PDA

View Full Version : NOD32 - v.1.1389 (20060131) - what a MONSTER!


webyourbusiness
January 31st, 2006, 04:34 PM
what a MASSIVE update! To all at Eset - GREAT WORK!! Keep it up guys and gals!

http://www.nod32usa.com/nod32-updates/updates/1185.html

Firecat
January 31st, 2006, 04:50 PM
Thanks Eset! You guys work really hard. :)

Brian N
January 31st, 2006, 04:51 PM
4 kb..

webyourbusiness
January 31st, 2006, 04:52 PM
I might be wrong, but I think this is the largest number of threats added in a single update - certainly one of the top few...

Brian N
January 31st, 2006, 04:53 PM
1.1185 had over 3000 or 4000, can't really remember, but it was huge :)

webyourbusiness
January 31st, 2006, 04:58 PM
that was before the (3) type scenario though I think.... so number of entries in the update and number of threats handled are different these days.... at least I think!

rdsu
January 31st, 2006, 05:03 PM
Excellent work, as always... ;) :thumb:

FanJ
January 31st, 2006, 05:12 PM
Great ! Thanks ! :thumb:

Firecat
January 31st, 2006, 05:17 PM
{QUOTE-> 1.1185 had over 3000 or 4000, can't really remember, but it was huge :) <-QUOTE}
This update (1.1389) seems to have about 70% of the number of signatures added in the biggest update 1.1185. This might be the second or third biggest update yet for NOD32.

Joliet Jake
January 31st, 2006, 05:45 PM
Good to know the guys are hard at work and it shows just how hard the naughty guys are working in creating viruses.

nameless
January 31st, 2006, 05:50 PM
There are a lot of entries that represent variants (e.g. lots of variants for Win32/TrojanDownloader.Agent). I wonder if one signature simply covers all the variants in some cases.

Gauthreau
February 1st, 2006, 01:14 AM
Yep. It's large. 1,370 signatures including all of the variants. Update 1.1185 had 3,818 signatures. How do I know? Simple, copy the signatures from the web page, paste them to MS Word, do a find/replace changing the "," to a ",," or whatever you want it to be, then add 1 to the total that MS Word reports that it has found and replaced. Viola! You have a quick means to tally the signatures for the update. Of course, you all knew how to do that now didn't you :)


Oh yes, good job ESET!

Neil

Capp
February 1st, 2006, 03:58 AM
Kinda gives ya chills....don't it ;D;)

Happy Bytes
February 1st, 2006, 04:13 AM
;D Hey... We only forgot to go out for lunch yesterday so this was more a accident :o ::)

pykko
February 1st, 2006, 07:11 AM
and today u'll forget to take the breakfast. :P ...an so on. ;D

Nice job ESET! Keep adding at least 500 signatures per update. :D

Mack Jones
February 1st, 2006, 08:00 AM
{QUOTE-> 1.1185 had over 3000 or 4000, can't really remember, but it was huge :) <-QUOTE}


3808 to be exact !
http://www.nod32usa.com/nod32-updates/updates/980.html

rothko
February 1st, 2006, 08:01 AM
{QUOTE-> Keep adding at least 500 signatures per update. :D <-QUOTE}

YEAH! Stop eating! We dont pay good money for our licenses for you to sit around eating!! ;)

Happy Bytes
February 1st, 2006, 08:50 AM
Just relax and take a look at the update tomorrow or day after tomorrow ;D
Let's hope that you have a stable internet connection :o ;D :o

pykko
February 1st, 2006, 09:00 AM
uuuu..... I just came from my internet provider to supply my internet connection with some kilos. ;D 512 KBS is enogh to be the first to receive the update? :P

RejZoR
February 1st, 2006, 09:01 AM
Such huge updates are usually released just before some major AV testing.
In this case most probably AV-Comparatives ;) Can't wait for the results;D

Happy Bytes
February 1st, 2006, 09:05 AM
{QUOTE-> Such huge updates are usually released just before some major AV testing.
In this case most probably AV-Comparatives ;) Can't wait for the results;D <-QUOTE}

This previous - let's call it medium sized - update has not much to do with the AV-Comparatives test. It might catch 50 or 60 threats, but it was not supposed for this test.

The bummer is coming soon - so please stay cold (shouldn't be that difficult especially if you're from europe or russia) and keep cool ;D

IBK
February 1st, 2006, 09:32 AM
{QUOTE-> This previous - let's call it medium sized - update has not much to do with the AV-Comparatives test. It might catch 50 or 60 threats, but it was not supposed for this test. <-QUOTE}

About 12 threats, to be exactly.

pykko
February 1st, 2006, 09:48 AM
I suggest to post a poll and the one who guess the number of viruses in the next update gets a prize. ;D

Happy Bytes
February 1st, 2006, 09:49 AM
{QUOTE-> About 12 threats, to be exactly. <-QUOTE}

As i wrote already - not supposed for you ;D 8)

rdsu
February 1st, 2006, 10:27 AM
You (ESET Team) are doing an excellent job to improve the detection of NOD32!!!

And seems that you (Michael Neitzel) are the person responsible of the start of that improvement... ;)

Thanks for your job!

