Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

UPDATES - January 10, 1006

Jan 9, 2006 7:02PM PST

Discussion is locked

- Collapse -
AntiVir VDF-Version: 6.33.00.109
Jan 9, 2006 7:20PM PST
- Collapse -
AntiVir VDF-Version: 6.33.00.110 (2)
Jan 9, 2006 7:27PM PST
- Collapse -
AntiVir VDF-Version: 6.33.00.111 (3)
Jan 9, 2006 8:52PM PST
- Collapse -
AntiVir VDF-Version: 6.33.00.112 (4)
Jan 10, 2006 12:04AM PST
- Collapse -
Tauscan
Jan 9, 2006 7:33PM PST
- Collapse -
ewido #1643
Jan 9, 2006 7:47PM PST
- Collapse -
ewido #1644
Jan 9, 2006 10:35PM PST
- Collapse -
F-Prot
Jan 9, 2006 8:03PM PST

Application/Script viruses and Trojans 10 Jan 2006
Document/Office/Macro viruses 6 Jan 2006
The latest versions of F-Prot Antivirus can detect a total of 228956 worms, viruses and other malicious programs with these latest virus signature files.
http://www.f-prot.com/products/currentversions.html

- Collapse -
BOClean FILEDATE: 01/10/06 - 07:00:20 (US EST)
Jan 9, 2006 8:21PM PST
FILEDATE: 01/10/06 - 07:00:20 (US EST) (12:00:20 UTC)
FIFTEEN new nasties today for a total of 9861 UNIQUE trojans (68,708 trojans, worms, rootkits, adware, spyware, keyloggers, "dialers" and other malware in total, including all variants) covered in today's update for BOClean 4.12 and BOClean 4.20.
http://www.nsclean.com/update.html
- Collapse -
IE-SPYAD & AGNIS Lists Updated (Jan. 10, 2006)
Jan 9, 2006 8:28PM PST
quote


Hi All:

IE-SPYAD (the IE Restricted zone list) and AGNIS (the AtGuard/NIS/NPF/Outpost/AdShield ad block list) have been updated again. They can be downloaded from:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

The ''original'' IE-SPYAD includes an install/uninstall utility. IE-SPYAD for ZonedOut requires the ZonedOut utility from FunkyToad:

http://www.funkytoad.com/zonedout.htm

The AGNIS block lists are compatible with AtGuard 3.x and ALL versions of NIS as well as NPF 2003 and 2004. There are separate versions AGNIS for users of Agnitum Outpost and AdShield.

If you're running any of the most recent versions of NIS or NPF, you must use the ProWAGoN utility written by Christian Haagensen to load, remove, and backup block lists:

https://netfiles.uiuc.edu/ehowes/www/resource.htm#prowagon

If you have questions or comments about IE-SPYAD or any of the AGNIS lists, please don't hesitate to let me know.

Best,

Eric L. Howes
eburger68@myrealbox.com
end quote

Please remember to re-immunize with SpywareBlaster & Spybot S&D.
Some items considered non-threats or defunct are disabled by IE-Spyad.
- Collapse -
Panda
Jan 9, 2006 10:23PM PST
- Collapse -
Thanks, but.....
Jan 9, 2006 10:43PM PST

.....I got all these updates a thousand years ago. [G]

- Collapse -
(NT) (NT) These updates were all released today.
Jan 9, 2006 11:02PM PST
- Collapse -
Windows Malicious Software Removal Tool
Jan 9, 2006 10:54PM PST
Windows Malicious Software Removal Tool <-- Download from Microsoft

File Name: Windows-KB890830-V1.12-ENU.exe
Version: 1.12
Date Published: 1/10/2006
Language: English
Download Size: 1.1 MB
Estimated Download Time: 3 min 56K

]Notes:

You may also get the updated version from Windows Update, Microsoft Update websites or by using Windows' Automatic Updates functionality.

Online version of the above tool is available in:
http://www.microsoft.com/security/malwareremove/default.mspx

If you prefer to run the tool more than once, it is recommended to download the tool or run the online version.

Please be aware that this tool reports anonymous information back to Microsoft in the event that an infection is found or an error is encountered. The below Microsoft KB article contains how to disable this functionality and what specific information is sent to Microsoft.

This tool is not a replacement for an anti-virus product. To help protect your computer, you should use an anti-virus product.

To use the tool, you must log on to the computer by using an account that is a member of the Administrators group. After you accept the one-time EULA, you can receive future versions of the tool without being logged on to the computer as an administrator.

The tool creates a log file named mrt.log in the %WINDIR%\debug folder.

Any malicious software that is not listed in below Microsoft KB article is not detected and not] removed by the tool. To scan for and remove other malicious software, use an up-to-date antivirus product.


