October 27, 2006

IE7 Spoofing/Phishing Bug "Pops Up"

Security researchers have identified a pop-up address bar spoofing weakness in Microsoft's newly released Internet Explorer 7 browser. The flaw, first reported by security notification firm Secunia, might
lend itself to phishing attacks and remains currently unpatched.

The details about this flaw are found here.

The security bug creates a means for hackers to display a popup with partially spoofed address bar where a number of special characters have been appended to a URL. Only part of the address bar will be
displayed, creating a possible mechanism to trick users into believing they are visiting a trusted site rather than one controlled by hackers.

The weakness has been confirmed to exist in IE7, running even on a fully patched Windows XP SP2 system. A number of possible workarounds have been suggested, pending a fix from Microsoft. Secunia advises surfers not to follow links from untrusted sources. The SANS Institute's Internet Storm Centre suggests a more sophisticated fix involving configuring IE7 to open a new Windows in a new tab.

"This vulnerability has a lot of potential for phishers or others that attempt to trick the user into trusting the popup window as they trust the site displayed in the main window," The Internet Storm Centre notes.

Last week, Secunia and Microsoft got into a dispute about whether a separate information disclosure vulnerability affected IE7 or Outlook Express.

Secunia has created a test page, so that IE7 users can check their browsers for this vulnerability.

Secunia Advisory: SA22542
Release Date: 2006-10-25
Last Update: 2006-10-27
Critical: Less critical
Impact: Spoofing
Where: From remote
Solution Status: Unpatched
Software: Microsoft Internet Explorer 7.x

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

Spybot S&D Definitions Updated on October 27, 2006

World reknowned anti-spyware program - Spybot Search and Destroy - was updated with new spyware definition files. If you use this program be sure to run manual updates as soon as possible.

If you see a program listed in these detections by name you should assume that is is malware. Update your Spybot Search and Destroy definitions, then scan for and fix any malware that is detected.

Spybot Search and Destroy (Multi-Lingual Landing Page. Choose your language).

2006-10-27 Updates

Adware
+ Win32.TrafficSol.c

Hijacker
+ ISearchTech.SideFind + Mirar

Keylogger
+ Perfect Keylogger

Malware
+ DyFuCA.InternetOptimizer + MediaMotor.IEMonitor + PestTrap + SurfSideKick + Smitfraud-C. + Smitfraud-C.Toolbar888 + Win32.Agent.aaf

PUPS
+ iPhox + NewDotNet + YazzleSudoku

Spyware
+ Targetsaver

Trojan
+ AstaKiller + Bifrose.LA + Downloader.Adload.aa + Kelvir + Nurech.D + Purityscan + PurityScan.Q + TagASaurus (2) + WarezP2P + Win32.Small-2854 + Win32.Small.ddx + Win32.Agent.ag + Win32.Ezula.cc (2) + Zlob.Downloader + Zlob.iMediaCodec + Zlob.HQVideo (2) + Zlob.XpassGenerator + Zlob.XPasswordManager (2)

Total: 328741 fingerprints in 51240 rules for 2354 products

English Language Company Links:
Spybot Search and Destroy Home Page
Spybot Search and Destroy Download page - Program and definition updates.
Full tutorial about using and setting up Spybot Search and Destroy
Spybot Search and Destroy Update History

See all security program update notices in this catagory

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

Ad-Aware SE Definitions Updated on 10/26/2006

Ad-Aware Personal provides advanced protection from known data-mining, aggressive advertising, Trojans, dialers, malware, browser hijackers, and tracking components. This software is downloadable free of charge.

Anti Spyware/Adware program Ad-Aware, by Lavasoft has had it's definition file updated on October 26, 2006. Users of the free version should check for and install the new definitions manually.

Current Definition File:
SE1R129 26.10.2006

Due to the fact that FunWeb has made requested changes in the behavior
of their program, their TAC (Threat Analysis Chart) has been reduced.

FunWeb is currently under a two week probation period.

