Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

UPDATES - December 20, 2005

Dec 19, 2005 7:06PM PST
BOClean FILEDATE: 12/20/05 - 05:15:45 (US EST) (10:15:45 GMT/UTC)
FOUR new nasties today for a total of 9492 UNIQUE trojans (65,499 trojans, worms, rootkits, adware, spyware, keyloggers, "dialers" and other malware in total, including all variants) covered in today's update for BOClean 4.12 and BOClean 4.20.
http://www.nsclean.com/update.html

Discussion is locked

- Collapse -
ewido #1586
Dec 19, 2005 7:17PM PST
- Collapse -
ewido #1587
Dec 20, 2005 3:07AM PST
- Collapse -
TrojanHunter Ruleset update: 4xx-2005-12-20
Dec 19, 2005 7:38PM PST

An updated TrojanHunter ruleset, containing 36075 ruleset entries, is available. This update adds 62 new trojan definitions:

TrojanDownloader.AdLoad.105
SDBot.329
SDBot.328
Agent.360
Agent.359
Agent.358
Agent.357
TrojanDownloader.Agent.216
TrojanDownloader.Agent.215
TrojanDownloader.Agent.214
TrojanDownloader.Agent.213
TrojanProxy.Agent.124
Agent.356
TrojanDropper.Agent.128
PWSteal.Agent.100
TrojanDownloader.Agent.212
Agent.355
Rootkit.Agent.103
TrojanSpy.Agent.105
TrojanSpy.Agent.104
TrojanDropper.Agent.127
TrojanDropper.Agent.126
TrojanDropper.Agent.125
TrojanDropper.Agent.124
TrojanDropper.Agent.123
TrojanDownloader.Agent.211
TrojanProxy.Agent.123
TrojanProxy.Agent.122
TrojanDownloader.Agent.210
TrojanDownloader.Agent.209
TrojanDownloader.Agent.208
TrojanDownloader.Agent.207
TrojanDownloader.Agent.206
TrojanDownloader.Agent.205
TrojanDownloader.Agent.204
TrojanDownloader.Agent.203
TrojanDownloader.Agent.202
TrojanDownloader.Qoologic.101
TrojanSpy.Goldun.108
TrojanDownloader.Small.147
StartPage.115
TrojanDownloader.Small.146
KLog.SCLog.227
TrojanSpy.Banker.129
TrojanSpy.Agent.103
TrojanSpy.Banbra.102
TrojanSpy.Goldun.107
KLog.SCLog.226
KLog.SCLog.225
TrojanSpy.Delf.101
Worm.Mydoom.104
TrojanSpy.Banbra.101
TrojanSpy.Goldun.106
TrojanSpy.Qukart.100
TrojanSpy.Banker.128
TrojanSpy.Banker.127
TrojanSpy.Banker.126
TrojanSpy.Banker.125
TrojanSpy.Banker.124
TrojanSpy.Banker.123
TrojanSpy.Banker.122
Banker.126

Licensed TrojanHunter users can easily update using TrojanHunter's LiveUpdate utility. If you are using the trial version of TrojanHunter, please see http://www.misec.net/trojanhunter/updating/ for instructions on how to update to the latest ruleset.


Please confirm false positives removed. Any problems please also send the alarming files to gavin (AT) misec.net
http://forum.misec.net/board/RulesetUpdates/1135068181

Note: Please see above link about the difference in the numbers.

- Collapse -
TrojanHunter Ruleset update: 4xx-2005-12-20 (2) (2nd update)
Dec 19, 2005 9:27PM PST

Ruleset update: 4xx-2005-12-20 (2)

An updated TrojanHunter ruleset, containing 36129 ruleset entries, is available. This update adds 27 new trojan definitions:

TrojanProxy.Agent.125
IM-Worm.Silewar.100
IM-Worm.Vampa.101
IM-Worm.Vampa.100
TrojanDropper.Joiner.101
TrojanDownloader.Vidlo.101
TrojanDownloader.Qoologic.103
TrojanDownloader.Qoologic.102
TrojanDownloader.Mediket.101
TrojanDownloader.Delf.104
Worm.Sober.129
Worm.Sober.128
Worm.Sober.127
Worm.Sober.126
Worm.Sober.125
Worm.Sober.124
Worm.Sober.123
Worm.Sober.122
Worm.Sober.121
Worm.Sober.120
Worm.Sober.119
Worm.Sober.118
Worm.Sober.117
Worm.Sober.116
Worm.Sober.115
Worm.Sober.114
Worm.Sober.113

