Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Integrity Clientless Security (ICS) Update 3.7.193.0

Subscribe

Check Point Reference: CPAI-2007-134
Date Published:
Severity:
Source: SmartDefense Research Center
Protection Provided by: Connectra
  • NGX R62
  • NGX R61
  • NGX
Who is Vulnerable?
Microsoft Windows clients
Vulnerability Description
Check Point Integrity ™ Clientless Security (ICS) protects your Web site by detecting and disabling spyware processes and allowing you to enforce security policies before a user logs onto your network. Using ICS you can prevent users with potentially harmful software from accessing your Web site, and also require that they conform to your antivirus and critical patch policies.

Integrity Clientless Security requires no pre-installed software on endpoint computers, except a supported browser. The scan is performed by an ActiveX component deployed from your Web server to each endpoint computer that requests access.
 
151 new malware signatures were added to ICS version 3.7.193.0. For a full list of the added malware, refer to the Details tab.
Vulnerability Details
ICS Update 3.7.193.0 includes 151 new malware patterns:

 Win32.Adware.Cdnup
 Win32.AdWare.IEHlpr.c
 Win32.Adware.Sogou.J
 Win32.Adware.WhenU.3
 Win32.aodxsavla
 Win32.Application.Aseye.LW
 Win32.Application.Bloodscroller.A
 Win32.Backdoor.Akbot.b
 Win32.Backdoor.Bifrose.NQ
 Win32.BackDoor.Generic.1210
 Win32.Backdoor.Generic.24686
 Win32.Backdoor.Generic.25160
 Win32.Backdoor.Gift.211
 Win32.Backdoor.Haxdoor.gl
 Win32.Backdoor.Hupigon.BIC
 Win32.Backdoor.Hupigon.cuu
 Win32.Backdoor.Hupigon.YQZ
 Win32.Backdoor.Hupigon.YSM
 Win32.Backdoor.IRCBot
 Win32.Backdoor.IRCBot.qs
 Win32.Backdoor.Oblivion.01.a
 Win32.Backdoor.PcClient.dh
 Win32.Backdoor.PcClient.dj
 Win32.Backdoor.PcClient.hs
 Win32.BackDoor.Pigeon.61
 Win32.Backdoor.Sdbot.DEZV
 Win32.Backdoor.Senik.b
 Win32.Backdoor.XiaoBird.6AF9
 Win32.Backdoor.Y3KRat.d
 Win32.bright
 Win32.Dialer.PlayGames.m
 Win32.Email.Worm.Magistr.b
 Win32.Email.Worm.Zhelatin.ek
 Win32.Email.Worm.Zhelatin.fy
 Win32.Exploit.MS05.039.ad
 Win32.for bike
 Win32.gate
 Win32.Generic.Malware.SHdld
 Win32.Generic.Malware.SL.g
 Win32.HackTool.Delf.bw
 Win32.Happy
 Win32.help plan
 Win32.IM.Worm.Delf.n
 Win32.James.3259
 Win32.Joke.Slippery.A
 Win32.Logger.Delf.uc
 Win32.mail draw
 Win32.mmsvc32
 Win32.Net.Worm.Lovesan.m
 Win32.Packer.Expressor.B
 Win32.PWS.Legmir.340
 Win32.RiskWare.Proxy.CCProxy.60
 Win32.Rootkit.Agent.lc
 Win32.SMS.Flooder.Bomber.l
 Win32.Trojan.Agent.AFJY
 Win32.Trojan.Agent.AFSH
 Win32.Trojan.Agent.AFST
 Win32.Trojan.Agent.ags
 Win32.Trojan.Agent.bnq
 Win32.Trojan.Agent.ciw
 Win32.Trojan.CA
 Win32.Trojan.Clicker.Agent.gr
 Win32.Trojan.Codbot.56
 Win32.Trojan.DDoS.VB.c
 Win32.Trojan.DDoS.VB.h
 Win32.Trojan.Delf.1076
 Win32.Trojan.DNSChanger.46
 Win32.Trojan.Downloader.26876
 Win32.Trojan.Downloader.29569
 Win32.Trojan.Downloader.33209
 Win32.Trojan.Downloader.35912
 Win32.Trojan.DownLoader.7380
 Win32.Trojan.Downloader.Agent.cbn
 Win32.Trojan.Downloader.Agent.eck
 Win32.Trojan.Downloader.Agent.ejc
 Win32.Trojan.Downloader.Banload.CH
 Win32.Trojan.Downloader.Banload.vu
 Win32.Trojan.Downloader.BYM
 Win32.Trojan.Downloader.Delf.NZE
 Win32.Trojan.Downloader.QQHelper.agd
