2011年3月26日星期六

Fake MSE updated. Did your real MSE updates too?

Recently, AVG caught a new variant of Fake MSE, which was more sophisticated and confusing. As usually, it will pop up to warn you that you have been infected. If you apply ?recommened? actions, the UI announces that the malware...

malware antivirus free antispyware free malware protection

Re: Norton DNS 1.5 beta now has web filtering

Hi Salihb! Your question has been moved to the Other Norton Products board for better exposure.

fix pc errors free download pc errors how to fix runtime error

Apple's silent updates

Apple has released MacOS X 10.6.7 with several bugfixes and security-patches. This patch bundle also includes a silent update to Apple‘s built-in Xprotect anti-virus functionality.


Xprotect
With the release of Snow Leopard (Mac OS X 10.6) Apple introduced a basic antivirus protection called „XProtect“. It scans and detect threats when files are downloaded through Safari, Mail, iChat, Firefox and a few more and afterwards executed. The Signature-List is updated via Apples Software Update.

Till now Xprotects database contained signatures for three well-known threats:
- OSX.RSPlug.A: changes local DNS-entries, came through fake video-codecs
- OSX.Iservice: attacks websites (DDoS), came bundled with pirated applications
- OSX.HellRTS: known as HellRaiser, tool which gives the attacker full access ofver the victims system. Version 4.2 public available, version 4.4 sold for 15$ by the creator in underground forums.

malware adware antispyware soft spyware cleaner

Mozilla Firefox 4 just arrived: where is Electrolysis?

Yesterday the long awaited fourth version of Mozilla Firefox was publicly released and the Mozilla download counter already hit more than six millions of downloads in less than 24 hours. Mozilla Firefox 4 arrived a bit later than the other major competitors - Microsoft and Google - who already updated their relative browsers a couple weeks ago.

Among the top three browsers, Firefox is the latest one that achieved the full compatibility to the HTML5 standard - even though at this time HTML5 could be considered all but a definitive standard. It features a new JavaScript engine called J�gerMonkey, full hardware acceleration, crash protection feature implemented by keeping all the various browser plugins out of the main browser process and putting them in a separate process called plugin-container.exe, a brand new user interface and other interesting features.

The Firefox roadmap has been quite long, with the release of twelve beta builds and two release candidates. Today, Firefox is ready to fight against Chrome 10 and Internet Explorer 9 in the surfing performance, system performance, web page compatibility and user customization fields. Sadly, in the security field Firefox lacks of what in my opinion can be considered a really critical feature: a proactive security sandbox. By looking at the browser process architecture, it's easy to spot that Firefox inherited the old architecture of Firefox 3.x, without any major change.

We focused many times in our blog about the potential risk when surfing the web, the high chance to run into a fake or compromised webpage containing an exploit able to execute malicious code on the victim PC. Last, but not least, the 0day flaw discovered in Adobe Flash Player fixed a couple days ago by Adobe with a new update to the player.

One of the challenges in the security industry is preventing exploit codes from getting executed and mitigate them whether they are able to get executed. I usually like to think about this concept this way: the big challenge is the proactive prevention of exploit code from damaging the system, then I usually think about two sub levels in this field, a proactive step and a reactive step. In the proactive step I usually put all the techniques that try to prevent exploits from getting executed, like Data Execution Prevention, Address Space Layout Randomization, SafeSEH, GS cookie protection. In the reactive step I put technologies able to handle the potential executed exploit and mitigate it so that it can't harm the system.

We have seen many times how a misconfigured proactive layer together with a poor software coding style helped attackers to infect victim's PC with nasty malware. Even if the user is running in a limited account, banking trojans like SpyEye, old ZeuS, Carberp can still infect the system and steal sensitive data.

This is why during these years there has been a huge development of tools able to put the browser session in a sandbox, a monitored section which would be able to prevent potential malware dropped by exploit to get outside the limited sandbox.