New Definitions:

========================

Adware.AskBar_HOLD +6
AntispywareSoldier +4
PestCapture + 6
SpyDefence + 5
SpyNoMore + 3
Win32.Trojan.Klone + 3
Win32.Trojan.MatrixHasYou +36
Win32.Worm.Warezov +8


Updated Definitions:

========================

Adware.Adhelper +3
Adware.BHO(generic) +7
Adware.DesktopMedia +2
Adware.DollarRevenue
Adware.VB
Adware.WeirWeb
Adware.ZenoSearch +2
ErrorSafe +16
Lop +15
Malware.Hacktool
SahAgent +6
SurfSideKick +3
Tracking Cookie +3
Win32.Backdoor.Agent +8
Win32.Dialer.Trojan +3
Win32.Generic.PWS +19
Win32.Nukers
Win32.Trojan.Agent +16
Win32.Trojan.Delf +4
Win32.Trojan.Downloader + 24
Win32.Trojan.Hexdoor
Win32.Trojan.Qhost +3
Win32.Trojan.Spy +2
Win32.Trojan.StartPage
Win32.TrojanClicker +4
Win32.TrojanDownloader.Agent +8
Win32.TrojanDownloader.ConHook
Win32.TrojanDownloader.Delf +10
Win32.TrojanDownloader.Small +4
Win32.TrojanDownloader.Swizzor.br +9
Win32.Trojandownloader.Zlob +15
Win32.TrojanDropper +4
Win32.TrojanProxy.Agent
Win32.Trojan-PSW.Lineage +13
Win32.TrojanSpy.Banker +5
Win32.TrojanSpy.Goldun +4
Win32.Worm.MSNMaker +3
Win32.Worm.Viking +5
Winfixer
Virtumonde +50
Zango + 9

The MD5 checksum for the defs.ref file is 2a9042d3cf6e21ff55bc9a23293a1e5b
============================================
You can use Webupdate to install the new reference file, or download
it manually from: http://download.lavasoft.de.edgesuite.net/public/defs.zip

Download the current version of Ad-Aware here: http://www.download.com/3405-8022-5153545.html

See all security program update notices in this catagory

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

October 24, 2006

Firefox 2.0 Breaks Many Extensions and Lacks an Email Icon

I just installed and checked out Firefox 2.0 and had to uninstall it almost immediately. It is missing the Email Client launch icon and disabled most of my important Extensions, which I depend on for my work. These included such Extensions as SpoofStick, Adsense Preview, Lorem Ipsum Generator, McAfee Site Advisor, Google Statusbar PageRank indicator, and my HTML Validator, DNSStuff Toolbar, and ForecastFox Accuweather forecasts. In all it disabled 6 Extensions and updated only one. I will wait a while to upgrade to version 2.0 for a while, to let the Extension authors make their plugins compatible with this version.

Going back to version 1.5.0.7 was as simple as running the setup file for that version. It overwrote the new files with the previous versions, and when Firefox opened it was exactly as I had it before performing the upgrade.

If you are using a lot of Extensions and depend on them you may want to hold off on updating to version 2.x until the Extension authors catch up to it, and Mozilla adds back the Email launching icon (if you used it). Keep the setup file for 1.5.0.7 on hand until the dust settles.

If I didn't use so many Extensions and depend on them I would have taken a longer look at version 2.0, but I didn't want to corrupt my saved personal settings with all the disabled and missing items.

Wiz

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

October 22, 2006

Firefox 2.0 Final Release to be available on or about October 24, 2006

Not to be outdone by Microsoft's recent release of Internet Explorer 7, Mozilla will release the second major version of its rival Firefox browser on Tuesday, October 24. The current beta release is RC3 and it is anticipated that not much needs to be changed to make it the official release version 2.0.

According to Mozilla Vice President of Products Christopher Beard, Firefox 2.0, which should be available on Tuesday if all goes according to schedule, includes key new usability features missing in the new IE 7.

Mozilla has also enhanced the popular tabbed browsing feature in 2.0 that Firefox introduced when it emerged two years ago as the first significant rival to IE in years, Beard adds. Tabs allow users to navigate more easily between multiple Web pages when browsing the Internet, and Microsoft added tabs to IE 7 after Firefox's success with the feature.

