May 23, 2008

BEHAVIOUR BLOCKING

· 0 comments

BEHAVIOUR BLOCKING Means strategies to monitor, that programs do notperform illegal operations during execution of programs.BOOT SECTOR VIRUS Means a virus, which replicates on boot sectors offloppy disks and/or on boot and/or partition sectors of hard disks.CMOS MEMORY FAILURE Means a situation where a computer's CMOS memory'scontent is changed by malicious program code. Execution of some maliciousprogram code may cause CMOS memory failures.COMPUTER VIRUS Means program code, which has a capability to replicaterecursively by itself. Computer viruses may include operations, which aretypical for Trojan horses and malicious toolkits, but this does not makeviruses as Trojan horses or malicious toolkits.DROPPER Means a trojan horse or a malicious toolkit, which installs avirus.FALSE ALARM Means a situation, where an antivirus product announces thatit has found a virus, when in reality there is no virus on the announcedobject.FILE VIRUS Means a virus, which replicates on executable files.FIRST GENERATION VIRUS Means the first replication generation of a virus.Often viruses are distributed as a known sample containing a firstgeneration virus and sometimes later replicates of a virus are differentfrom the first generation. A first generation virus can be, but does notneed to be, a dropper.HANGING Means a situation where a computer is halted. Execution of somemalicious code may cause hanging because of poor quality in maliciousprogram code, compatibility problems or on purpose.HEURISTIC SCANNING Means computer virus searching strategies, which aimfor finding unknown viruses by recognising virus specific behaviour inprogram code.IMAGE FILE a bit to bit image of a hard disk or a floppy diskette.integrity checking Means strategies to verify that integrity of desiredsystem areas has not been violated.INTENDED VIRUS Means program code, which has been designed to work like avirus, but for some reason the program code is not able to replicaterecursively. Intended viruses are often encountered in poorly organisedvirus collections.JOKE PROGRAM Means a program, which imitates harmful operation, but doesnot actually accomplish the object of imitation. Joke programs can beclassified as malware because they operate deliberately against system'sspecification.KEYBOARD CONTROLLING DEVICE A device which a computer uses for controllinganother computer's keyboard.known virus scanning Means computer virus detection methods, which aim forfinding and identifying viruses known so far or close variants of theviruses known so far.MACRO VIRUS Means a virus, which uses application macros for replication.malicious toolkit Means a toolkit program, which has been designed to helpsuch malicious intentions, which are aimed against computer systems.Furthermore, malicious toolkits may operate exactly as a user of themassumes and therefore they are different from Trojan horses. Malicioustoolkits include such programs as virus creation toolkits, sniffers andhacking programs.MEMORY RESIDENT SCANNING Means on-line virus scanning strategies, whichoccur before executable code gets it's chance to be executed. In otherwords memory resident scanning prevents infection.TROJAN HORSE Means self-standing program code, which performs or claims toperform something useful, while in the same time intentionally performs,unknowingly to the user, some kind of destructive function (see alsoBontchev 1998). Self-standing means that, in distinction to viruses, theprogram code does not have the capability to replicate. The program codemay be attached to any part of a system's program code. Trojan horses mayinclude operations, which are typical for malicious toolkits but this doesnot make trojan horses as malicious toolkits.VIRUS TEST BED A specially prepared set of virus samples meant to be usedfor computer antivirus product evaluation. Typically a virus test bed isprepared so that there are several specimens per each virus and animportant objective in preparing a test bed is to ensure that each virusspecimen is capable of replicating recursively.VULNERABILITY ANALYSIS An analysis that investigates antivirus product'scapability to prevent or detect different types of attack typical forviruses.

Read More......

