Welcome, Guest. Please login or register.
October 11, 2008, 10:55:12 AM

Login with username, password and session length

199239 Posts
22891 Topics
54943 Members

Latest Member: DorisM

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Anti Virus/Malware Products/Other Security products
| | |-+  Anti-Virus Killer Trojan Created by Mallware makers!!!!
« previous next »
Pages: [1] Go Down Print
Author Topic: Anti-Virus Killer Trojan Created by Mallware makers!!!!  (Read 1373 times)
ultragunner
Comodo Loves me
****
Offline Offline

Posts: 138



« on: December 05, 2007, 09:49:36 PM »

A new Retro Trojan has been created by mallware makers  Sad

Trojan.Win32.KillAV.cn - KernelMode Trojan.
A small Trojan program, designed for fighting against Antivirus, Firewall and Anti-malware utilities. The size of the executable file is about 5KB. If it is run, it silently performs the following actions:

1. Creates the driver C:\WINDOWS\system32\unpr.sys, file size 2.5KB (This file is stored in the body of the Trojan)

2. Registers the driver through the standard API, under the name of UNPR, after which it shuts down the computer.

The Trojan does not load the installed driver, which is why it's loading will commence only after rebooting the computer. The driver implements tracking of the loading [of processes] without intercepting functions, with the help of the documented notification mechanism on loading PE files into memory (LoadImageNotifyRoutine). After receiving notice about the launching of a process, the driver compares the name of the process being launched to its database of names, which are stored in the driver (there are two databases in the driver- database of EXE file names and database of driver names)
If it finds a match, the driver opens the process and terminates it.

The Trojan blocks/terminates processes with the following names:
avp.exe avpm.exe avz.exe bdmcon.exe bdss.exe ccapp.exe ccevtmgr.exe cclaw.exe ccpxysvc.exe fsav32.exe fsbl.exe fsm32.exe gcasserv.exe iao.exe icmon.exe inetupd.exe issvc.exe kav.exe kavss.exe kavsvc.exe klswd.exe livesrv.exe mcshield.exe msssrv.exe nod32krn.exe nod32ra.exe pavfnsvr.exe rtvscan.exe savscan.exe zclient.exe

As you can see, an entry exists for avz.exe in the Trojan database, which leads to the blocking of it's launch. To protect against this is simple- The process is identified by name, so to get around this and allow the file to execute, it is enough to rename the file, giving it a random name, such as 123.exe. For the deletion of the Trojan driver, it is possible to execute a script similar to the one below in AVZ:

begin
DeleteService('UNPR', true);
RebootWindows(true);
end. Sad
Logged


 
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5678



WWW
« Reply #1 on: December 05, 2007, 09:51:28 PM »

It can't install or start if you have CPF v3!!!

And thats the power of Prevention!!!! We even rescue AVs from malware itself Smiley


Melih

Logged

ultragunner
Comodo Loves me
****
Offline Offline

Posts: 138



« Reply #2 on: December 05, 2007, 11:55:52 PM »

IC that is good to know because I am using Comodo firewall version 3 myself. Congratulations on a job well done.
Logged


 
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3114


Sailor Warrior of Love and Justice


« Reply #3 on: December 06, 2007, 02:29:34 PM »

Won't have any chance against Comodo Firewall Pro 3  Comodo Rocks
Anyways, I would never open a .exe file that's 5 kB, so I don't have to worry about it Wink

Cheers,
Ragwing
Logged



XP SP3 2 GHz 768 MB RAM
5 services / 12 processes
Rotty
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 793

http://www.venganza.org/ - Noodly Appendage


« Reply #4 on: December 06, 2007, 04:50:28 PM »

A more advanced technique is to open the process but patch the first bit of code so that it returns with the code of 0 (Which means success) to the operating system  So the process is running, but does absolutely nothing.

Windows security monitor cannot tell that the anti virus program has been patched, it thinks the anti virus program is running (Which it is).

Logged

The opinions expressed in my posts are my own. 
They do NOT necessarily represent or reflect the views of my employer.
ultragunner
Comodo Loves me
****
Offline Offline

Posts: 138



« Reply #5 on: December 07, 2007, 06:17:01 AM »

Another method is to use Sandbox to capture & imprison it.
Sandbox is usage of a virtual container in which untrusted programs can be safely run.
Logged


 
Info-Sec
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 557



« Reply #6 on: January 02, 2008, 02:53:29 PM »

Tch not worried.  Besides the nod32 process isnt listed on their, and my ZA pro wud b like WTF mate allow or deny? id b like DENIED sucka Smiley
Logged

*Vista *CFP V3 *Avira * Avast *Spyware Doctor
*XP *Zone Alarm PRO *NOD32 V2.7 *Spysweeper
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.32 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com