According to Marcos, employee of security solutions vendor ESET, the well-known malware cleaning/removal program ComboFix created by sUBs is infected with the Sality virus. It seems that the current installer ComboFix contains an infected file, namely iexplore.exe
I haven’t checked the issue, however have to assume that ComboFix is indeed infected with the Sality virus, especially because other security vendors have confirmed the infection.
Please don’t download and use ComboFix until the author, sUBs, remedies the issue.
UPDATE 1: Infection is confirmed by a reliable source.
UPDATE 2: To be 100% sure I checked the issue by myself, ComboFix is indeed infected by Sality.
UPDATE 3: Added a temporary Google Drive downloadlink to obtain most recent CLEAN ComboFix.exe
Data of this clean version:
Combofix.exe
Version 13.1.28.1
Copyright sUBs
5.028.179 bytes
MD5 CHECKSUM: 0F6D28A70471051C4C7785335ACBA626
SHA256 CHECKSUM:
hex: 361548f74415a41f00d5345b3e3c489b3282b302c0c51266880eda586db01a12
HEX: 361548F74415A41F00D5345B3E3C489B3282B302C0C51266880EDA586DB01A12
h:e:x: 36:15:48:f7:44:15:a4:1f:00:d5:34:5b:3e:3c:48:9b:32:82:b3:02:c0:c5:12:66:88:0e:da:58:6d:b0:1a:12
base64: NhVI90QVpB8A1TRbPjxImzKCswLAxRJmiA7aWG2wGhI=
Download: removed
UPDATE 4 / FINAL UPDATE / 2013-01-30 22:00: problem infected ComboFix solved, clean ComboFix.exe is now live again, and available to download from its normal Bleeping Computer downloadlink here.
Because the problem is now solved I have removed the temporary downloadlink clean ComboFix.exe
January 29, 2013
Posted by Smokey |
Advisories, Alerts, Anti-Virus, Malware, Vulnerabilities | BC - Bleeping Computer, ComboFix Sality virus infection, downloadlink combofix.exe, iexplorer.exe infected, malware removal programs, MD5/SHA256 checksums, sUBs |
4 Comments
It’s just ‘great’, you are relying on a well-known company selling Backup & Recovery software, Acronis GmbH. On their website they are promising potential customers that their Acronis True Image 2013 software is fully compatible with Windows 8, so you are buying or upgrading a previous version of the software in full faith and trust, assuming that Acronis will save you in case an disaster will happen with your PC and you will be able to boot from a recovery image in case of an disaster.
Well better forget efforts to restore the Acronis image, Acronis will let you down without mercy, your Windows 8 system will tell you: “Selected boot image did not authenticate. Press ‘Enter’ to continue”. So now you have a serious problem…
Cause of the failure message is Secure Boot, a Windows 8 Anti-Rootkit feature that will prevent the PC from booting an unrecognised operating system. Unpleasant side effect: it will also blocking Linux-based recovery environments, such as Acronis Start Up manager.
Despite the fact that Acronis is informed about the issue, they still sell Acronis True Image 2013 as being Windows 8 Compatible. I call this product sale scam. My advise to Windows 8 users: don’t buy the Acronis crap, on your Windows 8 PC it’s a useless piece of emergency software.
January 17, 2013
Posted by Smokey |
Advisories, Alerts | Acronis Start Up manager, Backup & Recovery software, Disk imaging, emergency system recovery, Linux-based recovery environments, product sale scam, Selected boot image did not authenticate. Press 'Enter' to continue, system image, Windows 8 Anti-Rootkit feature, Windows 8 Secure Boot |
1 Comment
Published: Monday, January 14, 2013 by Microsoft
Version: 1.0
General Information
Executive Summary
This security update resolves one publicly disclosed vulnerability in Internet Explorer. The vulnerability could allow remote code execution if a user views a specially crafted webpage using Internet Explorer. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
This security update is rated Critical for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows clients and Moderate for Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8 on Windows servers. Internet Explorer 9 and Internet Explorer 10 are not affected. For more information, see the subsection, Affected and Non-Affected Software, in this section.
The security update addresses the vulnerability by modifying the way that Internet Explorer handles objects in memory. For more information about the vulnerability, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
This security update also addresses the vulnerability first described in Microsoft Security Advisory 2794220.
Recommendation. Most customers have automatic updating enabled and will not need to take any action because this security update will be downloaded and installed automatically. Customers who have not enabled automatic updating need to check for updates and install this update manually. For information about specific configuration options in automatic updating, see Microsoft Knowledge Base Article 294871.
For administrators and enterprise installations, or end users who want to install this security update manually, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service.
Known Issues. None
Affected and Non-Affected Software: see the Security Bulletin.
Some Frequently Asked Questions (FAQ) Related to This Security Update, for all FAQ’s see the Security Bulletin.
Is this update, MS13-008, a cumulative security update for Internet Explorer?
No. This security update, MS13-008, only addresses the vulnerability described in this bulletin.
Do I need to install the last cumulative security update for Internet Explorer, MS12-077?
Yes. In all cases MS13-008 protects customers from the vulnerability discussed in this bulletin. However, customers who have not installed the latest cumulative security update for Internet Explorer may experience compatibility issues after installing the MS13-008 update.
Customers need to ensure that the latest cumulative security update for Internet Explorer, MS12-077, is installed to avoid compatibility issues.
If I applied the automated Microsoft Fix it solution for Internet Explorer in Microsoft Security Advisory 2794220, do I need to undo the workaround before applying this update?
Customers who implemented the Microsoft Fix it solution, “MSHTML Shim Workaround,” in Microsoft Security Advisory 2794220, do not need to undo the Microsoft Fix it solution before applying this update.
However, since the workaround is no longer needed, customers may wish to undo the workaround after installing this update. See the vulnerability workarounds in this bulletin for more information on how to undo this workaround.
