1. Home
  2. Computing & Technology
  3. Antivirus Software
Mary Landesman
Mary's Antivirus Software Blog

By Mary Landesman, About.com Guide to Antivirus Software

Tunnel Vision

Thursday June 12, 2008

My uncle had this uncanny ability to swoop down and pluck a four-leaf clover without ever missing a step. This wasn't an occasional occurance; it happened pretty much every time we took a walk together when I was a child. I asked him once how he was so easily able to see the four-leaf clovers when most of us could only readily see the three-leaf variety. His reply, "What you see in your mind is what you will see in reality". He had 'programmed' himself to only see four-leaf clovers, so he simply never noticed the threes.

The same can be said of security vendors. They only see what their respective technologies have been programmed to see and thus that is what they report on. It's always good to remember this point when evaluating the information outflow, particularly in critical matters such as security.

I was reminded of this important lesson again this week after reading a news report asserting that "Zlob is among the most common type of Trojan downloaded onto Windows machines." The assertion was based on data collected by Microsoft's Malicious Software Removal Tool (MSRT). But the MSRT is only programmed to see 111 (as of today's date) malware families. Yet the number of active malware families in 2006 was 2,232 according to GData. And that number has likely surged significantly in the two years since. In April 2008, F-Secure reported they were logging 25,000 new malware samples per day. It seems rather obvious that if the number of individual malware has increased so dramatically, so have the number of active families. In any event, even at the 2006 figure, the 111 represents only 5% of total active families.

In other words, Zlob is not "among the most common type of Trojan downloaded onto Windows machines". Instead, Zlob is among the most common malware detected by the MSRT, which currently detects only about 5% of active malware families.

Comments
June 25, 2008 at 9:38 pm
(1) Peter Owens says:

This is not just a case of reporting what is seen, it’s a deliberate & ongoing mindset that we will be sold some “spin” rather than provide us with info properly evauated to be worthy of our attention & thus of use in building our understanding.
It is tragic that MS continues to “lead” in such duplicity.
Pretty much the same as we have come to expect from the public pronouncements of our politicians.

July 30, 2008 at 2:54 pm
(2) anon says:

You’d think that Microsoft selects the most prevalent families for inclusion into MSRT.

July 30, 2008 at 3:26 pm
(3) anon2 says:

Perhaps another “spin” is that 5% of malware families are responsible for a majority of malicious installations.

Anyone have stats on which families are most prevalent?

If MSRT is reporting back a set number of malware to target, how does new malware get added to MSRT detection?

Biased, and skewed conjecture.

July 30, 2008 at 3:45 pm
(4) Mary Landesman says:

PN, Speaking of bias, it’s probably best to remember IP addresses get logged. Also good to remember to use the same consistent email alias if trying to spoof something. :-)

I’ll stand by my comments which, as you know, are accurate.

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Explore Antivirus Software
About.com Special Features

Holiday Central

What to eat, where to go, fun things to do and how to save money on the perfect gifts. More >

Family Tech Center

Stay connected and entertained with reviews on tips on the latest HDTVs, cellphones and more. More >

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.