Tuesday, October 10, 2006

It's Patch Tuesday For Windows.

It's the second Tuesday of October and that means it's time to update Windows. There are 6 critical updates this time, along with several other ones to protect your computer. Details of what's in this month's updates can be read at the Microsoft Security Bulletin for October.

Go to Windowsupdate.com to get them and protect your computer.

Monday, October 09, 2006

Google to buy YouTube in $1.65 billion stock deal

Google has laid speculation to rest — it is buying YouTube for US$1.65 billion in a stock transaction. YouTube operates a wildly popular Web site showing original videos in a range from amateurish to professional. It will continue to operate independently after the Google acquisition “to preserve its successful brand and passionate community,”

From Macworld.

Sunday, October 08, 2006

Unlocking the Mysteries of 'Svchost.exe'

Svchost.exe can, and usually does, run several instances of itself at any given time, each instance running several associated services. How do you find out what these "services" are?

Posted on the Langa Blog. I've been so busy, I didn't notice Fred Langa has a blog now. Anyways, a good and brief explanation on why you see svchost.exe more than once in your process list on XP and Windows 2000.

read more | digg story

Friday, October 06, 2006

MS Security Bulletin Advance Notification for October

Microsoft have released an advance notification for the updates that are due to be released next Tuesday.

Don't forget to prepare for the updates as I've outlined in an earlier entry - How To Prepare for Patch Tuesday.

On 10 October 2006 Microsoft is planning to release:

Security Updates

  • Six Microsoft Security Bulletins affecting Microsoft Windows. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer. Some of these updates will require a restart.
  • Four Microsoft Security Bulletins affecting Microsoft Office. The highest Maximum Severity rating for these is Critical. These updates will be detectable using the Microsoft Baseline Security Analyzer. These updates may require a restart.
  • One Microsoft Security Bulletin affecting Microsoft .NET Framework. The highest Maximum Severity rating for this is Moderate. These updates will be detectable using the Microsoft Baseline Security Analyzer and the Enterprise Scan Tool. These updates may require a restart.
Microsoft Windows Malicious Software Removal Tool
  • Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Center.
    Note that this tool will NOT be distributed using Software Update Services (SUS).
Non-security High Priority updates on MU, WU, WSUS and SUS
  • Microsoft will release No NON-SECURITY High-Priority Updates for Windows on Windows Update (WU) and Software Update Services (SUS).
  • Microsoft will release two NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).
Microsoft Security Bulletin Advance Notification

Thursday, October 05, 2006

Microsoft give MVP Award to Adware Pusher

Microsoft's MVP program supposedly rewards "outstanding members of Microsoft's peer-to-peer communities, and is based on the past year's contributions those members make in those communities online and offline." So why have they given the creator of Messenger Plus an MVP Award, when he bundles the notorious LOP Adware in with his creation?

read more | digg story

Tuesday, September 26, 2006

Spyware Doctor 3.0567 0

Spyware Doctor has been updated with new spyware definitions.

Latest Database Version: 3.0567 0
Intelli-Signatures: 71,240

Spyware Doctor protects your computer in 3 ways. First, it has the On guard monitor which watches places spyware will change your computer settings. By alerting you, Spyware Doctor gives you the option to not allow unwanted programs on your computer. Second, Spyware Doctor has a feature called Immunize that completely blocks known spyware from even installing. Third, spyware Doctor has a large detection database that removes spyware that has gotten onto your computer. I have used Spyware Doctor in tests against SpyAxe and SpyFalcon. It completely removed the those two. A restart of the computer and resetting my wallpaper was the hardest part.

A free scan is available from the Spyware Doctor Homepage:
http://www.pctools.com/spyware-doctor/

New Intelli-Signatures:

3.0567 0 - Backdoor.Antilam.GEN, Trojan.Clicker.Aditer, Worm.Womble

3.0566 0 - Trojan.PSW.QQDragon

3.0565 1 - Backdoor.Augodor.GEN, Drive Cleaner, Popupwithcast, Worm.Licat

Extended Intelli-Signatures:

3.0567 0 - Backdoor.Delf.EE, Backdoor.Tilebot.AF, Mirar, Regifast, SpyAxe, Trojan.Banker, Trojan.Downloader.Small.CML, Trojan.Dropper.Small.AEK, Trojan.FavAdd.AE, Trojan.Popuper, Trojan.PSW.Hangame, Trojan.PWSteal.Lineage, YourEnhancement

3.0566 0 - Advertising, Backdoor.Tilebot.AF, Block-Checker, CasinoClient, Drive Cleaner, EliteBar, Known Bad Sites, PurityScan, Trojan.Busky, Trojan.Dialer.BY, Trojan.Goldun, Trojan.Proxy.Small.BO, YourEnhancement

3.0565 1 - Backdoor.Assasin, HideWindows, Known Bad Sites, Mirar, SpyAxe, Trojan.Downloader.Agent.XQ, Trojan.Downloader.Zlob.PJ, Trojan.PSW.QQRob.U, VX2.Look2Me

Tool Update releases:

Popup Blocker 3.6.0.2083

General Information:
Updates are posted 5 times per week on average.
Updates are installed by running Spyware Doctors' Smart Update feature.

