Thursday, April 21, 2016
Wednesday, April 13, 2016
Why antivirus uses so much RAM – And why that is actually a good thing!
Lots of computer blogs and magazines give smart advice on how to speed up your computer by reducing the load on your hardware resources. While it is true that having a few gigabytes of free hard disk space is better than no space, the same wisdom usually isn’t true for your RAM (Random Access Memory), your computer’s super-fast short term memory.
RAM is the fastest component of your PC
To give you some numbers to work with: An old school hard disk with spinning disks (HDD) usually allows for transfer rates of around 80-160 MB/second. A newer, solid state disk (SSD) that uses memory chips similar to those of the SD-card in your camera or smartphone, provides speeds of around 200-400 MB/s. But your RAM, that can’t store memory without power on, allows for 10-20 GB/second. That’s more than 100 times faster than the hard disk!
If you were an operating system architect, where would you preferably run programs from? RAM is the obvious choice.
How Windows uses RAM
When Windows starts up, it reads all the programs that are part of the system from the hard disk and puts them into RAM. That’s the place where the CPU can access them most efficiently. The working data that is created by your programs, along with other programs, are kept in RAM. That means the more programs you start and the bigger the data you’re working with, the earlier your RAM gets maxed out.
As RAM is typically between 2 and 16 GB nowadays, it may happen that Windows requires more RAM than you physically have installed. No cause for alarm, as the developers at Microsoft were aware of that risk and introduced something called Page File. The principle is simple: Programs or data in RAM that aren’t used frequently get written down to a ‘virtual RAM’ file on the hard disk (hidden at c:\pagefile.sys). That way, you get some free extra RAM space. However, any data required from virtual RAM needs to be read from the slow hard disk before it can be used again.
This is when your computer gets significantly slower and you start scratching your head, asking yourself what happened and if your computer is maybe about to bite the dust. Don’t be concerned, it has merely started swapping data to the page file.
Good high memory usage vs. bad high memory usage
Let’s conclude what we have learned so far: RAM is fast, make use of it! Reducing memory usage from e.g. 70% down to 40% doesn’t get you any advantage, as free RAM is wasted dead material. It doesn’t save you any power nor does it provide any performance improvements. From that point of view: Make sure you’re using as much RAM as possible to get the best overall system performance.
But there’s a tipping point when it’s maxed out and Windows starts to use the page file. You can avoid Windows hitting this point frequently by making sure you have enough RAM installed. RAM is cheap to buy and a bigger RAM module is probably the easiest way to extend the lifetime of your old computer for another year or two. For example, I’m a heavy computer user but I rarely need more than 4 GB of RAM.
Why does antivirus/anti-malware software need so much RAM after all?
We often hear customers blaming our software for using too much RAM. Well, we want to detect malware. To do that, we need recognition/search patterns to compare files with our database of known threats. Those patterns (sometimes called fingerprints or signatures) are not really that big, but there is a really huge number of threats out there, and therefore we need many signatures too.
At present, the Emsisoft protection software uses more than 7 million malware signatures. To load them all into RAM, it needs a bit more than 200 megabytes. That sounds like a lot, but keep in mind that this equals a short sequence of 28 bytes on average that we can use to confirm whether a file is good or bad. To illustrate that: Imagine a text sequence of just 28 letters that must be found in a library of 1 billion books, and you are not allowed to come up with a single false detection. A malware scanner has to check 7 million signatures against each of roughly 300,000 files on your hard disk, – all within a fraction of a second!
Technically there is no way to make 7 million signatures suddenly disappear. They must be stored somewhere if you want a really good detection rate instead of an absolute minimum (as seen in Windows Defender). They also need to be accessed somewhere quickly, so they can scan every new and modified file that enters the computer. Fast enough, so you don’t even notice that something was scanned in the background. The place to do this is the RAM.
The challenge with RAM usage doesn’t only affect Emsisoft, it’s an industry-wide issue. All signature-based antivirus or anti-malware scanners naturally require a significant amount of RAM to protect your computer effectively.
An insider’s secret: Antivirus programs tend to hide their RAM usage
High memory usage is bad for marketing, but what do you do if you can’t avoid it? You hide it. There are two major techniques to make a big program look like a small one:
- Use the page file: As described earlier, Windows puts less frequently used parts of programs onto the slow hard disk. Programs can also force that process and ‘ask’ Windows to swap them to the pagefile in regular intervals. Then the Windows Task Manager shows a very low memory usage, but the price for that is regular 1-3 second ‘thinking-periods’ when you access the program. That’s the amount of time needed to read the data from the harddisk again.
Reduced memory usage
In Emsisoft Anti-Malware and Emsisoft Internet Security, you have full control over that feature. When you turn off the “Memory usage optimization” in main settings, the software doesn’t initiate swapping to the page file. This means overall system performance is likely to increase if you have enough RAM.
