Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Integrity Clientless Security (ICS) Update 3.7.147.0

Subscribe

Check Point Reference: CPAI-2007-039
Date Published:
Severity:
Last Updated:
Source: SmartDefense Research Center
Protection Provided by: Connectra
  • NGX R62
  • NGX R61
  • NGX
  • 2.0
Who is Vulnerable?
Microsoft Windows clients
Vulnerability Description
Check Point Integrity ™ Clientless Security (ICS) protects your Web site by detecting and disabling spyware processes and allowing you to enforce security policies before a user logs onto your network. Using ICS you can prevent users with potentially harmful software from accessing your Web site, and also require that they conform to your antivirus and critical patch policies.

Integrity Clientless Security requires no pre-installed software on endpoint computers, except a supported browser. The scan is performed by an ActiveX component deployed from your Web server to each endpoint computer that requests access.
 
88 new malware signatures were added to ICS version 3.7.147.0. For a full list of the added malware, refer to the Details tab.
Vulnerability Details
ICS Update 3.7.147.0 includes 88 new malware patterns:

 Win32.Backdoor.Bifrose.ge
 Win32.Backdoor.Bifrose.kl
 Win32.Backdoor.Bifrose.lk
 Win32.Backdoor.Bifrose.qo
 Win32.Backdoor.Delf.awf
 Win32.Backdoor.Haxdoor.hj
 Win32.Backdoor.Nethief.63
 Win32.Backdoor.Rbot.adp
 Win32.BackDoor.YQ.dll
 Win32.Bifrost
 Win32.DDick.154
 Win32.dmusdskq
 Win32.execmdhc
 Win32.Generic.903
 Win32.Generic.g
 Win32.HackTool.Forcemail
 Win32.HackTool.SQLInject.f
 Win32.IRCFlood.dr
 Win32.Mapit
 Win32.ModKeylogger
 Win32.MulDrop.2589
 Win32.NetBus.170
 Win32.OverSpy
 Win32.Pong.10
 Win32.PWS.Bancos.130
 Win32.Rootkit.Vanti.bi
 Win32.Rundllw32
 Win32.Tool.WXCrack
 Win32.TotalSpy
 Win32.Trojan.Clicker.VB.36
 Win32.Trojan.DDoS.Agent.o
 Win32.Trojan.Downloader.Agent.agz
 Win32.Trojan.Downloader.Agent.io
 Win32.Trojan.Downloader.Banload.ayz
 Win32.Trojan.Downloader.Banload.bth
 Win32.Trojan.Downloader.Banload.jr
 Win32.Trojan.Downloader.Banload.lh
 Win32.Trojan.Downloader.Banload.np
 Win32.Trojan.Downloader.Dadobra.kv
 Win32.Trojan.Downloader.Delf.zf
 Win32.Trojan.Downloader.QQHelper.t
 Win32.Trojan.Downloader.Small.bwx
 Win32.Trojan.Downloader.Small.oj
 Win32.Trojan.Downloader.Tiny.fu
 Win32.Trojan.Downloader.Zlob.dq
 Win32.Trojan.Proxy.Horst.ue
 Win32.Trojan.PSW.Maran.cx
 Win32.Trojan.PSW.Nilage.awo
 Win32.Trojan.PSW.OnLineGames.bi
 Win32.Trojan.PSW.OnLineGames.bx
 Win32.Trojan.PSW.OnLineGames.gf
 Win32.Trojan.PSW.Passack.A
 Win32.Trojan.PSW.VB.id
 Win32.Trojan.Puper.bk
 Win32.Trojan.Puper.bl
 Win32.Trojan.Revell.110
 Win32.Trojan.Spy.749
 Win32.Trojan.Spy.Bancos.dx
 Win32.Trojan.Spy.Bancos.ea
 Win32.Trojan.Spy.Bancos.ij
 Win32.Trojan.Spy.Bancos.kd
 Win32.Trojan.Spy.Banker.bol
 Win32.Trojan.Spy.Banker.bzf
 Win32.Trojan.Spy.Banker.ces
 Win32.Trojan.Spy.Banker.cjq
 Win32.Trojan.Spy.SCKeyLog.m
 Win32.TypeAgent
 Win32.Virut
 Win32.W32Agent.BPO
 Win32.W32Backdoor.ZSE
 Win32.W32Banker.QHL
 Win32.W32Banker.ZDQ
 Win32.W32Beastdoor.AN0bd
 Win32.W32Downloader.ABCM
 Win32.W32Downloader.ANLB
 Win32.W32FunLove.4099
 Win32.W32Mydoom.dam
 Win32.W32NetBus.backdoor.567296
 Win32.W32OptixPro.N
 Win32.W32PWStealer.BPW
 Win32.W32PWStealer.DDE
 Win32.W32PWStealer.DZR
 Win32.W32Trojan.PLJ
 Win32.W32Trojan.RDX
 Win32.W32VirTool.GL
 Win32.W32Virtool.QT
 Win32.W32Virtool.RU
 Win32.W32Wuke

Protection Overview
The Update adds 88 new malware signatures, detecting threats posed by malware types such as worms, Trojan horses, hacker's tools, key loggers, browser plug-ins, Adwares, third party cookies, and so forth.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
Zone Labs Spyware Information Center

Connectra NGX R62

How Can I Protect My Network?
Update version for Connectra NGX R62: 692070328

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R62 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.Spy.Banker.bol

Connectra NGX R61

How Can I Protect My Network?
Update version for Connectra NGX R61: 692070328

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security and Integrity Secure Workspace.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R61 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.Spy.Banker.bol

Connectra NGX R60

How Can I Protect My Network?
Update version for Connectra NGX: 691070328

For instructions on how to update your SmartDefense Service including your Integrity Clientless Security component, please refer to CPSA-2005-11

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX who have updated their Connectra machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type
: 3rd party cookie
Malware Name: Win32.Trojan.Spy.Banker.bol

Connectra 2.0

How Can I Protect My Network?
Update version for Connectra 2.0: 690070328

For instructions on how to update your SmartDefense Service including your Integrity Clientless Security component, please refer to CPSA-2005-11

How Do I Know if My Network is Under Attack?
Users Of Connectra 2.0 who have updated their Connectra machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.Spy.Banker.bol