Wednesday, April 23, 2008

Nod32 Update 3046 (20080422)

NOD32 Antivirus detection database has been updated to version 3046 (20080422)

NOD32 Antivirus is in my opinion the best anti virus program available. It is light on resources, easy to maintain, and has one of the best detection and removal capabilities among anti virus programs.

Since its first submission for testing in May 1998, NOD32 was the only tested product that has never missed a single In the Wild virus. NOD32 has been selected as the "Antivirus program of 2001" by Australian PC User magazine, "Best Buy, Best Performance, Best Value" by the independent UK Consumer's Association
From Eset's NOD32 product information page.



Threats added in this update include the following:

3046 (20080422)
Win32/Adware.Vapsup (3), Win32/Adware.Vapsup.AB (2), Win32/Adware.Vapsup.AI, Win32/Adware.Vapsup.W, Win32/Adware.Virtumonde, Win32/Adware.Virtumonde.FP, Win32/Agent.NTQ, Win32/Agent.NTS, Win32/AutoRun.LQ (3), Win32/AutoRun.LR (2), Win32/AutoRun.LS (2), Win32/IRCBot.AEY, Win32/Mypis.AH (2), Win32/Pacex.Gen (6), Win32/Privaz.V (8), Win32/PSW.LdPinch.SUI, Win32/PSW.OnLineGames.NFF, Win32/PSW.OnLineGames.NHY, Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NMX, Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.NNU, Win32/PSW.OnLineGames.NOH (2), Win32/PSW.OnLineGames.NOI (2), Win32/PSW.OnLineGames.ODJ, Win32/PSW.OnLineGames.XTT (2), Win32/PSW.QQRob.NAQ, Win32/Qhost, Win32/Rootkit.Vanti.NBM (2), Win32/Socks.EQ (2), Win32/Spy.Agent.NES (3), Win32/Spy.Agent.NGA, Win32/Spy.Delf.NHF (3), Win32/Spy.Delf.NHV, Win32/Spy.Delf.NIG (3), Win32/Spy.Delf.NIK (5), Win32/Spy.Delf.NIL (5), Win32/Spy.KeyLogger.AEV, Win32/TrojanDownloader.Dadobra.IA, Win32/TrojanDownloader.Zlob.BTY, Win32/TrojanDownloader.Zlob.BUZ (2), Win32/TrojanDownloader.Zlob.BVD, Win32/TrojanDownloader.Zlob.BVE (16), Win32/TrojanDropper.Agent.NJR, Win32/Ysmarsys.H (3), Win32/Ysmarsys.I, Win32/Ysmarsys.J, Win32/Ysmarsys.K

Earlier
Update 3045 (20080422)

IRC/SdBot, PDF/Exploit.Pidief.M, VBS/Agent.AI (3), Win32/Adware.BHO.APH (2), Win32/Adware.Cinmus, Win32/Adware.Vapsup (5), Win32/Adware.Vapsup.AB, Win32/Adware.Vapsup.AI (2), Win32/Adware.Vapsup.W, Win32/Adware.Virtumonde.FP, Win32/Agent.KKP, Win32/Agent.KLQ, Win32/Agent.NHE, Win32/Agent.NKJ (6), Win32/Agent.NTV, Win32/BHO.NDR (2), Win32/DNSChanger, Win32/Hupigon (4), Win32/Inject.BCJ, Win32/Obfuscated.NBH (2), Win32/Pacex.Gen (5), Win32/PSW.Agent.NHN (46), Win32/PSW.LdPinch.NEL, Win32/PSW.OnLineGames.NFF, Win32/PSW.OnLineGames.NFL (2), Win32/PSW.OnLineGames.NHY, Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NNU (5), Win32/PSW.OnLineGames.NOF, Win32/PSW.OnLineGames.NOH (3), Win32/PSW.OnLineGames.WEA, Win32/PSW.OnLineGames.XTT (3), Win32/Rootkit.Vanti.NBM, Win32/Small.NDV, Win32/Spy.Agent.NFZ, Win32/Spy.Banker.LPX (2), Win32/Spy.Banker.LRB, Win32/Spy.Banker.OTP (2), Win32/TrojanDownloader.Agent.NXT, Win32/TrojanDownloader.Agent.NXU, Win32/TrojanDownloader.Agent.NXV, Win32/TrojanDownloader.Banload.LFX (2), Win32/TrojanDownloader.Delf.FBX (2), Win32/TrojanDownloader.FakeAlert.CD (2), Win32/TrojanDownloader.Zlob.BUZ (2), Win32/TrojanDownloader.Zlob.BVC (3), Win32/TrojanDownloader.Zlob.BVD (17), Win32/TrojanDropper.Agent.NJV (2), Win32/Ysmarsys.G (2)

Spyware Doctor 5.09660

Spyware Doctor has been updated with new spyware definitions.