In Firefox 2.0, Mozilla has added a "close" button on its tabs, as well as new visual features to make the tabs appear more obvious to the user, Beard says.

New usability features in Firefox 2.0 that differentiate it from IE 7 include one that will restore the browser to pages where the user was working if a sudden OS restart is required. "If your browser needs a restart or the OS asks you to reboot, losing all of those Web pages and content is pretty disruptive," Beard notes.

Firefox 2.0 is offering two options for enabling this feature. One way is that, by default, the browser will give the user an option to restore his or her browser sessions if there is an unexpected shutdown; the other is an advanced option to set the browser so that it always restores the last five pages visited before a sudden reboot.

Antiphishing Filters in Both Browsers

Like IE 7, Firefox 2.0 also has an antiphishing filter that will help protect users from divulging personal information to fraudulent Web sites. But Mozilla has taken a different approach to its antiphishing filter than Microsoft has, Beard says.

Instead of checking individual Web pages users visit against lists of known phishing sites, thus sending information from the site to third parties that keep lists of such sites, Firefox updates its blacklist of known fraudulent Web sites automatically every half-hour to an hour. Beard said this better protects users' privacy because no information from the sites they've visited is sent to any third parties.

Mozilla also has added spell-checking features to the browser similar to those found in word-processing applications. Whenever a user is typing text in the browser--as when typing the name of a Web site, a blog entry, or an e-mail--Firefox's spell checker will underline in red words that appear misspelled. Right-clicking on the word will give a user options for a corrected spelling.

In addition, Firefox 2.0 has a new feature in its integrated search box that will suggest a list of search terms after a user types a few letters of a word, depending on the search engine being used. Firefox 2.0 uses Google, Yahoo, and Ask.com search engines as options for the search box, and each uses a different algorithm to suggest search terms, Beard explains. To ensure that this feature is not disruptive to the user experience, the suggested search terms will appear in a separate pane below the search box, he adds.

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

Automatically Delete Image Spam With MailWasher Pro

If you are barraged with spam for junk stocks, with an image and garbage text, and want to put a stop to it clogging up your inbox, MailWasher Pro is the right tool for the job. If you already have a licensed version of MailWasher Pro you probably know how to use custom user created filter rules to detect and delete spam. But, you may not know how to block image-only spam that comes from zombie home and office computers that are part of a BotNet. I have created and tested filter rules to delete this crap off the mail server without ever seeing it. Learn all about MailWasher Pro here.

If you are already using custom filters you just have to add my filters to the MailWasher Pro filters.txt file. This file is located in your profile under Documents and Settings > (Your_Account_Name folder) > Application Data > MailWasher Pro. You will need to set your Folder View Options to display Hidden Files and Folders and to display known file extensions, or these items will not be visible. If you need to set these options follow the instructions in the Extended Comments ("Read more...").

You will see a file named Filters.txt, inside the MailWasher Pro Application Data folder. Open in it Notepad then open my special filter rules: Select all and copy the rules in the popup window, then paste the rules into Filters.txt, near the top of the filters list. Make sure that each rule is on it's own continuous line, starting with [enabled]. Be sure that you do not have any blank spaces after the end of any filter rules, or any blank lines between filter rules. These things cause problems in the program. The last rule in Filters.txt should end after the last character, without a linefeed or carriage return.

Since spammers change their particulars from time to time I will alter these rules, or add new ones to continue to block this senseless spam for junk stocks and all other spam. These and the rest of my custom filters are available on my MailWasher Pro page. To be safe in case a legitimate email is deleted by one of these filter rules I have included a rule to display any email that you restore from the MailWasher Pro Recycle Bin. You should turn on this feature by going to Tools > Options > Summary > Recycle Bin and check the option to restore email, then type a valid email address from which you can send email, into the Outgoing Mail Settings field.

