Welcome, Guest. Please login or register.
Did you miss your activation email?
May 21, 2013, 12:09:39 AM

Login with username, password and session length

663313 Posts
70516 Topics
145179 Members

Latest Member: CynthiaPf

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  malicious website got past comodo today - (possible prevention method enclosed?)
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: malicious website got past comodo today - (possible prevention method enclosed?)  (Read 6741 times)
nalacknick
Comodo Loves me
****
Offline Offline

Posts: 166


« on: March 29, 2012, 04:00:16 PM »

Hi guys, this morning I had the fright of my life just by clicking onto a website via google. My gf and i were discussing baby names so I decided to do a google search on modern names for boys. I clicked on this one particular link form google (cant remember name) and as soon as i did I got lots and lots of windows trying to open. Comodo isolated a couple of .exes to the sandbox (restricted). I thought CIS had caught everything so carried on chatting with my gf on msn. I then happened to notice that the shortcut to msn had gone off my desktop along with various other programs inc' CCE. So I rebooted thinking all would be ok upon reboot. How wrong I was...most of my programs were still missing from the desktop. numerous folders were missing doc, vids, pics etc. internet explorer had lost all of my favourites. Windows security had been disabled and the clock was an hour fast. Also some of the programs that were left wouldn't open. I did a sys restore and most of my progs came back (although CCE couldn't connect to the internet to update so i imported from CIS did a scan and all was fine. I checked killswitch all safe. Opened quick repair and security center had been disabled so i repaired that. I did a scan with mbam all ok. Did a scan with TDSSKiller all ok. Rebooted and my folders were still missing. To cut a very long story short-ish Wink I did a google search and found a piece of software on bleeping computers.com called unhide.exe. I ran it and hey presto all my hidden folders/shortcuts were restored (after reboot). So here is the log of what the malware changed and my question is...can these lines be added to the protected registry keys without causing any problems??
Log here
Searching for Windows Registry changes made by FakeHDD rogues.
 - Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
  * NoActiveDesktopChanges policy was found and deleted!
 - Checking HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
 - Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  * Start_TrackDocs was set to 0! It was set back to 1!
Thx in advance
Nick

win7 sp1 64bit (IE8)
CIS 5.10 fully updated Config internet security -  sandbox  - enabled set to restricted AV stateful - FW safe - D+ safe
CCE (not open/running at the  time of infection)
MBAM (on demand)
TDSSKiller (on demand)
UAC disabled at the time (now enabled and put up with the popups + using Comodo dragon as default browser)
« Last Edit: March 29, 2012, 04:16:00 PM by nalacknick » Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #1 on: March 29, 2012, 04:21:28 PM »

what dns servers are you running? Also can you provide me with a link in a PM to the site so I can test when I get a chance?
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
nalacknick
Comodo Loves me
****
Offline Offline

Posts: 166


« Reply #2 on: March 29, 2012, 04:40:23 PM »

Hi languy99 - I'm just using the standard DNS servers as used by sky (but I'm thinking of changing to Comodo as of today (unless you know of any better ones?) I cant supply you with the link as I have cleaned my system  so no history remains. As mentioned i just did a search on google for popular boys names/ modern boys names and it was in the first half dozen links that appeared. Sorry I cant be any more specific than that. All I can say is that Comodo did clear the infection but couldn't stop the registry from being changed (maybe restricted sandbox isn't restricted enough??) Also it would be good if CIS or CCE could include these things to check/fix when doing a scan.
Logged
Kelvin12
Comodo Member
**
Offline Offline

Posts: 30


« Reply #3 on: March 29, 2012, 05:28:12 PM »

That does sound scary  Shocked
Maybe this is a D+ leak?
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3064



WWW
« Reply #4 on: March 29, 2012, 05:30:01 PM »

That does sound scary  Shocked
Maybe this is a D+ leak?

sounds more like a sandbox leak. If the sandbox was disabled im sure he would have gotten an alert from d+ and been able to block it. Since the sandbox is restriction based (rules) it is allowed to do certain things so it slipped through the crack. once the sandbox becomes virtualized stuff like this will not happen.
« Last Edit: March 29, 2012, 05:32:40 PM by wasgij6 » Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
Chiron
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5570



« Reply #5 on: March 29, 2012, 06:26:55 PM »

How to Stay Safe While Online
Logged

offchu
Comodo Loves me
****
Offline Offline

Posts: 139



WWW
« Reply #6 on: March 29, 2012, 10:36:27 PM »

Administrator account + UAC disabled = Bad idea

A:
That does sound scary  Shocked
Maybe this is a D+ leak?

Q:
UAC disabled at the time (now enabled and put up with the popups + using Comodo dragon as default browser)
Logged

wasgij6
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3064



WWW
« Reply #7 on: March 29, 2012, 11:02:19 PM »

Administrator account + UAC disabled = Bad idea

A:
Q:

this is how i run my computer and i havent had any infections or problems.
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
nalacknick
Comodo Loves me
****
Offline Offline

Posts: 166


« Reply #8 on: March 30, 2012, 02:16:44 AM »

yes I too think it was a sandbox leak...so is it ok to add the lines that were modified to the protected registry keys?

Searching for Windows Registry changes made by FakeHDD rogues.
 - Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
  * NoActiveDesktopChanges policy was found and deleted!
 - Checking HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
- Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced

  * Start_TrackDocs was set to 0! It was set back to 1!
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #9 on: March 30, 2012, 07:09:56 AM »

well in D+ there is this protection enabled that should cover the first two,

*\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\*

and there is also one for *\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\*

so D+ should have prompted you about these, how do you have D+ set up to work for you? Can you provide a screen shot for use of the settings tabs?
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
naren
Comodo's Hero
*****
Offline Offline

Posts: 3860


« Reply #10 on: March 30, 2012, 07:15:51 AM »

Did you checked the Trusted Lists? Anything there related to this malware?
Logged
pc_pete
Comodo's Hero
*****
Offline Offline

Posts: 358


No idea where this came from!


« Reply #11 on: March 30, 2012, 07:51:15 AM »

this is how i run my computer and i havent had any infections or problems.

I see this a lot, usually after someone calls me because some critical Windows file has been overwritten.
Absolutely no criticism intended, but I'm really intrigued as to why?
Logged
lyn
Comodo Loves me
****
Offline Offline

Posts: 188



« Reply #12 on: March 30, 2012, 10:26:11 AM »

How about surfing in the manual sandbox in future!
Logged
Siketa
Comodo's Hero
*****
Offline Offline

Posts: 3127


ZIG ZAG


« Reply #13 on: March 30, 2012, 10:56:23 AM »

What browser were you using?
Were there any particular browser add-on such as WOT installed?
Logged
Seany007
Comodo's Hero
*****
Offline Offline

Posts: 1891


Comodo Commando


« Reply #14 on: March 30, 2012, 10:59:05 AM »

Well I don't want to scare nobody but it happened to me as well today! Half of my pics missing! Wtf? All security is in MAX settings with UAC and sandbox enabled! None of the AV's detect nothing... System restore don't help!
Logged

Proud Comodo User (CIS, CD, CID and CMS)
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.056 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com