Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Integrity Clientless Security (ICS) Update 3.7.111.0

Subscribe

Check Point Reference: CPAI-2006-135
Date Published:
Severity:
Last Updated:
Source: SmartDefense Research Center
Protection Provided by: Connectra
  • NGX R61
  • NGX
  • 2.0
Who is Vulnerable?
Microsoft Windows clients
Vulnerability Description
Check Point Integrity ™ Clientless Security (ICS) protects your Web site by detecting and disabling spyware processes and allowing you to enforce security policies before a user logs onto your network. Using ICS you can prevent users with potentially harmful software from accessing your Web site, and also require that they conform to your antivirus and critical patch policies .

Integrity Clientless Security requires no pre-installed software on endpoint computers, except a supported browser. The scan is performed by an ActiveX component deployed from your Web server to each endpoint computer that requests access.
 
68 new malware signatures were added to ICS version 3.7.111.0. For a full list of the added malware, refer to the Details tab.
Vulnerability Details
ICS Update 3.7.111.0 includes 68 new malware patterns:

 AdwareAlert
 CleanX
 Easy SpyRemover
 Easy Spyware Killer
 ETD Security Scanner
 Goodbye Spy
 Kazaap Adware & Spyware Remover
 Privacy Crusader
 ScanSpyware
 SecureMYpc
 Spy Sniper
 SpyDeface
 SpyShield
 TrueWatch
 Win32.AdWare.180Solutions.ar
 Win32.AdWare.HotBar.bo
 Win32.AdWare.NewWeb.e
 Win32.Adware.PageLinks
 Win32.ADWareBazooka
 Win32.AdwareRemoval
 Win32.AdwareSheriff
 Win32.AlfaCleaner
 Win32.Backdoor.Agobot.lo
 Win32.Backdoor.GrayBird.a
 Win32.Backdoor.GrayBird.al
 Win32.Backdoor.GrayBird.bh
 Win32.Backdoor.Hupigon.uh
 Win32.Backdoor.ServU.based.u
 Win32.Backdoor.ServU.based.v
 Win32.BitReader
 Win32.Destiny32
 Win32.Email.Worm.Bagz.j
 Win32.ErrorSafeScanner
 Win32.EyeCandyAdwareRemoval
 Win32.HitVirus
 Win32.Lsass32
 Win32.MalwareWiper
 Win32.MyNetProtector
 Win32.NsUpdate
 Win32.RazeSpyware
 Win32.RemedyAntispy
 Win32.SafeWebSurfer
 Win32.Scan&RepairUtilities2006
 Win32.SpyCut
 Win32.SpyDefence
 Win32.SpyiBlock
 Win32.SpywareCleaner
 Win32.SpywareDisinfectorMonitor
 Win32.Spywarehound
 Win32.SpywareSledgehammer
 Win32.SpywareSnooper
 Win32.SpywareWizard
 Win32.Trojan.BHO.g
 Win32.Trojan.Downloader.Cryptic.c
 Win32.Trojan.Downloader.Zlob.wp
 Win32.Trojan.Downloader.Zlob.xi
 Win32.Trojan.Downloader.Zlob.xj
 Win32.Trojan.Downloader.Zlob.ya
 Win32.Trojan.PSW.LdPinch.alt
 Win32.Trojan.PSW.LdPinch.bd
 Win32.Trojan.PSW.LdPinch.fu
 Win32.Trojan.PSW.LdPinch.wm
 Win32.Trojan.PSW.Lmir.azo
 Win32.Trojan.PSW.OnLineGames.av
 Win32.Trojan.PSW.QQRob.iv
 Win32.Trojan.PSW.Sinowal.p
 Win32.VirusBursters
 Win32.wdfmgr32

Protection Overview
The Update adds 68 new malware signatures, detecting threats posed by malware types such as worms, Trojan horses, hacker's tools, key loggers, browser plug-ins, Adwares, third party cookies, and so forth.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
Zone Labs Spyware Information Center

Connectra NGX R61

How Can I Protect My Network?
Update version for Connectra NGX R61: 692061114

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security and Integrity Secure Workspace.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R61 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.Downloader.Zlob.xj

Connectra NGX

How Can I Protect My Network?
Update version for Connectra NGX: 691061114

For instructions on how to update your SmartDefense Service including your Integrity Clientless Security component, please refer to CPSA-2005-11

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX who have updated their Connectra machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type
: 3rd party cookie
Malware Name: Win32.Trojan.Downloader.Zlob.xj

Connectra 2.0

How Can I Protect My Network?
Update version for Connectra 2.0: 690061114

For instructions on how to update your SmartDefense Service including your Integrity Clientless Security component, please refer to CPSA-2005-11

How Do I Know if My Network is Under Attack?
Users Of Connectra 2.0 who have updated their Connectra machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.Downloader.Zlob.xj