Welcome, Guest. Please login or register.
Did you miss your activation email?
May 22, 2013, 06:59:58 AM

Login with username, password and session length

663542 Posts
70552 Topics
145211 Members

Latest Member: CWVO

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  bypass v5.10.228257.2253 (dll malware, QQ pass)
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: bypass v5.10.228257.2253 (dll malware, QQ pass)  (Read 8592 times)
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #15 on: May 16, 2012, 01:38:28 PM »

so from what I can tell this is what is happening, a trusted file is loading malware into memory and if the AV does not catching it, it would bypass. Is that what you are saying?
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
a256886572008
Star Group
Comodo's Hero
*****
Online Online

Posts: 781



« Reply #16 on: May 22, 2012, 12:58:53 AM »

another sample:



enlpu.dll (50.1MB)
https://valkyrie.comodo.com/Result.html?sha1=929f6b272fc399fb1abc06801d52e844685f83fd&&query=0&&filename=enlpu.rar

https://www.virustotal.com/file/b7bc60780855a01e1f81853a279b6b53fbe528e1a1f5ac931b95859e84a9ba9d/analysis/1337665988/

MSUpdates.exe
https://valkyrie.comodo.com/Result.html?sha1=f7f57137a029457f132ae63c1b41eac24ac21524&&query=0&&filename=msupdates.exe

https://www.virustotal.com/file/239eee98bbcc692f13bffb4d01eb5588b69c75c3e97587f428ca6042d53fb573/analysis/1337666274/

---------------------------------------------------

Quote
2012-05-22 15:14:22   C:\Documents and Settings\Roger\桌面\virus\WindowsUpdate\MSUpdates.exe   Sandboxed As   Partially Limited   

2012-05-22 15:14:24   C:\Documents and Settings\Roger\桌面\virus\WindowsUpdate\MSUpdates.exe   Modify Key   HKUS\S-1-5-21-1993962763-796845957-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable   

2012-05-22 15:14:24   C:\WINDOWS\Explorer.EXE   Sandboxed As   Partially Limited   

2012-05-22 15:14:25   c:\hds1.exe   Sandboxed As   Partially Limited   

2012-05-22 15:14:27   C:\WINDOWS\system32\conime.exe   Sandboxed As   Partially Limited   

2012-05-22 15:14:27   c:\hds2.exe   Sandboxed As   Partially Limited   

2012-05-22 15:14:30   c:\hds3.exe   Sandboxed As   Partially Limited   

2012-05-22 15:14:30   C:\Documents and Settings\Roger\桌面\virus\WindowsUpdate\MSUpdates.exe   Access Memory   C:\WINDOWS\explorer.exe   

2012-05-22 15:14:44   C:\WINDOWS\system32\userinit.exe   Modify Key   HKUS\S-1-5-21-1993962763-796845957-1801674531-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows\Device   

2012-05-22 15:14:52   C:\WINDOWS\system32\userinit.exe   Access COM Interface   \RPC Control\spoolss
 


« Last Edit: May 22, 2012, 02:30:42 AM by a256886572008 » Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #17 on: May 22, 2012, 07:41:12 AM »

turning security to proactive will stop that, in the stock internet security mode the firewall lets anything out basically.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
a256886572008
Star Group
Comodo's Hero
*****
Online Online

Posts: 781



« Reply #18 on: May 22, 2012, 07:47:16 AM »

turning security to proactive will stop that, in the stock internet security mode the firewall lets anything out basically.

Because CIS trusts the MSUpdates.exe, it was bypassed by the malware.
« Last Edit: May 22, 2012, 07:49:56 AM by a256886572008 » Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16695



« Reply #19 on: May 22, 2012, 08:04:22 AM »

MSUPdates.exe is not trusted as it gets sandboxed. Or did you sandbox if manually for testing or instruction purposes?
Logged

a256886572008
Star Group
Comodo's Hero
*****
Online Online

Posts: 781



« Reply #20 on: May 22, 2012, 08:13:21 AM »

MSUPdates.exe is not trusted as it gets sandboxed. Or did you sandbox if manually for testing or instruction purposes?

I add it to the list, "always sandbox"
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #21 on: May 22, 2012, 08:14:34 AM »

go to the firewall tab, firewall behavior settings and turn off "Do not show popup alerts" does it still have access while in the sandbox?
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
a256886572008
Star Group
Comodo's Hero
*****
Online Online

Posts: 781



« Reply #22 on: May 22, 2012, 08:34:24 AM »

go to the firewall tab, firewall behavior settings and turn off "Do not show popup alerts" does it still have access while in the sandbox?

1. The configuration was "CIS"

2.The firewall was in "safe mode"

3.So, there were no firewall alerts
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #23 on: May 22, 2012, 10:39:06 AM »

that is not what I asked you to check.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
a256886572008
Star Group
Comodo's Hero
*****
Online Online

Posts: 781



« Reply #24 on: May 30, 2012, 11:22:18 PM »

test the malware with DW:

1.DW trusts this file

"photo.exe"



2.DW untrusts another file

"MSDTCTM.dll"




3.The user double clicks on the photo.exe

4.result: DW untrusts the photo.exe

« Last Edit: May 30, 2012, 11:24:08 PM by a256886572008 » Logged
Tags:
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.049 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com