Never, ever buy anything that is advertised in a spam email, and never reply to one. Delete, delete, delete! If you are a reporting member of SpamCop you can also report, report, report! MailWasher Pro has a checkbox to forward spam manually to your SpamCop account, but you must respond to their reply message to actually file the report.

MailWasher Pro is free to try for 30 days, and costs only $37.00 to register, which includes a one year, renewable subscription to the FirstAlert! spam reporting system, plus, FREE Mailwasher program updates for life.

MailWasher Pro has always supported Windows and now supports Mac OS X 10.3 and Linux (for list of supported distributions, please see the download page link on this page).

Try Firetrust Mailwasher® Pro

Here is how you reset your Folder View Options to display the contents of hidden folders and to show the file extensions of known file types.

  1. Open any folder, like "My Documents"
  2. Click on Tools
  3. Click on Folder Options
  4. Click on View
  5. Check this if available: "Display the contents of System folders"
  6. Place a dot in this: "Show hidden files and folders"
  7. Uncheck this: "Hide extensions for known file types"
  8. Click APPLY
  9. Click OK to close the Folder Options dialog
  10. Refresh the view in the folder by pressing the F5 key
Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

October 21, 2006

YPOPs has been updated (delivers Yahoo email via POP3)

YPOPs, a free POP3 email interface for sending and receiving Yahoo email via your POP3 email client, was updated on October 18, 2006. POP3 email clients include Outlook, Outlook Express, Thunderbird, Eudora, etc. If you use one of these programs and would like to be able use it to send and receive your Yahoo email, YPOPs will allow you to do so. Normally, Yahoo email must be accessed via HTTP, using a web browser. This program bridges the gap between HTTP and POP3 email.

I have written out instructions for configuring and using YPOPs on my Wiz's Workshop page. I am using YPOPs on various operating systems, including Windows Vista RC1. I am not affiliated with YPOPs in any way; I am just a happy user.

Download
You can download the latest version of YPOPs from Don Beusee's Download Site (He is involved in the project).

YPOPs Project information, documentation and discussion forums

What's New in Version 0.8.7 (18th October 2006)

# Support Yahoo! Mail Beta. YPOPs! will force it's own sessions to use the original web interface even if users have switched to beta. This way, users won't have to deal with these beta issues. In the long run, we need to use the SOAP API, but this will do for the moment.

# Put all ini file settings in the file - previously, defaults were excluded on the windows version. This allows users to copy some settings to an account section and modify it as needed. Hopefully some day someone can enhance the config UI to work with account-specific settings.

! Implement locking for the ypops.ini file to prevent other threads from trying to read it at the same time, clobbering over one another. This also prepares for a future version of YPOPs! being separated in 2 parts - a GUI front end the user can run and the service back end that works even without the GUI parts.

# Any dialog that ypops pops up during a send/receive (yahoo error, send verify, login verify) will automatically time out after 10 minutes, and it will be as though you cancelled or closed the dialog.

+ If you have a Yahoo Mail Plus account that can send from different email addresses, YPOPs! now supports this. Simply enter the desired email address in the email client in the account setup, and YPOPs! will pass this along to Yahoo. Note that the email address must be set up as a mail account in the mail options in Yahoo.

Bullet Type Legend

+ Feature Addition
- Feature Removal
! Bug Fix
# Feature/Performance Enhancement

Revision History and Change Log

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

October 20, 2006

AVG Free Program Version Update Notice

Grisoft, the makers or the world reknowned AVG anti virus program have just released a program update fror AVG Free Edition. The new release is labeled as version 7.5.x and it replaces the current version 7.1.x. All users of AVG Free 7.1 should upgrade to 7.5 as soon as possible. All definitions and program support for v7.1 will cease in January, 2007. I have just upgraded to 7.5 myself, without a hitch, and found that there was already a virus definition update waiting for it, which was not available a few minutes earlier when I checked with version 7.1.

Please note that you should perform this upgrade from an Administrator level account, not from a User, or even Power User account, not even using Run As. Also, do the Upgrade using the "Repair" option, when the installation halts at the installation type options screen. You must reboot to complete the installation.

