Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2013, 02:09:26 AM

Login with username, password and session length

664102 Posts
70639 Topics
153609 Members

Latest Member: Hefusase

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  AV False Positive/Negative Detection Reporting
| | | |-+  utm.exe & CIS
« previous next »
Pages: [1] Go Down Print
Author Topic: utm.exe & CIS  (Read 2666 times)
naren
Comodo's Hero
*****
Offline Offline

Posts: 3861


« on: April 11, 2012, 12:07:11 PM »

Was testing CIS latest with default settings.

utm.exe has a weird digital signature which is invalid. It is trusted by CIS i.e it gets into trusted lists.

If you keep the mouse over utm.exe it mentions company Microsoft Corporation. Trusted lists also shows Microsoft Corporation.

See the attached screenshots related to utm.exe & CIS.

VT Link - https://www.virustotal.com/file/362d492dfcf5b644c143844831a319f8d381a9cd1a81ebcfabe484c325cad792/analysis/1334163462/

Valkyrie Link - https://valkyrie.comodo.com/Result.html?sha1=e3cde656b494f1037c73c7220c38a52d2fe71d94&&query=0&&filename=uTM.exe

Comodo Dragon asks to discard the file during download as it finds it malicious.


* scr.PNG (593.47 KB, 1280x800 - viewed 35 times.)
Logged
Hause
Comodo's Hero
*****
Offline Offline

Posts: 962


« Reply #1 on: April 11, 2012, 12:23:50 PM »

Report in CIMA
http://cima.security.comodo.com/report/e3cde656b494f1037c73c7220c38a52d2fe71d94.htm
Verdict:
Suspicious++
Suspicious Actions Detected:
Creates autorun records
Deletes self
Injects code into other processes
Logged
Siketa
Comodo's Hero
*****
Online Online

Posts: 3164


ZIG ZAG


« Reply #2 on: April 11, 2012, 12:28:25 PM »

Wow!  Shocked
Nice catch, guys!  Thumb Up
Logged
naren
Comodo's Hero
*****
Offline Offline

Posts: 3861


« Reply #3 on: April 12, 2012, 08:47:40 AM »

I am wondering how a file with such a weird invalid digital signature was whitelisted by Comodo?

A mistake or a bug in the whitelisting process?
Logged
FlorinG
First Response Group
Comodo's Hero
*****
Offline Offline

Posts: 1888



« Reply #4 on: April 12, 2012, 09:04:00 AM »

Hello,

The sample you have provided is not trusted by CIS, in fact is has a malware signature and it is detected.

Best regards,
FlorinG
Logged

If possible please post your malware submissions as SHA1 lists. Always make sure first you have submitted the samples through CIS or CIMA . Thank you!
naren
Comodo's Hero
*****
Offline Offline

Posts: 3861


« Reply #5 on: April 12, 2012, 09:09:53 AM »

Hello,

The sample you have provided is not trusted by CIS, in fact is has a malware signature and it is detected.

Best regards,
FlorinG

Do you mean to say I am lieng in any way Huh

CIS is detecting the sample today BUT yesterday it was not detecting it, infact the sample was trusted by CIS as shown in the screenshot in the first post.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.046 seconds with 22 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com