<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Malware Research Group</title>
	<atom:link href="http://malwareresearchgroup.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwareresearchgroup.com</link>
	<description></description>
	<lastBuildDate>Thu, 09 Sep 2010 09:08:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>Comment on List of participants in our Facebook Security Test by Avira</title>
		<link>http://malwareresearchgroup.com/2010/09/list-of-participants-in-our-facebook-security-te/comment-page-1/#comment-59</link>
		<dc:creator>Avira</dc:creator>
		<pubDate>Thu, 09 Sep 2010 09:08:53 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=1920#comment-59</guid>
		<description>When test will be published?</description>
		<content:encoded><![CDATA[<p>When test will be published?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on List of participants in our Facebook Security Test by Chris</title>
		<link>http://malwareresearchgroup.com/2010/09/list-of-participants-in-our-facebook-security-te/comment-page-1/#comment-58</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 07 Sep 2010 12:39:51 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=1920#comment-58</guid>
		<description>&lt;blockquote cite=&quot;#commentbody-55&quot;&gt;
&lt;strong&gt;&lt;a href=&quot;#comment-55&quot; rel=&quot;nofollow&quot;&gt;Woodrowbone&lt;/a&gt; :&lt;/strong&gt;&lt;P&gt;Any chance that Immunet who market their product as an “Community Antivirus” will be included? Seems like the perfect test for them.&lt;/P&gt;
&lt;P&gt;Peace&lt;/P&gt;
&lt;P&gt;/W&lt;/P&gt;&lt;/blockquote&gt;
Hi, we wont be including Immunet in this test, but, will include it in one shortly.</description>
		<content:encoded><![CDATA[<blockquote cite="#commentbody-55"><p>
<strong><a href="#comment-55" rel="nofollow">Woodrowbone</a> :</strong>
<p>Any chance that Immunet who market their product as an “Community Antivirus” will be included? Seems like the perfect test for them.</p>
<p>Peace</p>
<p>/W</p>
</blockquote>
<p>Hi, we wont be including Immunet in this test, but, will include it in one shortly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on List of participants in our Facebook Security Test by Sveta</title>
		<link>http://malwareresearchgroup.com/2010/09/list-of-participants-in-our-facebook-security-te/comment-page-1/#comment-57</link>
		<dc:creator>Sveta</dc:creator>
		<pubDate>Tue, 07 Sep 2010 12:24:47 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=1920#comment-57</guid>
		<description>&lt;blockquote cite=&quot;#commentbody-56&quot;&gt;
&lt;strong&gt;&lt;a href=&quot;#comment-56&quot; rel=&quot;nofollow&quot;&gt;Frank&lt;/a&gt; :&lt;/strong&gt;
          &lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;Why do you play usually down Comodo Internet Security??? I think it must be role in this test.&lt;/p&gt;
         &lt;/blockquote&gt;

Comodo Internet Security or its creators are not yet ready to be included into any kind of group testing.</description>
		<content:encoded><![CDATA[<blockquote cite="#commentbody-56"><p>
<strong><a href="#comment-56" rel="nofollow">Frank</a> :</strong></p>
<p>Hello,</p>
<p>Why do you play usually down Comodo Internet Security??? I think it must be role in this test.</p>
</blockquote>
<p>Comodo Internet Security or its creators are not yet ready to be included into any kind of group testing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on List of participants in our Facebook Security Test by Frank</title>
		<link>http://malwareresearchgroup.com/2010/09/list-of-participants-in-our-facebook-security-te/comment-page-1/#comment-56</link>
		<dc:creator>Frank</dc:creator>
		<pubDate>Tue, 07 Sep 2010 11:01:42 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=1920#comment-56</guid>
		<description>Hello,

Why do you play usually down Comodo Internet Security??? I think it must be role in this test.</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>Why do you play usually down Comodo Internet Security??? I think it must be role in this test.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on List of participants in our Facebook Security Test by Woodrowbone</title>
		<link>http://malwareresearchgroup.com/2010/09/list-of-participants-in-our-facebook-security-te/comment-page-1/#comment-55</link>
		<dc:creator>Woodrowbone</dc:creator>
		<pubDate>Tue, 07 Sep 2010 09:55:50 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=1920#comment-55</guid>
		<description>Any chance that Immunet who market their product as an &quot;Community Antivirus&quot; will be included? Seems like the perfect test for them.

