<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Panda Research Blog</title><link>http://research.pandasecurity.com/default.aspx</link><description>, leading the way in proactive malware detection </description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP2 (Build: 61120.2)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/PandaResearch" type="application/rss+xml" /><item><title>Law enforcement = 0 / Bad guys = 1</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/RO-D7paHBO4/Law-enforcement-_3D00_-0-_2F00_-Bad-guys-_3D00_-1.aspx</link><pubDate>Tue, 30 Jun 2009 09:42:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:30116</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>2</slash:comments><comments>http://research.pandasecurity.com/comments/30116.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=30116</wfw:commentRss><description>&lt;p&gt;It&amp;#39;s a sad day for all of us when bad guys get caught, yet are allowed to walk freely.&lt;/p&gt;&lt;p&gt;As reported by TheReg, James Reno, involved in the creation, distribution and scams using Rogue Antivirus such as ErrorSafe, WinAntiviurs and XPAntivirus, &amp;nbsp;was allowed to &amp;quot;walk&amp;quot; with just a small fine of $116K. The article suggest he scammed users out of $50 million by infecting their PCs with rogue crapware and scaring them into paying up.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.theregister.co.uk/2009/06/29/scareware_settlement/"&gt;&lt;strong&gt;http://www.theregister.co.uk/2009/06/29/scareware_settlement/&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;What kind of message is&amp;nbsp;the FTC&amp;nbsp;sending to the rest of the bad guys? &lt;em&gt;&amp;quot;Go ahead, infect millions of users and don&amp;#39;t worry about jail time. Just give us a small percentage and we&amp;#39;ll let you go.&amp;quot;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;I already had small hopes that law enforcement and governments do anything useful to help protect users. But this goes beyond absurd and is sending the wrong message that &lt;em&gt;&lt;strong&gt;cyber-crime is OK as long as they pay their dues to governments&lt;/strong&gt;&lt;/em&gt;.&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=30116" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/RO-D7paHBO4" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/Law-enforcement-_3D00_-0-_2F00_-Bad-guys-_3D00_-1.aspx</feedburner:origLink></item><item><title>First Independent Test of Panda Internet Security 2010</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/_64BF1uMHdM/First-Independent-Test-of-Panda-Internet-Security-2010.aspx</link><pubDate>Fri, 26 Jun 2009 18:12:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:29720</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>13</slash:comments><comments>http://research.pandasecurity.com/comments/29720.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=29720</wfw:commentRss><description>&lt;p&gt;As you may know we released our &lt;a href="http://www.pandasecurity.com/usa/homeusers/solutions"&gt;&lt;strong&gt;Panda 2010&lt;/strong&gt;&lt;/a&gt; products yesterday.&amp;nbsp;In addition to the traditional &lt;a href="http://www.pandasecurity.com/homeusers/solutions/antivirus/"&gt;Panda Antivirus Pro 2010&lt;/a&gt;, &lt;a href="http://www.pandasecurity.com/homeusers/solutions/internet-security/"&gt;Panda Internet Security 2010&lt;/a&gt; and &lt;a href="http://www.pandasecurity.com/homeusers/solutions/global-protection/"&gt;Panda Global Protection 2010&lt;/a&gt;, this year we&amp;#39;ve also released a tailor-made product for netbooks and ultra portables called &lt;a href="http://www.pandasecurity.com/usa/homeusers/solutions/antivirus-netbooks/"&gt;Panda Antivirus for Netbooks&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;I just got word from Andreas Marx from &lt;a href="http://www.av-test.org"&gt;&lt;strong&gt;AV-Test.org&lt;/strong&gt;&lt;/a&gt; that they&amp;#39;ve put Panda Internet Security 2010 (PIS 2010) to the test today. Some conclusions from the test can be seen below, using Andreas&amp;#39; own words:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;WildList Test.&lt;/u&gt;&lt;/strong&gt; &amp;nbsp;&lt;em&gt;We started with a detection test against all samples from the most recent WildList 05/2009 and malware from older releases. Our test set includes 3,194 confirmed malicious and widespread samples. We tested the set with the on-demand scanner and on-access guard. In both cases, Panda was able to detect and remove these viruses, worms and bots easily.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Full Collection Test.&lt;/u&gt;&lt;/strong&gt; &lt;em&gt;We were able to test PIS 2010 against a larger set of about 680,000 malware samples, including ad- and spyware, trojan horses and other critters. It detected 99.6% of these files, without flagging any files in our false positive / clean file test set, which is a very good result.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;TruPrevent Test.&lt;/u&gt;&lt;/strong&gt; &amp;nbsp;&lt;em&gt;We have tested the dynamic (behaviour-based) detection with a few recently released malware samples which are not yet detected by heuristics, signatures or the &amp;quot;in the cloud&amp;quot; features and found that Panda warned in about 45% of the cases when we&amp;nbsp;executed the malware sample. However, it only blocked and quarantined just a few of these tested samples. (More testing in this area needs to be performed to report statistically significant results.)&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Disinfection&amp;nbsp;Test.&lt;/u&gt;&lt;/strong&gt; &lt;em&gt;The detection and removal of an already infected PC was working properly, all active components were removed during the system repair process and just in some cases, registry keys belonging to the malware were left behind. &lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;u&gt;Rootkit Test.&lt;/u&gt;&lt;/strong&gt;&amp;nbsp;&lt;em&gt;The detection and removal of actively running rootkits was quite impressive: all rootkits in our test were&amp;nbsp;successfully identified and deleted.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;As you may imagine we&amp;#39;re&amp;nbsp;very happy about the results of this test and hope other independent tests come along soon that also validate the highest level of quality provided by our most advanced ever anti-malware solutions.&lt;/p&gt;&lt;p&gt;For detailed testing methodology (for rootkit detection and removal, system disinfection, dynamic detection, etc.) I recommend you visit &lt;a href="http://www.av-test.org/index.php?sub=Papers&amp;amp;menue=1&amp;amp;lang=0"&gt;&lt;strong&gt;AV-Test.org Papers&lt;/strong&gt;&lt;/a&gt; selection.