 Win32.Trojan.Downloader.Small.amg
 Win32.Trojan.Downloader.Tiny.ke
 Win32.Trojan.Downloader.VB.bct
 Win32.Trojan.Downloader.VB.bnq
 Win32.Trojan.Downloader.VB.VIY
 Win32.Trojan.Downloader.VB.zn
 Win32.Trojan.Dropper.Agent.hk
 Win32.Trojan.Dropper.Delf.po
 Win32.Trojan.FirewallBypass
 Win32.Trojan.Generic.64688
 Win32.Trojan.Generic.64734
 Win32.Trojan.Generic.64771
 Win32.Trojan.Generic.64892
 Win32.Trojan.Generic.65068
 Win32.Trojan.Generic.65264
 Win32.Trojan.Generic.65528
 Win32.Trojan.Generic.68461
 Win32.Trojan.Generic.68638
 Win32.Trojan.Generic.68811
 Win32.Trojan.IRC.Script.95
 Win32.Trojan.KillProc.n
 Win32.Trojan.MulDrop.6429
 Win32.Trojan.New.Malware.H
 Win32.Trojan.Packed.2136
 Win32.Trojan.Packed.2228
 Win32.Trojan.Packed.2236
 Win32.Trojan.PcClient.11
 Win32.Trojan.Peed.INM
 Win32.Trojan.Proxy.Xorpix.bx
 Win32.Trojan.PSW.Lmir.wu
 Win32.Trojan.PSW.M2.16
 Win32.Trojan.PSW.Nilage.boa
 Win32.Trojan.PSW.OnLineGames.bkk
 Win32.Trojan.PSW.OnLineGames.bmk
 Win32.Trojan.PSW.OnLineGames.cyn
 Win32.Trojan.PSW.OnLineGames.fal
 Win32.Trojan.PSW.OnLineGames.fgr
 Win32.Trojan.PSW.OnLineGames.fmt
 Win32.Trojan.PSW.Onlinegames.NKF
 Win32.Trojan.PSW.QQGame.aj
 Win32.Trojan.PSW.Weird.d
 Win32.Trojan.PSW.WOW.mm
 Win32.Trojan.PSW.Wsgame.1464
 Win32.Trojan.PWS.Egold
 Win32.Trojan.Riler.k
 Win32.Trojan.Rootkit.Farfli.D
 Win32.Trojan.RTC.a
 Win32.Trojan.Spy.Agent.NIU
 Win32.Trojan.Spy.Ardamax.26
 Win32.Trojan.Spy.Banker.5113
 Win32.Trojan.Spy.Banker.5219
 Win32.Trojan.Spy.Banker.5940
 Win32.Trojan.Spy.Banker.ayo
 Win32.Trojan.Spy.Banker.blo
 Win32.Trojan.Spy.Banker.so
 Win32.Trojan.Spy.Delf.kd
 Win32.Trojan.Spy.Delf.qr
 Win32.Trojan.Srizbi.T
 Win32.Trojan.StartPage.aka
 Win32.Trojan.StartPage.asa
 Win32.Trojan.TrojanDropper.Bagle.G
 Win32.Trojan.VB.bjk
 Win32.Trojan.Vundo.DOY
 Win32.Trojan.Vundo.DQC
 Win32.Trojan.W32.Paradrop.A
 Win32.TrojanDownloader.Rameh.c
 Win32.W32.Jeefo
 Win32.W32Bagle.AM0mm
 Win32.W32Bagle.AQ0mm
 Win32.Worm.AutoIt.d
 Win32.Worm.Harwig

Protection Overview
The Update adds 151 new malware signatures, detecting threats posed by malware types such as worms, Trojan horses, hacker's tools, key loggers, browser plug-ins, Adwares, third party cookies, and so forth.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
Zone Labs Spyware Information Center

Connectra NGX R62

How Can I Protect My Network?
Update version for Connectra NGX R62: 692071129

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R62 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Worm.AutoIt.d

Connectra NGX R61

How Can I Protect My Network?
Update version for Connectra NGX R61: 692071129

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security and Integrity Secure Workspace.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R61 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Worm.AutoIt.d

Connectra NGX R60

How Can I Protect My Network?
Update version for Connectra NGX: 691071129

For instructions on how to update your SmartDefense Service including your Integrity Clientless Security component, please refer to CPSA-2005-11

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX who have updated their Connectra machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type
: 3rd party cookie
Malware Name: Win32.Worm.AutoIt.d