Billps Tudios

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Kaspersky. Show all posts
Showing posts with label Kaspersky. Show all posts

Sunday, 8 February 2009

Protection is Here for Win32/Conficker.A and .B

Posted on 14:28 by Unknown

Has your computer been infected recently?
Last month I wrote about the Conflicker Infection that has been the topic of many security experts.  Anyone who received an update patch from Microsoft last fall should be safe but apparently, plenty of people aren’t updating regularly.


Microsoft has recognized this infection is still around and has provided a fix along with additional information at http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx Thanks to Brett Roberts in Auckland, New Zealand for the tip.


Is it that bad?
The French publisher LibĂ©ration has reported the Conficker worm disrupted computers used by the Ministry of Defense in France and grounded the Navy's Dassault Rafale aircraft.


French Rafale Fighter Jet


Last Friday the City of Houston Courts System had been infected and shut itself down for the day.  While they expect the court system to be up and running on Monday, many expect to find Conficker popping up on other city systems. While I typically recommend waiting a week or so for Microsoft’s Windows Updates, this is one update too many people missed.


Additional Help
If you use OpenDNS, which I recommended last year, you’ll soon have additional protection.  Starting Monday, OpenDNS will offer a feature to help administrators detect local machines which have been infected and will block machines from phoning home their payload. This is an entirely new direction for OpenDNS but given the scope of Conficker I think they may be on the right track. If you missed my post on OpenDNS you can read more at http://billpstudios.blogspot.com/2008/03/speed-up-internet-access-with-opendns.html


Update 2/10: Reports out of Houston now indicate the city's infection was in fact W32/Virut.n a variant of the virus Virut. This is contrary to news stories still being filed. The city had been using antivirus software from McAfee which did not include a signature file for this infection. Total down time was 4 days.

PC World reports, OpenDNS has partnered with our comrades at Kaspersky to obtain updated lists of malicious IP addesses.

Update 2/12: To show how serious they think Conficker is, Microsoft has announced a $250,000 reward towards the arrest and conviction of the folks responsible for this virus.
http://www.microsoft.com/Presspass/press/2009/feb09/02-12ConfickerPR.mspx 

Update 3/26:
 Conficker Judgement Day on April 1st

 Real Conficker Danger is March 31st


 

Read More
Posted in conficker, Kaspersky, OpenDNS | No comments

Wednesday, 17 September 2008

WinPatrol Integration with Windows Explorer

Posted on 14:36 by Unknown

I'm happy to report the release of WinPatrol 15.9. I’ve made a few improvements but also made a great bug find thanks to support and screen shots from WinPatrol friends.  Our PLUS database now exceeds over 19,000 easy to understand program descriptions that can now be accessed directly from Windows Explorer.

The following information along with a download link is available at http://www.winpatrol.com/upgrade.html.


  • Explorer Integration of PLUS Info...


    One of the main features of WinPatrol PLUS is the ability to look up information for strange filenames. We now have over 19,000 descriptions available in a form that mere humans can understand. Our new WinPatrol now adds the ability to research programs to any executable on your system directly from Windows Explorer.

  • Quicker Access to PLUS Info

    In previous versions of WinPatrol we shipped PLUS descriptions of some of the most popular file requests. As our database grew and things changed it became obvious that we would never be installing our entire database on local machines. Our new version removes the check for local PLUS data saving you from unnecessary access to your hard drive and speeds up access to our online database

  • Bug Fix: Firefox 3 Cookies

    At this time WinPatrol hasn't been updated to manage cookies in Firefox 3. Cookies in Firefox 3 use a database method called SQlite which is completely different then its old plain cookies.txt file. We've removed the option if Firefox 3 or greater is detected so there is no confusion.

  • Bug Fix: AppInit_DLL

    One non-traditional startup location frequently used by malware is a registry key AppInit_DLL found at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows. This key is now also used by security programs as way to hide from users and malware. WinPatrol has always monitored this location successfully but recently the over use of this location helped us find a bug in the way we parsed this key. Users of Kaspersky Internet Security were the first to discover this problem because KIS 2009 actually stores four separate DLL's in this location.
    In previous versions of WinPatrol Scotty would incorrectly report filenames when there were three files or more located in this key.

Non-English version users with current language packs installed can just download our new default setup. No new text strings were added so all your text will still be localized.  New non-English setups will be available soon for new WinPatrol users.

