38 12
發新話題
打印

[討論] V8 引擎更新集中帖

本主題由 mofunzone 於 2008-4-26 04:52 置頂

V8 引擎更新集中帖



V8引擎的第一次升级8.01.00.32
- Added: EMF exploit detection
   EXP/CVE-2008-1087
   EXP/EMF.Damaged
- Updated: Heuristic detections
   HEUR/HTML.Malware
   HEUR/Exploit.HTML
- Fixed: false positives
   HEUR/HTML.Malware
   HEUR/Exploit.HTML
   EXP/CVE-2006-453

[ 本帖最後由 skyboy1101 於 2008-4-25 18:22 編輯 ]
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:08
  • Bug 威望 +5 謝謝分享 2008-8-7 11:08

TOP

新的引擎版本号是AV8 8.1.0.32 (2008-4-19)
以下是已做的改变:
- 增加: EMF 使用侦测
EXP/CVE-2008-1087
EXP/EMF.Damaged
- 更新: 启发式侦测
HEUR/HTML.Malware
HEUR/Exploit.HTML
- 修正: 误报
HEUR/HTML.Malware
HEUR/Exploit.HTML
EXP/CVE-2006-453
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:08
  • Bug 威望 +5 謝謝分享 2008-8-7 11:08

TOP

This is the version number of the new engine:
AV7 7.8.0.10 / AV8 8.1.0.35  (25 Apr 2008)


The following changes were done:

-  更新: 启发和基因侦测
   HEUR/HTML.Malware
   HEUR/Exploit.HTML
   HTML/Shellcode.Gen
   ADSPY/AdSpy.Gen
   BDS/Backdoor.Gen
   DR/Delphi.Gen
   TR/BHO.Gen
   TR/Crypt.CFI.Gen
   TR/Crypt.ULPM.Gen
   TR/Crypt.XDR.Gen
   TR/Crypt.XPACK.Gen
   TR/Dldr.Delphi.Gen
   TR/Downloader.Gen
   TR/Dropper.Gen
   TR/Hijacker.Gen
   TR/PWS.Sinowal.Gen
   TR/Proxy.Gen
   TR/Rootkit.Gen
   TR/Spy.Banker.Gen
   TR/Spy.Gen
   TR/Vundo.Gen
   WORM/Bagle.Gen
   WORM/Zhelatin.Gen
   
- 修正: 误报
   HEUR/HTML.Malware
   HEUR/Exploit.HTML
   HEUR/Malware
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:09
  • Bug 威望 +5 謝謝分享 2008-8-7 11:09

TOP



         
There was an Engine Update today.
The version number of the new engine is AV8 8.1.0.36.

The following changes have been done:
- Updated: Improvements and fixes in ARJ, BZ2, CAB, LHA, RAR, ZIP,
MSCompress and ZOO.
本帖最近評分記錄
  • Bug 威望 +5 謝謝分享 2008-8-7 11:09
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:09

TOP

Engine Update Notification (Engine AV7 7.8.0.11 / AV8 8.1.0.37)
引擎更新(V7 7.8.0.11/V8 8.1.0.37)
-修复:误报
   HEUR/HTML.Malware
   HEUR/Exploit.HTML
   HEUR/ELF.Malformed
   HEUR/Malware
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:09
  • Bug 威望 +5 謝謝分享 2008-8-7 11:09

TOP


Engine Update AV8 8.1.0.39 / AV7 7.8.0.14 (2008-05-07)

The following changes have been done:
- Added: Detection of polymorphic viruses

      W32/DunDun
      W32/Sality
      W32/Zazel.A
      W32/Vorcan
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:09
  • Bug 威望 +5 謝謝分享 2008-8-7 11:09

TOP

新的引擎版本号为:AV8 8.1.0.42 / AV7 7.8.0.17[09/05/08]