Google has been the first company to implement a sandbox feature in its Google Chrome, a sandbox framework compatible with Windows 2000 to Windows 7. All the browser tab sessions are divided in separate processes, each one of these stripped of all user privileges and put in a limited job object. This effectively helps Chrome in protecting the user from possible exploits that could be run against Chrome or browser plugins like Adobe Flash Player.

Then Microsoft implemented a sandbox-like feature starting from Internet Explorer 7, by using the new User Account Control and Mandatory Integrity Control features included in Windows Vista and Windows 7. The browser starts in protected mode and every browser process is run at low integrity level. All browser extensions and ActiveX controls run inside the low-integrity process. All processes run at low integrity level have highly limited access to system resources, registry and disk locations. This means that a potential malware dropped by an exploit could still be executed, but it couldn't easily go too far in the system because of the highly reduced privileges.

What about Firefox? I expected to see something similar in this fourth release, though as far I can see nothing about it has been implemented by Mozilla. Firefox sets up the main browser process firefox.exe and another child process called plugin-container.exe, which will contain all the browser plugins. Both processes are executed at medium integrity level, with the privileges of the user who executed the browser session. This could result in a situation where a possible malware executed by an exploit would run with standard user privilege, not so good actually.

While I think the proactive step based on exploit prevention is important, I strongly consider the reactive step a critical feature that should be implemented as well, in a perspective of a multi layered protection system able to mitigate as much as possible a potential malware. Mozilla had a project called Electrolysis (also known as e10s) already scheduled, that should allow Firefox running separate processes to display browser's tabs. The sandbox feature looks scheduled inside this project, though the roadmap is still to be defined.

Moreover, Firefox 4 is compatible with Windows XP and this is a very good news. The problem is that, while Windows XP can take advantage of Data Execution Prevention (DEP), XP lacks the more important Address space layout randomization (ASLR) feature from later versions of Windows, which helps DEP work more effectively. This means that a sandbox would be really useful to protect customers against web exploits.

Sure, there are a huge number of Firefox extensions that could help the browser in mitigating exploit attacks, most notably the very effective NoScript extension. NoScript actively helps in preventing exploits from working because it acts as a script firewall, preventing scripts from unauthorized Web sites from loading. Though I must admit that it's hard to me thinking about the average Joe using NoScript extension.

I think that Firefox 4 is a great browser, totally able to compete with Internet Explorer 9 and Google Chrome. I would have like to have seen in Firefox 4 a sandbox-like approach like Chrome and Internet Explorer, that would definitely help users stay safe while surfing the web.

how to fix pc errors fix pc errors freeware fix pc errors free

2011年3月25日星期五

Definition file update for Ad-Aware.


149.649 is now available, new definition file for Ad-Aware 8.2.

150.334 is now available, new definition file for Ad-Aware 9.x, 8.3.