- Use system drivers: Windows Task Manager only shows active programs and services, but not drivers. Drivers are code modules that are loaded directly by the operating system for certain core functionality. Some anti-virus vendors load hundreds of megabytes of data in their drivers to create the illusion of low memory usage. You can spot these by summing up the memory usage of all active programs and compare that with the value of total used RAM. If there is a huge difference, something is probably hiding high memory usage from you.
As the number of threats doubles every year, why doesn’t memory usage double at the same rate?
The good thing about malware is that many samples appearing in the real world (outside labs) are very similar. There is a limited number of malware families and often samples just differ in a few bytes of data. That means we can detect large numbers of threats with fewer, but smarter signatures. Using that method, the number of required signatures for best detection don’t grow as fast as the total number of threats out there in the wild.
Conclusion: Make use of your RAM
Take some time to open the Task Manager (right-click the taskbar, select “Task Manager”) and check how much RAM you effectively use during a busy computer day. If you’re not somewhere near the physical maximum, disable the “Memory usage optimization” feature in Emsisoft protection software, to make sure you get the best possible performance.
Emsisoft protection software settings
Don’t select your antivirus/anti-malware software based on memory usage reviews, unless you are really short of memory (less than 2 GB).
Related Posts:
- An in-depth look at the Emsisoft scanner technology
- Emsisoft Anti-Malware for Server wins VB100 Award with 100%…
- Poweliks: The file-less little malware that could
- Antivirus software: Protecting your files, at the price of…
- Stable Scan Engine Update Identifies Over 6000 New PUPs
Why antivirus uses so much RAM – And why that is actually a good thing!
Thursday, March 31, 2016
Video: Meet the Emsisoft File Guard – Scanning for malware in real-time
The Emsisoft File Guard is a crucial part of the 3 layers of malware prevention built into Emsisoft Anti-Malware and Emsisoft Internet Security. It checks all files that are downloaded or run against millions of signatures of known malicious software and self-optimizes continuously, allowing for real-time protection.
Most importantly, the Emsisoft File Guard operates in the background, meaning you don’t feel the impact of its power while it is scanning dozens of files every single second. That way, it is effectively and efficiently protecting you from the worst case scenario of a malware infection by not even allowing it to occur.
In this short demonstration you can take a peek at how the Emsisoft File Guard actually works.
For the best viewing experience, a fullscreen icon (right bottom corner) is available after starting the video.
Related Posts:
- Emsisoft Emergency Kit against a badly infected system
- Video: Emsisoft Surf Protection vs malicious hosts and…
- Innovations to Emsisoft Anti-Malware 8.1
- Emsisoft wins top security award
- Zberp Banking Trojan: A Hybrid of Carberp and Zeus
Video: Meet the Emsisoft File Guard – Scanning for malware in real-time
Tuesday, March 8, 2016
Video: Emsisoft Surf Protection vs malicious hosts and phishing domains
More than ever, phishing is becoming one of the main reasons for stolen login details, emptied bank accounts and theft of other private data. The reason is simple: fake e-mails and websites are looking more and more authentic these days, so that even professionals have to examine them very closely to see if they are fake or not.
This is precisely what Emsisoft’s Surf Protection is designed for: It warns you the moment you try to access a malicious website and interecepts connections to dangerous hosts at the system level so that no data can be exchanged.
In this short video we demonstrate Emsisoft Surf Protection, which is one of the amazing features of Emsisoft Anti-Malware and Emsisoft Internet Security, works and how it can prevent malware infections.
For the best viewing experience, a fullscreen icon (right bottom corner) is available after starting the video.
Like what you see? Feel free to share the video with your friends. For even more insight into the Emsisoft Surf Protection feature, feel free to digg into this older but still valid article “Prevent malware from entering your PC with Emsisoft Surf Protection“. And don’t forget to get to subscribe our newsletter to stay on top of the latest malware threats!
Related Posts:
- Emsisoft Emergency Kit against a badly infected system
- What’s the deal with protection vs cleaning?
- ALERT: Google Drive Phishing Scam
- Emsisoft Anti-Malware & Emsisoft Internet Security…
- Preview: Emsisoft Mobile Security offers protection for your
Video: Emsisoft Surf Protection vs malicious hosts and phishing domains
A typical Skype scam attempt by a spam bot
Skype scams have been around for ages. With technology constantly evolving, one would think that chat bots get a little more convincing too. As it so happens I recently got a contact request from a nice young lady that had something very special to offer.
I thought, OK, let’s play it through once and take some screenshots of the conversation:
Complete chat dialog with a scam-chatbot on Skype
This is how it works
Obviously, Katrina Kauffman is not a real woman (or even a man), but an automated program. At this point it is unclear if the bot hijacked someone’s personal Skype account by hacking their password or if the user account was just created to fool people.
