HYIP-Man
Saturday, December 22, 2007
Kaspersky Lab corrects false positive detection in threat signature database

Kaspersky Lab corrects false positive detection of a particular Windows explorer.exe file.

An incorrect threat signature was added to the company's antivirus databases on December 19, 2007, around 7PM GMT. It falsely detected a relatively uncommon version of explorer.exe as Worm.Win32.huhk.c and quarantined the file. The incorrect signature was removed from the database after two hours.

The version of explorer.exe which was falsely detected was released via Microsoft Windows Update service as an Update for Windows XP on 24.07.2007

Unfortunately, the incorrect signature caused a limited number of Kaspersky Lab product users to experience problems with system functionality.

Kaspersky Lab apologizes for any inconvenience caused to users by the error. The company's free 24-hour technical support service is available to assist any affected users in rectifying the problem.

A solution for the issue has also been added to the Kaspersky Lab Technical Support Site. It can be found at http://www.kaspersky.com/support/viruses/computers?qid=208279581 .

Related Posts:
Kaspersky inadvertently quarantines Windows Explorer

Labels: , ,

Friday, December 21, 2007
Kaspersky inadvertently quarantines Windows Explorer
Windows Explorer, one of the most crucial components of Microsoft's operating system, was quarantined earlier this week after being falsely identified as malicious code by an antivirus company.

Users of Kaspersky Lab's antivirus products noticed the issue, which Kaspersky claimed lasted two hours, on Wednesday night.

The security company's systems had decided that a virus called Huhk-C was present in the explorer.exe file, leading to its confinement or, in some cases, deletion. As Windows Explorer is the graphical user interface (GUI) for Windows' file system, this made it difficult to perform many common tasks within the operating system, such as finding files.

David Emm, a senior technology consultant at Kaspersky Lab, told ZDNet UK on Friday that the company was still examining its checklist to find out why the false positive "slipped through the net."

"This is classic false-alarm territory," Emm said. "We will check through our systems and see if we can tighten them up so we don't run into this problem in the future. No antivirus company, including ourselves, can say they have never had a false alarm, (but) on all fronts, we do what we can to minimize any potential risk for our customers."

Emm pointed out that Kaspersky adds about 3,000 records per week to its database, demonstrating the "scale of the issue, in terms of testing procedures."

The "offending signature" went out at around 7 p.m. on Wednesday, according to Emm, who claimed that it was pulled two hours later in a "makeshift" attempt to limit the damage while Kaspersky examined the signature.

"We proactively went out to our enterprise customers to make them aware there was this potential issue," Emm said. "Only one corporate customer (in the U.K.) encountered this problem, as well as a handful of home users." He added that users who have not changed their default settings would have found explorer.exe to be only quarantined, rather than deleted.

In March of this year, Kaspersky criticized Microsoft's consumer antivirus product, OneCare, for incorrectly quarantining and, in some cases, deleting Microsoft Outlook files.

source:
David Meyer of ZDNet UK reported from London.

Labels: , ,

Sunday, July 01, 2007
Kaspersky Lab releases its latest analytical report "The evolution of self-defense technologies in malware"

Kaspersky Lab, a leading developer of secure content management solutions, has released a new analytical report on the evolution of self-defense technologies in malicious programs. The report is authored by Alisa Shevchenko, one of the company's senior malware analysts.

The article provides an overview of how malicious programs have evolved to combat security solutions and which self-defense techniques are currently used. It also discusses techniques used by virus writers in the past which are no longer effective due to the continued evolution of security solutions. The article also includes predictions as to which technologies are likely to be used in the near future.

The complete report is available on Viruslist.com at the following link:

 http://www.viruslist.com/analysis?pubid=204791949

Labels: ,

Sunday, May 13, 2007
the best antivirus software
The latest test from virus.gr includes 52 different antivirus applications. They were rigorously tested using 174,770 virus samples, and the settings of each application were tweaked to ensure that they all caught maximum number of viruses.
 