Urgent Update For Windows Now Available

Microsoft has a patch or fix for a critical problem in the way Windows handles the so called VML Exploit. Without getting this patch, spyware, trojans, and viruses can be automatically installed on your computer from web pages and spam emails. The update is small and does not need to restart your computer to take effect. I strongly recommend everyone go to Windows Update now to get this patch. Normally, Microsoft only releases patches on the second Tuesday of the month. By releasing this fix early, this shows how serious this problem is.

The VML Exploit ( for Vector Markup Language) is described briefly in the update:

Typical download size: 250 KB , less than 1 minute
A security issue has been identified in the way Vector Markup Language (VML) is handled that could allow an attacker to compromise a computer running Microsoft Windows and gain control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer.

Keeping your computer up to date is important, but this update is really important. Here is a rather technical explanation of what the VML Exploit is and what it does. An example of what you might get in a spam email that uses this exploit from the Sunbelt Blog.

Monday, September 25, 2006

IE7 is immune to VML exploit

First of all.. what is the VML exploit?

First discovered by Sunbelt, the VML exploit allows a malicious website to install software without your knowledge or permission. The exploit uses a bug in VML in Internet Explorer to overflow a buffer and inject shellcode. Microsoft has been informed and we are hoping for a patch to be released in the October security update release.

Until then, the only way to protect your self from this exploit is to unregister the VML.dll or upgrade to IE7

Yes you did read correctly, IE7 is immune to this vulnerability. Fellow MVP, Sandi Hardmeier has written about this in her blog Spyware Sucks, not only are there some great screen shots but also links to further information.

If you are unable or unwilling to upgrade to IE7 then Bleeping Computer have recently posted an excellent tutorial on how to disable and unregister this dll.

Update:

Microsoft have released a security update today to address this issue..

Security Update for Windows XP (KB925486)
Date last published: 9/26/2006
Typical download size: 250 KB
A security issue has been identified in the way Vector Markup Language (VML) is handled that could allow an attacker to compromise a computer running Microsoft Windows and gain control over it. You can help protect your computer by installing this update from Microsoft. After you install this item, you may have to restart your computer.


Saturday, September 23, 2006

Sunbelt Counterspy Update 414

CounterSpy 1.5 latest update definition is 414

CounterSpy is able to catch more spyware than almost every other utility on the market because the CounterSpy threat database (with the signatures of every spyware and malware utility we can identify) is constantly updated. Our researchers constantly look for ways to improve our spyware searching database so that it catches all spyware that could potentially be on your system. Keyloggers, spyware cookies, remote access trojans (backdoors), and more are all identified.

http://research.sunbelt-software.com/download.cfm

CounterSpy offers a 15 day fully functional trial. So that means you can not only test how it detects spyware, but how well it removes spyware, malware, and other threats.

New Threats Added to Database

BadJoke.Win32.Delf.ak, BadJoke.Win32.Finger.b, Exploit.Levem.C, Trojan-Downloader.Win32.Zlob.akl, Trojan-Downloader.Win32.Zlob.akm, Trojan-Downloader.Win32.Agent.awy, Trojan-PSW.Win32.WOW.io, Trojan-Spy.Win32.Dolan, Zenotecnico.Think-Adz, SGOOPE, Trojan-Proxy.Win32.Lager.di, Trojan.PWStealer.09ED7DF4, Trojan.BE!dld.03CB7D33, Backdoor.Irc.Sdbot.EG, Backdoor.Hackarmy.AA, Trojan.PWStealer.B3E81E21, Backdoor.HackDef.Gen, Backdoor.Hupigon.CAF, Trojan.Banker.Delf.745CEDCB, Trojan-Downloader.Zlob.0CFA45AB, Trojan-Downloader.Dowdec.B