Happy Bytes
February 1st, 2006, 10:48 AM
Last update (right now) also provides proper name detection for this mass-spammed IRCBackdoor "Breplibot" - our name: "Win32/IRCBot.PH".
This threat was anyway detected via variant detection, but due to the fact that it was spammed recently we decided to give it a proper name.

pykko
February 1st, 2006, 11:13 AM
uu..what a small update..only 8 kb. I've seen you've added a lot of HTML samples. I've sent a long while ago Trojan-Spy.HTML.Bankfraud.jz but it's not in this update. :( Do you want to submit it again?

EDITED: Sample resubmitted. :)

Happy Bytes
February 1st, 2006, 11:54 AM
{QUOTE-> EDITED: Sample resubmitted. :) <-QUOTE}

Bugger :D ;D

pykko
February 1st, 2006, 11:59 AM
This means u'll add it? ;D Or u want to say hamBUrGGER. :D

Brian N
February 1st, 2006, 12:01 PM
That's it! No more beer for HB & Pykko ;)

pykko
February 1st, 2006, 12:03 PM
no alcohol, pls. :D

Happy Bytes
February 1st, 2006, 12:28 PM
{QUOTE-> That's it! No more beer for HB & Pykko ;) <-QUOTE}

You're just playing with your birth certificate ::)

Arcticowl
February 2nd, 2006, 02:41 AM
aye, good update

it found win32.TrojanDownloader.Small.BVH.Trojan in config.exe in system32 ... good work, lads, keep it up ! :)

whistl3r
February 2nd, 2006, 03:13 AM
Maybe, they are pulling our legs and decompiled solitaire into random data and sent it as an update, to make it look like they are working :P jk


Good job team... :D

DonKid
February 2nd, 2006, 09:27 AM
{QUOTE-> YEAH! Stop eating! We dont pay good money for our licenses for you to sit around eating!! ;) <-QUOTE}

Stop eating and sleeping too.
Or maybe Eset has a dormitory there ?

honeybunny
February 2nd, 2006, 02:49 PM
{QUOTE-> Just relax and take a look at the update tomorrow or day after tomorrow ;D
Let's hope that you have a stable internet connection :o ;D :o <-QUOTE}

Where's the " bummer" ;D

Marcos
February 2nd, 2006, 03:05 PM
Well, I'm already starving. But believe me, it's worth it :-))

auriell
February 2nd, 2006, 03:59 PM
637 KB - error updating argh..... ;)

Edit: got it :)

honeybunny
February 2nd, 2006, 04:09 PM
{QUOTE-> 637 KB - error updating argh..... ;)

Edit: got it :) <-QUOTE}

Which Version 1.139 ???

auriell
February 2nd, 2006, 04:16 PM
No, it's 1.1392 :)

honeybunny
February 2nd, 2006, 04:17 PM
{QUOTE-> No, it's 1.1392 :) <-QUOTE}

But it's not the bummer HB talk about, isn't it ? :-\

IBK
February 2nd, 2006, 04:25 PM
I think it is.

honeybunny
February 2nd, 2006, 04:29 PM
Marcos ?

DonKid
February 2nd, 2006, 07:19 PM
{QUOTE-> Well, I'm already starving. But believe me, it's worth it :-)) <-QUOTE}

You´re right.
Almost a full page.
Excellent work, Eset Team.

rothko
February 2nd, 2006, 07:46 PM
wow, that is huge! nice one guys

zashita
February 2nd, 2006, 07:50 PM
{QUOTE-> But it's not the bummer HB talk about, isn't it ? :-\ <-QUOTE}
7000+ sigs added .... I think it is that one :)
Good work Eset dev. team (and HB of course)

rothko
February 2nd, 2006, 07:51 PM
{QUOTE-> 7000+ sigs added .... I think it is that one :)
Good work Eset dev. team (and HB of course) <-QUOTE}

weird that the actual size of the update wasnt over 1mb, but the content is certainly impressive!

rothko
February 2nd, 2006, 08:35 PM
in fact, just a technical question - how come this update was under 700kb yet included so much?

Meitricsu
February 2nd, 2006, 09:05 PM
NOD32 - v.1.1389 (20060131)
7.684 new signatures? God! :o

mrtwolman
February 3rd, 2006, 03:37 AM
{QUOTE-> NOD32 - v.1.1389 (20060131)
7.684 new signatures? God! :o <-QUOTE}

7682 signatures added to be exact :)

rdsu
February 3rd, 2006, 04:37 AM
;D ;D ;D

Happy Bytes
February 3rd, 2006, 04:47 AM
{QUOTE-> 7682 signatures added to be exact :) <-QUOTE}

I hope our favorite NOD32 member "Honeybunny" aka Zipfelklatscher ;) is statisfied as well :o :D ;D

rothko
February 3rd, 2006, 05:02 AM
{QUOTE-> I hope our favorite NOD32 member "Honeybunny" aka Zipfelklatscher ;) is statisfied as well :o :D ;D <-QUOTE}
how could they not be?! All that was missing was a little trumpet fanfare as the update was downloaded....future enhancement perhaps.

honeybunny
February 3rd, 2006, 06:35 AM
{QUOTE-> I hope our favorite NOD32 member "Honeybunny" aka Zipfelklatscher ;) is statisfied as well :o :D ;D <-QUOTE}

What are you talking about ? I do not use different Nicks like you ;D

So delete this wrong infos immediately !!!

Happy Bytes
February 3rd, 2006, 06:38 AM
;D ;D ;D In the rokop forum - not here ;)