Sysservice.exe, run partially limited, causes protected files leak [V6][M398]

A. THE BUG/ISSUE (Varies from issue to issue)
[ol]- Summary - Give a clear summary in the topic subject, NOT here.

  • Can U reproduce the problem & if so how reliably?:

yes

  • If U can, exact steps to reproduce. If not, exactly what U did & what happened:

(1) I checked the protected objects.

It means "the sandboxed applications can not create any file under C:\WINDOWS "

(2) I ran the malware.

http://valkyrie.comodo.com/Result.html?sha1=c1c904f7c24057dfea2c64a38656cc310f36395a&&query=0&&filename=geloyun.exe

http://camas.comodo.com/cgi-bin/submit?file=34220f4abfe1a194b8ed3ac944b4a8bbb583e2573e58e8253542142e9acf6e56

(3) It was sandboxed as partially limited.

(4) logs:

2013-05-17 20:25:37 C:\Documents and Settings\All Users\Application Data\Shared Space\test.exe\geloyun.exe Sandboxed As Partially Limited

2013-05-17 20:25:39 C:\WINDOWS\SysService.exe Sandboxed As Partially Limited

2013-05-17 20:25:46 C:\Documents and Settings\All Users\Application Data\Shared Space\test.exe\geloyun.exe Modify Key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysService

2013-05-17 20:25:46 C:\Documents and Settings\All Users\Application Data\Shared Space\test.exe\geloyun.exe Modify File C:\WINDOWS\SysService.exe

(5) I checked the file.

The size of it is 0KB.

  • If not obvious, what U expected to happen:

Behavior Blocker should block the malware for creating the file.

  • If a software compatibility problem have U tried the conflict FAQ?:
  • Any software except CIS/OS involved? If so - name, & exact version:
  • Any other information, eg your guess at the cause, how U tried to fix it etc:
  • Always attach - Diagnostics file, Watch Activity process list, dump if freeze/crash. (If complex - CIS logs & config, screenshots, video, zipped program - not m’ware)
    [/ol]

B. YOUR SETUP (Likely the same for each issue, so you can copy forward)
[ol]- Exact CIS version & configuration:

version = 6.1 build 2813

configuration = internet security

  • Modules enabled & level. D+/HIPS, Autosandbox/BBlocker, Firewall, & AV:

HIPS=off, BBlocker=partially-limited, Firewall=Safe, AV=cloud is off

  • Have U made any other changes to the default config? (egs here.):

none

  • Have U updated (without uninstall) from a CIS 5?:

no

[li]if so, have U tried a a clean reinstall - if not please do?:
[/li]- Have U imported a config from a previous version of CIS:

no

[li]if so, have U tried a standard config - if not please do:
[/li]- OS version, SP, 32/64 bit, UAC setting, account type, V.Machine used:

Windows XP Pro, SP3, 32bit, UAC=off, admin, Real

  • Other security/s’box software a) currently installed b) installed since OS: a= b=

none
[/ol]

[attachment deleted by admin]

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Many thanks again.

Hi a256886572008,
Could you send this virus sample to me(jackwang(#)comodo{.}com)? We will analyze it.

Thanks again.

Can you please check and see if this is fixed with the newest version (6.2.282872.2847)? Please let us know whether it is fixed or you are still experiencing the problem.

Thank you.

PM sent.

Can you please check and see if this is fixed with the newest version (6.3.294583.2937)? Please let us know whether it is fixed or you are still experiencing the problem.

Thank you.

PM sent.

The devs have been unable to replicate this. Therefore, as there has been no response to the request for additional information, they have assumed that this is fixed for CIS version 7.0.313494.4115. I will therefore move this to Resolved.

If this is still not fixed for you please both respond to this topic and send me a PM (including a link to this bug report).

Thank you.