&lt;/p&gt;&lt;p&gt;Other advanced testing methodologies worth reading up on can also be found at &lt;a href="http://www.amtso.org/documents.html"&gt;&lt;strong&gt;ATMSO&amp;#39;s Document Library&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=29720" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/_64BF1uMHdM" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/behavior+analysis/default.aspx">behavior analysis</category><category domain="http://research.pandasecurity.com/archive/tags/stats/default.aspx">stats</category><category domain="http://research.pandasecurity.com/archive/tags/rootkits/default.aspx">rootkits</category><category domain="http://research.pandasecurity.com/archive/tags/heuristics/default.aspx">heuristics</category><category domain="http://research.pandasecurity.com/archive/tags/malware/default.aspx">malware</category><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/First-Independent-Test-of-Panda-Internet-Security-2010.aspx</feedburner:origLink></item><item><title>Panda USB Vaccine with NTFS Support</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/nwb9-eyQppg/Panda-USB-Vaccine-with-NTFS-Support.aspx</link><pubDate>Thu, 18 Jun 2009 22:48:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:28960</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>14</slash:comments><comments>http://research.pandasecurity.com/comments/28960.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=28960</wfw:commentRss><description>&lt;p&gt;First off many thanks to the hundreds of thousands of users who have downloaded, used and given us feedback on &lt;a href="http://research.pandasecurity.com/archive/Panda-USB-and-AutoRun-Vaccine.aspx"&gt;&lt;strong&gt;Panda USB Vaccine&lt;/strong&gt;&lt;/a&gt;. Not only is it allowing us to improve this free utility for the community, it also helps protect users a little better from spreading malware infections.&lt;/p&gt;&lt;p&gt;Finally Panda USB Vaccine is out of beta and version 1.0.0.50 is here. Some of the most notable improvements are the following:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Support&amp;nbsp;for vaccinating&amp;nbsp;NTFS drives. This uses a completely different technique than the vaccination of FAT/FAT32 drives.&lt;/li&gt;&lt;li&gt;Executing USBVaccine.exe launches an installer which allows you to configure whether you&amp;nbsp;want USBVaccine to start automatically with Windows.&lt;/li&gt;&lt;li&gt;Configuration option&amp;nbsp;during setup to hide the tray icon.&lt;/li&gt;&lt;li&gt;Configuration option during setup to automatically vaccinate any new USB drives inserted into the PC.&lt;/li&gt;&lt;li&gt;Fixed bug on PC shutdown when USBVaccine was running in the background (Vista).&lt;/li&gt;&lt;li&gt;Other bug fixes reported by users on certain types of USB drives.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Some screenshots of the new Panda USB Vaccine:&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="392" src="http://research.pandasecurity.com/blogs/images/usbvaccine/usbvaccine1.5.setup.jpg" style="width:503px;height:392px;" width="503" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="147" src="http://research.pandasecurity.com/blogs/images/usbvaccine/usbvaccine1.5.tray.jpg" style="width:411px;height:147px;" width="411" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="373" src="http://research.pandasecurity.com/blogs/images/usbvaccine/usbvaccine1.5.jpg" style="width:449px;height:373px;" width="449" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="302" src="http://research.pandasecurity.com/blogs/images/usbvaccine/usbvaccine1.5.new.jpg" style="width:387px;height:302px;" width="387" /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As always you can get it directly from download.com:&lt;/p&gt;&lt;p&gt;&lt;a href="http://download.cnet.com/Panda-USB-Vaccine/3000-2239_4-10909938.html?part=dl-55967&amp;amp;subj=dl&amp;amp;tag=button" target="_blank"&gt;&lt;img alt="Get it from CNET Download.com!" border="0" height="60" src="http://i.i.com.com/cnwk.1d/i/dl/button/dl-button_a.gif" width="150" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=28960" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/nwb9-eyQppg" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/utils/default.aspx">utils</category><feedburner:origLink>http://research.pandasecurity.com/archive/Panda-USB-Vaccine-with-NTFS-Support.aspx</feedburner:origLink></item><item><title>Feedback on Morro</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/Lrtt5yXn4hM/Feedback-on-Morro.aspx</link><pubDate>Thu, 18 Jun 2009 00:29:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:28868</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>4</slash:comments><comments>http://research.pandasecurity.com/comments/28868.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=28868</wfw:commentRss><description>&lt;p&gt;Excellent comment via &lt;a href="http://www.pcworld.com/article/166513/"&gt;pcworld&lt;/a&gt; regarding Morro (kudos to avdude15):&lt;/p&gt;&lt;blockquote&gt;&lt;p style="margin:12px 0px;padding:0px;"&gt;&lt;em&gt;Just what we need - a security&amp;nbsp;&lt;strong&gt;mono-culture&lt;/strong&gt;.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;If Microsoft&amp;#39;s free av product succeeds it will knock more than a few av developers out of the market and weaken the rest. This at a time when the more innovative players are investing heavily in the infrastructure and technology to deliver protection as a service. Cloud scanning, reputation systems, sand boxes are just a few of the new technologies being rolled out by many of the AV players. So Microsoft says, &amp;quot;let&amp;#39;s give away a product and kill all that innovation&amp;quot;. Whether or not Microsoft delivers a good product or not, all of our security will suffer.&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;To counter some press articles, Morro is &lt;strong&gt;not&lt;/strong&gt; cloud-based. It simply sends detection statistics back to MS over the Internet (encrypted over SSL so you can&amp;#39;t see what is being sent). &lt;/p&gt;&lt;p&gt;Also there&amp;#39;s nothing innovative about Morro. It requires big signature updates and doesn&amp;#39;t use cloud-scanning. Just&amp;nbsp;the same old traditional and basic AV.&lt;/p&gt;&lt;p&gt;What&amp;#39;s your take on MS Morro?&amp;nbsp;&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=28868" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/Lrtt5yXn4hM" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/Feedback-on-Morro.aspx</feedburner:origLink></item><item><title>Online banking</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/yVQ6H1gtFyA/Online-banking.aspx</link><pubDate>Mon, 08 Jun 2009 14:39:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:28277</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>1</slash:comments><comments>http://research.pandasecurity.com/comments/28277.