ESET NOD32 Antivirus 3.0.642

· 0 comments

Changelog for 3.0.642 * Fixed problem with EAV installation to machine with older version of CheckPoint * Fixed few firewall - related problems o fixed issue with false positive reports of attacks o fixed issue with network browsing o fixed issue with spurious firewall rule creation * Fixed issue with Web Access Protection module in Windows Vista * Fixed few issues in Microsoft Outlook Express and Windows Mail o fixed issue with disappearing user account information o fixed issue being unable to send receipts/delivery reports o fixed filtering/highlighting messages not functioning * Other small fixesESET NOD32 Antivirus System - Integrated, Real-Time Protection against viruses, worms, trojans, spyware, adware, phishing, and hackers. Best detection, fastest performance & smallest footprint.NOD32 Antivirus System provides well balanced, state-of-the-art protection against threats endangering your PC and enterprise systems running various platforms from Microsoft Windows, through a number of UNIX/Linux, Novell, MS DOS operating systems to Microsoft Exchange Server, Lotus Domino and other mail servers.ESET solutions are built on ESET?s one-of-a-kind ThreatSense technology. This advanced heuristics engine enables proactive detection of malware not covered by even the most frequently updated signature-based products by decoding and analyzing executable code in real time, using an emulated environment. By allowing malware to execute in a secure virtual world, ESET is able to clearly differentiate between benign files and even the most sophisticated and cleverly-disguised malware.Users of Microsoft½ Windows½ can experience the power and elegance of NOD32's ThreatSense Technology with ease and comfort. Our single optimized engine offers the best protection from viruses, spyware, adware, phishing attacks, and more. Keep tomorrow's threats at bay with our proactive detection technology.Unique to ESET Smart Security and ESET NOD32 Antivirus V3.0***********************************************************? Hands-on service ? All ESET customers receive the same level of excellent technical support service, whether an individual computer user or an SMB.? Ease of installation ? ESET Smart Security and ESET NOD32 Antivirus V3.0 scanning engines are quick and easy to install, no matter what solution is currently running.? Advanced threat protection network ? ESET solutions are backed by ThreatSense.Net, a global early warning system built into the products. ThreatSense.Net extends the power of ThreatSense?s powerful analytics by automatically submitting samples of and information about new malware to ESET researchers for analysis, thus helping to close the window of vulnerability opened by new threats.ESET NOD32 Antivirus + Antispyware:***********************************? This component is in fact an improved version of the award-winning scanning engine of NOD32 Antivirus v2.7. With respect to program's unprecedented scanning speed, the following improvements have been made:? Improved system of cleaning and deleting infiltrations. The antivirus system now intelligently cleans and deletes infiltrations with no need for user interaction.? Computer scan can be run in background in order to use only a part of system resources. Thus scanning will not affect theperformance of your computer and you will be able to work on it as usual.? The resident protection supports archive scanning.? Update optimization, smaller update package size than in version 2.7, more effective management and protection of update files against damage.? Email protection for users of Outlook Express.ESET?s new solutions are ideal for the small-to-medium size business environment. By incorporating ESET?s Remote Administrator, both ESET Smart Security and the new version of ESET NOD32 Antivirus can be deployed and managed remotely from a central location.----------------------Systems Requirements---------------------- * Processors supported: 32-bit (x86) and 64-bit(NOT INCLUDED) (x64) Intel½, AMD½ or 100% compatible * Operating Systems: Microsoft Windows 2000, Microsoft Windows XP (32 and 64-bit editions), Microsoft Windows Vista (32 and 64-bit editions) * Memory: 33 - 38 MB on average * Disk Space (download): 16MB * Disk Space (installation): 78MB

Read More......

Eset NOD32 Changelog for Remote Administrator

· 0 comments

May 21, 2008 - Version 2.0.107
Updates:
added capability of a mirror for NOD32 v2 clients
global logs level filtering (advanced settings)
updater errors with text information (in server log)
updated configuration template
Fixed issues:
incorrect formatting in OS application log
problem in configuration template is now fixed
copying the license key from a network drive in setup
few other minor bugs are fixed
March, 2008 - Version 2.0.56
Fixed problems in:
http server
updater
extensions in configuration editor
Update to epfw rules editor in configuration editor
Few minor bugs fixed
February 26, 2008 - Version 2.0.50
Fixed several problems related to
http server
updater
several other minor bugs fixed
Configuration tree update in ESET Configuration Editor included
Unix ESET Security section
Default user interface values
Other upgrades
ESET Remote Administrator Console/Server: firewall report added
ESET Remote Administrator Console/Server: user column in CSV reports added
ESET Configuration Editor: added xml format for saving files
ESET Configuration Editor: personal firewall zone and rule setup upgrades (defualt rules management updated, configuration for Detection of modification network-aware applications added, configuration for Internet browsers added)
December 20, 2007 - Version 2.0.33
Fixed ERA server installation problem (terminal server)
Replication password problem fixed
Unicode communication with the server set by default
Other minor problems fixed
November 26, 2007 - Version 2.0.29
Support for new ESET security products (ESET Smart Security, ESET NOD32 Antivirus 3.0)
Security enhancements
Improved performance
Forwarding of ThreatSense.Net data via ERA server
Mirror functionality in ERA server
GUI improvements
New template for reports
March 27, 2007 - Version 1.0.15
minor enhancements and minor bugs repaired (replication, remote installation, get info, setup)
nod32 2.70.32 ENU bundled
cfgedit 1.29.024 ENU bundled
January 17, 2007 - Version 1.0.14
support for Windows Vista
minor enhancements and minor bugs repaired (replication, remote installation, reports, setup)
nod32 2.70.23 ENU bundled
cfgedit 1.29.023 ENU bundled
June 15, 2006 - Version 1.0.11
extended database maintenance (clean-up, compact, repair)
enhanced logging (log rotation, windows application log, debug log)
extended server options
enhanced work with groups in filters
license key upload
browsing network from the viewpoint of server (push install)
groups/active directory synchronization option
smtp authentication
saving console environment settings (columns, filters)
changed internal storage structure
other internal enhancements of console and server
minor bugs repaired (remote installation)
new help and manual (pdf)
nod32 2.51.26 ENU bundled
cfgedit 1.27.021 ENU bundled
August 15, 2005 - Version 1.0.9
NOD32 2.51.8 ENU bundled
cfgEdit 1.25.018 ENU bundled
May 19, 2005 - Version 1.0.7
new cfgEdit (v1.23.017 ENU)
nod32 2.50.19 ENU bundled
fixed bug in reports
March 16, 2005 - Version 1.0.6
the console prepared for new numbering of NOD32 virus signature database version
big fonts problem in the console fixed
fixed a few small bugs
October 27, 2004 - Version 1.0.5
fixed a few small bugs
new cfgedit (v1.18)
nod32 2.12.3 bundled

Read More......