Where are the file information details?
Refer to the reference tables in the Security Update Deployment section for the location of the file information details.
Where are the hashes of the security updates?
The SHA1 and SHA2 hashes of the security updates can be used to verify the authenticity of downloaded security update packages. For the hash information pertaining to this update, see Microsoft Knowledge Base Article 2799329.
How are Server Core installations affected by the vulnerability addressed in this bulletin?
The vulnerability addressed by this update does not affect supported editions of Windows Server 2008, Windows Server 2008 R2, or Windows Server 2012 as indicated in the Non-Affected Software table, when installed using the Server Core installation option.
Disclaimer
The information provided in the Microsoft Knowledge Base is provided “as is” without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.
January 14, 2013
Posted by Smokey |
Advisories, Alerts, Downloads, Vulnerabilities | disclosed vulnerability internet explorer, Frequently Asked Questions (FAQ), KB2799329, Microsoft Fix it solution, Microsoft Security Advisory 2794220, MS12-077, MS13-008 - Critical, MSHTML Shim Workaround, out-of-band critical security update, technet |
Leave a Comment
Microsoft Security Response Center – MSRCTeam | 13 Jan 2013 3:00 PM
Today, we are providing Advance Notification to customers that at approximately 10 a.m. PST on Monday, January 14, 2013, we will release an out-of-band security update to fully address the issue described in Security Advisory 2794220. While we have still seen only a limited number of customers affected by the issue, the potential exists that more customers could be affected in the future. The bulletin has a severity rating of Critical, and it addresses CVE-2012-4792. Internet Explorer 9-10 are not affected by this issue and as always, we encourage customers to upgrade to the latest browser version.
We recommend that you install this update as soon as it is available. This update for Internet Explorer 6-8 will be made available through Windows Update and our other standard distribution channels. If you have automatic updates enabled on your PC, you won’t need to take any action. If you applied the Fix it released in Security Advisory 2794220, you won’t need to uninstall it before applying the security update.
January 14, 2013
Posted by Smokey |
Advisories, Alerts, Vulnerabilities | Advance Notification, Critical severity rating, CVE-2012-4792, IE Internet Expolrer 6 - 7 - 8 - 9 - 10, Microsoft Security Response Center - MSRCTeam, MS Fix it, Out-Of-Band Security Update, Security Advisory 2794220 |
Leave a Comment
ExynosAbuse Exploit: obtaining root on Exynos4 based Samsung Android devices without ODIN flashing, malicious apps will be able to gain total control over the device by gaining root without asking and without any permissions on a vulnerable device.
Source: XDA Developers (alephzain, Chainfire)
- alephzain: http://forum.xda-developers.com/showthread.php?t=2048511
- Chainfire: http://forum.xda-developers.com/showthread.php?t=2050297
Samsung solution status: unfixed
Vulnerable devices:
- Samsung Galaxy S2 GT-I9100
- Samsung Galaxy S3 GT-I9300
- Samsung Galaxy S3 LTE GT-I9305
- Samsung Galaxy Note GT-N7000
- Samsung Galaxy Note 2 GT-N7100
- Samsung Galaxy Note 2 LTE GT-N7105
- AT&T Galaxy Note 2 SGH-I317
- Verizon Galaxy Note 2 SCH-I605
- Samsung Galaxy Tab Plus GT-P6210
- Samsung Galaxy Note 10.1 GT-N8000, GT-N8010, GT-N8013, GT-N8020
Note: Google Nexus 10 not vulnerable, Exynos5.
Temporary patch (provided by Chainfire): http://forum.xda-developers.com/showthread.php?t=2050297
Note: Chainfire requested not to redistribute the patch, instead please link to http://forum.xda-developers.com/showthread.php?t=2050297
Update Dec 20 2012
Android Central | Dec 19 2012
Official Samsung Statement Exynos kernel vulnerability issue (in full)
“Samsung is aware of the potential security issue related to the Exynos processor and plans to provide a software update to address it as quickly as possible.
The issue may arise only when a malicious application is operated on the affected devices; however, this does not affect most devices operating credible and authenticated applications.
Samsung will continue to closely monitor the situation until the software fix has been made available to all affected mobile devices”
Third-party fixes
I will only mention Chainfire’s fix. It’s the only one that is secure. Both Supercurio’s and RyanZA’s method leave you with easily exploitable holes any serious malware author will abuse.
About Chainfire’s fix
Chainfire: “This is an APK that uses the ExynosAbuse exploit (by alephzain) to be able to do various things on your Exynos4 based device.
Features for non-rooters:
- Securely patch the exploit
Features for rooters:
- Root the device (SuperSU v0.99)
- Enable/disable the exploit at will
- Enable/disable patching the exploit at boot
- Unroot and cleanup (optionally leaving the exploit patch at boot in place)
Please note that patching the exploit may break camera functionality, depending on device and firmware. Also note that if use the patch method without rooting, or keep patching the exploit at boot enabled when unrooting, you need an alternate method to re-root the device to disable this feature (like CF-Auto-Root) – you cannot use ExynosAbuse to do this since it patched the exploit. Unlike other patch authors, I do not believe in keeping an invisible rooted process running in the background while pretending you aren’t rooted, to be able to unpatch this way.
While the exploit patches work (aside from possibly disabling your camera), these are more work-around than actual fixes. A proper patch would be a kernel fix, either from a third party or Samsung themselves”
Download the fix here: http://forum.xda-developers.com/showthread.php?t=2050297
Note: please do not redistribute the fix!
