Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Integrity Clientless Security (ICS) Update 3.7.249.0

Subscribe

Check Point Reference: CPAI-2008-190
Date Published:
Severity:
Source: SmartDefense Research Center
Protection Provided by: Connectra
  • NGX R62
  • NGX R61
  • NGX
Who is Vulnerable?
Microsoft Windows clients
Vulnerability Description
Check Point Integrity ™ Clientless Security (ICS) protects your Web site by detecting and disabling spyware processes and allowing you to enforce security policies before a user logs onto your network. Using ICS you can prevent users with potentially harmful software from accessing your Web site, and also require that they conform to your antivirus and critical patch policies.

Integrity Clientless Security requires no pre-installed software on endpoint computers, except a supported browser. The scan is performed by an ActiveX component deployed from your Web server to each endpoint computer that requests access.

68 new malware signatures were added to ICS version 3.7.249.0. For a full list of the added malware, refer to the Details tab.
Vulnerability Details
ICS Update 3.7.249.0 includes 68 new malware patterns:

Win32.Adware.MyWebS.A.60.C
Win32.Adware.NaviPromo.Gen.2.259
Win32.Adware.WildTangent.C 
Win32.Backdoor.Bifrose.xml 
Win32.Backdoor.Cakl.s  
Win32.Backdoor.Delf.mpy 
Win32.Backdoor.Flux.Y 
Win32.Backdoor.Frauder.ol 
Win32.Backdoor.Hupigon.asif 
Win32.Backdoor.Hupigon.bftd 
Win32.Backdoor.Hupigon.dck  
Win32.Backdoor.PcClient.edh 
Win32.Backdoor.PcClient.icl 
Win32.Backdoor.PoisonIvy.BH 
Win32.Backdoor.Server.Delf.aki.9 
Win32.Backdoor.Server.Oderoor.EJ.5 
Win32.Downloader.Agent.bqq  
Win32.Downloader.Zlob.aalj  
Win32.qmzsjy  
Win32.rapidooutdoor   
Win32.Spy.Agent.NJB  
Win32.Spyware.PortScan.S 
Win32.sxtcy.cn  
Win32.Trojan.Agent.454656  
Win32.Trojan.Agent.6938.A  
Win32.Trojan.Boaxxe.K.54 
Win32.Trojan.Crypt.Delf.AG.15 
Win32.Trojan.Downloader.Agent.amom 
Win32.Trojan.Downloader.Agent.amoz 
Win32.Trojan.Downloader.Agent.ngg 
Win32.Trojan.Downloader.Agent.uro 
Win32.Trojan.Downloader.Agent.urt 
Win32.Trojan.Downloader.BHOSta.be 
Win32.Trojan.Downloader.Exchanger.agr 
Win32.Trojan.Downloader.Exchanger.NC 
Win32.Trojan.Downloader.FakeAlert.AQ 
Win32.Trojan.Downloader.FraudLoad.vdcu 
Win32.Trojan.Downloader.Obfuscated.ebj 
Win32.Trojan.Downloader.RtkDL.fd 
Win32.Trojan.Downloader.Small.cwk 
Win32.Trojan.Downloader.Suurch.FC 
Win32.Trojan.Downloader.VB.bsa 
Win32.Trojan.Downloader.Zlob.abhy 
Win32.Trojan.Dropper.Agent.ybe  
Win32.Trojan.Dropper.IRC.TKB.311
Win32.Trojan.Dropperper.SGX.31
Win32.Trojan.GameThief.OnLineGames.skzu
Win32.Trojan.GameThief.OnLineGames.tnud
Win32.Trojan.Generic.221345 
Win32.Trojan.HeurMalware.414 
Win32.Trojan.Jevafus.A.269  
Win32.Trojan.Jevafus.A.277  
Win32.Trojan.Jevafus.A.282  
Win32.Trojan.Jevafus.A.335  
Win32.Trojan.Jevafus.A.364  
Win32.Trojan.Monderb.vgl 
Win32.Trojan.PSW.Agent.SFX.39
Win32.Trojan.PSW.Agent.SFX.53
Win32.Trojan.PSW.OnlineGames.AAAW 
Win32.Trojan.Renos.NEG.3 
Win32.Trojan.Small.504 
Win32.Trojan.Small.AJZ 
Win32.Trojan.Spy.Delf.NPF.22  
Win32.Trojan.TDss.1.Gen.24  
Win32.Trojan.Vundo.fqz.28 
Win32.Trojan.Vundo.SOH  
Win32.Trojan.Vundo.SOY  
Win32.Worm.Agent.A.429

Protection Overview
The Update adds 68 new malware signatures, detecting threats posed by malware types such as worms, Trojan horses, hacker's tools, key loggers, browser plug-ins, Adwares, third party cookies, and so forth.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
Zone Labs Spyware Information Center

Connectra NGX R62

How Can I Protect My Network?
Update version for Connectra NGX R62: 692081126

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R62 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.Boaxxe.K.54

Connectra NGX R61

How Can I Protect My Network?
Update version for Connectra NGX R61: 692081126

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security and Integrity Secure Workspace.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R61 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.Boaxxe.K.54

Connectra NGX R60

How Can I Protect My Network?
Update version for Connectra NGX: 691081126

For instructions on how to update your SmartDefense Service including your Integrity Clientless Security component, please refer to CPSA-2005-11

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX who have updated their Connectra machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type
: 3rd party cookie
Malware Name: Win32.Trojan.Boaxxe.K.54