Threats that have been updated

VirusBurst, Backdoor.Ciadoor, IST.ISTbar, Look2Me, ClickSpring.PuritySCAN, SC-KeyLog, Trojan.StartPage, Backdoor.Win32.Rbot.gen, WindUpdates.WinTaskAd, SearchWords.Toolbar, Clickspring, HalfLemon, KGB Keylogger, Zango.Toolbar, DropSpam, FakeAlert, P2P-Worm.Win32.SpyBot.gl, Trojan-Proxy.Win32.Lager, Backdoor.Win32.IRCBot.qc, Infostealer.Banpaes, Backdoor.Graybird, Infostealer, Backdoor.Trojan, W32.HLLW.Gaobot, Hacktool.Rootkit, Trojan.Alemod, Backdoor.Graybird.K, Backdoor.Formador, Infostealer.QQRob.A, Infostealer.Lineage, W32.Beagle.X@mm, Trojan.Flush.A, W32.SillyFDC, W32.Looked.I, Trojan-Spy.Win32.Ardamax.b, Trojan-Downloader.JS.Psyme.br, Trojan-Proxy.Win32.Delf.t, Infostealer.JiangHu, Trojan.Popper, W32.Looked.P, Trojan-Downloader.Win32.Adload.cz, Rootkit.Win32.Agent.cf, Dialer.TrafficAdvance, Spyware.Ardakey, Backdoor.Win32.Hupigon.buw, Trojan-Downloader.Win32.Zlob.yt, Trojan-Dropper.VBS.GoboTools, Trojan-Spy.Win32.Banker.bgw, Trojan-Dropper.Win32.VB.mg, Backdoor.HackDefender, Trojan-Downloader.BAT.Ftp.cn, Trojan-Spy.Win32.Banker.buv, Trojan-Dropper.Win32.Pakes, Trojan-Downloader.Win32.Small.dnv, Email-Worm.Win32.Mydoom.m.log, Backdoor.Win32.Rbot.be, Trojan.Wimad, Backdoor.Win32.Iroffer.13b11, Trojan.BAT.KillFiles.eg, W32.Stration.A@mm, Trojan.Remote Desktop, WUPC (Web is Under Parental Control), Backdoor.Win32.Cakl.a, Trojan-Dropper.Win32.Small.apg, Trojan-PSW.Win32.QQPass.hb, Trojan-PSW.Win32.PdPinch.gen, Trojan-Spy.Win32.Spav, Backdoor.Win32.Hupigon.bzn, Trojan-PSW.Win32.QQPass.kx, Trojan-Downloader.Win32.Agent.aut, Trojan.Win32.DNSChanger.en, Backdoor.Sdbot.AU, Trojan.Schoeberl.D, Trojan-Downloader.Win32.Small.dtq, Trojan-Downloader.Win32.Tibs.ic, Email-Worm.Win32.Warezov.aa, Trojan-Spy.Win32.Banker.bzf, Backdoor.Win32.IRCBot.vj, Trojan-Spy.Win32.Banker.bxm, Trojan-Clicker.Win32.Agent.hz, Trojan-Downloader.Win32.Zlob.ail, Trojan-Downloader.Win32.Delf.avu, Trojan-Downloader.Win32.Zlob.aja, Dialer.iDialer, Backdoor.Win32.Hupigon, Trojan-Downloader.Win32.Zlob.ajk, Hotbar, Hyperlinker/LinkMaker, Perfect Keylogger, Trojan-Downloader.Psyme, Slagent/Navipromo, Unclassified.Trojan.G, Deskwizz/ZQuest, VX2.Buddy, Trojan-Downloader.Qoologic, Zenotecnico, WinAntiSpyware, Yazzle Sudoku, C2.Lop.dldr, PigSearch, SpamTool.Win32.Agent.h, Trojan.Win32.Dialer.hz, Trojan-Spy.Win32.Banker.bdn, Trojan