December 17, 2012
Posted by Smokey |
Advisories, Alerts, Anti-Virus, Malware, News, Vulnerabilities | affected devices/smartphones, alephzain, Android Central, apk, Chainfire fix, Exynos4 processor, Exynos5 processor, ExynosAbuse Exploit, fix, Galaxy Nexus 10, Galaxy Note, Galaxy Note 2, Galaxy S2, Galaxy S3, Galaxy Tab Plus, non-rooters, Official Samsung Statement, patch, Root exploit, rooters, RyanZA fix, Samsung Android devices, Samsung software update, Supercurio fix, SuperSU, tablets, XDA Developers |
Leave a Comment
Microsoft Security Advisory (2718704)
Unauthorized Digital Certificates Could Allow Spoofing
http://technet.microsoft.com/en-us/security/advisory/2718704
Published: Sunday, June 03, 2012
Version: 1.0
General Information
Executive Summary
Microsoft is aware of active attacks using unauthorized digital certificates derived from a Microsoft Certificate Authority. An unauthorized certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks. This issue affects all supported releases of Microsoft Windows.
Microsoft is providing an update for all supported releases of Microsoft Windows. The update revokes the trust of the following intermediate CA certificates:
- Microsoft Enforced Licensing Intermediate PCA (2 certificates)
- Microsoft Enforced Licensing Registration Authority CA (SHA1)
Affected Software and Devices
This advisory discusses the following affected software and devices:
Operating System
Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows 7 for 32-bit Systems
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems
Windows 7 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for Itanium-based Systems
Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
Server Core installation option
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Windows Server 2008 R2 for x64-based Systems (Server Core installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
Affected Devices
Windows Mobile 6.x
Windows Phone 7
Windows Phone 7.5
Recommendation
For supported releases of Microsoft Windows, Microsoft recommends that customers apply the update immediately using update management software, or by checking for updates using the Microsoft Update service. For more information, see the Suggested Actions section of this advisory. For affected devices, no update is available at this time.
TechNet Blogs > MSRC > Microsoft releases Security Advisory 2718704
http://blogs.technet.com/b/msrc/archive/2012/06/03/microsoft-releases-security-advisory-2718704.aspx
We recently became aware of a complex piece of targeted malware known as “Flame” and immediately began examining the issue. As many reports assert, Flame has been used in highly sophisticated and targeted attacks and, as a result, the vast majority of customers are not at risk. Additionally, most antivirus products will detect and remove this malware. That said, our investigation has discovered some techniques used by this malware that could also be leveraged by less sophisticated attackers to launch more widespread attacks. Therefore, to help protect both targeted customers and those that may be at risk in the future, we are sharing our discoveries and taking steps to mitigate the risk to customers.
We have discovered through our analysis that some components of the malware have been signed by certificates that allow software to appear as if it was produced by Microsoft. We identified that an older cryptography algorithm could be exploited and then be used to sign code as if it originated from Microsoft. Specifically, our Terminal Server Licensing Service, which allowed customers to authorize Remote Desktop services in their enterprise, used that older algorithm and provided certificates with the ability to sign code, thus permitting code to be signed as if it came from Microsoft.
We are taking several steps to remove this risk:
• First, today we released a Security Advisory outlining steps our customers can take to block software signed by these unauthorized certificates.
• Second, we released an update that automatically takes this step for our customers.
• Third, the Terminal Server Licensing Service no longer issues certificates that allow code to be signed.
These actions will help ensure that any malware components that might have been produced by attackers using this method no longer have the ability to appear as if they were produced by Microsoft.
We continue to investigate this issue and will take any appropriate actions to help protect customers. For more information, please refer back to this site and check with your anti-malware vendor for detection support.
Mike Reavey
Senior Director, MSRC
June 4, 2012
Posted by Smokey |
Advisories, Alerts, Malware, Vulnerabilities | Duqu, Emergency Bulletin, Flame, Microsoft Certificate Authority, Microsoft Enforced Licensing Intermediate PCA (2 certificates), Microsoft Enforced Licensing Registration Authority CA (SHA1), Microsoft Security Advisory (2718704), Microsoft Security Response Center (MSRC), Out-Of-Band Patch, revoked certificates, Stuxnet, targeted cyber-attack, TechNet Blogs, Unauthorized Digital Certificates |
Leave a Comment
Symantec/Norton released Norton 360 v5.1.0.29 (patch 5.1). Note: the patch is currently available to ENGLISH users ONLY. Norton will release the patches in other regions soon. You can also receive the update by running LiveUpdate and download the update. A reboot will be required.
All downloads are originating directly from the Symantec/Norton servers, for security reasons I strongly advise only to download from these vendor servers.
Fixes and improvements patch 5.1
This patch contains many changes and fixes from the previous version. Some of these changes include:
- Added Firefox 4 Support
- Added New TidSrv detection & notification
- Improved Activation Process
- Corrected an issue where your product may report a loss of subscription days after upgrading from a previous version.
- Added performance improvements for IE 9 plugins.
- Fixed some Registry Cleaner hangs that may have previously occurred.
- Online Backup & Restore fixes for very large (> 4GB) files.
- Fixed compatibility issues with 3rd party software such as Corel Paint Shop Pro & Max SEA.
Downloadlinks full version / update / trial / Norton 360 v5.1.0.29 (patch 5.1)
- Norton 360 Standard edition English version 5.1: http://buy-download.norton.com/downloads/CLT/N360/US/2011/5.1/ESD/N360-ESD-18-6-0-29-EN.exe
- Norton 360 Premier edition English version 5.1: http://buy-download.norton.com/downloads/CLT/N360P/US/2011/5.1/ESD/N360-PREMIER-ESD-18-6-0-29-EN.exe
May 12, 2011
Posted by Smokey |
Advisories, Alerts, Anti-Spyware, Anti-Virus, Downloads, Malware, Phishing, Vulnerabilities | buy-download.norton.com, Downloadlinks full version - update - trial - Norton 360 v5.1, Fixes and improvements Norton 360 patch 5.1, LiveUpdate, N360-ESD-18-6-0-29-EN.exe, N360-PREMIER-ESD-18-6-0-29-EN.exe, Norton 360 v5.1.0.29 (patch 5.1) released, Premier edition, Standard edition |
Leave a Comment
UPDATE May 12, 2011: Norton 360 v5.1.0.29 (patch 5.1) released – ENGLISH ONLY
-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-
Symantec/Norton released v18.6.0.29 (patch 18.6) Norton Internet Security 2011, Norton Antivirus 2011 and Norton Internet Security Netbook Edition 2011. Note: the patch is currently available to ENGLISH users ONLY. Symantec/Norton will release the patches in other regions soon. You can also receive the update by running LiveUpdate and download the update. A reboot will be required.