http://forum.misec.net/board/RulesetUpdates/1135080695

- Collapse -
avast!
Dec 19, 2005 7:50PM PST
- Collapse -
avast! (2)
Dec 20, 2005 1:05PM PST
- Collapse -
AntiVir VDF-Version: 6.33.00.40
Dec 19, 2005 7:51PM PST
- Collapse -
AntiVir VDF-Version: 6.33.00.41 (2)
Dec 19, 2005 9:17PM PST
- Collapse -
AntiVir VDF-Version: 6.33.00.42 (3)
Dec 19, 2005 10:22PM PST
- Collapse -
AntiVir VDF-Version: 6.33.00.43 (4)
Dec 20, 2005 12:50AM PST
- Collapse -
IE-SPYAD & AGNIS Lists Updated (Dec. 20, 2005)
Dec 19, 2005 8:03PM PST

[QUOTE]
Hi All:

IE-SPYAD (the IE Restricted zone list) and AGNIS (the AtGuard/NIS/NPF/Outpost/AdShield ad block list) have been updated again. They can be downloaded from:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

The "original" IE-SPYAD includes an install/uninstall utility. IE-SPYAD for ZonedOut requires the ZonedOut utility from FunkyToad:

http://www.funkytoad.com/zonedout.htm

The AGNIS block lists are compatible with AtGuard 3.x and ALL versions of NIS as well as NPF 2003 and 2004. There are separate versions AGNIS for users of Agnitum Outpost and AdShield.

If you're running any of the most recent versions of NIS or NPF, you must use the ProWAGoN utility written by Christian Haagensen to load, remove, and backup block lists:

https://netfiles.uiuc.edu/ehowes/www/resource.htm#prowagon

If you have questions or comments about IE-SPYAD or any of the AGNIS lists, please don't hesitate to let me know.

Best,

Eric L. Howes
eburger68@myrealbox.com
[/QUOTE]

Please remember to re-immunize with SpywareBlaster & Spybot S&D.
Some items considered non-threats or defunct are disabled by IE-Spyad.

- Collapse -
Tauscan
Dec 19, 2005 8:06PM PST
- Collapse -
NOD32 - 1.1329 (20051220) / posted 08:18)
Dec 19, 2005 8:31PM PST
Virus signature database updates:
Win32/Agent.NAK, Win32/DelAll.N, Win32/Delf.AKR (2), Win32/Locksky, Win32/PassView.1_62, Win32/Spy.Delf.LW, Win32/Tivso.A (3)
http://www.nod32.ch/en/news/update.php

Note: Date is posted wrong at the website.
- Collapse -
NOD32 - 1.1330 (20051220) / posted 13:38) (2)
Dec 19, 2005 9:10PM PST

NOD32 antivirus system information
Virus signature database version: 1.1330 (20051220)
Dated: Tuesday, December 20, 2005
Virus signature database build: 6483

Virus signature database updates:
IRC/SdBot, Win32/Agent.RX, Win32/Bagle.DR, Win32/Delf.AKN, Win32/Delf.AKR (3), Win32/Downloader.ImLoader.B, Win32/Mole (2), Win32/PSW.Hangame.F (2), Win32/Rbot, Win32/Spy.Asher, Win32/Spy.Asher.D, Win32/Spy.Banker.NHC (2), Win32/Spy.Small.EB (4), Win32/Tivso.A (3), Win32/Tivso.B (4), Win32/TrojanDownloader.Agent.ABJ, Win32/TrojanDownloader.Quyl.A (3), Win32/TrojanDownloader.Zlob, Win32/TrojanDropper.Agent.NE (2), Win32/TrojanDropper.Small.NCU, Win32/TrojanDropper.Small.NCY, Win32/TrojanDropper.Small.NCZ (2), Win32/VB.ACL (2)

http://www.nod32.ch/en/news/update.php

- Collapse -
NOD32 - 1.1331 (20051220) / posted 23:07) (3)
Dec 20, 2005 6:23AM PST
Virus signature database updates:
Linux/Phobi.A, Win32/Agent.QS, Win32/Bagle.EG (2), Win32/Bagle.EH (2), Win32/Brontok.AO (2), Win32/Lasiaf.I (2), Win32/Locksky.N (8), Win32/Rbot, Win32/Small.GA, Win32/Spy.Bancos.U (2), Win32/Spy.Banker (2), Win32/Spy.Luhn.A (2), Win32/TrojanDownloader.Agent.BQ (3), Win32/TrojanDownloader.IstBar, Win32/TrojanDownloader.Small.BUY (2), Win32/Tsipe.AG, Win32/Tsipe.AH
http://www.nod32.ch/en/news/update.php
- Collapse -
AIMFix
Dec 19, 2005 8:32PM PST
- Collapse -
a-squared signature redo 12/20/2005
Dec 19, 2005 10:11PM PST

Downloading Signature update 12/18/2005 ...
1766 Signatures: 1532 Trojans, 24 Dialers, 48 Worms and 162 Spywares

Downloading Signature update 12/19/2005 ...
17141 Signatures: 14542 Trojans, 463 Dialers, 769 Worms and 1367 Spywares
http://forum.emsisoft.com/viewtopic.php?p=21191#21191

Note: old date.
Andreas Haak wrote:
If that happens it just means we have removed or changed some signatures of an earlier update cause they produced false positives. Nothing special.