引擎做了如下改变:
- 新增: 通用基因侦测
TR/ATRAPS.Gen

- 更新: 启发式和通用基因检测
ADSPY/AdSpy.Gen
BDS/Backdoor.Gen
BDS/Hupigon.Gen
DR/Delphi.Gen
DR/Dldr.DnsChanger.Gen
DR/PcClient.Gen
DR/Shelled.Gen
TR/BHO.Gen
TR/Crypt.CFI.Gen
TR/Crypt.Morphine.Gen
TR/Crypt.NSPI.Gen
TR/Crypt.NSPM.Gen
TR/Crypt.ULPM.Gen
TR/Crypt.TPM.Gen
TR/Crypt.XPACK.Gen
TR/Dldr.Delphi.Gen
TR/Dldr.Swizzor.Gen
TR/Downloader.Gen
TR/Dropper.Gen
TR/Hijacker.Gen
TR/Proxy.Gen
TR/Rootkit.Gen
TR/Spy.Gen
TR/Vundo.Gen
WORM/Bagle.Gen
HTML/RCE.Gen
HTML/Spoofing.Gen
HTML/Infected.WebPage.Gen
HEUR/Malware
HEUR/Crypted
HEUR/HTML.Malware
HEUR/Exploit.HTML

- 修正: 误报
HEUR/Malware
HEUR/HTML.Malware
HEUR/Exploit.HTML
HTML/Spoofing.Gen
HTML/Infected.WebPage.Gen
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:09
  • Bug 威望 +5 謝謝分享 2008-8-7 11:09

TOP



Engine Update AV8 8.1.0.46 / AV7 7.8.0.19 (2008-05-15)
- 更新: 启发式和通用基因检测
  ADSPY/AdSpy.Gen
  BDS/Backdoor.Gen
  DR/Delphi.Gen
  TR/ATRAPS.Gen
  TR/BHO.Gen
  TR/Crypt.XPACK.Gen
  TR/Dldr.Zlob.Gen
  TR/Dropper.Gen
  TR/Hijacker.Gen
  TR/Rootkit.Gen
  TR/Spy.Gen
  TR/Vundo.Gen
  HTML/Infected.WebPage.Gen
  HTML/Rce.Gen
  HTML/Crypted.Gen
  HEUR/HTML.Malware
  HEUR/Exploit.HTML

- 修正: 误报
  TR/ATRAPS.Gen
  TR/Backdoor.Gen
  TR/BHO.Gen
  TR/Downloader.Gen
  TR/Crypt.CFI.Gen
  TR/Crypt.NSPM.Gen
  TR/Crypt.ULPM.Gen
  TR/Crypt.XPACK.Gen
  TR/Dropper.Gen
  HTML/Infected.WebPage.Gen
  HTML/Rce.Gen
  HEUR/Malware
  HEUR/Crypted
  HEUR/HTML.Malware
  HEUR/Exploit.HTML
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:09
  • Bug 威望 +5 謝謝分享 2008-8-7 11:09

TOP

Engine Update AV8 8.1.0.49 / AV7 7.8.0.24 (2008-05-29)



The version number of the new engine is AV8 8.1.0.49 / AV7 7.8.0.24.

The following changes have been done:
- Added: Detection for Adobe Flash Player exploits
  EXP/Flash.Gen

- Updated: Heuristic and generic detections
  HTML/Infected.WebPage.Gen
  HTML/Rce.Gen
  HTML/Crypted.Gen
  HEUR/HTML.Malware
  HEUR/Exploit.HTML

- Fixed: False positives
  HTML/Infected.WebPage.Gen
  HTML/Rce.Gen
  HEUR/Crypted
  HEUR/HTML.Malware
  HEUR/Exploit.HTML
  HEUR/ELF.Malformed
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:09
  • Bug 威望 +5 謝謝分享 2008-8-7 11:09

TOP

(Engine AV7 7.8.0.25 / AV8 8.1.0.50), 30 May 2008



This is the version number of the new engine:
AV7 7.8.0.25 / AV8 8.1.0.50


The following changes were done:

- Added: Detection for malicious Adobe Flash Player files
  HTML/FlashFrame.Gen

- Updated: Heuristic and generic detections
  HTML/Crypted.Gen
  HEUR/HTML.Malware
  EXP/Flash.Gen


HTML/FlashFrame.Gen
************************

A generic routine designed to detect malicious IFRAMEs attached toAdobe Flash Files. These can for example be added to otherwiselegitimate Flash files as a result of automated hacker attacks on webservers.
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:10
  • Bug 威望 +5 謝謝分享 2008-8-7 11:10