The new NIS/NAV/NIS Netbook Edition 2011 v18.6.0.29 as offered for download in this blog can be installed over the top of existent version (18.5.0.125), the update will not deliver any problem, all previous 2011 settings will remain unaltered after the update. The update will be accomplished within 1 minute, reboot is required. All downloads are originating directly from the Symantec/Norton servers, for security reasons I strongly advise only to download from these vendor servers.
Fixes and improvements patch 18.6
- Added Firefox 4 Support
- Added New TidSrv detection & notification
- Improved Activation Process
- Corrected an issue where your product may report a loss of subscription days after upgrading from a previous version.
- Added performance improvements for IE 9 plugins.
- Fixed compatibility issues with 3rd party software such as Coral Paint Shop Pro & Max SEA.
This patch also contains fixes from previous patch 18.5. Some of those changes included:
- Fixed an issue where Norton Insight might falsely report 0% trusted when Performance Monitoring was disabled.
- Fixed an issue with the Activity Map might not update when Smart Definitions are enabled.
- Improved instances where the Norton AntiSpam Toolbar might be erroneously disabled (or “grayed out”) in Microsoft Outlook 2007 and Microsoft Outlook 2010.
- Corrected an issue where “Custom UI Runtime Error in Norton AntiSpam Outlook Plugin” might display when using Microsoft Outlook.
- Fixed an issue where the option to “run” an executable was missing from a File Insight/Download Insight window.
- Corrected an issue where Idle Full System Scans would show report inconsistent amounts of Scanned Files.
- Fixed an issue where Full System Scans would not run continuously, including when the machine is left idle.
- Fixed an issue where the Norton Product may display “Subscription Expired” after updating from a previous version.
- Fixed Internet Explorer crashes that were due to Intrusion Prevention.
- Performance Enhancements were made on the Norton Toolbar for Internet Explorer 9 Beta.
- Enhanced Settings migration when updating from an older version.
- Usability and Performance improvements to the support experience.
- Added better Norton AntiSpam support for Microsoft Outlook configured with multiple accounts.
- Corrected a few instances of 8504 errors that may appear when the Norton product is launched.
- Fixed a Registry Leak issue that may occur during shutdown.
Downloadlinks full version / update / trial / Norton Internet Security 2011, Norton Antivirus 2011 and NIS Netbook Edition v18.6.0.29 (patch 18.6)
- Norton Antivirus 2011 English version: http://buy-download.norton.com/downloads/CLT/NAV/US/2011/18.6/ESD/NAV-ESD-18-6-0-29-EN.exe
- Norton Internet Security 2011 English version: http://buy-download.norton.com/downloads/CLT/NIS/US/2011/18.6/ESD/NIS-ESD-18-6-0-29-EN.exe
- Norton Internet Security Netbook Edition 2011 English version: http://buy-download.norton.com/downloads/CLT/NISNE/US/2011/18.6/ESD/NIS-NETBOOK-ESD-18-6-0-29-EN.exe
May 9, 2011
Posted by Smokey |
Advisories, Alerts, Anti-Spyware, Anti-Virus, Downloads, Malware, Phishing, Vulnerabilities | buy download norton downloads clt nis nav netbook 2011 esd, Downloadlinks full version / update / trial, Fixes and improvements patch 18.6 v18.6.0.29 NIS/NAV/NIS Netbook Edition 2011, LiveUpdate, NAV-ESD-18-6-0-29-EN.exe, NIS Netbook Edition 2011, NIS-ESD-18-6-0-29-EN.exe, NIS-NETBOOK-ESD-18-6-0-29-EN.exe, Norton Antivirus 2011, Norton Internet Security 2011, patch 18.5, Symantec/Norton, Symantec/Norton 2011 patch 18.6 v18.6.0.29, v18.5.0.125 |
2 Comments
(CNN – May 2, 2011) — Osama bin Laden, the mastermind of the worst terrorist attacks on American soil, is dead, officials said — almost 10 years after the attacks that killed about 3,000 people.
The founder and leader of al Qaeda was killed by U.S. forces Monday in a mansion in Abbottabad, north of the Pakistani capital of Islamabad, along with other family members, a senior U.S. official told CNN.
In an address to the nation Sunday night, U.S. President Barack Obama called bin Laden’s death “the most significant achievement to date in our nation’s effort to defeat al Qaeda.”
“Today, at my direction, the United States launched a targeted operation against that compound in Abbottabad, Pakistan,” Obama said. “A small team of Americans carried out the operation with extraordinary courage and capability. No Americans were harmed. They took care to avoid civilian casualties. After a firefight, they killed Osama bin Laden and took custody of his body.”
To satisfy the curiosity of many people, here the location of Osama bin Laden’s compound on Google Maps. The compound is located at 34°10′9″N 73°14′33″E, 2.5 miles (4 km) northeast of the center of Abbottabad and three-quarters of a mile (1.3 km) southwest of the Pakistan Military Academy (PMA).
Expect a flurry of e-mails, and likely black hat search engine operations trying to take advantage of the event to distribute malware. Be aware for the dangers of emails proclaiming to have information and searching for websites about his death. If you look-out for news about the death of Bin Laden and related issues, please only visit trusted news sites, also don’t click blindly on images related to the news.
Update May 2: there are reports the Bin Laden death scams are already all over Facebook.