- Collapse -
a-squared signature redo (2nd)
Dec 20, 2005 2:12AM PST

Downloading Signature update 10/06/2005 ...
149363 Signatures: 95266 Trojans, 38556 Dialers, 10561 Worms and 4980 Spywares

Downloading Signature update 10/07/2005 ...
2278 Signatures: 1977 Trojans, 35 Dialers, 83 Worms and 183 Spywares

Downloading Signature update 10/12/2005 ...
408 Signatures: 350 Trojans, 10 Dialers, 13 Worms and 35 Spywares

Downloading Signature update 11/15/2005 ...
655 Signatures: 530 Trojans, 10 Dialers, 46 Worms and 69 Spywares

Downloading Signature update 11/19/2005 ...
350 Signatures: 318 Trojans, 1 Dialers, 10 Worms and 20 Spywares

Downloading Signature update 12/19/2005 ...
17111 Signatures: 14541 Trojans, 463 Dialers, 740 Worms and 1367 Spywares

[quote]
Note: old date.
Andreas Haak wrote:
If that happens it just means we have removed or changed some signatures of an earlier update cause they produced false positives. Nothing special.
[/quote]
http://forum.emsisoft.com/viewtopic.php?p=21204#21204

- Collapse -
(NT) (NT) A Squared is driving me crazy! ;) ;)
Dec 20, 2005 3:23AM PST
- Collapse -
Me too, I have to post these updates
Dec 20, 2005 4:23AM PST

all over the internet at various security websites with screenshots everywhere but here. The forum software doesn't support those here unless I just post a link. That takes some time to post them all over. LOL

- Collapse -
a-squared signature redo (3rd) and a new one 12/20/2005
Dec 20, 2005 5:20AM PST
- Collapse -
And another redo from the 12/20/2005 update (4)
Dec 20, 2005 7:20AM PST
- Collapse -
(NT) (NT) Is that it for the "do-overs" today? :-D
Dec 20, 2005 7:34AM PST
- Collapse -
(NT) (NT) They are in Europe so it is tomorrow there now. :)
Dec 20, 2005 7:46AM PST
- Collapse -
F-Prot
Dec 19, 2005 11:05PM PST
Latest virus signature files:
Application/Script viruses and Trojans 20 Dec 2005
Document/Office/Macro viruses 19 Dec 2005
The latest versions of F-Prot Antivirus can detect a total of 225238 worms, viruses and other malicious programs with these latest virus signature files.
http://www.f-prot.com/products/currentversions.html
- Collapse -
Panda
Dec 19, 2005 11:17PM PST
- Collapse -
McAfee Daily #4654
Dec 20, 2005 2:53AM PST
- Collapse -
Update AVG 7.1 - AVI 267.14.2/ 208
Dec 20, 2005 2:59AM PST
- Collapse -
NAV Daily and Weekly
Dec 20, 2005 4:15AM PST
Daily Updates
Virus Definitions created December 20
Virus Definitions released December 20
Defs Version: 71220i
Sequence Number: 50596
Extended Version: 12/20/2005 rev. 9
Total Viruses Detected: 71950

Weekly Updates
Virus Definitions created December 20
Virus Definitions released December 20
Defs Version: 71220i
Sequence Number: 50596
Extended Version: 12/20/2005 rev. 9
Total Viruses Detected: 71950
http://www.symantec.com/avcenter/download.html

New detections added for this release (5):
Threat Severity Type Discovered
PWSteal.Tarno.Q Category 1 Trojan Horse 12-19-2005
Trojan.Lodear.G Category 2 Trojan Horse 12-20-2005
Trojan.Lodeight.A Category 1 Trojan Horse 12-20-2005
W32.Beagle.CZ@mm Category 1 - -
W32.Dasher.D Category 2 Worm 12-19-2005
http://www.symantec.com/avcenter/defs.added.html
- Collapse -
NAV Daily & Weekly Updates (2)
Dec 20, 2005 1:21PM PST