TOP

(Engine AV7 7.8.0.26 / AV8 8.1.0.51), 30 May 2008


This is the version number of the new engine:
AV7 7.8.0.26 / AV8 8.1.0.51


The following changes were done:

- Updated: Heuristic and generic detections
  EXP/Flash.Gen
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:10
  • Bug 威望 +5 謝謝分享 2008-8-7 11:10

TOP

(Engine AV7 8.1.0.55 / AV8 8.1.0.55), 6 Jun 2008

This is the version number of the new engine:
AV7 8.1.0.55 / AV8 8.1.0.55  

The following changes were done:
- Updated: Heuristic and generic detections  
EXP/Flash.Gen  
HTML/Shellcode.Gen  
HEUR/HTML.Malware  
W32/Sality

- Fixed: False positives  
TR/Crypt.XPACK.Gen  
TR/Dropper.Gen  
HTML/ADODB.Exploit.Gen  
HTML/Infected.WebPage.Gen  
HTML/Spoofing.Gen  
EXP/MS06-001.WMF  
HEUR/HTML.Malware  
HEUR/ELF.Malformed
本帖最近評分記錄
  • Bug 威望 +5 謝謝分享 2008-8-7 11:10
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:10

TOP

avira官方引擎版本公布有误
昨晚,avira再次更新引擎。
我第一时间去看了一下。发现公布为这样:
Engine Update AV8   8.1.0.55 / AV7   8.1.0.55 (2008-06-06)

当时我就在群里说估计是德国人又犯错误了。因为针对AV7版本,其引擎版本应该是7.8.0.xx。
为了验证此问题,我于7日凌晨下载了其已经更新了的离线包。发现其v7引擎果然是7.8.0.55

v7专业升级包我立即制作,早晨发布。有需要下载的请去查看我的v7专帖。
特此帮avira更正说明,希望他们自己能发现此问题。

TOP

This is the version number of the new engine:
AV7 7.8.1.11 / AV8 8.1.1.11


The following changes were done:

- - Updated: Heuristic and generic detections
  HEUR/HTML.Malware
  HEUR/Malware
  TR/Vundo.Gen

- - Fixed: False positives
  DR/OLE.HiddenExe.Gen
  HEUR/HTML.Malware
  HEUR/Malware
  HTML/ADODB.Exploit.Gen
  HTML/Rce.Gen
  HTML/Spoofing.Gen
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:10
  • Bug 威望 +5 謝謝分享 2008-8-7 11:10

TOP

Engine Update AV8 8.1.1.12 / AV7 7.8.1.12 (24.07.2008)

The new engine, the version number AV8 8.1.1.12 / AV7 7.8.1.12.
There are the following changes:
-- - Added: detection of polymorphic viruses
W32/Sality.AH

-- - Updated: Heuristic and generic detection
HEUR/malware
TR/Vundo.Gen

-- - Fixed: false positive
HEUR/malware
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:10
  • Bug 威望 +5 謝謝分享 2008-8-7 11:10

TOP

Engine Update AV8 8.1.1.15 / AV7 7.8.1.15 (31.07.2008)

The new engine, the version number AV8 8.1.1.15 / AV7 7.8.1.15.

There are the following changes:
-- - Updated: detection of polymorphic viruses
W32/Sality

-- - Fixed: false positive
HEUR/HTML.Malware
HEUR/HTML/Infected.WebPage.Gen
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:11
  • Bug 威望 +5 謝謝分享 2008-8-7 11:11

TOP

Engine Update AV8 8.1.1.19 / AV7 7.8.1.19 (06.08.2008)

The new engine, the version number AV8 8.1.1.19 / AV7 7.8.1.19.

