Hi all. I wonder why Symantec does not focus its research on unraveling how the rogues change their code. Polymorphic malware is a huge problem because the detection signature is not a reliable system. Malware code changes frequently and has a different signature which is not recognized as a threat… In one week I have sent more than eight samples of malware that NIS09 not detected, and if they are running on the system then they are very difficult to completely disinfect.
I think Symantec should initiate new ways of establishing their safety directives, the detection signature is outdated and easy to circumvent. I think we should take a lot of improvements based on the application behavior.
A good idea would be to create an equivalent function to a virtual machine to assess how each new program behavior, and actions carried out in the system before allowing their integration into the computer
Greetings