More info in Microsoft KB890830
- Collapse -
Donna, I downloaded & installed via automatic update
Jan 10, 2006 5:17AM PST

Does the Removal Tool scan my pc without any further action on my part? If so, I never get any response after I install it. Guess that means my pc is clean. Happy

- Collapse -
(NT) (NT) That is correct Harv. You should be fine.
Jan 10, 2006 5:34AM PST
- Collapse -
Harv, maybe I am missing something...
Jan 10, 2006 6:02AM PST

From your question, but yes you do get something. Here is my procedure.

1. Save to disk.
2. Click the file.
3. Window appears and you follow the prompts.
4. When finished it gives a report.

Maybe I missed the point of your question but this is what I get.

Hope this helps.

Glenn

- Collapse -
There are 3 different ways to do this
Jan 10, 2006 6:19AM PST

1. You download the tool and save it to disk which so you can scan with it whenever you want. That is the way YOU and I both do it Glenn. That is this link.
http://www.microsoft.com/downloads/details.aspx?familyid=ad724ae0-e72d-4f54-9ab3-75b8eb148356&displaylang=en

2. Download it via Windows/Microsoft Update and it scans silently and you only get notice if you are infected. That is the way that Harv does it.

3. Do an online scan with it. That is this link.
http://www.microsoft.com/security/malwareremove/default.mspx

- Collapse -
Actually, I think the manual scan is preferable.
Jan 10, 2006 8:07AM PST

I have Microsoft Security set up to automatically alert me, whenever new patches are available. If I decide to d/l and install after viewing them, I don't have the option of Saving to Disk.

As I mentioned in the subject title, I would rather do a manual install and then scan my pc and get immediate confirmation whether it is clean or not. The method I've been using always left me in doubt as to the security status of my pc.

Thanks for your help you guys. Happy

- Collapse -
I agree Harv which is why I do it
Jan 10, 2006 8:17AM PST

manually. It's a different link that BOTH Donna and I posted earlier and you can still get it if you want it even though you did it through Windows Updates. I save it each month and I delete the previous one after I download the new one because the new one has ALL the detections included incuding the old ones. You get the same result whichever of the 3 ways that you do it but I prefer to have control over it. Here is the manual download link again if you care to do that Harv. Just save it to a place that you will remember and double click on it whenever you want to use it. Happy
http://www.microsoft.com/downloads/details.aspx?familyid=ad724ae0-e72d-4f54-9ab3-75b8eb148356&displaylang=en

- Collapse -
Manual scan indicates a clean machine. :-)
Jan 10, 2006 11:28AM PST

Thanks for the link, roddy. Do I return to this same site for the download when it gets updated?

- Collapse -
Yes Harv and the new version
Jan 10, 2006 7:09PM PST

is usually released a few hours before the regular Windows Updates are on the morning of the same day. Glad you were clean. Happy

- Collapse -
TrojanHunter Ruleset update: 4xx-2006-01-09
Jan 9, 2006 11:00PM PST

An updated TrojanHunter ruleset, containing 41540 ruleset entries, is available. This update adds 186 new trojan definitions:

Agent.423
Agent.422
Agent.421
Agobot.215
Agobot.214
Agobot.213
AphexSpy.100
Bandito.128
BAT.KillFiles.101
BiFrose.132
BiFrose.131
BiFrose.130
Codbot.136
CX2.100
Delf.175
Delf.174
Delf.173
Delf.172
Dragonbot.101
Dumador.112
EggDrop.173
IRCBot.174
IRCBot.173
IRCBot.172
IRCBot.171
Keylogger.SC.225
Landis.103
Leniv.100
Monitor.Ardamax.117
NinjaSpy.100
PcClient.120
PG.100
ProAgent.127
Protux.100
PWSteal.Agent.122
PWSteal.Delf.107
PWSteal.Delf.106
PWSteal.Hangame.101
PWSteal.LdPinch.117
PWSteal.Lineage.122
PWSteal.Maha.102
PWSteal.Maha.101
PWSteal.Sagic.104
TrojanClicker.Small.115
TrojanDownloader.Agent.298
TrojanDownloader.Agent.297
TrojanDownloader.Banload.174
TrojanDownloader.PassAlert.119
TrojanDownloader.PassAlert.118
TrojanDownloader.PassAlert.117
TrojanDownloader.PassAlert.116
TrojanDownloader.Small.219
TrojanDownloader.VB.126
TrojanDropper.Agent.169
TrojanDropper.Agent.168
TrojanDropper.Agent.167
TrojanDropper.Delf.150
TrojanDropper.Small.146
TrojanDropper.VBS.Inor
TrojanProxy.Small.109
TrojanSpy.Banbra.124
TrojanSpy.Bancos.160
TrojanSpy.Bancos.159
TrojanSpy.Banker.260
TrojanSpy.Banker.259
TrojanSpy.Banker.258
TrojanSpy.Banker.257
TrojanSpy.Delf.111
TrojanSpy.Outside.120
TrojanClicker.Small.114
TrojanDownloader.Delf.153
TrojanDownloader.Delf.152
TrojanDownloader.Delf.151
TrojanDownloader.Harnig.112
TrojanDownloader.Qoologic.116
TrojanDownloader.Small.218
TrojanDownloader.Small.217
TrojanDownloader.Small.216
TrojanDownloader.Small.215
TrojanDownloader.VB.125
TrojanDownloader.VB.124
TrojanDownloader.WMS.103
TrojanDropper.Cool.100
TrojanDropper.Joiner.108
TrojanDropper.Junta.109
TrojanDropper.Junta.108
TrojanDropper.Pakes.102
TrojanDropper.SE.100
TrojanDropper.Small.145
TrojanProxy.Agent.132
TrojanProxy.Inspir.100
TrojanSpy.Agent.120
TrojanSpy.Agent.119
TrojanSpy.Agent.118
TrojanSpy.Banker.256
TrojanSpy.Goldun.123
TrojanSpy.Hookit.100
TrojanSpy.IAmBigBrother.101
TrojanSpy.KaiserLog.100
TrojanSpy.KeyGhost.100
TrojanSpy.Keylogger.111
TrojanSpy.RemoteKeyLog.100
TrojanSpy.Small.114

