Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
July 25, 2008, 02:32:41 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
177036
Posts
20932
Topics
50752
Members
Latest Member:
morgen
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Anti-Viruspyware (CAVS)
Virus/Malware Removal Assistance
An exploit that defies detection
« previous
next »
Pages:
[
1
]
Author
Topic: An exploit that defies detection (Read 2006 times)
czl
Newbie
Offline
Posts: 11
An exploit that defies detection
«
on:
February 12, 2008, 12:41:52 AM »
My computer has been infested by something that no software can detect up to now. In spite of using all manners of protection from firewalls to malware / spyware detectors something has been loaded on my machine that I can't get rid of. How do I know? here are the cluses.
1. When the computer boots up, it claims to be loading from CD. (Untrue, there is no media in the drive.
2. The DVD drive activity light remains constantly on.
3. Disconnecting the DVD drive leads to a failure to boot at the BIOS level.
4. Replacing the DVD drive with another unit also leads to boot failure.
5. After draining then flashing the BIOS there is a "Wide Area Protection" warning from the BIOS on the first re-boot, but the computer starts normally as long as the original hard drive, and DVD drive are installed.
A change in any of the above leads to a boot failure.
6. Low level formatting the drive does not improve the situation either.
7. The TCP View utility from Sysinternals used to indicate both the local address and the remote address of any online communication. It now indicates both local and remote arresses as ports on my computer, and seems unable to see beyond, seemingly as in a "man in the middle" exploit.
To date I tried Microsoft's Malicious Software Removal Tool, Fix-It utilities (Trend Micro) Spyware Doctor, BOClean, various rootkit detectors,
nothing has any effect on this. By the way I managed to transfer the problem to a second computer via a USB device I used to transfer files.
If anyone has any ideas, I would sure like to hear from you.
Laz
Logged
MorphOS REBOL
Comodo's Hero
Offline
Posts: 742
Re: An exploit that defies detection
«
Reply #1 on:
February 12, 2008, 03:53:45 PM »
Buy a new PC, install Linux will help.
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Online
Posts: 5081
Re: An exploit that defies detection
«
Reply #2 on:
February 12, 2008, 04:41:27 PM »
Another evidence of my point of the inadequacies of Detection technologies !
The best thing is to re-install OS I am afraid
Once u have re-installed, then install v3 Comodo Firewall.
thanks
Melih
Logged
Melih's Blog
Pedro*
Comodo's Hero
Offline
Posts: 770
Former "Someone"
Re: An exploit that defies detection
«
Reply #3 on:
February 12, 2008, 05:35:24 PM »
Try to get professional help. I would, and probably sooner or later from the HW manufacturer.
Try a forum that analyses HijackThis logs first, one that has the best expertise of not only malware, but hardware also. I never used one, but i can try and find out some of the most reputable if you wish.
Logged
sded
Global Moderator
Comodo's Hero
Online
Posts: 1786
Re: An exploit that defies detection
«
Reply #4 on:
February 12, 2008, 05:40:03 PM »
One place to try posting would be the security forum at
http://www.dslreports.com
. Lots of MVPs and such provide help there.
Logged
CFP 3.0.24/368, Vista Ultimate 32x + SP1, Avast! 4.8, Windows Defender. SAS offline. Acronis True Image just in case.
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3008
Sometimes words are meaningless indeed...
Re: An exploit that defies detection
«
Reply #5 on:
February 12, 2008, 05:52:41 PM »
I guess you got a series of issues or a faulty hardware.
Sometime removing a dvd dive will cause an issue if the bios drive autodetection is disabled (may not apply to every brand).
Another thing to check is your DVD cable. Change it with a new one to see if you got a bad cable.
Remove any dust you see in your case using an air compressor. Dust can cause all kinds of issues.
If your DVD behave strangely before windows boot don't bother to load your OS.
Pay attention to cable orientation if your ide connectors don't have forced insertion connectors.
Even if there is only a remote chance consider a faulty ide controller to cause this issue. I guess that damaged ata cables could make this chance a reality.
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
czl
Newbie
Offline
Posts: 11
Re: An exploit that defies detection
«
Reply #6 on:
February 12, 2008, 09:29:34 PM »
Thank you all for the suggestions. I'm beginning to think Ubuntu will be the solution. The computer runs just fine, it isn't a hardware issue, although BIOS, firmware, and HD MBR's have been compromised. I can't blame Comodo Firewall, I am using version 3, and it just updated today. This thing
must have installed itself via a script from some web page I visited, somewhere around Jan 29 this year. I have been fighting with it ever since.
The machine works fine for routine stuff , but I can't trust it for communications with the outside. I'll have one more run at it with a new DVD drive, HD, and freshly flashed BIOS. I can't think where else this thing could have set root.
Logged
czl
Newbie
Offline
Posts: 11
Re: An exploit that defies detection
«
Reply #7 on:
February 12, 2008, 09:39:58 PM »
Quote from: Melih on February 12, 2008, 04:41:27 PM
Another evidence of my point of the inadequacies of Detection technologies !
The best thing is to re-install OS I am afraid
Once u have re-installed, then install v3 Comodo Firewall.
thanks
Melih
I would love to do that, but I'm afraid there is now a hidden partition on the HD, that I can't remove. Low level formatting doesn't touch it, so I'd end up with the same conditions after a system re-installation. There used to be a way to do a low, low level format using DEBUG in DOS, unfortunately I don't remember it any more.
Thanks for your interest Laz
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 485
Re: An exploit that defies detection
«
Reply #8 on:
February 13, 2008, 10:23:28 PM »
Certainly a strange set of symptoms.When you say low level formatting made no difference,how exactly was this done? If you used a boot util such as DBAN then NOTHING should remain on that drive and therefore that would include any malware.Any form of 'normal' formatting might not delete malware if it made changes to the file structure of the drive.
The most perplexing thing about your issue,is the fact that it'll only boot up with the original dvd drive installed,it's a new one on me for sure.The whole idea of your system being infected by a so-called malware hypervisor is in the realms of proof of concept rather than current threats in the wild.
The best way to be certain that the hard drive hasn't been affected by malware,or hidden partitions created would be to scan it from a boot cd such as UBCD4Win and run one of the disk utils on that.If you want to be 100% certain that the drive is clean,I suggest sticking it into another system and running DBAN,nothing will survive that!!
http://dban.sourceforge.net/
«
Last Edit: February 13, 2008, 10:26:24 PM by andyman35
»
Logged
MrSurfTurf
Comodo Family Member
Offline
Posts: 60
Re: An exploit that defies detection
«
Reply #9 on:
April 01, 2008, 03:18:25 PM »
Quote from: sded on February 12, 2008, 05:40:03 PM
One place to try posting would be the security forum at
http://www.dslreports.com
. Lots of MVPs and such provide help there.
Worthless search function. Can't search for anything on that site.
Logged
3xist
Guest
Re: An exploit that defies detection
«
Reply #10 on:
May 31, 2008, 11:48:02 PM »
Topic Locked.
Reason: Out-Dated post.
Josh
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.117 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com