Horse, W32.IRCBot, Backdoor.Bifrose, Infostealer.Wowcraft, W32.Feebs, W32.Linkbot, Trojan.Dermon.A, VBS.Inor, Adware.Zhong, Backdoor.IRC.Flood, Bat.Delsys.Trojan, Trojan-PSW.Win32.WOW.da, Trojan-Spy.Win32.Banbra.gl, Backdoor.Subot, Backdoor.Win32.SdBot.aad, Backdoor.Win32.Aimbot.ae, Backdoor.Win32.SdBot.gen, Trojan.Ducky.B, Bloodhound.Exploit.64, DialupPwd, W32.Randex.GEL, Trojan-Downloader.Win32.Zlob.afq, Backdoor.Win32.FireFly.i, Trojan-Downloader.Win32.Zlob.afr, Trojan.Win32.Qhost.hs, Trojan-Downloader.Win32.Delf.amn, Trojan-Dropper.Win32.Delf, Trojan-Proxy.Win32.Horst.hl, Ultimate Cleaner, DialXS, Backdoor.SDBot.gen, Zango.SearchAssistant, TargetSaver, Radmin, UniversalSearchToolbar, PurityScan.VirtueScope, DollarRevenue, Ultimate Defender, Advertismen, IRC Trojan, Trojan.Emcodec, W32.HLLW.Antinny.G, Trojan.Gobrena, Dialer.Trojan, Constructor.Win32.MicroJoiner.17, SpamTool.Win32.Gadina.d, Trojan.LinkOptimizer, Trojan-Spy.Win32.Banbra.he, Trojan-Dropper.Multi.Gen, Backdoor.Sdbot, Trojan-Spy.Win32.Banbra.hb, W32.Looked.O, Trojan.Win32.LipGame.ab, Trojan.Emcodec.G, W32.Wargbot, Backdoor.Mulim, Trojan.Logger, Trojan-Downloader.Win32.Zlob.in, Trojan-PSW.Win32.Lineage.ahe, Trojan-Downloader.Win32.Agent.alw, Trojan.Win32.DNSChanger.eq, Trojan.Downloader.Small.DFB, W32.Stration.AC@mm, Netbus, C2.Lop, Mirar, DialerPlatform, W32.Spybot.Worm, Marketscore.RelevantKnowledge, Virtumonde, Trojan.Abwiz, EnergyPlugin, SpySheriff, Desktop Weather, Trojan.LowZones, Maxifiles, DesktopMedia, Goldun.Fam, Haxdoor.Fam, Trojan.KillAV, Henbang, Trojan-Downloader.Zlob.Media-Codec, Trojan-Proxy.Win32.Small.bo, Yazzle.Cowabanga, Trojan-Downloader.Win32.Agent.uj, Trojan.Anserin, Trojan.Adclicker, Backdoor.Prorat, Dialer.Target, Trojan.Zlob, Backdoor.Mosuck, Trojan.Emcodec.B, Trojan.Hachilem, Dialer.Generic, BAT.Trojan, W32.Buchon.A@mm, Backdoor.Win32.Delf.api, Trojan-Spy.Win32.Banker.awa, Trojan-Spy.Win32.Banbra.gf, Adware.Roogoo, Trojan-Dropper.Win32.MultiJoiner.13.h, Trojan.Win32.Dialer.qi, Trojan-Dropper.Win32.Small.apz, Infostealer.Wabber, Trojan.Vxgame.z, Trojan-Downloader.Win32.Delf.acc, W32.Bugbear.B.Dam, Backdoor.Win32.Hupigon.rc, Backdoor.Win32.Small.ls, Trojan-Downloader.Win32.Zlob.aec, Trojan-Downloader.Win32.Zlob.aee, Trojan-Dropper.Win32.Agent.ati, Trojan-Proxy.Win32.Lager.aq, Backdoor.EggDrop, Dropped:Trojan.Spy.Agent.NZ, Trojan-Proxy.Win32.Horst.hr, Trojan-Downloader.Win32.Banload.aon, Trojan-Spy.Win32.Perfloger.w, Backdoor.Evilbot.C, MediaMotor.Popupwithcast, IM-Flooder.Win32.RoomDestroyer, Trojan-PSW.Win32.IcqSmiley.c, Trojan-Downloader.Win32.Banload.bfo, Trojan-Spy.Win32.Delf.ta, Backdoor.Win32.VB.axj, Trojan.Galapoper.A, Backdoor.Win32.Webdor.af, Trojan-Downloader.Win32.Agent.awm, Trojan-Clicker.Win32.VB.dn, Backdoor.Win32.Sbot.10, Trojan.Win32.BHO.e