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=28277</wfw:commentRss><description>&lt;p&gt;&lt;img border="0" height="678" src="http://research.pandasecurity.com/blogs/images/cartoon/online_banking.JPG" style="width:1030px;height:678px;" width="1030" /&gt;&lt;/p&gt;&lt;p&gt;:)&amp;nbsp;&lt;/p&gt;&lt;p&gt;Don&amp;#39;t know where I got this from. I think it&amp;#39;s from &lt;a href="http://www.pcvey.com"&gt;Vey&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=28277" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/yVQ6H1gtFyA" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/fun/default.aspx">fun</category><feedburner:origLink>http://research.pandasecurity.com/archive/Online-banking.aspx</feedburner:origLink></item><item><title>When the going gets tough, AMTSO gets going</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/sc2tgaqL9mg/When-the-going-gets-tough_2C00_-AMTSO-gets-going.aspx</link><pubDate>Tue, 02 Jun 2009 00:42:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:27595</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>1</slash:comments><comments>http://research.pandasecurity.com/comments/27595.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=27595</wfw:commentRss><description>&lt;p&gt;&lt;img border="0" height="88" src="http://research.pandasecurity.com/blogs/images/amtso-budapest/logo.gif" style="width:255px;height:88px;" width="255" /&gt; &lt;/p&gt;&lt;p&gt;You&amp;#39;ve probably read about this in other blogs already. At the risk of sounding like a broken record I&amp;#39;ll post it here as well as this is &lt;strong&gt;&lt;em&gt;really important&lt;/em&gt;&lt;/strong&gt; and I think we should all help spread the word as much as possible. As you may know AMTSO is a non-profit organization made up of a lot of companies from the industry, from independent tests (such as AV-Test, AV-Comparatives, CascadiaLabs, Dennis Technology Lab, ICSA, NSS, PC Security Labs, and West Coast Labs) to antivirus vendors and academia.&amp;nbsp;Visit AMTSO website to view the &lt;a href="http://amtso.org/members.html"&gt;full member list&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;img align="left" border="0" height="234" hspace="10" src="http://research.pandasecurity.com/blogs/images/amtso-budapest/amtso-min.jpg" style="width:354px;height:234px;" width="354" /&gt;Last month we attended the 5th Anti-Malware Testing Standards Organization (AMTSO) meeting held in Budapest and hosted by VirusBuster. This follows a bunch of other meetings held in Bilbao (Panda), The Netherlands (Norman), Oxford (Sophos) and &lt;a href="http://research.pandasecurity.com/archive/Progress-on-Anti_2D00_Malware-Testing-Standards-Organization-_2800_AMTSO_2900_.aspx"&gt;&lt;strong&gt;Cupertino&lt;/strong&gt;&lt;/a&gt; (Symantec). You can read the AMTSO Press Release titled &lt;em&gt;&lt;a href="http://www.amtso.org/antimalware-testing-standards-organization-to-start-analysis-of-antimalware-reviews.html"&gt;&lt;strong&gt;AMTSO to start analysis of Anti-Malware Reviews&lt;/strong&gt;&lt;/a&gt;&lt;/em&gt; for the official details. &lt;/p&gt;&lt;p&gt;Most of the work went into validating in a face to face meeting the different documented methodologies and processes which we&amp;#39;ve all been working on over the last few months. In all, AMTSO has now published a respectable &lt;a href="http://amtso.org/documents.html"&gt;&lt;strong&gt;document library&lt;/strong&gt;&lt;/a&gt; about different issues concerning Anti-Malware Testing, and the list keeps on growing. &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://amtso.org/uploads/AMTSO_Principles_-_FINAL_31_Oct_2008-1.pdf"&gt;&lt;strong&gt;AMTSO Fundamental Principles of Testing&lt;/strong&gt;&lt;/a&gt;. A high level overview which covers the 9 principle guidelines to follow while testing anti-malware products.&lt;/li&gt;&lt;li&gt;&lt;a href="http://amtso.org/uploads/AMTSO_Best_practices_for_Dynamic_Testing_-_FINAL_31__Oct_2008.pdf"&gt;&lt;strong&gt;AMTSO Best Practices for Dynamic Testing&lt;/strong&gt;&lt;/a&gt;. Probably the first document AMTSO started working on the early days of its foundation. Covers the main issues while running dynamic tests (versus static tests which consist of on-demand scans of many samples).&lt;/li&gt;&lt;li&gt;&lt;a href="http://amtso.org/uploads/amtso-suggested-methods-for-the-validation-of-samples.pdf"&gt;&lt;strong&gt;AMTSO Best Practices for Validation of Samples&lt;/strong&gt;&lt;/a&gt;. One of the most important and most often overlooked issues of anti-malware testing. How to select valid samples for testing.&lt;/li&gt;&lt;li&gt;&lt;a href="http://amtso.org/uploads/amtso-best-practices-for-testing-in-the-cloud-security-products.pdf"&gt;&lt;strong&gt;AMTSO Best Practices for Testing In-the-Cloud Security Products&lt;/strong&gt;&lt;/a&gt;. Specially important for products which incorporate this latest method of protection. We were specially interested in this document as you can imagine as some of our latest products such as &lt;a href="http://www.cloudantivirus.com"&gt;Panda Cloud Antivirus&lt;/a&gt; and &lt;a href="http://research.pandasecurity.com/archive/Panda-2010-Beta-Now-Open.aspx"&gt;Panda 2010&lt;/a&gt; products include cloud-scanning.&lt;/li&gt;&lt;li&gt;&lt;a href="http://amtso.org/uploads/amtso-analysis-of-reviews-process.pdf"&gt;&lt;strong&gt;AMTSO Analysis of Reviews Process&lt;/strong&gt;&lt;/a&gt;. Viewed as one of the most important tasks of AMTSO, this document provides insight into the process that AMTSO will follow to review, based on the principles and methodologies published, the different Anti-Malware Tests that are published out there. This process is completely transparent and open to the publlic, so anybody can request a &amp;quot;Review Analysis&amp;quot; of a published test.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;One of the most interesting things during these AMTSO meetings is the of openness &amp;amp;&amp;nbsp;sharing of information between&amp;nbsp;what are normally fierce competitors. It&amp;#39;s not a very common practice to link to &amp;quot;competitors&amp;quot; sites (and I&amp;#39;m sure I&amp;#39;ll get in trouble for it when/if my boss sees this), but I do recommend that you read up some of our colleagues blog posts about AMTSO progress, such as the ones from &lt;a href="http://www.sophos.com/blogs/sophoslabs//?p=4369"&gt;Sophos&lt;/a&gt;, &lt;a href="http://www.norman.com/security_center/blog/righard_zwienenberg/68979/de"&gt;Norman&lt;/a&gt;, &lt;a href="http://www.avertlabs.com/research/blog/index.php/2009/05/21/double-strike-by-amtso/"&gt;McAfee&lt;/a&gt;, &lt;a href="http://blog.trendmicro.com/happy-birthday-amtso/"&gt;Trend&lt;/a&gt;, &lt;a href="http://techblog.avira.com/2009/05/11/new-documents-from-amtso/en/"&gt;Avira&lt;/a&gt;, &lt;a href="http://blog.threatfire.com/2009/05/amtso-in-budapest.html"&gt;PC Tools&lt;/a&gt;, &lt;a href="http://www.viruslist.com/en/weblog?weblogid=208187733"&gt;Kaspersky&lt;/a&gt;, &lt;a href="http://www.eset.com/threat-center/blog/?p=1085"&gt;ESET&lt;/a&gt;, and last but not least&amp;nbsp;&lt;a href="http://www.virusbuster.hu/en/company/press/090430_amtso"&gt;VirusBuster&lt;/a&gt;&amp;nbsp;who hosted the event (sorry if I left someone out).