Read More
Posted in Kaspersky, upgrade, WinPatrol | No comments

Wednesday, 20 June 2007

Do All Signatures Come From Kaspersky?

Posted on 09:33 by Unknown

You might think there exists a huge number of anti-malware programs out there. If so, you’d be right but you might be surprised to find out how many use the same anti-virus engine and signature files.

My mailbox was flooded yesterday with a number of freaked out WinPatrol users who had our software removed by Kaspersky Internet Security Suite. It seems Kaspersky was identifying WinPatrol as “pornware not-a-virus:Porn-Dialer.Win32.Agent.aw“.

I was pleased that most folks knew this must be some kind of false-positive error, but I also had my share of users in a panic blaming me for infecting their systems.

By evening, I did hear back from Kaspersky Virus Analyst, Yury Nesmachny who apologized and said,

“Sorry, it's false alarm. Its detection will be deleted in the next update. Thank you for your help.”

According to tests today with VirusTotal.com, Kaspersky has corrected this error.


I had created a standard reply for Kaspersky users but as the day continued it got worse. Apparently, a significant number of other products use signature files from Kaspersky for their products.

It wasn’t long before I received notices that Zone Alarm Security Suite was reporting WinPatrol as a porn dialer. This was followed by a couple F-Secure Internet Security users and a few who use AOL’s Active Virus Shield.


This isn’t the first time this error has occurred. Last December Panda Software tried to tell users WinPatrol was a porn dialer. Panda was pretty responsive and I appreciate the quick action from Kaspersky which hopefully, will be deployed quickly to all their partners. I’ve also been told WinPatrol isn’t alone. AdobeUpdaterInstallMgr, Quicken and many other popular applications were mis-identified.

Update: Thanks to Don Pelotas who pointed me to this list of Kaspersky partners.
http://www.kaspersky.com/oemsuccess

Read More
Posted in false-positive, Kaspersky, pornware | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Support for Downloads without Surprises
    Last week I posted a message about the  packaging of ad supported programs along with popular software. It appears to be a common practice t...
  • Employee Manual to Prevent Cryptolocker and More
    A common way computers are infected or compromised has always been a simple yet well thought out deception. It can happen to anyone and the ...
  • What on Earth is “Cloud” Computing
    The new big buzz word in the computing world is “Cloud” computing. In the past I’ve been critical of the concept and even poked fun at Cloud...
  • SQLite C Code to Read Cookies
    While most of the technology leaking from my brain is for a wide audience, today’s post is very technical in nature. I expected the informat...
  • WinPatrol Cloud Edition Public Beta
    WinPatrol Adds the Newest Technology Available. You’ll now have access the knowledge of thousands of WinPatrol users shared in real-tim...
  • Four Secret Reasons Why Win7 is Ten Times Better
    It’s no secret that I’ve never been a fan of Windows Vista. I really wanted to love it but even as a designated Microsoft MVP I couldn’t dri...
  • Free #1 Tweak to Improve Windows Performance
    Every year billions of dollars are spent by folks just trying to improve the performance of their computers. Over the last couple years ther...
  • Forget the DVD & Save on your New Laptop
    I’ve written before about the coming death of the CD/DVD ’s for data storage.  While that time hasn’t come yet for desktop there is one real...
  • Can Facebook be Trusted?
    Last week Facebook rolled out another round of what they consider easy to use privacy settings. What they’re really doing is trying to appea...
  • TWITTER ALERT
    Anyone who uses Twitter, DO NOT use the Twitter web interface until further notice. There is a code injection vulnerability being used tha...

