The first results were very positive with this tool and we are actively reviewing the telemetry of our customers who use it to better understand aspects of the impact of threats from specific malware families. In addition, we invite our customers to install security updates provided by Microsoft operating systems and applications, as well as other third-party applications and all the security updates that can be provided by Internet service providers. Telemetry collected by the first release of Microsoft security scanner echoes this constant messaging.
During the first seven days of the issuance MSS, there were close to 420,000 downloads, or 60,000 downloads a day, of the product. And 'clean computers infected 20,097 in total, for users who suspect their computers were infected and downloaded MSS to scan their machines. Congratulations to these users for security awareness.
Among the findings, 7 of the top 10 threats are files that contain exploits for the vulnerabilities of Java as CVE-2008-5353, CVE-2010-0094, CVE-2010-0840 and CVE-2009-3867. (For more information about these exploits, see the blog post "Have you checked the Java?" From our colleague Holly Stewart.)
Below is a detailed table observations Microsoft security scanner in the first seven days of its release:
Threat | Threat Count | Machine Count | Note |
CVE-2008-5353 | 7,739 | 2,272 | Java Exploit |
CVE-2010-0840 | 5,387 | 2,785 | Java Exploit |
CVE-2010-0094 | 4,744 | 1,579 | Java Exploit |
OpenConnection | 3,929 | 2,396 | Java Exploit |
OpenCandy | 3,408 | 3,238 | Adware |
CVE-2009-3867 | 2,759 | 1,445 | Java Exploit |
Wimad | 1,658 | 637 | Malicious Win Media File |
Keygen | 1,287 | 1,234 | Key Generator Hacking Tool |
Mesdeh | 1,156 | 714 | Java Exploit |
OpenStream | 1,125 | 759 | Java Exploit |