.funkyblue { color:#0000AF; }
Hi all there,
after a long silent period without any news I am proud to announce the new version of the AVG Anti-Spyware 7.5.1.36
Here a short overview about the changes in the new release:
- Windows Vista support
- Support for 64-Bit editions of Windows (Windows XP 64-bit & Windows Vista 64-Bit)
- Better reliability + speed of updates
- Higher priority for paying users on update servers
- Fixes for many bugs (including high CPU usage + scheduler bugs)
The problem with the slow/unreliable updates will not be fixed at once, it will take some time until the vast majority of the user base has switched to the new version.
The new version will also be released via online-update in the next days. You can either wait for the update or manually download it from:
http://downloads.grisoft.cz/softw/70/filedir/inst/avgas-setup-7.5.1.36.exe
In any case, a system reboot is required.
Regards,
Vinzenz Feenstra
I have previous posted about the Windows threat ‘Trojan.downloader.uj’ and that I have build a removal help tool for it.
I think it would be best for all if I post here some removal steps for this special threat which is really tricky, since it is a trojan but uses userland rootkit techniques.
Here are the steps:
Or you can try Grisoft AVG Anti-Rootkit Beta 1.0.0.13, but be careful it is a beta!
Thats’s all the threat should be removed now.
Aliases for this threat are:
| Antivirus | Alias |
| AntiVir | TR/Dldr.Agent.uj.1 |
| Authentium | W32/Downloader.LTB |
| Avast | Win32:Agent-IU |
| AVG | Downloader.Agent.BAH |
| BitDefender | Trojan.Downloader.FFZ |
| CAT-QuickHeal | TrojanDownloader.Agent.uj |
| ClamAV | Trojan.Downloader.Agent-262 |
| DrWeb | Trojan.DownLoader.4316 |
| eTrust-InoculateIT | Win32/SillyDL.51200!Trojan |
| eTrust-Vet | Win32/Alureon.Y |
| Ewido | Downloader.Agent.uj |
| Fortinet | RuinDl.G!tr |
| F-Prot | security risk named W32/Downloader.LTB |
| F-Prot4 | W32/Downloader.LTB |
| Ikarus | Trojan-Downloader.Win32.Agent.uj |
| Kaspersky | Trojan-Downloader.Win32.Agent.uj |
| McAfee | Downloader-ASI |
| Microsoft | TrojanDownloader:Win32/Agent.RR |
| NOD32v2 | a variant of Win32/Small.FB |
| Norman | W32/DLoader.NNL |
| Panda | Trj/Ruins.MB |
| Sophos | Troj/RuinDl-G |
| Symantec | Downloader |
| TheHacker | Trojan/Downloader.Agent.uj |
| UNA | TrojanDownloader.Win32.Agent.68D6 |
| VBA32 | Trojan.DownLoader.4316 |
I hope this is helpful.
Regards,
Vinzenz Feenstra
I was reading blog entry of Joanna Rutkowska, a really smart and good looking (*fg*) expert in security and rootkits from Poland, and I was really asking myself, should we be scared about rootkits in the future? To give you a short answer: Yes we should!
Ok of course such rootkit can maybe be blocked before they’re installed or while it tries to installs itself or any other malware tries to install it. I am reading about the technology and the evolution of the knowledge in this area for a while and I need to say that it is really scary how fast the evolution moves forward.
Last year I was reading something about DKOM (Direct Kernel Object Manipulation), after thinking about the concept I was sure something like this is comparative easy to detect. Also hooking SSDT, IAT, EAT or using Inline Hooks (Detours) is almost harmless if you know how to get rid of it (see my previous post Trojan.Downloader.uj which is about an userland rootkit)
Anyway this year, only about 6 months later I read something which really scared me. joanna Rutkowska held some presentations about rootkits again and there she demonstrated a rootkit she is calling ‘deepdoor’. After taking a look at what she can do with this threat I was really asking myself how should you detect something like this. Ok there will be some smart guy who will be abled to detect (I am sure there will be one!). But now (ok it was already in June, but it doesn’t matter) she is writing about ‘Blue Pill’. Think about this: You are running VMWare on your computer and host another windows in there. This no great deal, that’s right but what would you say if somebody tells you that you’re hosting VMWare already in a virtual environment?
