Welcome, Guest. Please login or register.
December 10, 2009, 06:44:59 PM

Login with username, password and session length

341577 Posts
37750 Topics
85708 Members

Latest Member: beastman

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  D+ Engine could not able to intercept malware properly
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: D+ Engine could not able to intercept malware properly  (Read 3557 times)
harsha_mic
Computer Security Testing Group
Newbie
*****
Offline Offline

Posts: 16


« on: June 08, 2009, 02:26:54 PM »

Hi,

I have an malicious sample which i believe it is bypassing D+ execution engine partially. Pls. find the steps to re-create the issue -

1. double-click install.exe (new variant of Antivirus Pro)
2. D+ prompts stating that "install.exe wants to run you computer". and clicked "ALLOW".
3. From the second prompt onwards, i have clicked "BLOCK" for all the follow-up prompts.

Result: Rogue program could able to modify host file successfully but luckily could not able to start.

Note: I have run above malware sample under Sandboxie 3.38 version. So, luckily it couldn't harm my system.

CIS 3.9 Proactive Mode
XP SP3
NOD32 v4

If anyone really finds this as an bug wants to further look into the issue, then i can provide the malware sample.

Thanks,
Harsha.
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1564


The only thing i ask for are eggs.


WWW
« Reply #1 on: June 08, 2009, 02:53:18 PM »

Can you PM me a link to the malware please  Wink thanks

Also what Security mode did you use? proative or internet security?

It does, the problem is you hit allow on the first one!
« Last Edit: June 08, 2009, 02:56:55 PM by OmeletGuy » Logged

What you see isn’t what you always get!
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 875



« Reply #2 on: June 08, 2009, 03:02:01 PM »

proactive security should block the host file from being modified.
Logged

http://www.youtube.com/languy99

Software Reviews For All
harsha_mic
Computer Security Testing Group
Newbie
*****
Offline Offline

Posts: 16


« Reply #3 on: June 08, 2009, 08:11:01 PM »

OmeletGuy, pls. check you pm folder. sent you the sample. password is infected

languy99, thats the problem. i guess it needs to be fixed.

i'm using proactive internet security and more importantly i could able to see below entry under D+ --> My Protected Files = %windir%\system32\*. So, logically i guess an alert or entry should be blocked. or else am i missing some thing??

Can any mods look into this....

Thanks,
Harsha.
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1564


The only thing i ask for are eggs.


WWW
« Reply #4 on: June 08, 2009, 08:36:29 PM »

I got it harsha_mic thx i will start testing soon and post results if i can copy this!
Logged

What you see isn’t what you always get!
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1564


The only thing i ask for are eggs.


WWW
« Reply #5 on: June 08, 2009, 09:02:53 PM »

Yup the same thing happens, i will also submit this rouge to AV analysts should be added soon!


Some dev please look into this.
Logged

What you see isn’t what you always get!
harsha_mic
Computer Security Testing Group
Newbie
*****
Offline Offline

Posts: 16


« Reply #6 on: June 08, 2009, 09:07:05 PM »

thanks friend. but the important thing is the D+ bug(probably) should be rectified...
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 1564


The only thing i ask for are eggs.


WWW
« Reply #7 on: June 08, 2009, 09:12:33 PM »

thanks friend. but the important thing is the D+ bug(probably) should be rectified...

Yes it should
Logged

What you see isn’t what you always get!
J2897
Comodo's Hero
*****
Offline Offline

Posts: 224


Limted User Account Enforcer


WWW
« Reply #8 on: June 09, 2009, 02:54:09 AM »

Has anyone tried it in a VM (without 'Sandboxie')?

PM it to me if not, thanks.
Logged

egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2142



« Reply #9 on: June 09, 2009, 09:15:46 AM »

Can you please send me PM me the link for the malware? Also can you please try without Sandboxie inside a virtual machine? IT is quite possible that Sandboxie redirects the file system requests and the actual file modification is not really the hosts file but something else. This might be the reason.

However lets be sure. Pls PM me the link and let me test.


Thanks,
Egemen
Logged
harsha_mic
Computer Security Testing Group
Newbie
*****
Offline Offline

Posts: 16


« Reply #10 on: June 09, 2009, 12:10:15 PM »

Can you please send me PM me the link for the malware? Also can you please try without Sandboxie inside a virtual machine? IT is quite possible that Sandboxie redirects the file system requests and the actual file modification is not really the hosts file but something else. This might be the reason.

However lets be sure. Pls PM me the link and let me test.


Thanks,
Egemen

I have sent you the link for the malware sample and password is infected

Thanks,
Harsha.
Logged
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2142



« Reply #11 on: June 09, 2009, 12:49:18 PM »

I have sent you the link for the malware sample and password is infected

Thanks,
Harsha.


Thanks Harsha.

I have tested in a VM and CIS produced expected popups. I think it is related to Sandboxie.

Interestingly, CIS reported many buffer overflow attacks in this malware too. Smiley
Logged
LaserWraith
Usability Study Member
Comodo's Hero
*****
Offline Offline

Posts: 3226


BSOD is my friend. He should be yours!


WWW
« Reply #12 on: June 09, 2009, 01:10:26 PM »


Thanks Harsha.

I have tested in a VM and CIS produced expected popups. I think it is related to Sandboxie.

Interestingly, CIS reported many buffer overflow attacks in this malware too. Smiley

CIS may have alerted, but if you block the alerts was the host file still modified?


BTW, it looks like you have CIS 3.10.   Grin

(See attached.)


Logged

In peace sons bury fathers; in war fathers bury sons.

Visit my site!

Some of my articles - click for blog page.


languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 875



« Reply #13 on: June 09, 2009, 01:18:16 PM »

yeah what is that about  Shocked what do I have to do to get it  Kiss   Wink jk
Logged

http://www.youtube.com/languy99

Software Reviews For All
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2142



« Reply #14 on: June 09, 2009, 01:38:16 PM »

CIS may have alerted, but if you block the alerts was the host file still modified?


BTW, it looks like you have CIS 3.10.   Grin

(See attached.)


Yep. Thats our bug fixed version to be released soon. It will address some of the issues with antivirus engine.
Logged
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in -0 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com