Peace

/W</description>
		<content:encoded><![CDATA[<p>Any chance that Immunet who market their product as an &#8220;Community Antivirus&#8221; will be included? Seems like the perfect test for them.</p>
<p>Peace</p>
<p>/W</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Good Passwords, Safer Accounts by sethtp</title>
		<link>http://malwareresearchgroup.com/2010/08/good-passwords-safer-accounts/comment-page-1/#comment-54</link>
		<dc:creator>sethtp</dc:creator>
		<pubDate>Wed, 01 Sep 2010 06:35:09 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=1842#comment-54</guid>
		<description>How do you remember that password?
I hear some people use a sentence and replace letters with symbols and numbers.
1H@\/3n&#039;tB33nT0Th3D0c+0rL@+3ly
iHaventBeenToTheDoctorLately
Or something similar.</description>
		<content:encoded><![CDATA[<p>How do you remember that password?<br />
I hear some people use a sentence and replace letters with symbols and numbers.<br />
1H@\/3n&#8217;tB33nT0Th3D0c+0rL@+3ly<br />
iHaventBeenToTheDoctorLately<br />
Or something similar.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Malwarebytes&#8217; Anti-Malware 1.45 Vs. Early Life Malware by dallas7</title>
		<link>http://malwareresearchgroup.com/2010/03/joined-sun-aug-02-2009-505-pm-posts-348-location-serbia-user-flagged-no-flag-delete-post-information-report-this-post-edit-post-reply-with-quote-malwarebytes-anti-malware-1-45-vs-earl/comment-page-1/#comment-53</link>
		<dc:creator>dallas7</dc:creator>
		<pubDate>Sun, 22 Aug 2010 17:23:11 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?p=1471#comment-53</guid>
		<description>It should be noted Shuriken heuristics is solely dependent on code within the rules.ref database file.  This code was not implemented until August 4, 2010 with database version 4390.  So, even though the heuristics option was &quot;enabled&quot; for this test, in fact no heuristics were in effect.

The Shuriken heuristics announced with the release of v1.45 on March 29 took almost 20 weeks to be implemented in v1.46.  The ability to toggle the option in the UI settings not only hoodwinked users and reviewers but even Malwarebytes&#039; &quot;Forum Deity&quot; experts.   There was never any news or progress reports as to the status of Shuriken.  Indeed, as of this August 22 writing, their Web site &quot;Latest News&quot; and the application&#039;s own &quot;Latest News&quot; both read... &quot;April 29, version 1.46 released.&quot;  Inquiries by paying customers directed at their forum were answered with unmoderated and unchallenged guesses, misinformation or blatant fabrication. 

Since the rules.ref file is updated several times a day, there is no way for the user to determine if the heuristics code is present for any given database number.  Regardless of the enabled status of the UI setting, Malwarebytes can turn it off or on at will.  For the users of the free on-demand version, who cares?  But the customers who paid for the protection module and who place faith in the real-time heuristics deserve better. 

Clearly, the UI setting mislead countless users and customers to think they were getting heuristics while the corporate diplomacy was, &quot;Let them think so.&quot;  This, of course, is from the same company that levied charges of deception at IObit - charges that never met with any peer review.</description>
		<content:encoded><![CDATA[<p>It should be noted Shuriken heuristics is solely dependent on code within the rules.ref database file.  This code was not implemented until August 4, 2010 with database version 4390.  So, even though the heuristics option was &#8220;enabled&#8221; for this test, in fact no heuristics were in effect.</p>
<p>The Shuriken heuristics announced with the release of v1.45 on March 29 took almost 20 weeks to be implemented in v1.46.  The ability to toggle the option in the UI settings not only hoodwinked users and reviewers but even Malwarebytes&#8217; &#8220;Forum Deity&#8221; experts.   There was never any news or progress reports as to the status of Shuriken.  Indeed, as of this August 22 writing, their Web site &#8220;Latest News&#8221; and the application&#8217;s own &#8220;Latest News&#8221; both read&#8230; &#8220;April 29, version 1.46 released.&#8221;  Inquiries by paying customers directed at their forum were answered with unmoderated and unchallenged guesses, misinformation or blatant fabrication. </p>
<p>Since the rules.ref file is updated several times a day, there is no way for the user to determine if the heuristics code is present for any given database number.  Regardless of the enabled status of the UI setting, Malwarebytes can turn it off or on at will.  For the users of the free on-demand version, who cares?  But the customers who paid for the protection module and who place faith in the real-time heuristics deserve better. </p>
<p>Clearly, the UI setting mislead countless users and customers to think they were getting heuristics while the corporate diplomacy was, &#8220;Let them think so.&#8221;  This, of course, is from the same company that levied charges of deception at IObit &#8211; charges that never met with any peer review.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MRG Tests by Igsloth</title>
		<link>http://malwareresearchgroup.com/malware-tests/comment-page-1/#comment-51</link>
		<dc:creator>Igsloth</dc:creator>
		<pubDate>Sun, 27 Jun 2010 11:18:58 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?page_id=139#comment-51</guid>
		<description>Great tests.