Categories

  • 2007
  • 3G
  • AAPL
  • ABC
  • accelerometer
  • Achilles
  • Acrobat
  • Activex
  • adobe
  • Ads
  • advertising
  • Adware
  • Adwords
  • Airlines
  • Albany Medical Center
  • algorithm
  • Amazon
  • amber alert
  • AMUST
  • Animation
  • antimalware
  • Antivirus 2009
  • antivirus2008
  • AOL
  • Apple
  • applets
  • AQuantive
  • archive
  • Aruba
  • ASC
  • Ask.com
  • ATI
  • Audio
  • Autorun
  • AutoUpdate
  • autoupdates
  • AVG
  • Azure
  • backup
  • badware
  • Bakugan
  • Baseball
  • battery
  • Ben Edelman
  • Beta
  • BillP
  • Birthdayware
  • Bitlocker
  • Blackberry
  • BlackViper
  • bloatware
  • Blogger
  • Blogs
  • Blogspot
  • Blu-ray
  • Bluehoo
  • bluetooth
  • boinc
  • Bonjour
  • Brazil
  • break
  • Breakaway games
  • Brookman
  • Browser wars
  • C64
  • camera
  • Carpal Tunnel
  • CBS News
  • cell phone
  • CES
  • charity
  • Child Safety
  • chinese
  • Chris Cook
  • Christmas
  • Chrome
  • CIPAV
  • clampi
  • Cloud
  • CNet
  • codec
  • comodo
  • conficker
  • Control Panel
  • copy
  • coupon
  • craplets
  • crapware
  • Crawford
  • credit
  • credit card
  • credit cards
  • ctfmon
  • daylight savings time
  • Dell
  • demo
  • Discount
  • Disney
  • DNS
  • Dollar
  • Domain
  • Donna
  • Doubleclick
  • Downadup
  • Dreamscene
  • droid
  • DVD
  • Dvorak
  • Easter egg
  • eclipse
  • Ed Bott
  • Edelman
  • egreeting
  • Email
  • Environment
  • Epilepsy
  • EU
  • eWeek
  • explorer
  • facebook
  • false positive
  • false-positive
  • FBI
  • file types
  • finnish
  • FiOS
  • Firefox
  • fireworks
  • fix
  • flash
  • Flashpix
  • Fort Drum
  • foxit
  • fraud
  • FTC
  • games
  • garmin
  • Gateway
  • GE
  • George Bush
  • Germany
  • global
  • Godmode
  • Google
  • Google Research
  • GotoMyPC
  • gps
  • green
  • Groceries
  • Habitat
  • Hacks
  • hallmark
  • Halo
  • hard drive
  • Harry McCracken
  • Harry Potter
  • Harvard
  • HD-DVD
  • help
  • hidden files
  • Hijack
  • History
  • Hiton
  • homeland security
  • Honor Flight
  • hosts
  • Hubble
  • IAC
  • ICANN
  • IE
  • IE6
  • IE7
  • IE8
  • installers
  • interface
  • Internet
  • IPAddress
  • iPhone
  • iPod
  • Iraq
  • iTouch
  • iTunes
  • java
  • Kaspersky
  • Kazaa
  • kenmore
  • key logger
  • keygen
  • Keylogger
  • Kosovo
  • LA
  • lady chalupa
  • langa
  • Laptop
  • lawsuit
  • Legoland
  • Levar Burton
  • Linksys
  • Little League
  • Live Writer
  • Live.com
  • localize
  • Logo
  • London
  • LOP
  • lottery
  • Lucasfilm
  • Macintosh
  • Malware
  • Marie Domingo
  • Mary
  • McCracken
  • Media
  • Memorial Day
  • mgrs.exe
  • Micosoft
  • Microsoft
  • Microsoft Surface
  • MiFi
  • mit
  • moon
  • Mossberg
  • Mothers Day
  • MPack
  • MSFT
  • msn
  • MTV
  • Multicore
  • Music
  • MVP
  • MVP09
  • nasa
  • NBC
  • Nero
  • Netbook
  • Network
  • network solution
  • New York
  • newsletter
  • Nintendo
  • Nintendo Wii
  • NNEDV
  • Norton
  • NYAG
  • OAuth
  • obama
  • Office
  • OLPC
  • Olympics
  • OpenDNS
  • oprah
  • optimize
  • optout
  • Paperghost
  • passwords
  • Patch
  • Patriot Flight
  • PC Guy
  • pc pitstop
  • PC World
  • pcmag
  • PCWorld
  • PDC
  • PDF
  • pedipaws
  • performance
  • phishing
  • photos
  • Photoshop
  • Pinnacle
  • Piracy
  • Pirillo
  • pogue
  • Porn
  • pornware
  • postcard
  • prediction
  • prefetch
  • Preview
  • Price
  • privacy
  • Prodigy
  • Programming
  • PSP
  • Public Relations
  • Pytlovany
  • Q-Link
  • Quicktime
  • quotes
  • radio
  • realnetworks
  • realplayer
  • RegCleaner
  • RegCure
  • regedit
  • Registry
  • registry cleaner
  • Release
  • remove
  • Research
  • return policy
  • review
  • RIAA
  • Rivera
  • RMS
  • Road Runner
  • rogue
  • router
  • RTM
  • Rumor
  • safari
  • safety
  • sale
  • Sales
  • Santa Monica
  • scam
  • Schenectady
  • Scoble
  • Scott Dunn
  • Scotty
  • sd
  • Search
  • Sears
  • Security
  • Services
  • seti
  • ShellExecute
  • Shirt
  • SimCity
  • site advisor
  • slingbox
  • snopes
  • social engineering
  • social network
  • solid state disk
  • Sounds
  • Sp3
  • space station
  • SPAM
  • spamhaus
  • Special
  • speedtest
  • Spyware
  • SSD
  • Startup
  • Stats
  • Steve Bass
  • stopbadware
  • storm
  • STS-125
  • Sugar
  • Sunbelt
  • support
  • Symantec
  • tagged
  • Task Catcher
  • Task Scheduler
  • taskbar
  • Tax
  • Techorati
  • techwatch
  • teens
  • temp
  • Thinkpad
  • Thurrott
  • tinyurl
  • Tips
  • TiVo
  • TLD
  • Today Show
  • Toolbar
  • toolbars
  • top ten
  • topten
  • toys
  • Translator
  • transunion
  • Tree
  • Trend Micro
  • tricks
  • trillian
  • Trojan
  • tweaks
  • twitter
  • UAC
  • UI
  • Ultimate
  • Unbox
  • Unboxed
  • update
  • Updates
  • upgrade
  • url
  • USB
  • Utility
  • Valentine
  • Verizon
  • versions
  • Veteran
  • Video Games
  • Vista
  • Vulnerability
  • wall-e
  • war
  • Washington
  • web2.0
  • Webslice
  • WGA
  • Widget
  • WiFi
  • Wii
  • WiiItis
  • wiimote
  • Win7
  • Windows 7
  • Windows Secrets
  • Windows Update
  • Windows7
  • WinPartrol
  • WinPatrol
  • winpatrolflash
  • WinPatrolToGo
  • Winter
  • Wireless
  • Wristband
  • WSJ
  • WWII
  • x64
  • Xbox
  • XO
  • XO Laptop
  • XOActivity
  • Xobni
  • xolaptop
  • XP
  • XP SP3
  • xp3
  • Yahoo
  • Zero Day
  • Zone Alarm
  • Zwinky