There are the following changes:
-- - Added: generic detection
SPR/ASF.GetCodec.Gen

-- - Updated: detection of polymorphic viruses
W32/Sality.J
W32/Sality.Y

-- - Updated: Heuristic and generic detection
ADSPY/AdSpy.Gen
BDS/Backdoor.Gen
BDS/Hupigon.Gen
DR/Delphi.Gen
DR/Dldr.DnsChanger.Gen
DR/Zlob.Gen
TR/ATRAPS.Gen
TR/BHO.Gen
TR/Crypt.CFI.Gen
TR/Crypt.FKM.Gen
TR/Crypt.Morphine.Gen
TR/Crypt.PEPM.Gen
TR/Crypt.TPM.Gen
TR/Crypt.XPACK.Gen
TR/Dldr.Delphi.Gen
TR/Dldr.Zlob.Gen
TR/Downloader.Gen
TR/Dropper.Gen
TR/Hijacker.Gen
TR/PWS.Sinowal.Gen
TR/Rootkit.Gen
TR/Spy.Gen
TR/Vundo.Gen
WORM/Bagle.Gen
HEUR/HTML.Malware
HTML/Rce.Gen
HTML/Malicious.ActiveX.Gen
HTML/Downloader.Gen
HTML/Spoofing.Gen
HTML/Crypted.Gen
HTML/Infected.WebPage.Gen
HTML/Silly.Gen
HTML/Shellcode.Gen

-- - Fixed: false positive
HEUR/HTML.Malware
HTML/Infected.WebPage.Gen
HTML/Rce.Gen
本帖最近評分記錄
  • Bug 黃金 +5 謝謝分享 2008-8-7 11:11
  • Bug 威望 +5 謝謝分享 2008-8-7 11:11

TOP

Engine Update AV8 8.1.1.23 / AV7 7.8.1.23 (2008-08-18)

The version number of the new engine is AV8 8.1.1.23 / AV7 7.8.1.23.

The following changes have been done:
- - Updated: Detection of polymorphic viruses
W32/Sality.Z

- - Updated: Improved detection for PDF Exploits

- - Updated: Heuristic and generic detections
HEUR/HTML.Malware
HTML/Spoofing.Gen
HTML/Silly.Gen
TR/Crypt.XPACK.Gen
TR/Dropper.Gen
TR/Dldr.Swizzor.Gen

- - Fixed: False positives
HEUR/HTML.Malware
HTML/Spoofing.Gen
HTML/Silly.Gen

TOP

Engine Update AV8 8.1.1.28 / AV7 7.8.1.28 (2008-09-03)


这次更新包含以下内容:
- - 修复: 误报
HEUR/Malware
HEUR/HTML.Malware
HTML/Spoofing.Gen
HTML/ADODB.Exploit.Gen
HTML/Zones.Gen
HTML/Rce.Gen
HTML/Silly.Gen
HTML/Infected.WebPage.Gen

- - 修复: 特定压缩配置下可能导致的文件处理泄露
[/img]http://www.publicons.de/my/pub_REACHING+NEW+FRONTIERS+-+cyberarmy_2,3,823,39,30,98,274,640,621,825,158,9,271,742,306,178,168,197,126,48,133,728,578,743,925_1.png[/img]

TOP

The version number of the new engine is AV8 8.1.1.34 / AV7 7.8.1.34.

The following changes have been done:
- Added: Generic detection
GAME/Casino.Gen

- Updated: Heuristic and generic detections
DIAL/Dialer.Gen
BDS/Backdoor.Gen
BDS/Bifrose.Gen
DIAL/Dialer.Gen
DR/Delphi.Gen
DR/MicroJoiner.Gen
TR/ATRAPS.Gen
TR/BHO.Gen
TR/Crypt.CFI.Gen
TR/Crypt.FKM.Gen
TR/Crypt.TPM.Gen
TR/Crypt.ULPM.Gen
TR/Crypt.XDR.Gen
TR/Crypt.XPACK.Gen
TR/Crypt.FSPM.Gen
TR/Crypt.PEPM.Gen
TR/Dldr.Delphi.Gen
TR/Dldr.Swizzor.Gen
TR/Dldr.Zlob.Gen
TR/Downloader.Gen
TR/Dropper.Gen
TR/Hijacker.Gen
TR/Rootkit.Gen
TR/Spy.Banker.Gen
TR/Spy.Gen
TR/Vundo.Gen
WORM/Bagle.Gen
WORM/Zhelatin.Gen
HTML/Crypted.Gen
HEUR/HTML.Malware

- Fixed: False positives
HEUR/HTML.Malware
HTML/ADODB.Exploit.Gen

TOP

 38 12
發新話題