The download page for the newest version of AVG Free is here.

Also, if you have a software firewall (you do don't you?) it will probably popup a warning that the various parts of AVG have been changed and you must allow those components to access the Internet. I use ZoneAlarm and it has popped up a couple of times in the few minutes since I upgraded the program. Allow the changes that you initiated.

New in AVG 7.5

* Improved virus detection based on better heuristics and NTFS data streams scanning
* Smaller installation and update files
* Improved user interface
* Windows Vista ready
================================================================
What you get with AVG Anti-Virus Free

Easy to use
Regular and automatic virus database updates
Realtime protection of files and e-mails
Scheduled and manual testing
Windows and Linux

What you do not get with AVG Free Edition

no Anti-Spyware Available only with commercial versions
no Anti-Spam
no Firewall
no 24/7 Technical Support
no Priority updates
no Multiple languages
no Detailed settings
no Consent for commercial use

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

October 16, 2006

Ad-Aware SE Definitions Updated on 10/12/2006

Ad-Aware Personal provides advanced protection from known data-mining, aggressive advertising, Trojans, dialers, malware, browser hijackers, and tracking components. This software is downloadable free of charge.

Anti Spyware/Adware program Ad-Aware, by Lavasoft has had it's definition file updated on October 12, 2006. Users of the free version should check for and install the new definitions manually.

Current Definition File:
SE1R126 12.10.2006

New definitions:
====================
Anonymouse +2
Win32.Worm.MSNMaker

Updated definitions:
====================
Adware.Agent
Adware.DesktopMedia +9
Adware.DollarRevenue +8
Adware.Funweb +3
Adware.LinkOptimizer
Adware.ToolbarDeepDive
Adware.WSearch +3
Dialer
Lop +6
Purityscan +3
ShowBehind
Win32.Dialer.Trojan +3
Win32.Downloader +2
Win32.Trojan.Agent +8
Win32.Trojan.Delf
Win32.Trojan.Downloader +23
Win32.Trojan.Keylogger +4
Win32.Trojan.Pakes
Win32.Trojan.Small.ref
Win32.Trojan.Spambot
Win32.Trojan.Spy
Win32.Trojan.StartPage
Win32.TrojanDownloader.Agent +4
Win32.TrojanDownloader.Delf +3
Win32.TrojanDownloader.Small +5
Win32.Trojandownloader.Zlob +5
Win32.TrojanDropper +2
Virtumonde +10

MD5 checksum is d6e2fdbb28185853f03fe1c5fc63c123
============================================
You can use Webupdate to install the new reference file, or download
it manually from: http://download.lavasoft.de.edgesuite.net/public/defs.zip

Download the current version of Ad-Aware here: http://www.download.com/3405-8022-5153545.html

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

October 10, 2006

Today is Patch Tuesday for Microsoft and Windows Updates

October 10, 2006

Today is Patch Tuesday as Microsoft rolls out it's newest critical patches and security updates. If you have turned on Automatic Windows Updates you will receive some or all of the available updates, pertaining to your particular computer, sometime today. If you do not have Automatic Updates turned on you should manually visit the Windows or Microsoft Updates website to download and install all available patches. Some of these patches will require a reboot to install them.

Keeping your computer up to date with Windows Updates is critical for keeping your computer safe from the latest threats that are being exploited in the wild.

However, this is not the end of securing you computer. You also need to run up-to-date anti virus and anti spyware applications. There are links to various security programs in the right sidebar and in my ads on these pages.

You should also consider reducing your permissions to that of a Limited User, for your daily browsing and emailing user account. See my blog article about running as a Limited User and how this can protect you against most malware threats.

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

Support Ends for Windows XP SP1 on October 10, 2006

Microsoft will end support for Windows XP Service Pack 1 and SP 1a on October 10, 2006, leaving users no option but to upgrade to SP2 if they wish to continue to receive support for crucial components, including security software. The move to drop support for SP1 is in line with Microsoft's stated strategy for support. According to its guidelines, Microsoft guarantees to provide 'mainstream support' for a full product for five years, but will only guarantee to support a Service Pack for 12 months after the launch of the next version of that pack.