Latest Database Version: 5.09660

Intelli-Signatures: 641,913



Spyware Doctor protects your computer in 3 ways. First, it has the On guard monitor which watches places spyware will change your computer settings. By alerting you, Spyware Doctor gives you the option to not allow unwanted programs on your computer. Second, Spyware Doctor has a feature called Immunize that completely blocks known spyware from even installing. Third, spyware Doctor has a large detection database that removes spyware that has gotten onto your computer.

A free scan is available from the Spyware Doctor Homepage:

http://www.pctools.com/spyware-doctor/



New Intelli-Signatures:

5.09660 - Adware.BHO.AJ, RogueAntiSpyware.AntiSpywareMaster, Trojan.BurningHardDisk.HOAX, Trojan.Chaincodr, Trojan-Downloader.Agent.HNP, Trojan-PWS.OnlineGames.CVQ, Trojan-PWS.OnlineGames.NFE, Trojan-PWS.QQPass.ARG, Trojan-PWS.Tibia.DB, Trojan-Spy.Agent.AZB, Trojan-Spy.Agent.BBO, Trojan-Spy.Bancos.U, Trojan-Spy.Yazoka

5.09650 - Backdoor.Hupigon, Backdoor.VB.BDZ

5.09640 - HackTool.QQShou, IM-Worm.Kelvir, Trojan.Startpage.U, Trojan-Spy.Lorex

Extended Intelli-Signatures:

5.09660 - Adware.Adbars, Adware.BHO.GEN, Adware.Borlander, Adware.Cinmus, Adware.WebDir, Application.Ardamax_Keylogger, Backdoor.Bifrose.ACI, Backdoor.Cakl, Backdoor.Hupigon, Backdoor.PCclient, Backdoor.Sdbot.AAD, HackTool.Hupigon, PSWTool.Brutus, Trojan.Startpage, Trojan-Downloader.Banload, Trojan-Downloader.Small.GEN, Trojan-PWS.Lineage.ACJ, Trojan-PWS.Lineage, Trojan-PWS.Magania, Trojan-PWS.OnlineGames, Trojan-PWS.QQPass, Trojan-PWS.Tibia, Trojan-Spy.Banker.CHC

5.09650 - Adware.Comet_Cursor, Adware.NewdotNet, Adware.NewWeb, Adware.OneStepSearch, Adware.Sogou, Adware.Starware, Adware.WhenU_SaveNow, Backdoor.Beastdoor, Backdoor.CIADoor, Backdoor.G_Door, Backdoor.Hupigon.GEN, Backdoor.Nuclear, RogueAntiSpyware.Ultimate_Defender, Trojan.Dumaru, Trojan.SC_Keylogger, Trojan.Vipgsm, Trojan-PWS.Magania, Trojan-PWS.OnlineGames, Trojan-PWS.Tibia, Trojan-Spy.Banbra.H, Trojan-Spy.Banker.GEN

5.09640 - Adware.EliteBar, Adware.Webbuying, Backdoor.IRC.Flood, Backdoor.Poison, Backdoor.SkRat, PSWTool.Brutus, Rootkit.Agent, Trojan.FakeAlert, Trojan.Laoshen, Trojan.Popuper, Trojan-Downloader.Agent.AKQ, Trojan-Downloader.Small.BUY, Trojan-Downloader.Small.GEN, Trojan-PWS.LdPinch, Trojan-PWS.OnlineGames, Trojan-PWS.QQShou, Worm.Spybot


General Information:

Updates are posted 5 times per week on average.

Updates are installed by running Spyware Doctors' Smart Update feature.

Tuesday, April 22, 2008

Firefox 2.0.0.14 Update

Firefox v2.0.0.14 released
From an admin account, start Firefox, then >Help >Check for Updates
-or-

Download
- http://www.mozilla.com/firefox/

What's new:
- http://www.mozilla.com/en-US/firefox.../releasenotes/
April 16, 2008

- http://www.mozilla.org/projects/secu...irefox2.0.0.14

- http://secunia.com/advisories/29787/

Release Date: 2008-04-17
Critical: Highly critical
Impact: DoS, System access
Where: From remote
Solution Status: Vendor Patch...
Solution: Update to version 2.0.0.14.