&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=27595" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/sc2tgaqL9mg" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/When-the-going-gets-tough_2C00_-AMTSO-gets-going.aspx</feedburner:origLink></item><item><title>Panda 2010 Beta Now Open</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/uMBIni80Bhw/Panda-2010-Beta-Now-Open.aspx</link><pubDate>Mon, 18 May 2009 22:42:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:26905</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>32</slash:comments><comments>http://research.pandasecurity.com/comments/26905.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=26905</wfw:commentRss><description>&lt;p&gt;Today we&amp;#39;ve officially launched the beta program for our Panda 2010 products.&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="311" src="http://research.pandasecurity.com/blogs/images/panda2010/pgp2010-1.jpg" title="undefined" width="489" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;As functionality-wise Panda Global Protection 2010 is the most complete product of the bunch we&amp;#39;re releasing it as the main beta product. It includes a complete Anti-Malware Engine, Identity Theft Protection, Safe Internet Browsing filters and PC Backup &amp;amp; Optimization tools. More information can be found in the &lt;a href="http://updates.pandasoftware.com/beta/pgp2010/pgp2010_nc_en.pdf"&gt;&lt;strong&gt;full functionality list&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;One of the most interesting improvements this year is a 40% improvement in memory consumption, which results in a lower performance impact and better overall user experience.&lt;/p&gt;&lt;p&gt;You can find all the details, download link, installation details, list of known bugs and a list of recommended test at &lt;a href="http://www.pandasecurity.com/beta"&gt;&lt;strong&gt;http://www.pandasecurity.com/beta&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="575" src="http://research.pandasecurity.com/blogs/images/panda2010/pgp2010-2.jpg" style="width:797px;height:575px;" width="797" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="575" src="http://research.pandasecurity.com/blogs/images/panda2010/pgp2010-3.jpg" style="width:798px;height:575px;" width="798" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="576" src="http://research.pandasecurity.com/blogs/images/panda2010/pgp2010-4.jpg" style="width:798px;height:576px;" width="798" /&gt;&lt;/p&gt;&lt;p&gt;Before you ask, Windows 7 support is not yet included in this 2010 beta. It&amp;#39;ll be announced later on. In the meantime you can check the &lt;a href="http://research.pandasecurity.com/archive/Compatibility-with-Windows-7.aspx"&gt;Panda Antivirus Pro Beta for Windows 7&lt;/a&gt;.&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=26905" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/uMBIni80Bhw" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/Panda-2010-Beta-Now-Open.aspx</feedburner:origLink></item><item><title>New Technical Support Forum</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/4tYwnDADllg/New-Technical-Support-Forum.aspx</link><pubDate>Thu, 07 May 2009 22:06:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:26444</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>6</slash:comments><comments>http://research.pandasecurity.com/comments/26444.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=26444</wfw:commentRss><description>&lt;p&gt;Our folks from support have recently opened their new &lt;a href="http://support.pandasecurity.com/forum/"&gt;&lt;strong&gt;Panda Technical Support Forum&lt;/strong&gt;&lt;/a&gt; which you can find at &lt;a href="http://support.pandasecurity.com/forum/"&gt;http://support.pandasecurity.com/forum/&lt;/a&gt;. You can subscribe to alerts for updates, news, releases, betas, as well as get community-based support for all Panda products. Also there&amp;#39;s a section to download utilities and troubleshoot malware related issues. Great job guys !&lt;/p&gt;&lt;p&gt;&lt;a href="http://support.pandasecurity.com/forum/" target="_blank"&gt;&lt;img border="0" src="http://research.pandasecurity.com/blogs/images/support/SupportForum.jpg" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=26444" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/4tYwnDADllg" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/utils/default.aspx">utils</category><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/New-Technical-Support-Forum.aspx</feedburner:origLink></item><item><title>Panda Cloud Antivirus - Free AV thin-client</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/Zq6x87LOAG8/Panda-Cloud-Antivirus-_2D00_-Free-AV-thin_2D00_client.aspx</link><pubDate>Wed, 29 Apr 2009 00:44:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:26171</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>16</slash:comments><comments>http://research.pandasecurity.com/comments/26171.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=26171</wfw:commentRss><description>&lt;p&gt;&lt;span class="Apple-style-span" style="font-size:12px;line-height:17px;font-family:Verdana;"&gt;I&amp;#39;m happy to announce that we&amp;#39;ve finally published our first release beta version of &lt;strong&gt;Panda Cloud Antivirus&lt;/strong&gt;, the first free cloud-based antivirus thin-client (yes, it&amp;#39;s a free AV and yes, it&amp;#39;s really a thin-client). It is available at &lt;a href="http://www.cloudantivirus.com/"&gt;&lt;strong&gt;www.cloudantivirus.com&lt;/strong&gt;&lt;/a&gt;. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span" style="font-size:12px;line-height:17px;font-family:Verdana;"&gt;&lt;a href="http://research.pandasecurity.com/blogs/images/cloudav/cloudav.jpg"&gt;&lt;img align="left" border="0" height="239" hspace="5" src="http://research.pandasecurity.com/blogs/images/cloudav/cloudav-min.jpg" style="width:310px;height:239px;" width="310" /&gt;&lt;/a&gt;Panda Cloud Antivirus consists of a lightweight antivirus agent that is connected in real-time to PandaLabs&amp;rsquo; Collective Intelligence servers to protect faster against the newest malware variants while barely impacting PC performance.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span" style="font-size:12px;line-height:17px;font-family:Verdana;"&gt;With Panda Cloud Antivirus we introduce a new protection model based on a thin-client agent &amp;amp; server architecture which services malware protection as opposed to locally installed products. By combining local detection technologies with cloud-scanning capabilities and applying non-intrusive interception techniques on the client architecture, Panda Cloud Antivirus provides some of the best protection with a lightweight antivirus thin-client agent that barely consumes any PC resources.