Update May 3: malware is found on numerous sites optimized to show up on Web searches related to the event, also in scams on social networks like Facebook, Twitter & Co.
May 2, 2011
Posted by Smokey |
Advisories, Alerts, Malware, News | 9/11, Abbottabad - Pakistan, al Qaeda, Al-Qaida, Bin Laden scams on Facebook, black hat search engine operations, CIA, CNN, Google Maps, Islamabad, latitude and longitude, location Osama Bin Laden's compound - mansion, Osama Bin Laden dead, Pakistan Military Academy (PMA), poisened images and seacrh engine results, statement president President Barack Obama, terrorism, terrorist attacks, U.S. Navy Seals, U.S. Special Forces |
Leave a Comment
UPDATE May 9, 2011: Norton Internet Security 2011, Norton Antivirus 2011 and Norton Internet Security Netbook Edition 2011 v18.6.0.29 (patch 18.6) released – ENGLISH ONLY
UPDATE May 12, 2011: Norton 360 v5.1.0.29 (patch 5.1) released – ENGLISH ONLY
-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-
Symantec/Norton released v18.5.0.125 (patch 18.5) Norton Internet Security 2011, Norton Antivirus 2011 and Norton Internet Security Netbook Edition 2011 (Stable/Official Release).
Like before, I installed the new NIS 2011 v18.5.0.125 over the top of my existent version (18.1.0.37), also this time the update was no problem, all previous 2011 settings remained unaltered after the update. The update was accomplished within 1 minute, reboot was required.
Note: all downloads are originating directly from the Symantec/Norton servers, for security reasons I strongly advise only to download from these vendor servers.
Fixes and improvements
- Fixed an issue where Norton Insight might falsely report 0% trusted when Performance Monitoring was disabled.
- Fixed an issue with the Activity Map might not update when Smart Definitions are enabled.
- Improved instances where the Norton AntiSpam Toolbar might be erroneously disabled (or “grayed out”) in Microsoft Outlook 2007 and Microsoft Outlook 2010.
- Corrected an issue where “Custom UI Runtime Error in Norton AntiSpam Outlook Plugin” might display when using Microsoft Outlook.
- Fixed an issue where the option to “run” an executable was missing from a File Insight/Download Insight window.
- Corrected an issue where Idle Full System Scans would show report inconsistent amounts of Scanned Files.
- Fixed an issue where Full System Scans would not run continuously, including when the machine is left idle.
- Fixed an issue where the Norton Product may display “Subscription Expired” after updating from a previous version.
- Fixed Internet Explorer crashes that were due to Intrusion Prevention.
- Performance Enhancements were made on the Norton Toolbar for Internet Explorer 9 Beta.
- Enhanced Settings migration when updating from an older version.
- Usability and Performance improvements to the support experience.
- Added better Norton AntiSpam support for Microsoft Outlook configured with multiple accounts.
- Corrected a few instances of 8504 errors that may appear when the Norton product is launched.
- Fixed a Registry Leak issue that may occur during shutdown.
Important Symantec Corporation Statement
The issues that some users were experiencing where the Norton product would lock up after installing the 18.5 update was due to a definition that was applied after 18.5 was installed. Symantec have since corrected that definition and the issue will not occur.
Downloadlinks full version / update / trial / Norton Internet Security 2011 and Norton Antivirus 2011 v18.5.0.125 (patch 18.5)
- Norton Antivirus 2011 English version: http://buy-download.norton.com/downloads/CLT/NAV/US/2011/18.5/ESD/NAV-ESD-18-5-0-125-EN.exe
- Norton Internet Security 2011 English version: http://buy-download.norton.com/downloads/CLT/NIS/US/2011/18.5/ESD/NIS-ESD-18-5-0-125-EN.exe
- o – o – o – o – o – o – o – o -o -
- Norton Antivirus 2011 French version: http://buy-download.norton.com/downloads/CLT/NAV/FR/2011/18.5/ESD/NAV-TW-30-18-5-0-125-FR.exe
- Norton Internet Security 2011 French version: http://buy-download.norton.com/downloads/CLT/NIS/FR/2011/18.5/ESD/NIS-TW-30-18-5-0-125-FR.exe
- o – o – o – o – o – o – o – o -o -
- Norton Antivirus 2011 German version: http://buy-download.norton.com/downloads/CLT/NAV/GE/2011/18.5/ESD/NAV-TW-30-18-5-0-125-GE.exe
- Norton Internet Security 2011 German version: http://buy-download.norton.com/downloads/CLT/NIS/GE/2011/18.5/ESD/NIS-TW-30-18-5-0-125-GE.exe
- o – o – o – o – o – o – o – o -o -
- Norton Antivirus 2011 Dutch version: http://buy-download.norton.com/downloads/CLT/NAV/NL/2011/18.5/ESD/NAV-TW-30-18-5-0-125-NL.exe
- Norton Internet Security 2011 Dutch version: http://buy-download.norton.com/downloads/CLT/NIS/NL/2011/18.5/ESD/NIS-TW-30-18-5-0-125-NL.exe
- o – o – o – o – o – o – o – o -o -
Downloadlinks full version / update / trial / Norton Internet Security Netbook Edition 2011 v18.5.0.125 (patch 18.5)
- Norton Internet Security Netbook Edition 2011 English version: http://buy-download.norton.com/downloads/CLT/NISNE/US/2011/18.5/ESD/NIS-NETBOOK-ESD-18-5-0-125-EN.exe
December 29, 2010
Posted by Smokey |
Advisories, Alerts, Anti-Spyware, Anti-Virus, Bundleware, Downloads, Malware, Phishing, Recommended External Security Related Links, Toolbarware, Vulnerabilities | 30 day trial, buy, change log, Downloads, fixes and improvements, links, LiveUpdate, NAV-ESD-18-5-0-125-EN.exe, NAV-TW-30-18-5-0-125-FR.exe, NAV-TW-30-18-5-0-125-GE.exe, NAV-TW-30-18-5-0-125-NL.exe, NIS 2011/NAV 2011/NIS Netbook 2011 v18.5.0.125 released, NIS-ESD-18-5-0-125-EN.exe, NIS-NETBOOK-ESD-18-5-0-125-EN.exe, NIS-TW-30-18-5-0-125-FR.exe, NIS-TW-30-18-5-0-125-GE.exe, NIS-TW-30-18-5-0-125-NL.exe, Norton 2011 English - German - Dutch - French, Norton Antivirus 2011, Norton Internet Security 2011, Norton Internet Security Netbook Edition 2011, patch 18.5 released, Stable/Official Release, Symantec/Norton download servers, upgrade, v18.5.0.125 |
1 Comment
Intro by PCLabs
It’s no longer enough for antivirus software to scan files on your PC. You need someone looking over your shoulder and telling you whether it’s safe to click that link; whether the popup for that software update is legitimate; and whether that download from your favorite social network is actually a tool created by organized criminals for stealing your personal information. You need an all-in-one Internet security suite capable of identifying, blocking, and cleaning up after a wide array of malware.