New definitions:
====================


Updated definitions:
====================
MSIL.Backdoor.Agent
MSIL.Trojan.Agent
MSIL.TrojanDropper.Agent
MSIL.TrojanDropper.StubRC
MSIL.TrojanPWS.Agent
MSIL.TrojanSpy.Agent
MSIL.TrojanSpy.KeyLogger
MSIL.TrojanSpy.Zbot
NSIS.TrojanDownloader.Agent
NSIS.TrojanDropper.Agent
VBS.TrojanClicker.Agent
Win32.Adware.Adnur
Win32.Adware.BHO
Win32.Adware.Cinmus
Win32.Adware.EzuLa
Win32.Adware.Gaba
Win32.Adware.Ksg
Win32.Adware.PurityScan
Win32.Adware.RON
Win32.Backdoor.Agent
Win32.Backdoor.Bifrose
Win32.Backdoor.BlackHole
Win32.Backdoor.Bredolab
Win32.Backdoor.Clemag
Win32.Backdoor.Dusta
Win32.Backdoor.Floder
Win32.Backdoor.Gbot
Win32.Backdoor.Hupigon
Win32.Backdoor.IRCBot
Win32.Backdoor.Krafcot
Win32.Backdoor.Nbdd
Win32.Backdoor.Papras
Win32.Backdoor.Poison
Win32.Backdoor.Prorat
Win32.Backdoor.Prosti
Win32.Backdoor.RBot
Win32.Backdoor.Ripinip
Win32.Backdoor.SDBot
Win32.Backdoor.Turkojan
Win32.Backdoor.VB
Win32.Backdoor.Yobdam
Win32.Backdoor.Yoddos
Win32.Dialer.Megadial
Win32.Hoax.ArchSMS
Win32.Monitor.Ardamax
Win32.Monitor.EliteKeylogger
Win32.Monitor.FreeKeylogger
Win32.Monitor.Perflogger
Win32.Monitor.PowerSpy
Win32.P2PWorm.Bacteraloh
Win32.P2PWorm.Palevo
Win32.P2PWorm.Polip
Win32.Rootkit.Agent
Win32.Rootkit.TDSS
Win32.Trojan.Agent
Win32.Trojan.Agent2
Win32.Trojan.AntiAV
Win32.Trojan.AutoIT
Win32.Trojan.BHO
Win32.Trojan.Buzus
Win32.Trojan.Chifrax
Win32.Trojan.Chydo
Win32.Trojan.Cosmu
Win32.Trojan.Cospet
Win32.Trojan.Cossta
Win32.Trojan.Delf
Win32.Trojan.Delfinject
Win32.Trojan.Diple
Win32.Trojan.FakeAV
Win32.Trojan.Fakewarn
Win32.Trojan.Fraudpack
Win32.Trojan.Gabba
Win32.Trojan.Genome
Win32.Trojan.Inject
Win32.Trojan.Jorik
Win32.Trojan.Krament
Win32.Trojan.Llac
Win32.Trojan.Logoninvader
Win32.Trojan.Mahato
Win32.Trojan.Menti
Win32.Trojan.Midgare
Win32.Trojan.Monder
Win32.Trojan.Oner
Win32.Trojan.Pasmu
Win32.Trojan.Pasta
Win32.Trojan.Pincav
Win32.Trojan.Pirminay
Win32.Trojan.Refroso
Win32.Trojan.Regie
Win32.Trojan.Sasfis
Win32.Trojan.Scar
Win32.Trojan.Searches
Win32.Trojan.Sefnit
Win32.Trojan.Siscos
Win32.Trojan.Small
Win32.Trojan.Swisyn
Win32.Trojan.Tdss
Win32.Trojan.VB
Win32.Trojan.Vaklik
Win32.Trojan.Vbkrypt
Win32.Trojan.Vilsel
Win32.Trojan.Webprefix
Win32.Trojan.Zapchast
Win32.Trojan.Zmunik
Win32.TrojanClicker.Cycler
Win32.TrojanClicker.VB
Win32.TrojanClicker.VBiframe
Win32.TrojanDownloader.Agent
Win32.TrojanDownloader.Autoit
Win32.TrojanDownloader.Banload
Win32.TrojanDownloader.CodecPack
Win32.TrojanDownloader.Dadobra
Win32.TrojanDownloader.Delf
Win32.TrojanDownloader.Exchanger
Win32.TrojanDownloader.Fraudload
Win32.TrojanDownloader.Genome
Win32.TrojanDownloader.Geral
Win32.TrojanDownloader.Kido
Win32.TrojanDownloader.Lipler
Win32.TrojanDownloader.Mufanom
Win32.TrojanDownloader.Murlo
Win32.TrojanDownloader.Pher
Win32.TrojanDownloader.Qhost
Win32.TrojanDownloader.Small
Win32.TrojanDownloader.VB
Win32.TrojanDropper.Agent
Win32.TrojanDropper.Cadro
Win32.TrojanDropper.Clons
Win32.TrojanDropper.HeliosBinder
Win32.TrojanDropper.Microjoin
Win32.TrojanDropper.MuDrop
Win32.TrojanDropper.Renum
Win32.TrojanDropper.SennaOneMaker
Win32.TrojanDropper.Small
Win32.TrojanDropper.TDSS
Win32.TrojanDropper.VB
Win32.TrojanDropper.Vedio
Win32.TrojanMailfinder.Delf
Win32.TrojanPWS.Alipay
Win32.TrojanPWS.Bjlog
Win32.TrojanPWS.Kykymber
Win32.TrojanPWS.Lmir
Win32.TrojanPWS.Magania
Win32.TrojanPWS.Nilage
Win32.TrojanPWS.Novlog
Win32.TrojanPWS.OnlineGames
Win32.TrojanPWS.Papras
Win32.TrojanPWS.QQPass
Win32.TrojanPWS.Qbot
Win32.TrojanPWS.Ruftar
Win32.TrojanPWS.VB
Win32.TrojanProxy.Slaper
Win32.TrojanRansom.Fakeinstaller
Win32.TrojanRansom.HmBlocker
Win32.TrojanRansom.PornoBlocker
Win32.TrojanSpy.Agent
Win32.TrojanSpy.Banbra
Win32.TrojanSpy.Bancos
Win32.TrojanSpy.Banker
Win32.TrojanSpy.Flystudio
Win32.TrojanSpy.Qhost
Win32.TrojanSpy.SpyEyes
Win32.TrojanSpy.Zbot
Win32.Worm.Agent
Win32.Worm.Allaple
Win32.Worm.Aspxor
Win32.Worm.AutoIt
Win32.Worm.AutoTsifiri
Win32.Worm.Autorun
Win32.Worm.Ckbface
Win32.Worm.Fearso
Win32.Worm.Fujack
Win32.Worm.Joleee
Win32.Worm.Kido
Win32.Worm.Kolab
Win32.Worm.Mabezat
Win32.Worm.Mydoom
Win32.Worm.Mytob
Win32.Worm.Vbna