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span" style="font-size:12px;line-height:17px;font-family:Verdana;"&gt;Of course keep in mind that this is still beta code and as such we continue improving and tuning both the cloud architecture and detection techniques as well as the agent architecture, specially now during the initial phases. That&amp;#39;s why we&amp;#39;re calling out to betatesters out there to help us test this new protection model in different scenarios.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span" style="font-size:12px;line-height:17px;font-family:Verdana;"&gt;Feel free to download Panda Cloud Antivirus&amp;nbsp;from&amp;nbsp;&lt;a href="http://www.cloudantivirus.com/"&gt;&lt;strong&gt;http://www.cloudantivirus.com&lt;/strong&gt;&lt;/a&gt;. For submitting&amp;nbsp;reports please use &lt;a href="mailto:beta@pandasecurity.com" style="color:#2970a6;text-decoration:none;padding:0px;margin:0px;"&gt;&lt;strong&gt;beta@pandasecurity.com&lt;/strong&gt;&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=26171" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/Zq6x87LOAG8" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/utils/default.aspx">utils</category><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/Panda-Cloud-Antivirus-_2D00_-Free-AV-thin_2D00_client.aspx</feedburner:origLink></item><item><title>Panda USB and AutoRun Vaccine</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/mKVQ0kK0lAs/Panda-USB-and-AutoRun-Vaccine.aspx</link><pubDate>Thu, 05 Mar 2009 21:01:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:24125</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>178</slash:comments><comments>http://research.pandasecurity.com/comments/24125.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=24125</wfw:commentRss><description>&lt;p&gt;&lt;strong&gt;UPDATE June 19, 2009: New &lt;a href="http://research.pandasecurity.com/archive/Panda-USB-Vaccine-with-NTFS-Support.aspx"&gt;version 1.0.0.50 released&lt;/a&gt; with NTFS support.&lt;/strong&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The Microsoft Windows Operating Systems use the AUTORUN.INF file from removable drives in order to know which actions to perform when a new external storage device, such as a USB drive or CD/DVD, is inserted into the PC. The AUTORUN.INF file is a configuration file that is normally located in the root directory of removable media and contains, among other things, a reference to the icon that will be shown associated to the removable drive or volume, a description of its content and also the possibility to define a program which should be executed automatically when the unit is mounted. &lt;br /&gt;&lt;br /&gt;The problem is that this feature, widely critizised by the security community, is used by malware in order to spread by infecting as soon as a new drive is inserted in a computer. The malware achieves this by copying a malicious executable in the drive and modifying the AUTORUN.INF file so that Windows opens the malicious file silently as soon as the drive is mounted. The most recent examples of this are the W32/Sality, W32/Virutas and also the &lt;strong&gt;&lt;a href="http://research.pandasecurity.com/archive/Warning_3A00_-Conficker-worm-infections-gaining-traction.aspx"&gt;W32/Conficker&lt;/a&gt;&lt;/strong&gt; worm which, in addition to spreading via a vulnerability and network shares, also spreads via USB drives.&lt;br /&gt;&lt;br /&gt;Due to the large amount of malware-related problems associated with Microsoft AutoRun we have created a free utility for our user community called Panda USB Vaccine.&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="404" src="http://research.pandasecurity.com/blogs/images/usbvaccine/usbvaccine.jpg" width="486" /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;u&gt;&lt;strong&gt;Computer Vaccination&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt;The free Panda USB Vaccine allows users to vaccinate their PCs in order to disable AutoRun completely so that no program from any USB/CD/DVD drive (regardless of whether they have been previously vaccinated or not) can auto-execute. This is a really helpful feature as there is no user friendly and easy way of completely disabling AutoRun on a Windows PC. &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;strong&gt;USB Vaccination&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt;The free Panda USB Vaccine can be used on individual USB drives to disable its AUTORUN.INF file in order to prevent malware infections from spreading automatically. When applied on a USB drive, the vaccine permanently blocks an innocuous AUTORUN.INF file, preventing it from being read, created, deleted or modified. Once applied it effectivelly disables Windows from automatically executing any malicious file that might be stored in that particular USB drive. The drive can otherwise be used normally and files (even malware) copied to/from it, but they will be prevented from opening automatically. Panda USB Vaccine currently only works on FAT &amp;amp; FAT32 USB drives. Also keep in mind that USB drives that have been vaccinated cannot be reversed except with a format.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p style="font-weight:bold;text-decoration:underline;"&gt;Download&lt;/p&gt;&lt;p&gt;Panda USB Vaccine is a 100% free utility. We&amp;#39;ve tested it under Windows 2000 SP4, Windows XP SP1-SP3,&amp;nbsp; and Windows Vista SP0 and SP1. Feedback is always welcomed. Click on the download button below to start downloading.&lt;br /&gt;&lt;/p&gt;&lt;a href="http://download.cnet.com/Panda-USB-Vaccine/3000-2239_4-10909938.html?part=dl-55967&amp;amp;subj=dl&amp;amp;tag=button" target="_blank"&gt;&lt;img alt="Get it from CNET Download.com!" border="0" height="60" src="http://i.i.com.com/cnwk.1d/i/dl/button/dl-button_a.gif" width="150" /&gt;&lt;/a&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;u&gt;&lt;strong&gt;Command line Operation&lt;/strong&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt;For advanced users who wish to run Panda USB Vaccine automatically at boot to notify every time a new USB device is mounted on the system or to perform network-wide computer vaccinations via login scripts or other distribution methods, Panda USB Vaccine can be operated via command-line. Its input parameters are the following:&lt;/p&gt;&lt;p&gt;&lt;code&gt;USBVaccine.exe [ A|B|C&amp;hellip;|Z ] [ +system|-system ] [ /resident [/hidetray] ]&lt;/code&gt; &lt;/p&gt;&lt;p&gt;[drive unit]:&amp;nbsp;&amp;nbsp; Vaccinate drive unit&lt;br /&gt;+system :&amp;nbsp;&amp;nbsp;&amp;nbsp; Computer vaccination&lt;br /&gt;-system :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remove computer vaccination&lt;br /&gt;/resident:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Start