(list too long)

Licensed TrojanHunter users can easily update using TrojanHunter's LiveUpdate utility. If you are using the trial version of TrojanHunter, please see http://www.misec.net/trojanhunter/updating/ for instructions on how to update to the latest ruleset.
http://forum.misec.net/board/RulesetUpdates/1136901011

Note: The date on this is the 9th but it was just posted at the website and I believe the date was posted wrong and it should be the 10th.

- Collapse -
TrojanHunter Ruleset update: 4xx-2006-01-09 (2)
Jan 10, 2006 6:40AM PST
- Collapse -
NOD32 - 1.1358 (20060110) / posted 11:17AM)
Jan 9, 2006 11:16PM PST
Virus signature database updates:
IRC/SdBot (2), Win32/Adware.Look2Me (6), Win32/Adware.SpySheriff, Win32/Agent.C (4), Win32/Agent.JK, Win32/Agent.NAG (2), Win32/Agent.OZ (4), Win32/Anker.T (2), Win32/Aprel.B, Win32/Bagle.CR, Win32/Bagle.CS, Win32/Bagle.CT, Win32/Bagle.EU, Win32/Bropia (2), Win32/Combra.F, Win32/Combra.G, Win32/Combra.NAC, Win32/Dedler.AA (2), Win32/Delf.WH (2), Win32/Dialer.DialHub, Win32/DoS.VB.Q (2), Win32/Faker.U (2), Win32/Fluzer.A (2), Win32/Guap.I (2), Win32/Guap.NAA, Win32/Harwig.AC (2), Win32/Hoax.SpyWare.A, Win32/Hupigon, Win32/IRCBot.OO, Win32/Kelvir (3), Win32/Lewor.NAC (2), Win32/Lewor.NAD, Win32/Locksky.X (9), Win32/Maslan.F (5), Win32/Mocalo.D (3), Win32/Mofei.Q, Win32/Monikey.H (4), Win32/Monikey.NAA, Win32/Mydoom.BO, Win32/Mytob.OD (2), Win32/Mytob.OE (2), Win32/Nanspy.G, Win32/Nucleroot.A (3), Win32/Oleloa (2), Win32/Oleloa.I, Win32/Opanki.BG, Win32/Opanki.BH, Win32/Opanki.BI, Win32/Opanki.BJ, Win32/Plexus.NAA, Win32/PSW.Delf.IP (4), Win32/PSW.LdPinch, Win32/PSW.LdPinch.RG, Win32/PSW.Legendmir.APN, Win32/Qhosts (3), Win32/Rbot, Win32/Savage.NAA, Win32/Silva.E (3), Win32/Small.GA, Win32/Small.NAG (2), Win32/Small.NAH (8), Win32/Spy.Bancos.OB (2), Win32/Spy.Banker (4), Win32/Spy.VB.FP, Win32/SpyBot, Win32/TrojanClicker.Delf.CU, Win32/TrojanDownloader.Agent.BQ (4), Win32/TrojanDownloader.Agent.WO, Win32/TrojanDownloader.Banload.QH (2), Win32/TrojanDownloader.Dadobra.IL, Win32/TrojanDownloader.Delf.NCB (2), Win32/TrojanDownloader.Delf.YJ, Win32/TrojanDownloader.IstBar, Win32/TrojanDownloader.Small.CDY (3), Win32/TrojanDownloader.VB.UV (2), Win32/TrojanDownloader.Zlob.AP, Win32/TrojanDropper.Delf.BW (2), Win32/TrojanDropper.Oleloa, Win32/TrojanDropper.VB.NAN, Win32/TrojanProxy.Inspir.12 (2), Win32/VB.NBR, Win32/VB.NDQ (7), Win32/VB.NEH (2), Win32/Zafi.F
http://www.nod32.ch/en/news/update.php
- Collapse -
NOD32 - 1.1359 (20060110) / posted 22:33) (2)
Jan 10, 2006 6:12AM PST
[COLOR=blue] [/COLOR]
Virus signature database updates:
