Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 18, 2013, 05:34:22 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
662896
Posts
70571
Topics
145144
Members
Latest Member:
lodec
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
bypass v5.10.228257.2253 (dll malware, QQ pass)
« previous
next »
Pages:
[
1
]
2
Author
Topic: bypass v5.10.228257.2253 (dll malware, QQ pass) (Read 8564 times)
a256886572008
Star Group
Comodo's Hero
Online
Posts: 778
bypass v5.10.228257.2253 (dll malware, QQ pass)
«
on:
May 11, 2012, 09:20:58 AM »
1. I double click on the photo.exe.
It can terminate the existing process of QQ IM software.
2.Then, I restart QQ IM and type some words on the window of it.
The photo.exe can connect to the internet.
3.comodo trusts the photo.exe which is injected with the MSDTCTM.dll.
4.The malware creates an autorun entry.
5.environment:
Windows XP SP3 32bit
«
Last Edit: May 11, 2012, 06:36:54 PM by a256886572008
»
Logged
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3944
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #1 on:
May 11, 2012, 09:40:29 AM »
do you have a virustotal of the photo.exe
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
a256886572008
Star Group
Comodo's Hero
Online
Posts: 778
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #2 on:
May 11, 2012, 09:56:36 AM »
MSDTCTM.dll
https://www.virustotal.com/file/4581626dab4a6d00acdc5e98625eb623b281252a4fc5df960ffb214069a011f2/analysis/
https://valkyrie.comodo.com/Result.html?sha1=9c681206752576e9a4a37ade967c4e2c0111105d&&query=1&&filename=msdtctm.dll
photo.exe
https://www.virustotal.com/file/9d35d265a684e67268f63ba245f2c5d4cfec31178743e42153a7b5f967d0fff0/analysis/
https://valkyrie.comodo.com/Result.html?sha1=44e0e5af367432eeacfc1257083bf8605229fed0&&query=1&&filename=photo.exe
«
Last Edit: May 11, 2012, 10:05:05 AM by a256886572008
»
Logged
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3944
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #3 on:
May 11, 2012, 11:05:05 AM »
can you open up kill switch and show me the active processes and then show me the associated dll's with the photo.exe and QQ?
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
Ionel
Comodo Staff
Comodo's Hero
Offline
Posts: 667
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #4 on:
May 11, 2012, 11:30:20 AM »
Quote from: a256886572008 on May 11, 2012, 09:20:58 AM
1. I double click on the photo.exe.
It can terminate the existing process of QQ IM software.
2.Then, I restart QQ IM and type some words on the window of it.
The photo.exe can connect to the internet.
3.comodo trusts the photo.exe which is injected with the MSDTCTM.dll.
4.environment:
Windows XP SP3 32bit
Hi a256886572008,
We are looking into this issue and provide a fix as soon as possible.
Thank you for reporting it!
Regards,
Ionel
Logged
a256886572008
Star Group
Comodo's Hero
Online
Posts: 778
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #5 on:
May 11, 2012, 11:37:14 AM »
1.
2.The malware puts a transparent window on the window of QQ IM.
So, it can connect to the internet, after the user types some words on that.
«
Last Edit: May 11, 2012, 06:07:00 PM by a256886572008
»
Logged
Hause
Comodo's Hero
Offline
Posts: 962
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #6 on:
May 12, 2012, 04:31:03 AM »
Quote from: Ionel on May 11, 2012, 11:30:20 AM
We are looking into this issue and provide a fix as soon as possible.
Thank you for reporting it!
Regards,
Ionel
Аlmost half a year has passed since the first reports of this problem.
https://forums.comodo.com/news-announcements-feedback-cis/allegation-of-comodo-defence-plus-byapssed-by-zeroaccess-rootkit-t79079.0.html
Seems will have to wait another six months, up to version CIS 6...
Logged
fake5
Comodo Loves me
Offline
Posts: 101
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #7 on:
May 12, 2012, 04:39:45 AM »
Quote from: Ionel on May 11, 2012, 11:30:20 AM
Hi a256886572008,
We are looking into this issue and provide a fix as soon as possible.
Thank you for reporting it!
Regards,
Ionel
plz fix it as soon as possible, thx!
Logged
Seany007
Comodo's Hero
Offline
Posts: 1884
Comodo Commando
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #8 on:
May 12, 2012, 08:52:13 AM »
Quote from: Hause on May 12, 2012, 04:31:03 AM
Аlmost half a year has passed since the first reports of this problem.
https://forums.comodo.com/news-announcements-feedback-cis/allegation-of-comodo-defence-plus-byapssed-by-zeroaccess-rootkit-t79079.0.html
Seems will have to wait another six months, up to version CIS 6...
Oh well... The chances of you walking into such malware is low same as ransom...
Logged
Proud Comodo User (CIS, CD, CID and CMS)
OmeletGuy
Back for a while.
Global Moderator
Comodo's Hero
Offline
Posts: 2905
Dragon Theme Maker
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #9 on:
May 12, 2012, 06:03:05 PM »
Current CIS can likely be made to stop this with D+ rules... will it cut into compatibility and stability? maybe.
Logged
Comodo Dragon themes, including windows Aero options. Download
Here
System Details: W7-64bit | 4GB DDR2 | Intel Core 2 Extreme X6800 | CIS 5.10 | Geforce 560 GTX 1
a256886572008
Star Group
Comodo's Hero
Online
Posts: 778
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #10 on:
May 13, 2012, 10:24:36 AM »
Automatically sandbox process whose modules contain unrecognized files ?
Logged
OmeletGuy
Back for a while.
Global Moderator
Comodo's Hero
Offline
Posts: 2905
Dragon Theme Maker
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #11 on:
May 13, 2012, 10:41:40 AM »
Quote from: a256886572008 on May 13, 2012, 10:24:36 AM
Automatically sandbox process whose modules contain unrecognized files ?
Well maybe not like that with the current version thats more 6.0. I mean I could make a custom rule for Photo.exe to prevent it from getting infected.
Logged
Comodo Dragon themes, including windows Aero options. Download
Here
System Details: W7-64bit | 4GB DDR2 | Intel Core 2 Extreme X6800 | CIS 5.10 | Geforce 560 GTX 1
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1795
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #12 on:
May 13, 2012, 02:55:27 PM »
In Defence+, Would changing from "partially limited" to "limited" solve this?
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
a256886572008
Star Group
Comodo's Hero
Online
Posts: 778
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #13 on:
May 13, 2012, 11:37:59 PM »
Quote from: jay2007tech on May 13, 2012, 02:55:27 PM
In Defence+, Would changing from "partially limited" to "limited" solve this?
comodo would still trust the malware.
Logged
pykko
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 517
Re: bypass v5.10.228257.2253 (dll malware, QQ pass)
«
Reply #14 on:
May 16, 2012, 12:38:57 PM »
This is a very serious issue. Is any Deve looking into it ?
Logged
IT Security blog
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.097 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com