Do antivirus vendors create viruses?

Do antivirus vendors create viruses?


  • Total voters
    20

WinAndLinuxTutorials

Level 4
Thread author
Verified
Honorary Member
Aug 23, 2011
2,291
167
277
27
Jordan
youtube.com
:welcomewave:
Do antivirus vendors create viruses? I asked this question because I found a link on malc0de from a well known antivirus vendor, it may also be a false positive. What do you think?
 
of course they create somes and then they shout out they have the solutions against it. happened already, not all vendors do it but some.
 
  • Like
Reactions: Kent and rocky
There will be a small ammount who do of course, same goes for the silly text jokes which mobile phone companies devise in order to boost activity and revenue.
 
happened with a chinese vendor that create a malware, spreaded it, then proclaim had the signature; unfortunately for them, later the trick was discovered and the CEO was sentenced to death by the government.
 
CEO = Chief executive officer.

btw , i found out the development of this case and the truth : http://malwaretips.com/Thread-How-Chinese-AV-company-Rising-tried-to-stole-a-concurrent-technology
 
WinAndLinuxTutorials said:
:welcomewave:
Do antivirus vendors create viruses? I asked this question because I found a link on malc0de from a well known antivirus vendor, it may also be a false positive. What do you think?

Recent reports suggest that around 60.000 new pieces of malware are released daily so I doubt any security company will be able to release that amount of malware daily.
As you know there are a lot of security companies on the market and each time they spot a new threat into the wild they analyze the code and trace it back to its source.It would be very hard for a security company to release malware and hide that fact on the long term because the competition would analyze the code and trace it back to them at some point and than we would have a major news.

Ten years ago malware was mostly written by hackers wanting to test the realms of what was possible but these day the 'game' has changed , cyber criminals use malware in order to gain financial benefits so this is a very tempting activity for a lot of good programmers due to the huge possible profits.


Here is what Christian Mairoll, CEO of Emsisoft had to say on this subject in a blog post :

Christian Mairoll said:
Background
As CEO of an anti-virus company my friends and associates often ask me “Who writes all these viruses?” and hidden behind this question is the sometimes serious accusation that “You write them yourself, just to drum up business!”.

If it was only so simple… The reality is however very different. Apart from the fact that this would be morally reprehensible and also illegal, it is actually pretty easy to prove that it is technically impossible for the anti-virus companies to manufacture the sheer volume of viruses produced.

Cost/Benefit calculation
The currently produced Viruses, Trojans and Bots are the result of an enormous amount of programming work. Intentionally and unintentionally released source code only allows a rough estimate of the original effort required but one can easily assume that every new genus of Malware is the result of at least 1-3 months of programming work. New variants that are further developments of old Malware are of course easier to produce.

At Emsisoft, we add around 20,000 new Malware signatures (fingerprints) to our detection database every day, i.e. roughly half a million each month. Historical developments indicate that the number of new threats doubles each year. Emsisoft Anti-Malware currently has 5.5 million signatures in its database. This also includes many signatures that detect variants of the same Malware using generic detection, so the total number of signatures is less than the actual number of Malware programs.

If I was the CEO of an evil anti-virus company I would first need a new employee to write a Virus in the first place. I would also need someone for further development and maintenance to protect my investment by ensuring that the Virus will still run on future operating systems. Once the Virus is finally finished it would then released into the wild and entered into the detection database of our own Antivirus software.

Great! In only one month we have managed to build one new Virus – one single Virus among 500,000 others in this month.

By now, it should be clear to everyone that it simply makes no commercial sense for us to write the Viruses ourselves. The advantages obtained through detection of one extra piece of Malware against the sheer unbelievable volume released each month are simply too small. Even when the cost of hiring programmers in dumping-wage countries is very low, it is absolutely certain that no Antivirus manufacturer can afford to do this. Even all the Antivirus manufacturers in the world together would not be able to generate the current volume of new Malware.

Read more

Mikko H. Hypponen Chief Research Officer at F-Secure has made a great presentation at TEDTalks ,in the below video he explains how malware has evolved :






Do antivirus vendors create viruses?

NO.
 
Last edited:
  • Like
Reactions: Kent
They don't really have to. I mean, they could of course... but there are plenty of legitimate malicious files out in the world for them to have their work cut out for them.
 
I had no idea if they could or not, unrolled I saw this all the information in this thread.
Learnt something new. Thanks guys.:)
 
happened with a chinese vendor that create a malware, spreaded it, then proclaim had the signature; unfortunately for them, later the trick was discovered and the CEO was sentenced to death by the government.
For creating malware or for getting caught ?
 
happened with a chinese vendor that create a malware, spreaded it, then proclaim had the signature; unfortunately for them, later the trick was discovered and the CEO was sentenced to death by the government.
Why sentenced to death for creating maleware?
 
BIG BIG NO because blackhat hackers make viruses for
1. make money
2.steal confidential files on your comp and sell to advertisers
3. or simply they want to destroy and cause damages on your pc

and it makes no sense making viruses and spreading it for money "i break it i fix it" makes no sense and making a unique and undetectable virus takes a long time to finish