We examined 13 security suites for this story. To handle our expanded Internet security testing, PCWorld contracted for the services of AV-Test.org, a respected security testing company. We looked at traditional signature-based detection (which indicates how well products can block known malware) and at how well the suites cleaned infections and blocked brand-new, live malware attacks.
In many respects, the suites we looked at produced closely bunched results, but they did vary in the efficacy of their protection and in the extra features they offered. Ultimately, we picked Symantec’s Norton Internet Security 2011–the most balanced of the suites–as our overall winner.
Source / full tests: http://www.pcworld.com/article/214618/battle_of_the_security_superpowers.html
Tested Security Suites
Symantec Norton Internet Security 2011
Kaspersky Internet Security 2011
BitDefender Internet Security 2011
PC Tools Internet Security 2011
G-Data Internet Security 2011
F-Secure Internet Security 2011
Trend Micro Titanium Internet Security 2011
Panda Internet Security 2011
Eset Smart Security 4.2
Avira AntiVir Premium Security Suite
Comodo Internet Security 2011 Complete
McAfee Internet Security 2011
Webroot Internet Security Essentials 2011
December 28, 2010
Posted by Smokey |
Advisories, Anti-Spyware, Anti-Virus, Bundleware, Malware, Phishing, Recommended External Security Related Links, Toolbarware | antivirus test, AV-Test.org, Avira AntiVir Premium Security Suite, BitDefender Internet Security 2011, Comodo Internet Security 2011 Complete, Eset Smart Security 4.2, F-Secure Internet Security 2011, G-Data Internet Security 2011, Kaspersky Internet Security 2011, McAfee Internet Security 2011, Panda Internet Security 2011, PC Tools Internet Security 2011, PCWorld Labs, Review, security suites, Symantec Norton Internet Security 2011, Trend Micro Titanium Internet Security 2011, Webroot Internet Security Essentials 2011 |
Leave a Comment
Statement Microsoft Outlook product team, 17 Dec 2010:
On Tuesday, December 14, we released an update (KB2412171) for Microsoft Outlook 2007. We have discovered several issues with the update and want to inform you about problems you might encounter and what corrective steps we recommend. As of December 16, this Outlook 2007 update has been removed from Microsoft Update.
This Outlook 2007 update was distributed via Microsoft Update. Many of you receive updates automatically and if you installed the update between Tuesday, December 14, and Thursday, December 16, it is likely that you are affected.
The three issues identified in the December 2010 update for Outlook 2007 are as follows:
Outlook fails to connect if Secure Password Authentication (SPA) is configured for an account and the mail server does not support SPA. This is important for Google Gmail users because Gmail does not support SPA. Outlook customers using Gmail who have the SPA option turned on cannot connect to Gmail.
Noticeable performance issues are experienced when switching between folders if you do not have a Microsoft Exchange Server account configured in Outlook. Switching folders might take several seconds depending on the performance of your computer. This issue only applies when you use an IMAP, POP3, or Outlook Live Connector account, such as Windows Live Hotmail, and do not have an Exchange Server account configured in the same Outlook profile.
AutoArchive cannot be configured for IMAP, POP3, or Outlook Live Connector accounts if there is no Exchange Server account configured in the same Outlook profile. If you previously configured AutoArchive, no additional items are archived.
If you are experiencing any of the listed issues with Outlook 2007, we recommend that you uninstall the December 2010 update by doing the following:
Uninstalling KB2412171 on Windows 7 or Windows Vista
1. Click Start, and then click Control Panel.
2. Click Programs, and then under Programs and Features, click View installed updates.
3. Click the entry for KB2412171, and then click Uninstall.
Uninstalling KB2412171 on Windows XP
1. Click Start, and then click Control Panel.
2. Click Add or Remove Programs, and then make sure that the Show Updates check box is selected.
3. Click the entry for KB2412171, and then click Remove.
Note for Office 365 Beta customers: You do not need to uninstall this update. The listed folder switching and AutoArchive issues do not apply because Office 365 accounts are Exchange Server accounts. However, the issue with SPA when connecting to non-Exchange Server accounts that don’t support SPA does apply. In this case, turn off the SPA option by doing the following:
1. In Outlook, on Tools menu, click Account Settings.
2. Select your account, and then click Change.
3. Clear the Require logon using Secure Password Authentication (SPA) check box.
We are working to fix these issues and will post a release date for those fixes, and link to download them, as soon as that information is available.