program hidden and prompt for vaccinating every new drive &lt;br /&gt;/hidetray:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hides tray icon when used with the /resident command&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;u&gt;Examples:&lt;/u&gt;&lt;br /&gt;To vaccinate USB drives F:\ and G:\, use &lt;br /&gt;&amp;nbsp;&amp;nbsp; &lt;code&gt;USBVaccine.exe F G&lt;/code&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;To vaccinate the computer, use&lt;br /&gt;&amp;nbsp;&amp;nbsp; &lt;code&gt;USBVaccine.exe +system&lt;/code&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;To vaccinate computer and prompt for vaccinating every new drive without showing a tray icon, use &lt;br /&gt;&amp;nbsp;&amp;nbsp; &lt;code&gt;USBVaccine.exe /resident /hidetray +system&lt;/code&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;It could be very useful to create a Shortcut in the Startup folder to USBVaccine.exe with this last command line (or without the /hidetray) to make sure that every time you boot the computer USBVaccine gets loaded by the system and it vaccinates the computer and prompts the user for vaccinating any new non-vaccinated USB drive. However if you do this under Vista, UAC will block it from running at Startup as it requires admin priviledges. We&amp;#39;ll fix this in future versions.&lt;br /&gt;&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=24125" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/mKVQ0kK0lAs" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/utils/default.aspx">utils</category><feedburner:origLink>http://research.pandasecurity.com/archive/Panda-USB-and-AutoRun-Vaccine.aspx</feedburner:origLink></item><item><title>Compatibility with Windows 7</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/nIUP1ClKP9Y/Compatibility-with-Windows-7.aspx</link><pubDate>Thu, 26 Feb 2009 18:46:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:23881</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>29</slash:comments><comments>http://research.pandasecurity.com/comments/23881.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=23881</wfw:commentRss><description>&lt;p&gt;As some of you may know Microsoft is currently working on its next Operating System called Windows 7. It introduces quite some improvements in usability, efficiency and information management. It&amp;#39;s definately worth a try.&lt;/p&gt;&lt;p&gt;To help you evaluate Windows 7 we&amp;#39;ve just released a beta of Panda Antivirus Pro 2009 for Windows 7. It includes the latest Panda anti-malware engine, heuristics and Collective Intelligence scanning-from-the-cloud.&amp;nbsp;&lt;/p&gt;&lt;p&gt;You can download the beta of Panda Antivirus Pro 2009 for Windows 7 directly from &lt;strong&gt;&lt;a href="http://updates.pandasoftware.com/beta/pavp2009cw7/pavp2009cw7.exe"&gt;here&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;More information about Panda for Windows 7 at &lt;strong&gt;&lt;a href="http://www.pandasecurity.com/windows7/"&gt;http://www.pandasecurity.com/windows7&lt;/a&gt;&lt;/strong&gt;. &lt;br /&gt;&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=23881" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/nIUP1ClKP9Y" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/Compatibility-with-Windows-7.aspx</feedburner:origLink></item><item><title>Panda Collective Intelligence and VirusTotal</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/FHqvQslwdz8/Panda-Collective-Intelligence-and-VirusTotal.aspx</link><pubDate>Thu, 12 Feb 2009 11:40:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:23354</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>21</slash:comments><comments>http://research.pandasecurity.com/comments/23354.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=23354</wfw:commentRss><description>&lt;p&gt;As you know we&amp;#39;ve been using &lt;strong&gt;&lt;a href="http://research.pandasecurity.com/archive/Technology-Paper_3A00_-From-AV-to-Collective-Intelligence.aspx"&gt;Panda Collective Intelligence&lt;/a&gt;&lt;/strong&gt; from-the-cloud-scanning technologies since about two years ago, initially in our online scanners &lt;a href="http://research.pandasecurity.com/archive/Panda-ActiveScan-2.0.aspx"&gt;ActiveScan&lt;/a&gt; and also in our &lt;a href="http://research.pandasecurity.com/archive/Panda-Internet-Security-2009-BETA.aspx"&gt;Panda 2009 consumer products&lt;/a&gt;. Thanks to Collective Intelligence we are able to use complete automation (community-driven information, threat analysis, multiple technology checks, malware/goodware determination and signature creation) to protect against the newest and most dangerous variants faster than using the traditional signature approach. &lt;br /&gt;
&lt;/p&gt;
&lt;p&gt;I&amp;#39;m happy to report that we&amp;#39;ve now integrated the Panda Collective Intelligence cloud-scanning technology into the &lt;strong&gt;&lt;a href="http://www.virustotal.com"&gt;VirusTotal&lt;/a&gt;&lt;/strong&gt; service. You&amp;#39;ll notice it by the 10.x version numbering next to the Panda engine.&lt;/p&gt;
&lt;p&gt;To see Panda Collective Intelligence in action let&amp;#39;s look at a new malware that started spreading a few hours ago (MD5: a0713a3639c9d4901daf774022f4bfd2). It is an Adware/Antivirus2009 rogue antivirus. Let&amp;#39;s run it through VirusTotal and see the results as of 02.12.2009 12:35:51 (CET):&lt;/p&gt;
&lt;p&gt;&lt;img border="0" height="769" src="http://research.pandasecurity.com/blogs/images/virustotal/vtscan.jpg" width="439" /&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Check the updated VirusTotal scan result &lt;a href="http://www.virustotal.com/buscaHash.html"&gt;&lt;strong&gt;here&lt;/strong&gt;&lt;/a&gt; (search for a0713a3639c9d4901daf774022f4bfd2) to see how other engines add detection progressively. &lt;br /&gt;
&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=23354" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/FHqvQslwdz8" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/behavior+analysis/default.aspx">behavior analysis</category><category domain="http://research.pandasecurity.com/archive/tags/heuristics/default.aspx">heuristics</category><category domain="http://research.pandasecurity.com/archive/tags/malware/default.aspx">malware</category><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><category domain="http://research.pandasecurity.com/archive/tags/prevalence/default.aspx">prevalence</category><feedburner:origLink>http://research.pandasecurity.com/archive/Panda-Collective-Intelligence-and-VirusTotal.aspx</feedburner:origLink></item><item><title>Progress on Anti-Malware Testing Standards Organization (AMTSO)</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/5--hnSuQR8A/Progress-on-Anti_2D00_Malware-Testing-Standards-Organization-_2800_AMTSO_2900_.aspx</link><pubDate>Mon, 09 Feb 2009 15:16:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:23197</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>3</slash:comments><comments>http://research.pandasecurity.com/comments/23197.