Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Integrity Clientless Security (ICS) Update 3.7.252.0

Subscribe

Check Point Reference: CPAI-2009-004
Date Published:
Severity:
Source: SmartDefense Research Center
Protection Provided by: Connectra
  • NGX R62
  • NGX R61
  • NGX
Who is Vulnerable?
Microsoft Windows clients
Vulnerability Description
Check Point Integrity ™ Clientless Security (ICS) protects your Web site by detecting and disabling spyware processes and allowing you to enforce security policies before a user logs onto your network. Using ICS you can prevent users with potentially harmful software from accessing your Web site, and also require that they conform to your antivirus and critical patch policies.

Integrity Clientless Security requires no pre-installed software on endpoint computers, except a supported browser. The scan is performed by an ActiveX component deployed from your Web server to each endpoint computer that requests access. 

134 new malware signatures were added to ICS version 3.7.252.0. For a full list of the added malware, refer to the Details tab.
Vulnerability Details
ICS Update 3.7.252.0 includes 134 new malware patterns:

 Win32.2 size
 Win32.Adware.Generic.44016
 Win32.Backdoor.Generic.49997
 Win32.Backdoor.Generic.57770
 Win32.Bind 32
 Win32.Dash Cool
 Win32.eq dead
 Win32.Frag Soap
 Win32.free dash
 Win32.Hijacker.VB.cln
 Win32.Load Exit
 Win32.Sality.2.OE
 Win32.Tick Bias
 Win32.Trojan.Agent.akuj.5
 Win32.Trojan.Agent.ALBT
 Win32.Trojan.Downloader.Agent.29700
 Win32.Trojan.Downloader.Agent.anti
 Win32.Trojan.Downloader.Agent.aotn
 Win32.Trojan.Downloader.Tibs.aiq
 Win32.Trojan.Downloader.Tibs.kwj.102
 Win32.Trojan.Downloader.Tibs.kwj.71
 Win32.Trojan.Downloader.Tibs.kwj.73
 Win32.Trojan.FakeAlert.AIM
 Win32.Trojan.Fakealert.ane.9
 Win32.Trojan.Generic.1000065
 Win32.Trojan.Generic.1000073
 Win32.Trojan.Generic.1001496
 Win32.Trojan.Generic.1001497
 Win32.Trojan.Generic.1001518
 Win32.Trojan.Generic.1001520
 Win32.Trojan.Generic.1006657
 Win32.Trojan.Generic.1006693
 Win32.Trojan.Generic.1006697
 Win32.Trojan.Generic.1011258
 Win32.Trojan.Generic.1013968
 Win32.Trojan.Generic.1015933
 Win32.Trojan.Generic.1016299
 Win32.Trojan.Generic.1017415
 Win32.Trojan.Generic.1020031
 Win32.Trojan.Generic.1020437
 Win32.Trojan.Generic.1023268
 Win32.Trojan.Generic.1024212
 Win32.Trojan.Generic.1024213
 Win32.Trojan.Generic.1024245
 Win32.Trojan.Generic.1024251
 Win32.Trojan.Generic.1024254
 Win32.Trojan.Generic.1024255
 Win32.Trojan.Generic.1024265
 Win32.Trojan.Generic.1024491
 Win32.Trojan.Generic.1025602
 Win32.Trojan.Generic.1025605
 Win32.Trojan.Generic.1025606
 Win32.Trojan.Generic.1025614
 Win32.Trojan.Generic.1026491
 Win32.Trojan.Generic.1028242
 Win32.Trojan.Generic.1028343
 Win32.Trojan.Generic.1028917
 Win32.Trojan.Generic.1029444
 Win32.Trojan.Generic.1029456
 Win32.Trojan.Generic.1029531
 Win32.Trojan.Generic.1030581
 Win32.Trojan.Generic.1031912
 Win32.Trojan.Generic.1036563
 Win32.Trojan.Generic.1036576
 Win32.Trojan.Generic.1041215
 Win32.Trojan.Generic.1041975
 Win32.Trojan.Generic.1042007
 Win32.Trojan.Generic.1042070
 Win32.Trojan.Generic.1042071
 Win32.Trojan.Generic.1052329
 Win32.Trojan.Generic.1053848
 Win32.Trojan.Generic.1060316
 Win32.Trojan.Generic.1060333
 Win32.Trojan.Generic.1060452
 Win32.Trojan.Generic.1060753
 Win32.Trojan.Generic.1060757
 Win32.Trojan.Generic.1060770
 Win32.Trojan.Generic.1061313
 Win32.Trojan.Generic.1061317
 Win32.Trojan.Generic.1062293
 Win32.Trojan.Generic.1063137
 Win32.Trojan.Generic.1072813
 Win32.Trojan.Generic.1076208
 Win32.Trojan.Generic.1080157
 Win32.Trojan.Generic.1080162
 Win32.Trojan.Generic.1080163
 Win32.Trojan.Generic.1080205
 Win32.Trojan.Generic.1080209
 Win32.Trojan.Generic.1080210
 Win32.Trojan.Generic.1080224
 Win32.Trojan.Generic.1080225
 Win32.Trojan.Generic.1080228
 Win32.Trojan.Generic.1080229
 Win32.Trojan.Generic.1080479
 Win32.Trojan.Generic.1080502
 Win32.Trojan.Generic.1080704
 Win32.Trojan.Generic.1080965
 Win32.Trojan.Generic.1081010
 Win32.Trojan.Generic.1081012
 Win32.Trojan.Generic.1081049
 Win32.Trojan.Generic.1082696
 Win32.Trojan.Generic.1085450
 Win32.Trojan.Generic.1096637
 Win32.Trojan.Generic.1100715
 Win32.Trojan.Generic.1101130
 Win32.Trojan.Generic.1101697
 Win32.Trojan.Generic.1102023
 Win32.Trojan.Generic.1102194
 Win32.Trojan.Generic.1102589
 Win32.Trojan.Generic.1102840
 Win32.Trojan.Generic.1105015
 Win32.Trojan.Generic.1108002
 Win32.Trojan.Generic.1109646
 Win32.Trojan.Generic.1109651
 Win32.Trojan.Generic.1109654
 Win32.Trojan.Generic.1109801
 Win32.Trojan.Generic.322059
 Win32.Trojan.Generic.531527
 Win32.Trojan.Generic.538002
 Win32.Trojan.Generic.694374
 Win32.Trojan.Generic.937232
 Win32.Trojan.Generic.975772
 Win32.Trojan.Generic.995687
 Win32.Trojan.Generic.995706
 Win32.Trojan.Generic.995708
 Win32.Trojan.Generic.995836
 Win32.Trojan.Generic.995837
 Win32.Trojan.Generic.995842
 Win32.Trojan.Jevafus.A.325
 Win32.Trojan.PSW.VB.AR
 Win32.Trojan.Spy.Delf.NNX
 Win32.Trojan.VB.gom
 Win32.Warn rdr
 Win32.Worm.Socks.2