Rank:
 
 1.  Kaspersky version 7.0.0.43 beta - 99.23%
 2.  
Kaspersky version 6.0.2.614 - 99.13%
 3.  
Active Virus Shield by AOL version 6.0.0.308 - 99.13%
 4. 
ZoneAlarm with KAV Antivirus version 7.0.337.000 - 99.13%
 5. 
F-Secure 2007 version 7.01.128 - 98.56%
 6. 
BitDefender Professional version 10 - 97.70%
 7.  
BullGuard version 7.0.0.23 - 96.59%
 8. 
Ashampoo version 1.30 - 95.80%
 9. 
eScan version 8.0.671.1 - 94.43%
10.
Nod32 version 2.70.32 - 94.00%
11.
CyberScrub version 1.0 - 93.27%
12.
Avast Professional version 4.7.986 - 92.82%
13.
AVG Anti-Malware version 7.5.465 - 92.14%
14.
F-Prot version 6.0.6.4 - 91.35%
15.
McAfee Enterprise version 8.5.0i+AntiSpyware module - 90.65%
16.
Panda 2007 version 2.01.00 - 90.06%
17.
Norman version 5.90.37 - 88.47%
18.
ArcaVir 2007 - 88.24%
19.
McAfee version 11.0.213 - 86.13%
20.
Norton Professional 2007 - 86.08%
 
21. Rising AV version 19.19.42 - 85.46%
22. Dr. Web version 4.33.2 - 85.09%
23. PC-Cillin 2007 version 15.00.1450 - 84.96%
24. Iolo version 1.1.8 - 83.35%
25. Virus Chaser version 5.0a - 79.51%
26. VBA32 version 3.11.4 - 77.66%
27. Sophos Sweep version 6.5.1 - 69.79%
28. ViRobot Expert version 5.0 - 69.53%
29. Antiy Ghostbusters version 5.2.1 - 65.95%
30. Zondex Guard version 5.4.2 - 63.79%
31. Vexira 2006 version 5.002.62 - 60.07%
32. V3 Internet Security version 2007.04.21.00 - 55.09%
33. Comodo version 2.0.12.47 beta - 53.94%
34. Comodo version 1.1.0.3 - 53.39%
35. A-Squared Anti-Malware version 2.1 - 52.69%
36. Ikarus version 5.19 - 50.56%
37. Digital Patrol version 5.00.37 - 49.80%
38. ClamWin version 0.90.1 - 47.95%
39. Quick Heal version 9.00 - 38.64%
40. Solo version 5.1 build 5.7.3 - 34.52%
41. Protector Plus version 8.0.A02 - 33.13%
42. PcClear version 1.0.4.3 - 27.14%
43. AntiTrojan Shield version 2.1.0.14 - 20.25%
44. PC Door Guard version 4.2.0.35- 19.95%
45. Trojan Hunter version 4.6.930 - 19.20%
46. VirIT version 6.1.75 - 18.78%
47. E-Trust PestPatrol version 8.0.0.6 - 11.80%
48. Trojan Remover version 6.6.0 - 10.44%
49. The Cleaner version 4.2.4319 - 7.26%
50. True Sword version 4.2 - 2.20%
51. Hacker Eliminator version 1.2 - 1.43%
52. Abacre version 1.4 - 0.00%
 
 
 