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=23197</wfw:commentRss><description>&lt;p&gt;Last week the 4th &lt;strong&gt;&lt;a href="http://www.amtso.org" target="_blank"&gt;AMTSO&lt;/a&gt;&lt;/strong&gt; meeting took place in Cupertino, hosted by Symantec. As you may remember &lt;a href="http://www.amtso.org/press/5-formationpressrelease.html" style="font-weight:bold;" target="_blank"&gt;Panda Security hosted the first AMTSO&lt;/a&gt; meeting in Bilbao early last year.&lt;/p&gt;&lt;p&gt;This has been by far the most productive AMTSO meeting so far. We really advanced a lot in specifying different testing guidelines, principles, education documents and methodologies. Please watch the AMTSO website at &lt;a href="http://www.amtso.org/" target="_blank"&gt;www.amtso.org&lt;/a&gt; for these official documents. Some of the most important documents that are either already published or which we worked on during last week are the following:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;AMTSO Fundamental Principles of Testing&lt;/li&gt;&lt;li&gt;AMTSO Best Practices for Dynamic Testing&lt;/li&gt;&lt;li&gt;AMTSO Best Practices for In-The-Cloud Testing&lt;/li&gt;&lt;li&gt;AMTSO Review of Reviews&lt;/li&gt;&lt;li&gt;AMTSO Whole Product Testing&lt;/li&gt;&lt;li&gt;Educational Documents such as Obtaining Samples, Creating Samples and Verificating Samples&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;It was truly a great experience to work alongside such a great group of professionals including testing organizations such AV-Test, ICSA, NSS, CheckMark, AV-Comparatives, PC Magazine and competing AV vendors. As always I have some pics for you:&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="576" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/amtso1.jpg" width="768" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="712" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/amtso2.jpg" width="1068" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="712" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/amtso3.jpg" width="1068" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="1068" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/amtso4.jpg" width="712" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="712" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/amtso5.jpg" width="1068" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="712" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/amtso6.jpg" width="1068" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="712" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/amtso7.jpg" width="1068" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="576" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/amtso8.jpg" width="768" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;Of course there was also a fun part to the trip. We had a few days to relax and went to San Francisco with Philipp from Avira and Nick from SonicWall to have a good time. As you can see from the pics below the locals were really friendly :)&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="576" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/fun1.jpg" width="768" /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="576" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/fun3.jpg" width="768" /&gt; &lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="576" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/fun2.jpg" width="768" /&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="712" src="http://research.pandasecurity.com/blogs/images/amtso-cupertino/fun4.jpg" width="1068" /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=23197" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/5--hnSuQR8A" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><category domain="http://research.pandasecurity.com/archive/tags/fun/default.aspx">fun</category><feedburner:origLink>http://research.pandasecurity.com/archive/Progress-on-Anti_2D00_Malware-Testing-Standards-Organization-_2800_AMTSO_2900_.aspx</feedburner:origLink></item><item><title>Panda participates in new AV comparative</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/QgKrv0tDFqU/Panda-participates-in-new-AV-comparative.aspx</link><pubDate>Thu, 15 Jan 2009 14:52:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:21668</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>8</slash:comments><comments>http://research.pandasecurity.com/comments/21668.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=21668</wfw:commentRss><description>&lt;p&gt;Since a few months ago we&amp;#39;ve started participating in a new AV comparative test from &lt;a href="http://www.pcsecuritylabs.net" style="font-weight:bold;" target="_blank"&gt;PC Security Labs&lt;/a&gt; called &lt;span style="font-weight:bold;"&gt;Total Protection Testing&lt;/span&gt;. It&amp;#39;s a pretty kewl test since, as opposed to other AV comparatives out there, PC Security Labs has a very interesting testing methodology that takes into consideration:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Freshness of malware samples. Only the newest samples from the previous month are tested, not year old samples.&lt;/li&gt;&lt;li&gt;Static detection using traditional signature files, very similar to what other AV comparative testers are doing.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Dynamic (behavioral) detection of malicious running processes. Only a handful of professional AV testers are doing this.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Cloud-based detection such as Panda&amp;#39;s Collective Intelligence. As far as I know PCSL is the first AV tester with a methodology that takes this type of technology into account.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;False positive testing. Global scores are lowered on each false positive.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;All-in-all a very complete testing methodology that gives a broad view of the global performance of different anti-malware solutions. It&amp;#39;s no surprise that PC SecurityLabs has recently joined the &lt;a href="http://www.amtso.org"&gt;AntiMalware Testing Standards Organization&lt;/a&gt; (AMTSO).&lt;/p&gt;&lt;p&gt;I&amp;#39;m glad to report that Panda has achieved an &amp;quot;Excellent&amp;quot; score in each of the three tests we&amp;#39;ve participated in so far.