Please test [new] Free Anti Keylogger Keystroke Interference 1.4 if you can.

http://download.cnet.com/Free-Anti-Keylogger-Keystroke-Interference/3000-2144_4-75211735.html</description>
		<content:encoded><![CDATA[<p>Great tests.</p>
<p>Please test [new] Free Anti Keylogger Keystroke Interference 1.4 if you can.</p>
<p><a href="http://download.cnet.com/Free-Anti-Keylogger-Keystroke-Interference/3000-2144_4-75211735.html" rel="nofollow">http://download.cnet.com/Free-Anti-Keylogger-Keystroke-Interference/3000-2144_4-75211735.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MRG Tests by ssj100</title>
		<link>http://malwareresearchgroup.com/malware-tests/comment-page-1/#comment-50</link>
		<dc:creator>ssj100</dc:creator>
		<pubDate>Fri, 25 Jun 2010 11:01:27 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?page_id=139#comment-50</guid>
		<description>You write:
&quot;...real financial malware commonly, will NOT use the same exploit/vector as a simulator...
...An application blocking these simulated attacks does NOT necessarily mean it will be effective against REAL malware.&quot;

I&#039;ve highlighted the key words in capitals.  Unfortuntately, this test doesn&#039;t really prove anything.  Fact is, most (clever) zero day malware will be released after testing against anti-logging mechanims.  And they will NOT be blocked.  Right?

Hence, a default deny mechanism of protection with a sandbox containment mechanism (which is easily flushed) is the best way to block these (non-existent haha) malware loggers.

You know what I would really like to see?  A test against real-world malware, NOT simulators.

Thanks and keep up the &quot;good&quot; work.</description>
		<content:encoded><![CDATA[<p>You write:<br />
&#8220;&#8230;real financial malware commonly, will NOT use the same exploit/vector as a simulator&#8230;<br />
&#8230;An application blocking these simulated attacks does NOT necessarily mean it will be effective against REAL malware.&#8221;</p>
<p>I&#8217;ve highlighted the key words in capitals.  Unfortuntately, this test doesn&#8217;t really prove anything.  Fact is, most (clever) zero day malware will be released after testing against anti-logging mechanims.  And they will NOT be blocked.  Right?</p>
<p>Hence, a default deny mechanism of protection with a sandbox containment mechanism (which is easily flushed) is the best way to block these (non-existent haha) malware loggers.</p>
<p>You know what I would really like to see?  A test against real-world malware, NOT simulators.</p>
<p>Thanks and keep up the &#8220;good&#8221; work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on MRG Tests by dallas7</title>
		<link>http://malwareresearchgroup.com/malware-tests/comment-page-1/#comment-49</link>
		<dc:creator>dallas7</dc:creator>
		<pubDate>Wed, 23 Jun 2010 18:31:15 +0000</pubDate>
		<guid isPermaLink="false">http://malwareresearchgroup.com/?page_id=139#comment-49</guid>
		<description>Outstanding piece of work; a real eye opener and of great value to the community!  Looking forward to the ongoing results in the coming month of days.

What was the environment of the Prevx installation...
PrevxFree/SOLFree (setup.exe default) or then licensed as
PrevxPaid/SOLfree or
PrevxFree/SOLpaid or
PrevxPaid/SOLpaid???

Thank you.</description>
		<content:encoded><![CDATA[<p>Outstanding piece of work; a real eye opener and of great value to the community!  Looking forward to the ongoing results in the coming month of days.</p>
<p>What was the environment of the Prevx installation&#8230;<br />
PrevxFree/SOLFree (setup.exe default) or then licensed as<br />
PrevxPaid/SOLfree or<br />
PrevxFree/SOLpaid or<br />
PrevxPaid/SOLpaid???</p>
<p>Thank you.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