Abba.9849.B, Adindin.1588 (2), Adindin.1654 (2), Adindin.1976, Adindin.1990, AEP.626.A, AEP.626.B, AEP.626.C, Alarm.1820, Alladin.1827, Andromeda.594, Anticom.8359 (2), AntiMIT.800, AntiMIT.806, ARCV.255 (2), ARCV.330.B, Arjworm, AusIH.823, Backfont.847, Backsu.3152, Backsu.3189, Backsu.3192, Bashar.670, Bashar.671, Bashme.6570, Bashme.6771, Bashme.6785, BitAddict.477, Black_Jec.358.D, Blood.418.Damaged, BMBB.766, Boojum.334, Burger.560.AV, Burma.442.A, Burma.442.H, Burma.442.L, Burma.442.P (2), Burma.563.A, Burma.756, Caesar.655, Caesar.755, Cancerbero.1000.C, Cancerbero.670, Cascade.1701, Cezar.4570, Cezar.4626, Cheeba.1434, Cheeba.1690, Cheeba.1699, Clawfinger.2444, CNTV.2630, CodeBreakers.307.Intended, Conner.239, Connie.2835, Copyleft.4772, Datacrime.1280.A.Damaged, Datacrime.1514.A, Dauq.1537, Dauq.2465, Deadhead.1000.A, Deadhead.1000.B, Deadhead.1000.C, Deadman.272, Deathboy.893.Packed, Deathboy.912.Packed, Dev.138, Devastator.512.A, Devastator.512.B, Devastator.512.C, Diamond.1173, Die_Hard.4000.K, Die_Hard.4000.N, DIR-II.1024.AK, DIR-II.1024.AL, DIR-II.1024.AO, DIR-II.1024.E, DIR-II.1024.I (2), DIR-II.1024.L, DIR-II.1024.N, Direct.351.A (2), Direct.351.B (2), Dracula.827, ExeHeader.GhostDog.389.Damaged, Win32/Aimdes.E, Win32/DelAll.O, Win32/Dongdor.NA (3), Win32/Dumador, Win32/HideProc.D, Win32/IRCBot.OV, Win32/IRCBot.PS, Win32/Locksky.Y (8), Win32/Locksky.Z (8), Win32/Modobot.I (3), Win32/Mytob.OF (2), Win32/Oleloa.I (3), Win32/PSW.Agent.NAG (4), Win32/Rootkit.Agent.AD, Win32/Rootkit.Agent.AN (4), Win32/Rootkit.Agent.AT (4), Win32/Spy.Banbra.DT (2), Win32/Spy.Banker (2), Win32/Spy.Delf.MQ (5), Win32/Spy.Goldun.NF (3), Win32/Spy.VB.JM (3), Win32/TrojanDownloader.Agent.UF (4), Win32/TrojanDownloader.Banload.NAG (2), Win32/TrojanDownloader.PassAlert.K, Win32/TrojanDownloader.Small.ARJ, Win32/TrojanDownloader.Tiny.AM, Win32/TrojanDownloader.VB.NX, Win32/TrojanDropper.Oleloa.I, Win32/TrojanDropper.Small.ABM (2), Win32/TrojanDropper.Small.AJN (2), Win32/TrojanProxy.Ranky, Win32/VB.NDV (3)
http://www.nod32.ch/en/news/update.php
- Collapse -
ClamWin AV v0.88
Jan 10, 2006 12:52AM PST
- Collapse -
New AVG Anti-Virus 7 Update - AVI 267.14.17 / IAVI 0226
Jan 10, 2006 1:25AM PST

--- AVG Anti-Virus Update ---
(1/10/2006)

********************************
** AVG Anti-Virus 7 **
********************************

--- information about Update ---

Update Summary:

- added new variants of I-Worm/Locksky
- added new variants of trojan Downloader.Zlob

- Collapse -
NAV Daily
Jan 10, 2006 2:51AM PST
- Collapse -
McAfee Daily #4671
Jan 10, 2006 3:03AM PST