The only purpose of the bot is to convince people to provide their credit card information on a fraudulent website. The shorturl leads to a fake adult entertainment website where you are supposed to sign up to see more.
Scammer website that tries to steal your credit card information
Example 2
Just a few weeks later I have received another contact request from a lady called “dear.churchill”. It was obviously a scam bot too and looked like it was made by the same people that were behind the first one. The only ‘improvement’ I could notice was that the new version also had a proper profile image set.
The full Skype scam conversation with a bot-script.
This poor girl maybe doesn’t even know that her pictures are mis-used for scamming
Of course, this website requires your credit card detaily ONLY for age verification. Who still believes that?
How to recognize a scam-chat-bot?
- Ask any question. In the case above, the bot ignored what I was writing or asking and just kept sending me messages, trying to convince me to sign up and pay.
- Watch for behavior patterns. This bot didn’t just run a series of plain messages. It always waited for me to say something first, then posted a message back after exactly 30 seconds. When I paused, the bot paused too. When I typed more, the bot replied more.
What to do now?
If you think you have already fallen for a (suspected) Skype or credit card scam, contact your bank or credit card provider as soon as possible and ask them to cancel your card immediately. Otherwise scammers could use your credit card for purchasing goods on the Internet (or worse) and you’ll end up with a pile of debt – or even be at risk of criminal conviction.
Related Posts:
- New Skype scam uses chat bots: Fake webcam girls want your…
- Beware of these popular WhatsApp scams
- Data Breach Alert: 51 UPS Stores Affected!
- ALERT: Google Drive Phishing Scam
- ALERT: The Google Drive Phishing Scam Returns!
A typical Skype scam attempt by a spam bot
Thursday, March 3, 2016
Emsisoft – the anti-malware solution professionals and enthusiasts increasingly use
Nil Satis Nisi Optimum
(Nothing but the best is good enough)
Are we there yet? No, but due to continuous commitment to providing the very best, Emsisoft is certainly heading in the right direction, as confirmed once again by the latest AV-Comparatives independent annual IT Security Survey (PDF download).
As the questionaire shows, users rate AV-Comparatives, AV-Test and Virus Bulletin as the three most respected, trustworthy antivirus testing agencies. Emsisoft is tested by all three, AV-Test for the first time in 2016.
Our key points of this survey in a nutshell:
- According to the survey, Emsisoft is now the 7th most preferred main protection solution in Europe, steadily improving its rank and now ranked ahead of Microsoft in 8th and Symantec in 10th place.
Which anti-malware security solution do you primarily use?
- On a Worldwide scale, Emsisoft moved up one position to the 9th rank. Being a newcomer in the industry, this confirms we’re becoming well established amongst the 50 competitors.
- Participants were asked “What are the most important things in a security product?”. The most frequent answers were: 1. “Good detection rate”; 2. “Low impact on system performance”; 3. “Good offline proactive/heuristic protection”; 4. “Good online surfing protection”; 5. “Good malware removal/cleaning”. We’re proud to say that all of these are what we are specialized in.
Some more interesting general facts:
- The number of users who rely on free desktop security has fallen again in 2016. Maybe that’s because nothing is truly free?
- Almost 47% of respondents now use windows 10.
- Google Chrome and Mozilla Firefox were very close to even as the preferred browser chosen by survey participants.
Would you ask a plumber to re wire your house?
Finally, you will read in the survey that over 70% of respondents refer to themselves as either IT experts or enthusiasts. While perhaps suggesting that the survey is not necessarily representative of the average computer user, wouldn’t you take the advice of an expert in their field as a guide to which product to use, especially when it could matter to you and your business as much as it mattered to these Australian guys?
We at Emsisoft will continue to work towards the “Nil Satis Nisi Optimum” motto. Getting feedback such as in the described survey is more than enough reason why we do so.
Related Posts:
- AV-Comparatives Survey: Emsisoft #8 most common antivirus in
- Advanced+ Rating in AV-Comparatives Proactive Test – March
- 2nd out of 20: AV-Comparatives confirms huge speed…
- VB100 Award: Emsisoft ranks 2nd out of 27 in PC slowdown…
- Speedy and spot-on: Emsisoft makes the AV-Comparatives Top…
Emsisoft – the anti-malware solution professionals and enthusiasts increasingly use
Thursday, February 25, 2016
True story: Ransomware almost destroyed their tourism company
Imagine if all of your company cloud apps, financial data and security video footage – representing 10 years work – was instantly inaccessible to every single computer user in your business. It’s the stuff of nightmares, but it was all too real for a successful Australian tourism company last month.
On New Year’s Day, while most of the Western world was relaxing and celebrating, the Emsisoft team was busy fighting a very big fire – our chief technology officer (CTO) Fabian Wosar had dissected Ransom32, the first JavaScript ransomware to be unleashed on the world, and quickly reverse engineered the software to create a decrypter – free of charge as usual.