 
  • The test was made on 23 April-10 May 2007, using Windows XP Professional SP2 on a P4 3000 Mhz, 1024MB DDRAM.
  • All programs tested had the latest versions, upgrades and updates and they were tested using their full scanning capabilities e.g. heuristics, full scan etc.
  • The default settings of each program were not used, in order for each program to achieve its maximum detection rate. Because of this, there is a possibility for the tested programs to detect a few false positives.
  • All programs were updated on 22 April 2007, between 10.00AM and 13.00PM GMT.
  • The 174770 virus samples were chosen using VS2000 according to Kaspersky, F-Prot, Nod32, Dr.Web, BitDefender and McAfee antivirus programs. Each virus sample was unique by virus name, meaning that AT LEAST 1 antivirus program detected it as a new virus.
  • ALL virus samples were unpacked and the only samples that were kept were the ones that were packed using external-dos-packers (that means not winzip, winrar, winace etc).
  • The virus samples had the correct file extension using a special program (Renexts) and were unique, according to checksum32 filesize.
  • Most "fake" virus samples were removed, as well as "garbage" files.
  • The programs MKS_VIR , PER and IPArmor were not tested because there was no english demo version available.
  • The programs Anti-Hacker Expert , Command , Extendia AVK , GDATA AVK , BOClean , UNA , VET and Freedom were not tested because there was no demo version available.
  • Thorough mode was not used in VBA32 due to extremely slow scan process.
  • A-Squared Anti-Malware and eTrust PestPatrol are anti-trojan/anti-spyware programs, not antivirus programs
  • F-Prot was tested using its command line scanner (options /adware /applications /report /streams /maxdepth=4 /heurlevel=4) because its GUI kept crashing.
  • Windows Live OneCare, BKAV, PC Tools kept crashing while scanning the samples.
  • TheShield uses the exact same engine as VirobotExpert.
  • Avira uses the exact same engine as AntiVir.
  • Fire uses the exact same engine as Solo.
  • MKS_VIR uses the exact same engine as ArcaVir.
  • VirusBuster uses the exact same engine as Vexira.
  • BullGuard uses the exact same engine as BitDefender free edition.
  • Avast Professional uses the exact same engine as Avast free edition.
  • AVG Anti-Malware uses the exact same engine as AVG Antivirus free edition plus the Ewido scan engine, so it has better detection than AVG Antivirus free edition. (More information here )
  • A-squared Anti-Malware Professional uses the exact same engine as A-squared free edition.
  • InVircible did not include a "typical" scanner-function and could not be tested.
  • V-Catch checks only mail accounts and could not be tested.
  • DOS-Based scanners were not tested.

The following file types were used.

SH, ELF, COM, EXE, PL, BAT, PRC, DOC, XLS, BIN, MDB, IMG, PPT, VBS, MSG, VBA, OLE, HTM, INI, SMM, TD0, REG, CLASS, HTA, JS, VI_, URL, PHP, WMF, HLP, XML, SCR, PIF, SHS, WBT, CSC, MAC, DAT, CLS, STI, INF, HQX, XMI, SIT.

The virus samples were divided into these categories, according to the type of the virus :

  • File = BeOS, FreeBSD, Linux, Mac, Palm, OS2, Unix, BinaryImage, BAS viruses, MenuetOS.
  • MS-DOS = MS-DOS viruses.
  • Windows = Win.*.* viruses.
  • Macro = Macro, Multi and Formula viruses.
  • Malware = Adware, DoS, Constructors, Exploit, Flooders, Nukers, Sniffers, SpamTools, Spoofers, Virus Construction Tools, Droppers, PolyEngines.
  • Script = ABAP, BAT, Corel, HTML, Java, Scripts, MSH, VBS, WBS, Worms, PHP, Perl, Ruby viruses.
  • Trojans-Backdoors = Trojan and Backdoor viruses.

Labels: ,

Friday, April 06, 2007
Kaspersky Lab discovers the first virus for iPod

Kaspersky Lab, a leading developer of secure content management solutions, has discovered the first virus designed to infect iPod portable media players. The virus, which has been named Podloso, is a proof of concept program which does not pose a real threat.

The virus is a file which can be launched and run on an iPod. It should be stressed that in order for the virus to function, Linux has to be installed on the iPod. If the virus is installed on the iPod by the user, the virus then installs itself to the folder which contains program demo versions. Podloso cannot be launched automatically without user involvement.

Once launched, the virus scans the device’s hard disk and infects all executable .elf format files. Any attempt to launch these files will cause the virus to display a message on the screen which says "You are infected with Oslo the first iPodLinux Virus".

