionals most probably have no idea how important specific [fill-in-the-blank] news Yes, they do. There are lots of hedge funds that do nothing but analyze news feeds and trade on them all day long.

...unless their computers are down. :)

Seriously though, although there are plenty of algorithms that crawl news all day and trade accordingly, I still think there is money to be made by watching the news with a financial eye. After reading Google's "A New Approach to China" post (which I saw on HN minutes after it was posted), I specifically remember thinking it would be a good time to go long BIDU. And of course, kicked myself after the stock gained ~15% over the next three days. The market responds fast, but consensus is not always reached immediately.

I think the opportunity exists because events like this are like tiny "black swan" events, the lasting effects of which are not immediately perceptible to most people, let alone a computer algorithm. It's easy to write a script to trade on something like "expected earnings were 3c/share, actual earnings 5c/share" but this is complex information. The ability to put the pieces together and realize what a significant outage this is, why it is significant, why there is not an easy fix, and what most companies will do about it (prolly sue 'em or switch to Symantec) is more than a computer can do.

And I'm sure hedge funds are doing the math right now, trying to estimate the possible damages from lawsuits and how it changes the company's value. But remember, you don't have to beat the fastest hedge funds, you just have to beat most of the market, and you'll still make money. Anyway, it will be interesting to see what happens at market open tomorrow :)

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#87
post #56

I don't have time to counter all the misinformation here. Just a couple quick points: - McAfee has been crap for a long time now; they're not much better than Norton's products from the last few years. - Corporate networks are running McAfee because McAfee (and TrendMicro, and other garbage a/v vendors) provide incentives to VARs, consultants, resellers, etc. - However, this is a far cry from "all antivirus is bad".…

Speaking as someone who knows something about these things, it is clear that you are not as informed as you are making yourself out to be. There are two reasons why I say that. (1) Your knowledge of the AV industry is outdated. McAfee has actually been trending upwards in recent years. (2) A 97% detection rate is obviously bullshit. If any product achieved a detection rate anywhere close to that number, the false pos…

If I'm reading this report right there are several that hit 97% with low false positives. http://www.av-comparatives.org/images/stories/test/ondret/av... The methodology is linked in the document. I mean, it's certainly at least less of a conjecture than your "he doesn't know anything because these things are obviously BS" argument.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#88
post #55

Earlier quoted context omitted.

Wow. Kinda makes me wonder if we should be using general-purpose computers for so many things. The anti-virus is kind of a major single point of failure for machines that need to do just a few specific things.

Best Practices, n.: Making the same mistakes everyone else does. However, what are the odds of someone being able to make special-purpose machines to do everything COTS boxes are used for, and making those machines as fast, cheap, and reliable as COTS systems are now? Some things seem obvious (x-ray machines, lab machines) but accounting and record-keeping? Going back to adding machines and purely manual filing is no…

I think virtualization takes you a long way towards the solution to this issue. With Win7 I've gotten into the habit of routinely working on virtual instances using the boot from .vhd feature. This means that if something goes wrong my host is not impacted and I can revert to an earlier version of my .vhd to solve problems like this one. The standard IT "wait and see" policy makes this something that will take awhile to become common but I think it is the way to go for pretty much any critical path task you do on a Windows PC (other OSes such as OS X have similar features as well but I only use OS X for "media" stuff).

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#89

Earlier quoted context omitted.

I think it's interesting to consider computer viruses and biological pathogens in terms of "optimum harmfulness." A cold virus's best strategy, for example, is to keep you awake coughing so your immune system is weak, make you sneeze and cough and have a runny nose so you spread germs, etc. But it shouldn't kill you, especially not before you pass it on. I've heard (did I read it in Guns, Germs and Steel?) that syphi…

> McAfee has just demonstrated a computer autoimmune disease. My goodness, what a fascinating idea. (And a search suggests the you are the first person in all of history to think of that.) When will the biological parallels end? Will we someday get viral transmission of OS code snippets from one machine to another, leading to improved OSs? The mind boggles ....

Sounds reasonable. Maybe a virus will carry a usable Windows API into *nix so windows viruses can do something? I know this wouldn't work at first glance, but there's probably something along those lines....

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#90

Earlier quoted context omitted.

The last computer virus I got was the stoned virus on a DOS 6.2 machines sometime around 1989-90. And I never run anti-virus software. At home I have Windows, OS X and Linux boxen and not in 20 years have I had a computer virus. It's really all about usage patterns more than anything else.

That's like saying that having sex without a condom is safe as long as you have certain 'usage patterns'. Chances are you have contracted something, but just don't know about it. The OS X and linux boxes are pretty safe, but if you use your windows machines online you're bound to have been bitten by drive by malware at least once. Unless those machines have never been used to surf the web. Even very reputable sites h…

That's like saying that having sex without a condom is safe as long as you have certain 'usage patterns'.

Erm. Sex with one partner who is not promiscuous and doesn't have a disease is pretty safe without a condom. That's a usage pattern, right?

Post reply on HN