As we mentioned in our earlier blog post “Ransomware for Hire: 3 Steps to Keeping Your Data Safe“, companies risk having to reinvent man-years worth of intellectual property should their data be lost – and for thousands of companies this nightmare becomes reality every day.
Only a few weeks after we had published this blog, the IT & Compliance Manager at an Australian tourism company contacted us with a story that made our hair curl.
The malicious ransomware software hijacked the company’s cloud solutions (Dropbox and One Drive accounts), all of their financial records and security footage amongst other things – all up a total of almost 20 TB of data and 10 years’ work, which was instantly inaccessible to the company’s 500 users.
As the manager writes below, it was a ‘TRUE DISASTER, one for which we were ill-prepared…’
Read on to learn how the company responded.
Hi Fabian,
I wish to thank you for your help and support during the past week when we were hit with a RANSOMWARE virus. Your promptness in responding to our dilemma has literally saved our business!
It took us a week to find THE EXPERT and identify the virus / solution, and a further week for me to go around to every computer and reverse the damage.
I have since purchased 10 licenses of EMSISOFT due to its behaviour analysis which could have saved us from all the drama.
As you are aware this specific MALWARE scans all drives (including mapped) and in our case, a peer Windows 10 network, with all the machines storing personal files locally and group files on the server.
Our downfall was that all the PCs have shares to other data areas on other drives. ONE user clicking the Zip/EXE, therefore changed the DATA on 8 machines plus the server (via Shares). Local PCs are NOT backed up (not many do) with the server holding critical historical data.
Examples of data unusable were:
All ONLINE data shared via DROPBOX and 365 OneDrive Business for all our external agents – Currently 500 users – 2 x 1TB accounts
MYOB Account backup Zip file from last year and beyond
Legal & insurance records
Banking and other XLS files
Client marketing (PDF)
VOIP recording data
Video security footages
Website development (images)
Audit data
Tender documents / presentations (DOC, PPT)
etc., etc., etc.
Even backup data was affected
You may ask why no backup? There is, but again, it is file based / user (NAS)…e.g. \\SERVER\(N:)\User
All the client backups are “mapped” – therefore ALL copies of the files were also affected including all users’ PC File Histories saved from their respective PCs.
The server is backed up on a 3 drive rotation so by the time we found the issue they had also been copied over.A file is either on a Client PC, the NAS, PC file History, the Server or Online…..However in OUR case- ALL NO GOOD.
An archive is taken every month, so we could have gone back 6 weeks for the server data but not the live NAS backups or the 8PC current data
To retrieve all the online storage again would have taken a considerable time.OBVIOUSLY TAKING COPIES OF DATA IS NO LONGER AN OPTION…
We are currently searching for image based systems that can be both Archival and Incremental, while being able to restore to a point in time, rather than just changes in files – since the virus did change them, they were subsequently added into the backup.In ALL, 1 Server (2TB), 8 PC (100GB each), various ONLINE storage (Business -2TB and Personal – 4TB), Client NAS Storage (4TB) and 6TB of Server Backup
Totalling almost 20 TB of data, and 10 years of work – inaccessible and users unable to function … a TRUE DISASTER, one for which we were ill-prepared…
Literally, a fire would have done less damage…this is a wake-up call and one which other companies should be made aware…
Again FABIAN, we cannot thank you enough for your tireless work in combatting the data threats in which we currently live, please accept our gratitude….
ALL DATA RECOVERED – NOT A Single file missing…
Regards
[Name withheld]
IT & Compliance Manager
What you can do to prevent nightmares like that:
1. Don’t store backups on local hard drives or mapped network shares, as they can be reached by malware too.
This case study validates our observation that security is only as good as the weakest link. To reduce the impact of a (hopefully never to strike) malware attack, make sure you don’t store backups on any drives that can be reached by your local user accounts without manually entering a password.
2. Close the entry gates: Keep your systems and your programs up to date and use a good real-time protection.
Often, the weakest links are well-intentioned employees who are focused on doing a good job, but don’t realize the security risks inherent in today’s online world. To close the entry gates, top priority is keeping your operating system and all your programs always up to date (not just once in a while – always, as in ‘every day’). Also make sure you’re running a trustworthy real-time protection that catches all malicious files as they try to enter your computers. Because you know what they say: An ounce of prevention is always worth a pound of cure.
Related Posts:
- Ransomware for Hire: 3 Steps to Keeping Your Data Safe
- Warning: Dropbox and Box File Sharing Security Bug
- Special: backup software for free with your order at…
- How it’s done right: Emsisoft’s Behavior Blocker
- Protect your laptop data from theft – Here’s how
True story: Ransomware almost destroyed their tourism company