Protection Overview
The Update adds 134 new malware signatures, detecting threats posed by malware types such as worms, Trojan horses, hacker's tools, key loggers, browser plug-ins, Adwares, third party cookies, and so forth.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
Zone Labs Spyware Information Center

Connectra NGX R62

How Can I Protect My Network?
Update version for Connectra NGX R62: 692090107

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R62 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.VB.gom

Connectra NGX R61

How Can I Protect My Network?
Update version for Connectra NGX R61: 692090107

To update your Integrity Clientless Security (ICS) component:

1. On the navigation tree, click Security > SmartDefense Updates.
2. In the Download updated content pane, enter your credentials and check Update Integrity Clientless Security and Integrity Secure Workspace.
3. Click Download Updates.
4. Install security policy. 

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX R61 who have updated their machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type: 3rd party cookie
Malware Name: Win32.Trojan.VB.gom

Connectra NGX R60

How Can I Protect My Network?
Update version for Connectra NGX: 691090107

For instructions on how to update your SmartDefense Service including your Integrity Clientless Security component, please refer to CPSA-2005-11

How Do I Know if My Network is Under Attack?
Users Of Connectra NGX who have updated their Connectra machines will identify logs such as the following (example only, malware name varies by malware detected):

Malware Type
: 3rd party cookie
Malware Name: Win32.Trojan.VB.gom