Spyware Doctor Update 3.0565 0

Spyware Doctor has been updated with new spyware definitions.

Latest Database Version: 3.0565 0
Intelli-Signatures: 71,110

Spyware Doctor protects your computer in 3 ways. First, it has the On guard monitor which watches places spyware will change your computer settings. By alerting you, Spyware Doctor gives you the option to not allow unwanted programs on your computer. Second, Spyware Doctor has a feature called Immunize that completely blocks known spyware from even installing. Third, spyware Doctor has a large detection database that removes spyware that has gotten onto your computer. I have used Spyware Doctor in tests against SpyAxe and SpyFalcon. It completely removed the those two. A restart of the computer and resetting my wallpaper was the hardest part.

A free scan is available from the Spyware Doctor Homepage:
http://www.pctools.com/spyware-doctor/

New Intelli-Signatures:

3.0565 0 - Backdoor.Augodor.GEN, Drive Cleaner, Popupwithcast, Worm.Licat

3.0564 0 - Backdoor.Bancodor.GEN, Trojan.Clicker.VB.FQ

3.0563 0 - Trojan.Busky, VirusBurst

Extended Intelli-Signatures:

3.0565 0 - Backdoor.Assasin, HideWindows, Known Bad Sites, Mirar, SpyAxe, Trojan.Downloader.Agent.XQ, Trojan.Downloader.Zlob.PJ, Trojan.PSW.QQRob.U, VX2.Look2Me

3.0564 0 - Backdoor.Graybird.GEN, Backdoor.LegMir.BZ, Common Components Unrelated, I-Search Desktop Search Toolbar, Maxifiles, MediaTickets, PurityScan, Trojan.Agent.HT, Trojan.Downloader.Agent.AWM, Trojan.Downloader.Banload.M, Trojan.Downloader.Small.CYH, Trojan.Downloader.Zlob.GEN, Trojan.Dropper.MultiJoiner, Trojan.Mailbot, Trojan.Popuper, Trojan.PSW.Hangame, Worm.Spybot, Zeno Search Assistant

3.0563 0 - Backdoor.Berbew.N, Backdoor.Robobot, BookedSpace, Common Components for Trojans, Enbrowser, Maxifiles, PurityScan, TargetSavers, Trojan.Downloader.Zlob.GEN, Trojan.Popuper, Trojan.Proxy.Webber.O

Deleted Intelli-Signatures:

3.0564 0 - WhenU.Search

General Information:
Updates are posted 5 times per week on average.
Updates are installed by running Spyware Doctors' Smart Update feature.

Ad Aware SE1R124 19.09.2006

The latest update for Ad Aware is SE1R124 19.09.2006

New Definitions:
========================
Adware.Agent +3
Adware.Baidubar +5
Adware.LetsCool +6
Adware.LoopAd
Adware.MyToolbar +4
Adware.Podcast +5
Adware.Soso +8
Adware.WeirWeb +2
Win32.Hacktool.Craagle
Win32.Trojan.IZD

Updated Definitions:
========================
Adware.180Solutions.SeekmoSearchAssistant +3
Adware.Adhelper
Adware.CasClient +9
Adware.DesktopMedia +9
Adware.MMSAssist
Adware.Sidesearch +2
Dogpile Toolbar +3
Elitum.ElitebarBHO +3
MegaSearch Toolbar
NetPal
RedSwoosh +4
SahAgent +3
Win32.Trojan.Downloader +15
Win32.Trojandownloader.Zlob +5
Win32.Trojan-PSW.Lineage
Winfixer +2
Virtumonde +9
VirusBurst +4
Zango +9
ZSearch +11

Ad Aware can be downloaded from the official Lavasoft Ad Aware page.

Spy Sweeper & Ewido Antispyware Latests Updates

Spy Sweeper latest update

Program Version 5.0.7. (Build 1608)
Spyware definition: version 766
Updated September 22nd,2006
Protection against 150,734 spyware traces.

Spy Sweeper protects your computer in two ways. First, it uses what is called shields to monitor places on your computer that spyware will likely change. By alerting you, you can prevent spyware from even getting on your computer. The second way is the large threat database. With this update, there are over 140,000 known spyware threats that Spy Sweeper detects and removes, should anything undesirable get onto your computer.


Spy Sweeper available from http://www.webroot.com/consumer/products/spysweeper/


Ewido Antispyware

Note that all future updates the we give for Ewido are for the newer version, which has been renamed to Ewido Antispyware. The new version doesn't have a numer for the update. You can tell if you have the most recent update by the number of threats in the database, however.


Date of Update: September 23rd, 2006
Known threats in database: 440,074

Ewido Antimalware scans your computer to clean any spyware that may have gotten on your computer. Ewido also has active protection to prevent spyware from getting on to your computer.

Hijackers and Spyware
-Secure surfing in the Internet without fear of annoying changes of the start page of your browser, tracking cookies and advertising bars.
Worms
-Nobody should receive e-mails in your name with malicious files in the appendix anymore.
Dialers
-Security against all kinds of dialers. No fear when receiving the next phone bill.
Trojans and Keyloggers
-No chance for thieves to steal your bank data and personal sensitive information by tapped Internet connections, remote controlled webcams or secret keyboard recordings.

Product Info & Download: Ewido Anti-Spyware