MD5 checksum for Ad-Aware core.aawdef is 0998e331649d0dafd028f7d139a7545b

virus removal malware detection spyware malware removal free

Unhappy New Year

Malware authors don’t miss any major event in their attempts to spread malware. Evidently, they see the upcoming New Year as yet another opportunity to get their creations into unsuspecting users' computers. We have already seen signs of malware misusing this happy event. In most cases, these are spammed emails that look like legitimate “Happy New Year” messages or “New Year”-themed greetings. 

Here is a recent example:

As you can see, the video can’t be played without, you guessed it, a fake version of Adobe’s Flash Player.  As you probably realized, this is just a trick to download something malicious, which in this case is a variant of the well-known password stealer Win32/Zbot (SHA1: 6C5B80A73B4B728D7DF8BFBB142E10A6A29A0950). Once executed, it will inject itself into the address space of explorer.exe in an attempt to bypass security. When it connects to the Internet, an alert similar to the one below may be triggered:

Another example of malware using the New Year is related to a blog post from earlier this week. One of the samples of Exploit:Win32/CVE-2010-3333 (00d9af54c5465c28b8c7a917c9a1b1c797b284ab) drops malware detected as TrojanDropper:Win32/Meciv.A and Backdoor:Win32/Meciv.A. To hide its malicious dropping activities, it also drops a clean DOC file with the following New Year's message:

The message is in Russian and means: "Dear colleagues and friends! Happy New Year!"

While the techniques are not new, the social engineering employed may actually dupe users into running these malicious programs, because the New Year passing is regarded as a happy event and people tend to see the good rather than the bad.

As usual, we suggest that you stay sharp and carefully check all links and e-mail messages containing greetings and holiday themed e-cards, especially those from strangers or entities you haven’t been in contact with.

Many thanks to our colleague Kai Yu from the Antispam team for providing us with the sample.

We warmly wish you a “Happy New Year!” and may it be malware-free!

 

Andrei Saygo && Patrik Vicol && Rodel Finones

 

fix runtime error fix errors on pc for free fix computer errors for free

AVG for Linux achieved VB100 award

Just a quick look back to the latest VB100 Comparative review published in February's Virus Bulletin. The review was done on Ubuntu Linux platform and our version of AVG for Linux was granted by another VB100 award. It was its...

remove spyware spyware search and destroy security tool virus removal