Huh? That’s really scary. And I must admit that using the name ‘Blue Pill’ is a really good choosen name.
I am right in the beginning in understanding how malware works and how it can be detected and removed but if I read something like this I am really asking myself how should we prevent ourselves from such threats?
I hope that we will be abled to have an idea how to get a ‘Red Pill’ for such threats and are abled to remove or at least to warn the users about such a threat.
Further reading about this subject you can find at:
Edit: (8th August 2006) I found another really interesting blog entry about this at http://www.ryanpmanning.com/?p=56
Be aware! Be scared!
Regards,
Vinzenz Feenstra
I am proud to announce that Grisoft has released the AVG Anti-Rookit Beta available at http://beta.grisoft.cz after a registration (which is for free)
It is abled to detect and to remove a lot of rootkits. How good it is you will really know if you have a rootkit on your system
The Screenshots below are showing the tests in a VMWare Session where I have installed the Vanquish rootkit which is available at rootkit.com
I really warn everyone this is a beta software it may work but you should be careful!
Please report your test results and your opinion about it.
Regards,
Vinzenz
Hi,
A long time we couldn’t help users to get rid of the "Userland Rootkit" Downloader.Agent.uj.
Today I wrote an utility to help users getting rid of this damn threat. If someone has a problem with removing a threat please feel free contact our support forums
at wilders[1] and we’ll assist you to remove this threat.
[1] ewido anti-spyware Support Forums at Wilders
Regards,
Vinzenz
Hey guys,
First of all I must admit that this is not really a brand new news but ewido anti-spyware 4.0 is somehow my baby although I don’t have developed it from the beginning and I don’t have developed everything, but an huge amount of it.
So I’d like to talk about ewido anti-spyware 4.0 a little bit
Back in July 2005 I have started working as freelancer for ewido networks, the company who has started developing the ewido security suite several years ago. My first job was to implement an autostart analysis module for this version 4.0 and at this time ewido 4 has still the old graphical user interface style. About one month after starting working at ewido networks I was asked to become an employee, that was an overwhelming majority offer for me since I am just a self-educated person who has made an apprenticeship as cook, and becoming an employee as software developer was always my dream. One month later, on September 1st 2005, I was the first official employee of ewido networks and I walked on air
From this time I have implemented a lot of features, and overhauled almost every code line already exist.
Now back to ewido anti-spyware 4.0 ewido anti-spyware 4.0 was released on the 19th June 2006 and has the following new features:
Visit http://www.ewido.net and download ewido anti-spyware 4.0ewido anti-spyware protects you against Spyware like Tracking-Cookies, KeyLoggers etc, Ad-Ware, Trojans, Internet-Worms, Browser-Hijacker and Dialers.
You should really take a look and improve your protection. ewido anti-spyware 4.0 was designed to be used beside existing anti-virus software to improve the protection of the users since anti-virus applications are not protecting you against everything.
And using ewido anti-spyware 4.0 improves the detection rate.
Check out ewido anti-spyware 4.0
Here are somescreenshots:
I know that sounds like an ad but I’m so proud of it.
:)
Regards,
Vinzenz
| M | T | W | T | F | S | S |
|---|---|---|---|---|---|---|
| « Mar | ||||||
| 1 | 2 | 3 | 4 | 5 | 6 | 7 |
| 8 | 9 | 10 | 11 | 12 | 13 | 14 |
| 15 | 16 | 17 | 18 | 19 | 20 | 21 |
| 22 | 23 | 24 | 25 | 26 | 27 | 28 |
| 29 | 30 | 31 | ||||