PDA

View Full Version : is this possible ?!!


minacross
November 28th, 2003, 01:14 PM
I just checked the newly detected viruses pages of both the InoIT engine and the Vet engine of eTrust7 promo (Newly Detected Viruses (http://www3.ca.com/support/vicdownload/NewlyDetected.aspx))..
I just copied each one to Ms-Word and checked the document properties..
InoIT contains 1694 lines, Vet contains 1803 lines.
each line is a virus..
So, we have about 2000 newly detected viruses since the last update ??? ??? ??? ???
this is the largest newly detected amount I have ever seen ::) ::) ??? ???

Firefighter
November 28th, 2003, 03:19 PM
To Minacross from Firefighter!

Even I have just sent some 30 -35 differerent infected archives to CA, but I can't remember how many of those were new to Inoculate or VET.

Inoculate is almost perfect scanning engine as a common family use in my mind when u only admit it's limitations!


"The truth is out there, but it hurts!"

Best regards,
Firefighter!

Madsen DK
November 29th, 2003, 12:14 PM
Hi Mina. :)
I think it goes this way.
If you look at the version 23.63.34 ( that is the latest) you can see, that there is 16 new entries, if you understand what i mean.
The next update will be called 23.63.35 and so it goes.
Best regards
Ole

EDIT. This is the latest update.
23.63.34 POLY.LOG DETECTION
23.63.34 VBS/INOR.VARIANT DETECTION
23.63.34 VBS/MYSS.O DETECTION/SYSTEM CURE
23.63.34 W97M/ASSILEM.J DETECTION/CURE
23.63.34 WIN32/KILLAV.10240 DETECTION/SYSTEM CURE
23.63.34 WIN32/MIMAIL.J DETECTION/SYSTEM CURE
23.63.34 WIN32/MYSS.N DETECTION/SYSTEM CURE
23.63.34 WIN32/MYSS.O DETECTION/SYSTEM CURE
23.63.34 WIN32/MYSS.O.HOOKDLL DETECTION/SYSTEM CURE
23.63.34 WIN32/MYSS.P DETECTION/SYSTEM CURE
23.63.34 WIN32/MYSS.P.DLL DETECTION/SYSTEM CURE
23.63.34 WIN32/NORTH DETECTION
23.63.34 WIN32/NVRDOC.A DETECTION/SYSTEM CURE
23.63.34 WIN32/SDBOT.29019 DETECTION/SYSTEM CURE
23.63.34 WIN32/SOD.A DETECTION/SYSTEM CURE
23.63.34 WINNT/HACKERDEFENDER.ROOTKIT DETECTION

If you look at the Mimail j. entry it was detected on day one, but now they have added a systemcure, therefore the new entry.

minacross
November 29th, 2003, 12:20 PM
do you mean the update is cumulative ???? if it is, then eTrust detects these only 2000 viruses? ::) ::) ::)

Madsen DK
November 29th, 2003, 12:42 PM
No no they detects more, dont worry ;D
This list is the latest detected. 23.63.34. The list contains the latest 34 updates.
When they reach 23.63.99, the list starts all over again with 00. AFAIK.
Regards
Ole

Edit. Next time 63 will probably be 64, something with the engine i think, but the routine will be the same.
Perhaps some Etrust wizards can jump in to confirm or to correct me if im wrong.

groundling
November 29th, 2003, 03:43 PM
Minacross: this is for the VET engine

updated on 27/11/03 to version 5064
updated on 28/11/03 to version 5067
What was added :
Boot Sector
No Changes

Macro
Bumdoc.C
Bumdoc.D
Liar.M
Nid.G

Memory Resident
No Changes

DOS EXE and COM
No Changes

16-bit Windows
No Changes

32-bit Windows
Win32.Agobot.BU
Win32.Bumdoc.C
Win32.Startpage.V

Polysearch (Exotic)
No Changes


you can find what's been added at this site:
http://www.vet.com.au/servlet/updatediff

Update info (and just about anything else) is under view/ log viewer/ distribution events
I really like the detailled logs.

minacross
November 29th, 2003, 04:03 PM
thanx ;D