December 23, 2010
Posted by Smokey |
Advisories, Alerts, Downloads, News, Recommended External Security Related Links | AutoArchive cannot be configured, bugs, cannot connect to Gmail, cumulatieve update, Exchange Server account, fix, IMAP, KB2412171 Alert, Mail, Microsoft Outlook 2007, Microsoft Update, Outlook Live Connector account, performance issues, POP3, Secure Password Authentication (SPA), Windows Live Hotmail, wreaking havoc |
4 Comments
Official Symantec/Norton statement regarding Norton Internet Security 2011 and Norton AntiVirus 2011 v18.5.0.125
12-11-2010
There have been several reports on the forums where after applying the Norton Internet Security/Norton AntiVirus 18.5 patch (is version 18.5.0.125), the Norton product may lock up or cause the system to become unstable.
While this issue only seems to affect a small number of installations, we’re still taking this issue seriously and are quickly researching the cause of this problem.
We will be halting the throttled LiveUpdate release of 18.5 for the time being while we investigate these issues.
If you are experiencing this issue and would like to assist us in gathering information (debug logs and process dumps) for this issue, please post a response in THIS THREAD. The more logs and dumps we get, the more information we have that will help us make the proper corrections.
If you are having these issues and need to revert your system back to 18.1 (is version 18.1.0.37), simply uninstall 18.5 using Control Panel (or Uninstall from the Norton Product Program Group), and reinstall 18.1 from the following locations:
Norton Internet Security 18.1 – http://www.norton.com/nis11
Norton AntiVirus 18.1 – http://www.norton.com/nav11
Norton Internet Security 18.1, Norton AntiVirus 18.1 and Norton Netbook Edition 18.1 in English, French, German and Dutch language (direct downloads from Symantec/Norton servers too) – http://smokeys.wordpress.com/2010/08/28/norton-internet-security-2011-and-norton-antivirus-2011-final-rtm-released/Some users are reporting troubles uninstalling. Try uninstalling from Safe Mode. If that fails, you can use the Norton Removal Tool.If you have 18.5, but are not experiencing any issues, it is advised that you remain on 18.5.
Update 12-29-2010
Symantec Statement: “The issues that some users were experiencing where the Norton product would lock up after installing the 18.5 update was due to a definition that was applied after 18.5 was installed. Symantec have since corrected that definition and the issue will not occur.”
Download Norton Internet Security 2011, Norton Antivirus 2011 and Norton Internet Security Netbook Edition 2011 v18.5.0.125 (patch 18.5, stable/official release) here: http://smokeys.wordpress.com/2010/12/29/norton-internet-security-2011-and-norton-antivirus-2011-v18-5-0-125-patch-18-5-released/
December 12, 2010
Posted by Smokey |
Advisories, Alerts, Anti-Virus, Downloads, Recommended External Security Related Links, Vulnerabilities | Application Hang, bugs, ccSvcHst.exe, errors, Event ID: 1002, fix, Help and Advice, LiveUpdate, lock up problems, NAV-TW-30-18-1-0-37-EN.exe, NIS-TW-30-18-1-0-37-EN.exe, Norton Internet Security 2011 and Norton AntiVirus 2011 v18.5.0.125, Norton Removal Tool, patch 18.5 - version 18.5.0.125, solution, symantec, system become unstable, uninstalling troubles, version 18.1 |
Leave a Comment
UPDATE Dec. 29, 2010: v18.5.0.125 (patch 18.5) Norton Internet Security 2011, Norton Antivirus 2011 and Norton Internet Security Netbook Edition 2011 released; release info, fixes/improvements and downloads here: – http://smokeys.wordpress.com/2010/12/29/norton-internet-security-2011-and-norton-antivirus-2011-v18-5-0-125-patch-18-5-released/
UPDATE May 9, 2011: Norton Internet Security 2011, Norton Antivirus 2011 and Norton Internet Security Netbook Edition 2011 v18.6.0.29 (patch 18.6) released – ENGLISH ONLY
UPDATE May 12, 2011: Norton 360 v5.1.0.29 (patch 5.1) released – ENGLISH ONLY
-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-o-
Aug. 28, 2010
Symantec offered today via their download servers Norton Internet Security 2011 and Norton Antivirus 2011 v18.1.0.37 Final RTM. Like I wrote before regarding NIS 2009, same positive words are (even more!) valid for today’s released Norton 2011 AV products: “without any hesitation I highly recommend Norton Internet Security 2011 to all people looking for a top-notch, reliable, easy to use all-in-one security suite.” Of course I also highly recommend NAV 2011: like NIS, great product for an acceptable price.
I installed NIS 2011 on top of my NIS 2010 , the upgrade was no problem, all previous 2010 settings remained unaltered after the upgrade. The upgrade was accomplished within 1 minute, reboot was required.