If you aren't sure which XP Service Pack you have, you can check by right-clicking on the My Computer desktop, or Start Menu icon and then selecting Properties. The Service Pack level will be displayed on the opening General tab.

You can download Service Pack 2 (SP2) via Windows Updates. However, if you cannot download huge files, or if Windows Updates no longer work on your SP1 or SP1a version of XP, you can order the Windows XP SP2 upgrade on a CD, from Microsoft.

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

October 7, 2006

Spybot S&D Definitions Updated on October 6, 2006

World reknowned anti-spyware program - Spybot Search and Destroy - was updated with new spyware definition files. If you use this program be sure to run manual updates as soon as possible.

If you see a program listed in these detections by name you should assume that is is malware. Update your Spybot Search and Destroy definitions, then scan for and fix any malware that is detected.

Spybot Search and Destroy (Multi-Lingual Landing Page. Choose your language).

2006-10-06 Updates

Adware
+ WorldToStartBV.AdTech2005

Hijacker
+ CoolWWWSearch

Keylogger
+ Ardamax

Malware
+ Smitfraud-C. (4) + ErrorSafe + Bills.Inc + SpyAxe + Deskbar + PornPasswordGenerator

Spyware
+ PurityScan

Trojan
+ Win32.Moodown.B + AccountMaker + Win32.Delf.amb + Lineage.DN + Zlob.WinMediaCodec + Zlob.MPVideoCodec + Downloader.Tsupdate.L + Delfin Project + Win32.Small.jm + Haxdoor-H + BHO.IESpy + Sox.Autoupdater + Adclicker + SpySheriff.Ticker + Troj.SVC + Tibia

Total: 324,917 fingerprints in 50,044 rules for 2,294 products.

English Language Company Links:
Spybot Search and Destroy Home Page
Spybot Search and Destroy Download page - Program and definition updates.
Full tutorial about using and setting up Spybot Search and Destroy
Spybot Search and Destroy Update History

See all security program update notices in this catagory

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

October 1, 2006

Microsoft Patch MS06-055 Issued for VML Exploit

Microsoft Security Bulletin MS06-055:

Vulnerability in Vector Markup Language Could Allow Remote Code Execution - Patched

Published: September 26, 2006

This information deals with the VML vgx.dll buffer overflow vulnerability announced on September 19, 2006, and the VML exploits that are currently in the wild.

http://www.microsoft.com/technet/security/bulletin/ms06-055.mspx

VML Buffer Overrun Vulnerability - CVE-2006-4868:

A remote code execution vulnerability exists in the Vector Markup Language (VML) implementation in Microsoft Windows. An attacker could exploit the vulnerability by constructing a specially crafted Web page or HTML e-mail that could potentially allow remote code execution if a user visited the Web page or viewed the message. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Microsoft has issued an out-of-cycle patch for the Vector Markup Language vulnerability mentioned above and in a previous entry on my blog. This is a critical vulnerability and if you have not already obtained the patch you should do so immediately. Go to Windows Updates to receive it manually, or turn on Automatic Windows Updates (Control Panel > Automatic Updates), or visit the page linked to above and download the patch for your OS.

Undo the suggested Microsoft workaround if you applied it! See my extended comments for details.

Impact of Workaround: Applications that render VML will no longer do so once Vgx.dll has been unregistered. This security update does not automatically re-register vgx.dll so any applications that render VML will no longer do so until vgx.dll has been re-registered.

To re-register vgx.dll follow these steps:

Copy and paste this code into your Run box (Start > Run) and hit Enter:

regsvr32 "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"

A dialog box appears to confirm that the registration process has succeeded. Click OK to close the dialog box.

If you get an error message and the code fails, try copying and pasting this command instead:

Click Start, click Run, and type, or copy and paste :

"%SystemRoot%\System32\regsvr32.exe" "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll"

and then click OK. A dialog box appears to confirm that the registration process has succeeded. Click OK to close the dialog box.