Tuesday, February 12, 2008

Leopard Graphics Update for 10.5.2

After you update to Mac OS 10.5.2 Leopard, there's an update for your video graphics. Not much detail provided on the download page, but performance is reported to greatly increase for World of Warcraft. After you update to 10.5.2, run software update again to get this update.

Monday, February 11, 2008

Mac OS 10.5.2 and Security Update 2008-001

Apple released the next big update for Leopard today, 10.5.2. There's also a security update for users running 10.4 Tiger, Security Update 2008-001. Security updates for Leopard are included in 10.5.2 while tiger will have the 2008-001 as an update.


Mac OS 10.5.2 includes updates for Airport, Back to My Mac, iCal, iChat, Mail, Printing, Safari, Time Machine, and much more. The security update includes fixes for Safari, Mail, Parental Controls, Samba, Terminal and X11.

Here are links to more information about the Leopard 10.5.2 update and Security Update 2008-001. To get these updates, click the Apple in the top left of the screen and select Software Update.

Friday, February 08, 2008

VirusHeat, Yet Another Rogue

The latest fake antispyware program is called VirusHeat. It does the usual fake warning ballon down by the clock telling you have spyware and other scary stuff. Luckily, it's not hard to remove, and the crew at Bleeping Computer have a VirusHeat removal guide.

SmitFraudFix can get this pest off your PC and it's free. So click the link above to see how to get this crap off your computer.


Here's what the fake warning looks like. It may say something different, but it's the same idea.

Tuesday, January 15, 2008

Macs Join the Rogue Program Club

F-Secure has reported about the first known rogue antispyware program for MacIntosh computers. Macsweeper is what it goes by. With the growing number of reported fake codec zlob trojans made for Macs, this doesn't surprise me. The first known Mac fake codec was reported just last November. Since then, there has been a steady release of Mac fake codecs to go along with the Windows versions. The last one discovered was on January 11th. If you go through Sunbelt's blog, you'll find many more.

For now, I'm not sure how you remove it, but it appears to be mainly a nuisance. More updates on this later.

Saturday, January 05, 2008

Microsoft Advance Security Bulletin For January 2008

Microsoft have released an advance notification for the normal monthly updates that are due to be released next Tuesday. Don’t forget to prepare for the updates as I’ve outlined in an earlier entry - How To Prepare for Patch Tuesday.

On 8th January 2008 Microsoft is planning to release:

Security Updates

One Critical Bulletin.

  • One Microsoft Security Bulletin affecting Microsoft Windows with a Maximum Severity rating of Critical. This update will require a restart and will be detectable using the Microsoft Baseline Security Analyzer.

One Important Bulletin.

  • One Microsoft Security Bulletin affecting Windows with a Maximum Severity rating of Important. This update will require a restart and will be detectable using the Microsoft Baseline Security Analyzer.

Microsoft Windows Malicious Software Removal Tool

  • Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services and the Download Centre.

Non-security High Priority updates on MU, WU,WSUS and SUS

  • Microsoft will release two NON-SECURITY High-Priority Updates for Windows on Windows Update (WU)
  • Microsoft will release five NON-SECURITY High-Priority Updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).

Microsoft Security Bulletin Advance Notification

Obtaining Other Security Updates

Updates for other security issues are available from the following locations:

  • Security updates are available from Microsoft Download Center. You can find them most easily by doing a keyword search for “security update”.
  • Updates for consumer platforms are available from Microsoft Update.
  • You can obtain the security updates offered this month on Windows Update, from Download Center on Security and Critical Releases ISO CD Image files. For more information, see Microsoft Knowledge Base Article 913086.

Microsoft will host a webcast to address customer questions on these bulletins on January 9, 2008, at 11:00 AM Pacific Time (US & Canada). Register now for the January Security Bulletin Webcast. After this date, this webcast is available on-demand. For more information, see Microsoft Security Bulletin Summaries and Webcasts.

Thursday, January 03, 2008

Ad-Aware SE No Longer Supported

If you are using Lavasoft’s Ad-Aware SE then you must uninstall it and replace it with Ad-Aware 2007 Free.  Lavasoft will no longer provide definition updates for Ad-Aware SE.. and an anti-malware program that doesn’t get regular updates is as much use to you as a chocolate teapot.