Podloso is a typical proof of concept virus, which is created in order to demonstrate that it is possible to infect a specific platform. It does not have a malicious payload and is unable to spread on its own: a user has to save the virus to the iPod for the device to become infected.

Labels: ,

Kaspersky Anti-Virus 6.0, Kaspersky Internet Security 6.0 - 5 vulnerabilities fixed in Maintenance Pack 2.0 build 6.0.2.614

Vulnerabilities fixed:

  • Kaspersky Antivirus ActiveX Unsage Methods Vulnerability
  • Kaspersky Anti-Virus SysInfo ActiveX Control Information Disclosure Vulnerability
  • Kaspersky AV Library Remote Heap Overflow
  • klif.sys Heap Overflow Vulnerability
  • KLIF Local Privilege Escalation Vulnerability

Kaspersky Antivirus ActiveX Unsafe Methods Vulnerability1

This vulnerability allows remote attackers to download and remove any file on vulnerable versions of Kaspersky Anti-Virus. User interaction is required to exploit this vulnerability: the user must visit a webpage which takes advantage of this vulnerability. The specific flaw exists within the ActiveX controls in AxKLProd60.dll and AxKLSysInfo.dll

During installation of Maintenance Pack 2, the DLLs will be removed from the system.

Kaspersky Anti Virus SysInfo ActiveX Control Information Disclosure Vulnerability2

The remote exploitation of the information disclosure vulnerability in Kaspersky Anti-Virus 6.0 could allow malicious websites to steal files from end user machine running Kaspersky Anti-Virus.

The SysInfo ActiveX control includes a method called StartUploading which allows malicious web scripts to perform an anonymous FTP transfer of any file the scripts identify on the victim's machine. No dialogs, warnings or user action is required to perform the transfer.

During installation of Maintenance Pack 2, this DLL will be removed from system.

Kaspersky AV Library Remote Heap Overflow1

This vulnerability affected systems which are running the Kaspersky Anti-Virus Engine. User interaction is not required to exploit this vulnerability.

The OnDemand Scanner incorrectly parses specially crafted ARJ archives inside the arj.ppl module. This results in a memory overrun. Most often the product simply crashes. The corruption potentially can be exploited to execute arbitrary code without user interaction. Any products using arj.ppl are vulnerable.

klif.sys Heap Overflow Vulnerability2

Locally executed code can write some special values into registry that hangs klif.sys driver, part of the proactive protection. The driver hooks and screens certain system calls, including registry functions. One of the hook functions is vulnerable to an integer overflow that leads to a kernel heap overflow. If a large unsigned value for the data size argument is passed an arithmetic overflow occurs when the amount of memory to allocate is calculated. A copy operation into this buffer causes a corruption of kernel page pool memory.

KLIF Local Privilege Escalation Vulnerability

This vulnerability allows locally executed code to receive Ring-0 privileges through klif.sys unsafe code. User interaction is required to execute the code. The vulnerability is local and code should first appear on user's computer.

All these vulnerabilities have been fixed in the build 6.0.2. 614.


1 Kaspersky would like to thank an anonymous researcher working with TippingPoint (www.tippingpoint.com) and the Zero Day Initiative (www.zerodayinitiative.com) for reporting this issue.

2Kaspersky would like to thank iDefence (http://labs.idefense.com) for reporting this issue.

Download Here

Labels: , ,

Tuesday, July 04, 2006
Recommended Security for Auto surfing and your computer in general.
First thing to do is download Firefox and starting using it and never use IE again.

2nd get Kaspersky Antivirus and Zonealarm Pro. and do not use the windows firewall.

Get Ad-Ware Pro. And keep ad-watch on all the time.

Get Spyware doctor.

Get Robo-form;(Free) make your passwords min of 128bit encryption.

ALWAYS use the SRK with robo-form.

Spend the money to upgrade to PRO versions of all these programs.

Labels: , ,