Full version / Upgrade / Trial download links NIS/NAV 2011 Final RTM 18.1.0.37 versions
- Norton Antivirus 2011 English version: http://buy-download.norton.com/downloads/CLT/NAV/US/2011/18.1/ESD/NAV-TW-30-18-1-0-37-EN.exe
- Norton Internet Security 2011 English version: http://buy-download.norton.com/downloads/CLT/NIS/US/2011/18.1/ESD/NIS-TW-30-18-1-0-37-EN.exe
- o – o – o – o – o – o – o – o -o -
- Norton Antivirus 2011 French version: http://buy-download.norton.com/downloads/CLT/NAV/FR/2011/18.1/ESD/NAV-TW-30-18-1-0-37-FR.exe
- Norton Internet Security 2011 French version: http://buy-download.norton.com/downloads/CLT/NIS/FR/2011/18.1/ESD/NIS-TW-30-18-1-0-37-FR.exe
- o – o – o – o – o – o – o – o -o -
- Norton Antivirus 2011 German version: http://buy-download.norton.com/downloads/CLT/NAV/GE/2011/18.1/ESD/NAV-TW-30-18-1-0-37-GE.exe
- Norton Internet Security 2011 German version: http://buy-download.norton.com/downloads/CLT/NIS/GE/2011/18.1/ESD/NIS-TW-30-18-1-0-37-GE.exe
- o – o – o – o – o – o – o – o -o -
- Norton Antivirus 2011 Dutch version: http://buy-download.norton.com/downloads/CLT/NAV/NL/2011/18.1/ESD/NAV-TW-30-18-1-0-37-NL.exe
- Norton Internet Security 2011 Dutch version: http://buy-download.norton.com/downloads/CLT/NIS/NL/2011/18.1/ESD/NIS-TW-30-18-1-0-37-NL.exe
- o – o – o – o – o – o – o – o -o -
Full version / Upgrade / Trial download links Norton Internet Security Netbook Edition 2011 Final RTM 18.1.0.37, English and German versions
- Norton Internet Security Netbook Edition 2011 English version: http://buy-download.norton.com/downloads/CLT/NISNE/US/2011/18.1/ESD/NIS-NETBOOK-ESD-18-1-0-37-EN.exe
- Norton Internet Security Netbook Edition 2011 German version: http://buy-download.norton.com/downloads/CLT/NISNE/GE/2011/18.1/ESD/NIS-NETBOOK-ESD-18-1-0-37-GE.exe
- o – o – o – o – o – o – o – o -o -
Reviews, tests and awards NIS 2011 and NAV 2011
- PCMag review Norton AntiVirus 2011: http://www.pcmag.com/article2/0,2817,2368764,00.asp
- PCMag review Norton Internet Security 2011: http://www.pcmag.com/article2/0,2817,2368876,00.asp
- CNet review Norton AntiVirus 2011: http://download.cnet.com/Norton-AntiVirus-2011/3000-2239_4-10592477.html
- CNet review Norton Internet Security 2011: http://download.cnet.com/Norton-Internet-Security-2011/3000-18510_4-10592551.html
- AV-Comparatives Award Best Anti-Virus Product of 2009: Symantec/Norton
- PCWorld/AV-Test.org review Norton Internet Security 2011: http://www.pcworld.com/article/id,214625/article.html
- Chip Online review Norton Internet Security 2011 (German language): http://www.chip.de/downloads/Norton-Internet-Security-2011_16463672.html
August 28, 2010
Posted by Smokey |
Advisories, Alerts, Anti-Spyware, Anti-Virus, Downloads, Malware, Phishing, Recommended External Security Related Links, Toolbarware, Vulnerabilities | AV-Comparatives test, Best Anti-Virus Product, buy Norton Antivirus 2011, Chip Online review, CNet review/test, Final RTM, NAV-TW-30-18-1-0-37-EN.exe, NAV-TW-30-18-1-0-37-FR.exe, NAV-TW-30-18-1-0-37-GE.exe, NAV-TW-30-18-1-0-37-NL.exe, NIS-NETBOOK-ESD-18-1-0-37-EN.exe, NIS-NETBOOK-ESD-18-1-0-37-GE.exe, NIS-TW-30-18-1-0-37-EN.exe, NIS-TW-30-18-1-0-37-FR.exe, NIS-TW-30-18-1-0-37-GE.exe, NIS-TW-30-18-1-0-37-NL.exe, Norton 2011 English - German - Ducth - French, Norton Antivirus 2011 released, Norton Internet Security 2011 released, Norton Internet Security Netbook Edition 2011 Final RTM English and German versions, Norton Support, PCMag review/test, PCWorld/AV-Test.org review, Reviews/tests NIS 2011 and NAV 2011, symantec, Trial / Upgrade download links NIS/NAV 2011 Final RTM |
1 Comment
Smokey’s Security Forums is pleased to announce that the board offer now free OTL (OldTimer ListIt) Log Analysis Help and Support Services in English, German and Spanish language. Board visitors with native language English, German or Spanish will now be helped in preferred language, the board have analysers speaking and writing all mentioned languages fluently.
Like before, all malware removal help & support services on Smokey’s are free. To board guests it is also possible to offer their logs.
Our current OTL (OldTimer ListIt) Log Analysis Help and Support Forums Survey:
* English speaking visitors are welcome to post their OTL log here: OTL Log Analysis – Malware, Adware and Popup Removal – Alureon TDSS TDL3 Rootkit Removal Help – System Cleaning
* Spanish speaking visitors are invited to post logs here: Análisis de registros utilizando OTL – Eliminación de Programas Maliciosos, Programas de Mercadeo y Popups & Limpieza del Sistema Operacional – Ayuda Malware Infeción Rootkit TDSS TDL3
* German speaking visitors can post their OTL logs here: OTL Log Analyse – Malware/Schädlingen und Adware Entfernung – Popup Bekämpfung – TDSS TDL3 Rootkit Beseitigung
Smokey’s wish everyone Happy Surfing!
June 5, 2010
Posted by Smokey |
Advisories, Alerts, Anti-Spyware, Bundleware, Recommended External Security Related Links, Toolbarware | Alureon TDSS TDL3 Rootkit Removal Help, Análisis de registros utilizando OTL, Ayuda Malware Infeción Rootkit TDSS TDL3, complete and unabridged, completo e íntegro, download OTM File Mover, download OTS System Scanner, download TFC Temp File Cleaner, Eliminación de Programas Maliciosos, German and Spanish language, HJT (HijackThis) logs, Infeción Virus Troyano, Limpieza del Sistema Operacional, Malware and Adware and Popup Removal, Malware/Schädlingen und Adware Entfernung, Manual de OTL - Como utilizar OldTimer ListIt, Oldtimer, OTL (OldTimer ListIt) Log Analysis, OTL Analysis and Malware Removal Help in English, OTL Analysis en Español, OTL Anleitung - Wie man Oldtimer ListIt benutzt, OTL Tutorial - How to use OldTimer ListIt, Popup Bekämpfung, Programas de Mercadeo y Popups, system cleaning, TDSS TDL3 Rootkit Beseitigung |
Leave a Comment