Please note; Ad-Aware 2007 Free is only compatible with Windows 2000, XP, 2003 Server and Vista(32-bit).  If you are running earlier versions of Windows (Windows 98 or ME) then you will not be able to use it.

Friday, December 28, 2007

New Rogue - MalwareCrush

They don’t stop trying do they? I’ve just had a report about another new rogue that goes by the name of MalwareCrush.

MalwareCrush is a rogue anti-spyware program that uses aggressive advertising and is installed onto your computer through the use of Trojans and other malware. This software is typically installed on your computer when you download programs masquerading as a video codecs required to view a video on a web page. In reality, though, when you install these Trojans, they will instead show fake security alerts in your Windows taskbar and install MalwareCrush onto your computer without your consent.

Once MalwareCrush is installed, it will automatically start and scan your computer. When the scan is finished it will have found the malware that actually installed it in the first place, but will require you to purchase the software before you can attempt to remove it. This is obviously a scam and you should not purchase the software under any circumstances.

Removal guide and screenshots at Bleeping Computer

Monday, December 10, 2007

Microsoft Security Bulletin Advance Notification for December 2007

Microsoft have released an advance notification for the normal monthly updates that are due to be released next Tuesday. Don't forget to prepare for the updates as I've outlined in an earlier entry - How To Prepare for Patch Tuesday.

The following updates are planned for release on Tuesday December 11th.

Critical (3)

Microsoft Security Bulletin 2
Maximum Severity Rating: Critical
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows, DirectX, DirectShow...

Microsoft Security Bulletin 6
Maximum Severity Rating: Critical
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows, Windows Media Format Runtime...

Microsoft Security Bulletin 7
Maximum Severity Rating: Critical
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows, Internet Explorer...

Important (4)

Microsoft Security Bulletin 1
Maximum Severity Rating: Important
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows...

Microsoft Security Bulletin 3
Maximum Severity Rating: Important
Impact of Vulnerability: Remote Code Execution...
Affected Software: Windows...

Microsoft Security Bulletin 4
Maximum Severity Rating: Important
Impact of Vulnerability: Elevation of Privilege...
Affected Software: Windows...

Microsoft Security Bulletin 5
Maximum Severity Rating: Important
Impact of Vulnerability: Local Elevation of Privilege...
Affected Software: Windows...
---

Microsoft Windows Malicious Software Removal Tool
Microsoft will release an updated version of the Microsoft Windows Malicious Software Removal Tool on Windows Update, Microsoft Update, Windows Server Update Services, and the Download Center.

Non-Security, High-Priority Updates on MU, WU, and WSUS
For this month:
• Microsoft is planning to release -six- non-security, high-priority updates on Microsoft Update (MU) and Windows Server Update Services (WSUS).
• Microsoft is planning to release -one- non-security, high-priority update for Windows on Windows Update (WU).
Note that this information pertains only to non-security, high-priority updates on Microsoft Update, Windows Update, and Windows Server Update Services released on the same day as the security bulletin summary. Information is not provided about non-security updates released on other days..."

Saturday, November 24, 2007

MSN Messenger Trojan

An MSN trojan is infecting thousands of PC’s worldwide via an IRC botnet. The malware is being introduced by MSN Messenger files posing as pictures, mostly seeming to come from known contacts.

So you get a message saying ‘Hey, this is your pic’ or ‘Hey this is your pic on this site’ with a link to a picture rating site. Click on the link and you will find that your computer has been recruited into the botnet!

From e-Week

The Trojan is an IRC bot that’s spreading through MSN Messenger by sending itself in a .zip file with two names. One of the names includes the word “pics” as a double extension executable—a name generally used by scanners and digital cameras: for example, DSC00432.jpg.exe. The Trojan is also contained in a .zip file with the name “images” as a .pif executable—for example, IMG34814.pif.

The files are infiltrating new systems by using either known contacts from which the Trojan has harvested instant messaging names, as well as from the systems of unknown users.

The infection vector—an IM program—isn’t new. But the Trojan is the first that eSafe has tracked that has tried to scan for VNC (Virtual Network Computing) instances, likely in order to multiply the botnet’s number of connections.

Use your common sense when chatting with friends, don’t click on links or open files sent from friends or otherwise unless you are 100% sure that your friend intended to send you the link. They won’t be offended if you decline to click…. !

Here is some good advice from Get Safe Online about using Instant Messaging Safely