Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 18, 2013, 06:59:40 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668792
Posts
71123
Topics
145727
Members
Latest Member:
Thomas Murray
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Virus/Malware Removal Assistance
Network Worm Signs, Identification, Protection, and Removal
« previous
next »
Pages:
[
1
]
Author
Topic: Network Worm Signs, Identification, Protection, and Removal (Read 2073 times)
NetFX
Newbie
Offline
Posts: 1
Network Worm Signs, Identification, Protection, and Removal
«
on:
June 05, 2012, 06:48:26 AM »
Hello, this is my first post on the forum, just like to take the time to say.., CIS is Amazing software absolutely first rate. To the business of this post....
I have been monitoring high volumes of intrusion attempts from hackers, ranging from man-in-the-middle attacks (ARP Poisoning) and mySQL injections to full on virus, trojans, and network worms. I have reported it to service providers but alas I fear I may not be catching everything that has snaked its way into the LAN.
Overview: System Specs: Windows 7 Ultimate x64 Edition x 3 PC's on a Bridged Router/Modem combo. Disabled the vast majority of services that are un-required not needed as well as adjusting Local Security Policies as best I can, without sacrificing user capability.
Currently I have been availing myself of CIS Defense+ and have identified numerous PID's as well as Ports that i believe maybe related to an as yet uncharted Network Worm. CIS Defense only caught bits of it as I was deleting partitions it flagged several .exe's in the D:\$recycle.bin\(Reg Key#'s\$idepius.exe. (Or something similar.) After doing some research online I turned off system restore. But am still seeing some sort of XML activity suggesting local security settings and restricted registry entries are being modified along with control sets for applications showing up in common files folder, temp folders application data folders and system32 folder.
I have also been monitoring large amounts of Protected COM access, system certificate modifications, and many many other suspect process's that I do not initialize nor necessarily can stop. I have successfully stealth-ed my ports, but have some lingering questions. (Please keep in mind I have Formatted and Re-Installed my OS.)
Much of the outgoing traffic being monitored is svchost.exe but mulitple PID's on ports 80,443,1900,5000,5355 and more... Is there a way to utilize CIS Defense to filter multiple PID's of the same .exe??? When I add the svchost.exe from the running process list it will not add another, or is it sufficient to simply add more rules restrictions and parameters to the same PID? (This does not seem to work might just be me.)
Also I have noticed regardless of the global rules added to the firewall security policies and defense settings are being circumvented through RPCSS and Protected COM interfaces and API even a fake CIS update and windows update have been attempted here.) So is there a means of refining restrictions to these services through use of the DCOM SDDL Syntax?? If so can someone point me to a reference manual or guide on how to set these settings effectively?
Also I have seen a rather huge amount of Multi-Cast Address's sending and receiving packet information, Again I require guidance as how to most effectively adjust CIS to filter the undesirable address's leaving only what is absolutely essential. (A guide or refrence, rule of thumb, or any other suggestion that someone has for similar issues would be of great use. Currently I have flat out blocked ICMP, IGMP, GRE etc. But understand I am blocking some legitimate packets as well.)
I also suspect ngen has left vulnerabilities in such environments exposed to such attacks, as my hardware precludes the use of the TPM, bitlocker is not an option for me. Are there any other resources I might avail myself of that are similar?
I have found the vast majority of attacks that I have been suffering from stem from online gaming services, where the admins are misusing there authority to gain access and infect PC's. It is also suspect that partially due to holes in the monitoring of dedicated hosts using newer cloud computing resources have left vulnerabilities that make people susceptible to such attacks.
At any rate I shall leave it there for now as I have many more questions and would love some feedback on any of these topics. Thank you for your time and apologies for the length of this post.
Logged
jay2007tech
Malware Research Group
Global Moderator
Comodo's Hero
Offline
Posts: 1840
Re: Network Worm Signs, Identification, Protection, and Removal
«
Reply #1 on:
June 11, 2012, 03:54:39 AM »
1) You can switch to a more secure dns then the ones your ISP provides
https://www.comodo.com/secure-dns/
Quote
Is there a way to utilize CIS Defense to filter multiple PID's of the same .exe??? When I add the svchost.exe from the running process list it will not add another, or is it sufficient to simply add more rules restrictions and parameters to the same PID? (This does not seem to work might just be me.)
https://forums.comodo.com/news-announcements-feedback-cce/comodo-cleaning-essentials-24225190192-released-t82013.0.html
You can inspect it with cce
Quote
I require guidance as how to most effectively adjust CIS to filter the undesirable address's leaving only what is absolutely essential.
http://www.peerblock.com/
That should be a good start
Quote
I have found the vast majority of attacks that I have been suffering from stem from online gaming services, where the admins are misusing there authority to gain access and infect PC's
Are the gaming servers official ones?? If not, there's not much you can do because they have been given access.
If you want to block ip address ranges
Click on "firewall"
Click on "Network Security Policy"
Click on "Global Rules"
«
Last Edit: June 11, 2012, 03:56:54 AM by jay2007tech
»
Logged
It's hard being a crooked Admin when the files won't pass an md5checksum test. But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.039 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com