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.pcsecuritylabs.net/document/PCSL-Total-Protection-Testing-Report(2008NO.11).zip"&gt;&lt;img border="0" height="80" src="http://research.pandasecurity.com/blogs/images/pcsl/200811.jpg" width="152" /&gt;&lt;/a&gt; &lt;a href="http://www.pcsecuritylabs.net/document/PCSL%20Total%20Protection%20Testing%20Report%202008%20NO.12.zip"&gt;&lt;img border="0" src="http://research.pandasecurity.com/blogs/images/pcsl/200812.jpg" /&gt;&lt;/a&gt;&lt;a href="http://www.pcsecuritylabs.net/document/PCSL%20Total%20Protection%20Testing%20Report%202009%20NO.1.zip"&gt;&lt;img border="0" height="85" src="http://research.pandasecurity.com/blogs/images/pcsl/200901.jpg" width="160" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Total Protection Testing reports from PCSL can be downloaded directly from the following locations:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.pcsecuritylabs.net/document/PCSL-Total-Protection-Testing-Report(2008NO.11).zip" style="font-weight:bold;"&gt;PC SecurityLabs Total Protection Testing 2008/11&lt;/a&gt;&amp;nbsp;&lt;/li&gt;&lt;li style="font-weight:bold;"&gt;&lt;a href="http://www.pcsecuritylabs.net/document/PCSL%20Total%20Protection%20Testing%20Report%202008%20NO.12.zip"&gt;PC SecurityLabs Total Protection Testing 2008/12&lt;/a&gt;&lt;/li&gt;&lt;li style="font-weight:bold;"&gt;&lt;a href="http://www.pcsecuritylabs.net/document/PCSL%20Total%20Protection%20Testing%20Report%202009%20NO.1.zip"&gt;PC SecurityLabs Total Protection Testing 2009/01&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The tests are performed on a monthly basis, so make sure to visit &lt;a href="http://www.pcsecuritylabs.net" style="font-weight:bold;" target="_blank"&gt;PC Security Labs&lt;/a&gt; every now and then to get the latest results!&lt;br /&gt;&lt;/p&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=21668" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/QgKrv0tDFqU" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/stats/default.aspx">stats</category><category domain="http://research.pandasecurity.com/archive/tags/news/default.aspx">news</category><feedburner:origLink>http://research.pandasecurity.com/archive/Panda-participates-in-new-AV-comparative.aspx</feedburner:origLink></item><item><title>Warning: Conficker worm infections gaining traction</title><link>http://feedproxy.google.com/~r/PandaResearch/~3/R6bRvZc8Igk/Warning_3A00_-Conficker-worm-infections-gaining-traction.aspx</link><pubDate>Mon, 12 Jan 2009 10:49:00 GMT</pubDate><guid isPermaLink="false">d7e3e9bb-5233-4678-86f9-982b9ed22d90:21437</guid><dc:creator>Pedro Bustamante</dc:creator><slash:comments>11</slash:comments><comments>http://research.pandasecurity.com/comments/21437.aspx</comments><wfw:commentRss>http://research.pandasecurity.com/commentrss.aspx?PostID=21437</wfw:commentRss><description>&lt;p&gt;We&amp;#39;re seeing quite a large number of Conficker worm infections since the start of the New Year and specially since the &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?IdVirus=204292&amp;amp;sind=0&amp;amp;sitepanda=particulares" style="font-weight:bold;"&gt;Conficker.C variant&lt;/a&gt; appeared on December 31. It seems that the return to work after the Christmas break has kick-started Conficker again. Daniel Nystr&amp;ouml;m, our Tech Support front man in Sweden, already &lt;a href="http://www.icmpecho.com/2009/01/09/conficker-worm-growing/" style="font-weight:bold;" target="_blank"&gt;noticed an increase in infections&lt;/a&gt; a few days ago.&lt;/p&gt;&lt;p&gt;As you may recall Conficker is a worm that spreads via networks and USB drives. It attempts to brute force usernames and passwords and takes advantage of Server Service vulnerability in Windows which allows for remote code execution. The worm also auto-updates itself every day from a long list of URLs so it looks like its preparing for a larger attack. &lt;/p&gt;&lt;p&gt;Checking again the &lt;a href="http://isc.sans.org/port.html?port=445" style="font-weight:bold;" target="_blank"&gt;SANS activity by port&lt;/a&gt; it&amp;#39;s obvious this is something you need to worry about:&lt;/p&gt;&lt;p&gt;&lt;img border="0" height="424" src="http://research.pandasecurity.com/blogs/images/ms08-067/portgraph2.jpg" width="600" /&gt;&lt;/p&gt;&lt;p&gt;As posted about a month and a half ago, &lt;a href="http://research.pandasecurity.com/archive/TruPrevent-stops-Conficker.A-worm-proactively.aspx" style="font-weight:bold;"&gt;TruPrevent prevents Conficker&lt;/a&gt; worm network infections proactively thanks to a new Policy Rule we pushed out to all our retail products. In addition we&amp;#39;ve added signature detection for all Conficker variants. I&amp;#39;ll post details on manually creating and pushing out TruPrevent Policy Rules on corporate networks as soon as possible.&lt;/p&gt;&lt;p&gt;As a curiosity I was travelling the other day and while connected to the WiFi network of a German airport I noticed the following Conficker worm variant trying to brute force its way into my machine:&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;img border="0" height="366" src="http://research.pandasecurity.com/blogs/images/ms08-067/netcap.jpg" width="1258" /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The Conficker worm means business so be careful out there. Some preventive steps you should be following if you haven&amp;#39;t done so already:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;If you&amp;#39;re responsible for a network, scan for vulnerable machines (using &lt;a href="http://technet.microsoft.com/en-us/security/cc184924.aspx" target="_blank"&gt;Baseline Analyzer&lt;/a&gt;, &lt;a href="http://www.nessus.org" target="_blank"&gt;Nessus&lt;/a&gt;, etc.).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Patch your servers and workstations by visiting &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank"&gt;Microsoft Security Bulletin MS08-067&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;Disinfect infected machines using &lt;a href="http://www.malwareradar.com"&gt;Malware Radar&lt;/a&gt; on networks or &lt;a href="http://www.activescan.com"&gt;ActiveScan&lt;/a&gt; for stand-alone PCs.&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.howtogeek.com/howto/windows/disable-autoplay-of-audio-cds-and-usb-drives/" target="_blank"&gt;Turn off AutoRun&lt;/a&gt; feature for USB drives on your machines (and ask your Microsoft representative for a global solution to AutoRun).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Make sure your antivirus and security solution is up-to-date on the latest version and signature database.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;img src="http://research.pandasecurity.com/aggbug.aspx?PostID=21437" width="1" height="1"&gt;&lt;img src="http://feeds.feedburner.com/~r/PandaResearch/~4/R6bRvZc8Igk" height="1" width="1"/&gt;</description><category domain="http://research.pandasecurity.com/archive/tags/malware/default.aspx">malware</category><category domain="http://research.pandasecurity.com/archive/tags/vulns/default.aspx">vulns</category><feedburner:origLink>http://research.pandasecurity.com/archive/Warning_3A00_-Conficker-worm-infections-gaining-traction.aspx</feedburner:origLink></item></channel></rss>