Blog Archive

  • ▼  2013 (31)
    • ▼  November (2)
      • Employee Manual to Prevent Cryptolocker and More
      • My First State-Sponsored Attack
    • ►  October (1)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (5)
    • ►  May (2)
    • ►  April (3)
    • ►  March (2)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (30)
    • ►  December (3)
    • ►  November (3)
    • ►  October (2)
    • ►  September (2)
    • ►  August (2)
    • ►  July (3)
    • ►  June (2)
    • ►  May (1)
    • ►  April (4)
    • ►  March (4)
    • ►  February (2)
    • ►  January (2)
  • ►  2011 (28)
    • ►  December (4)
    • ►  November (2)
    • ►  October (4)
    • ►  September (2)
    • ►  August (2)
    • ►  July (2)
    • ►  June (2)
    • ►  May (2)
    • ►  April (2)
    • ►  March (2)
    • ►  February (3)
    • ►  January (1)
  • ►  2010 (44)
    • ►  December (2)
    • ►  November (3)
    • ►  October (3)
    • ►  September (4)
    • ►  August (3)
    • ►  July (3)
    • ►  June (3)
    • ►  May (4)
    • ►  April (4)
    • ►  March (3)
    • ►  February (3)
    • ►  January (9)
  • ►  2009 (90)
    • ►  December (6)
    • ►  November (8)
    • ►  October (6)
    • ►  September (4)
    • ►  August (4)
    • ►  July (12)
    • ►  June (6)
    • ►  May (11)
    • ►  April (7)
    • ►  March (9)
    • ►  February (9)
    • ►  January (8)
  • ►  2008 (122)
    • ►  December (9)
    • ►  November (11)
    • ►  October (14)
    • ►  September (6)
    • ►  August (9)
    • ►  July (9)
    • ►  June (10)
    • ►  May (13)
    • ►  April (8)
    • ►  March (10)
    • ►  February (10)
    • ►  January (13)
  • ►  2007 (155)
    • ►  December (15)
    • ►  November (14)
    • ►  October (12)
    • ►  September (14)
    • ►  August (12)
    • ►  July (13)
    • ►  June (11)
    • ►  May (19)
    • ►  April (17)
    • ►  March (21)
    • ►  February (7)
Powered by Blogger.

About Me

Unknown
View my complete profile