a-squared Malware-IDS
What is the Malware-IDS? How does it work?
Malware protection without signatures?
The a-squared Anti-Malware Background Guard scans all running programs with a signature scanner the same as all other antivirus guards. The scan can only detect the malware if it has the correct signature. Although the a-squared Team wish to create signatures for new malware and provide them as fast as possible via the online update, the process of creating a new signature can take a while. During this time you are not protected against new malware.
This is where our a-squared Intrusion Detection System (Malware-IDS) comes in. This is a special system which is able to detect and block malware without the need for signatures.
Behavior Analysis
Usually, Malware is detected with the help of heuristics. Heuristic scanning analyses the code in a file and decides whether or not it is harmful. The a-squared IDS works differently, as it watches any active program and stops it if it notices anything suspicious. If a program is trying to change something, you will be told immediately, and given the chance to authorize this change. If the a-squared IDS pops up a warning when you are not doing anything on your computer, you can be fairly sure that the program is working without your approval.
And this is the way it works..
Malware always wants to achieve a particular result. A virus always infects, a worm always spreads, a trojan always sends files and a dialer always dials. Their methods may differ, but the result is the same.
It is at this point that a-squared Malware-IDS interrupts the program. It analyses the behavior of all active programs, and alerts you if anything harmful is detected. The program is stopped and cannot continue until you decide whether or not to authorize the behavior.
All this probably sounds too good to be true, and there is one disadvantage: the a-squared IDS only recognizes behavior, and cannot give you the actual name of the malware in question. In other words, you will know if it's a worm, but not if it's the NetSky or Bagle worm. Of course, this doesn't really matter - the important thing is that you know it's there, and you can run the appropriate removal program.
What does it detect?
Currently the a-squared Malware-IDS can detect the following malware types:
-
Email worms
-
Spyware/Adware
-
HiJackers
-
Backdoor trojans
-
Trojan downloader with reverse connection logic
-
Dialers
-
Keylogger
-
Rootkits (v3.0)
-
Viruses (v3.0)
In addition, the a-squared Malware-IDS can monitor and stop any of the following actions:
- Installation of new drivers and services
-
Any kind of process manipulation like DLL-injection, code-injection, patching, termination, etc.
-
Installation of new BHOs (Browser Helper Objects)
-
Changes to your Internet Explorer configuration
-
Hidden installations of software (v3.0)
-
Changes to your Hosts file (redirects domains) (v3.0)
What should I do if it gives me an alert?
The Malware-IDS is a system which was designed to detect suspicious behavior. The behavior of programs and malware is sometimes very similar, so the system may give you a false alert from time to time. It is important to consider what you are doing with your computer at the time of the alert and whether you recognize the program the alert is about before clicking allow or terminate. If you are unsure you should close the program and send it to us for further analysis.
-> Read more about IDS alert messages and how to handle them
A general tip for using the Malware-IDS:
After installing a-squared, please ensure that the background guard is running. Then start your most used programs one by one so that you can tell IDS that these programs are allowed. This procedure only takes a few minutes to correctly configure IDS on your PC.
Who can I ask if I have a problem?
If you are not sure if a specific program is really dangerous, please ask our specialists at the discussion forum. Your questions will be quickly answered.