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

Spybot S&D Definitions Updated on September 29, 2006

World reknowned anti-spyware program - Spybot Search and Destroy - was updated with new spyware definition files. If you use this program be sure to run manual updates as soon as possible.

If you see a program listed in these detections by name you should assume that is is malware. Update your Spybot Search and Destroy definitions, then scan for and fix any malware that is detected.

Spybot Search and Destroy (Multi-Lingual Landing Page. Choose your language).

2006-09-29 Updates

Adware
+ DropSpam + Win32.LinkOptimizer (2) + Suggestor

Hijacker
+ Teslaplus.com

Keylogger
+ SCKeylogger

Malware
+ RegFreeze + TitanShield + Smitfraud-C. + IconDropper + Win32.Bomka.r + KodakFoto + Win32.Downloader.Small.dib + Win32.LowZones.DG + SurfSideKick + Smitfraud-C. + Amircivil
Spyware + webHancer + UCmore + PurityScan

Trojan
+ Zlob.ICodecPack + WinSmurf + Win32.Small.czl + Win32.Delf.JKH + Win32.Agent.AWM + BraveSentry + Win32.Viking.V + Win32.Agent.AVS + Tarma + Downloader.Tsupdate.L + Win32.Adload.gw + Fake.WinsDriver + IEFeatinstaller + Zlob.Downloader + Zlob.MSSearch + Haxdoor-H (2) + Win32.Small.js + Win32.Agent.rk + Zlob.HQCodec + Win32.Downloader.Wzip32 + CastGen + DeskMate.Tahni + Vcodec.Intcodec

Total: 322963 fingerprints in 49517 rules for 2280 products.

English Language Company Links:
Spybot Search and Destroy Home Page
Spybot Search and Destroy Download page - Program and definition updates.
Full tutorial about using and setting up Spybot Search and Destroy
Spybot Search and Destroy Update History

See all security program update notices in this catagory

Facebook Twitter LinkedIn Pinterest Instapaper Google+ Addthis

back to top ^

Blog Links

Sponsored Message

I recommend Malwarebytes to protect your computers and Android devices from malicious code attacks. Malwarebytes detects and blocks spyware, viruses and ransomware, as well as rootkits. It removes malware from an already infected device. Get an 18 month subscription to Malwarebytes here.

If you're a fan of Robert Jordan's novels, you can buy boxed sets of The Wheel Of Time, here.

As an Amazon and Google Associate, I earn commissions from qualifying purchases.


CIDR to IPv4 Address Range Utility Tool | IPAddressGuide
CIDR to IPv4 Conversion



About the author
Wiz FeinbergWiz's Blog is written by Bob "Wiz" Feinberg, an experienced freelance computer consultant, troubleshooter and webmaster. Wiz's specialty is in computer and website security. Wizcrafts Computer Services was established in 1996.

I produce this blog and website at my own expense. If you find this information valuable please consider making a donation via PayPal.

Follow @Wizcrafts on Twitter, where I post short updates on security issues, spam trends and things that just eat at my craw.

Follow Wizcrafts on Twitter


Malwarebytes' Anti-Malware is the most frequently recommended malware removal tool in malware removal forums, like Bleeping Computers. It is extremely effective for removing fake/rogue security alerts, Bots, Spyware and the most prevalent and current malware threats in the wild. Learn about Malwarebytes Anti-Malware.


MailWasher Pro is an effective spam filter that protects your desktop email client. Using a combination of blacklists and built-in and user configurable filters, MailWasher Pro recognizes and deletes spam before you download it. MailWasher Pro reveals the actual URL of any links in a message, which protects you from most Phishing scams. Try it free for 30 days.





Creative Commons License This weblog is licensed under a Creative Commons License.
The content on this blog may be reprinted provided you do not modify the content and that you give credit to Wizcrafts and provide a link back to the blog home page, or individual blog articles you wish to reprint. Commercial use, or derivative work requires written permission from the author.
Powered by Movable Type

back to top ^