Wilders Security Forums  

Go Back   Wilders Security Forums > Security Software > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 2nd, 2008, 03:21 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Hmm... still another rootkit bypassing CFP?

I tried this rootkit installer detected as Win32/TrojanClicker.Agent.BCI by NOD32 on VT( the only detection on VT for it). It installs a hiddden driver via windows installer, so I removed pre-defined rules for windows installer in CFP, marking it as untrusted. I used max paranoid settings.

Hope some one can confirm my findings. I allowed all pop up alerts.

Here are my settings.

Name:  3.jpg
Views: 810
Size:  70.4 KB
Name:  4.jpg
Views: 809
Size:  73.8 KB
Name:  s.jpg
Views: 805
Size:  50.7 KB
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!

Last edited by aigle : August 2nd, 2008 at 03:30 PM.
  #2  
Old August 2nd, 2008, 03:23 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Re: Hmm... still another rootkit bypassing CFP?

Here are the popups by CFP, no pop up about driver install/ loading though there is pop up about a new sys file craetion and services registry modification( probably showing ne service install but it must be more obvious like other HIPS). Even no popup alert about SCM access alert.

Name:  1.jpg
Views: 800
Size:  49.8 KB Name:  2.jpg
Views: 801
Size:  57.6 KB
Name:  5.jpg
Views: 799
Size:  61.6 KB Name:  6.jpg
Views: 798
Size:  59.8 KB
Name:  7.jpg
Views: 798
Size:  43.4 KB
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!

Last edited by aigle : August 2nd, 2008 at 03:31 PM.
  #3  
Old August 2nd, 2008, 03:24 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Re: Hmm... still another rootkit bypassing CFP?

Alerts by EQS about driver install/ loading.
Attached Images
  
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #4  
Old August 3rd, 2008, 07:34 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Re: Hmm... still another rootkit bypassing CFP?

They have repsponded to all other queries and in all cases it was a real bug, nothing wrong on my side.

Only this issue is not addressed so far and I am almost sure that again here it,s a bug in CFP.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #5  
Old August 3rd, 2008, 08:57 AM
baerzake baerzake is offline
Infrequent Poster
 
Join Date: Aug 2007
Posts: 42
Default Re: Hmm... still another rootkit bypassing CFP?

It is a bug of cfp, I just want it be fixed as soon as possible
  #6  
Old August 3rd, 2008, 10:16 AM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,838
Default Re: Hmm... still another rootkit bypassing CFP?

But if you block the new file creation, I suppose the driver gets blocked? But yes it should give the alert about driver loading anyway. I think the problem with CFP is that it´s giving way too many alerts, it should get smarter.
  #7  
Old August 3rd, 2008, 12:50 PM
CogitoErgoSum CogitoErgoSum is offline
Frequent Poster
 
Join Date: Aug 2005
Location: Cerritos, California
Posts: 637
Default Re: Hmm... still another rootkit bypassing CFP?

For those who are interested,

I can personally confirm that DefenseWall v2.45 successfully blocks and contains install.exe's rootkit driver, dll's and malicious new program installation. I have attached both my DW events log and rollback list as proof.


Peace & Gratitude,

CogitoErgoSum
Attached Files
File Type: txt DWEventsLog.txt (2.1 KB, 29 views)
File Type: txt DWRollbackList.txt (2.6 KB, 20 views)
__________________
Current Vista 32 SP2 Resident Security Arsenal: (DefenseWall Personal Firewall v3.00 Beta - KeyScrambler Pro - Proxomitron)

DefenseWall HIPS(http://www.softsphere.com/)

*Loyal & diehard DefenseWall user since 1/06!*
~Living dangerously without a resident antivirus since late 2/07!~
  #8  
Old August 3rd, 2008, 01:15 PM
Alcyon's Avatar
Alcyon Alcyon is offline
Frequent Poster
 
Join Date: Jan 2008
Location: Earth
Posts: 363
Default Re: Hmm... still another rootkit bypassing CFP?

Code:
HKLM\SYSTEM\ControlSet001\Services\msliksurserv.sys
There's something wrong with the registry path.
__________________
~ϡ Win7 / Avira Antivir / Proxomitron / A² / W7FC / LUA / WRT54G ϡ~
  #9  
Old August 3rd, 2008, 01:25 PM
ambient_88 ambient_88 is offline
Frequent Poster
 
Join Date: Jun 2008
Location: Redmond, Washington
Posts: 789
Default Re: Hmm... still another rootkit bypassing CFP?

Quote:
Originally Posted by Alcyon
Code:
HKLM\SYSTEM\ControlSet001\Services\msliksurserv.sys
There's something wrong with the registry path.
What's wrong with it?
__________________
Windows 7 Ultimate 32-bit - UAC: Enabled - AppLocker: Disabled - Hardware-DEP: Enabled

Realtime: Norton Internet Security 2010
On-demand:
Hitman Pro + Malwarebytes' Anti-Malware + Sandboxie
Backup: Windows Backup
  #10  
Old August 3rd, 2008, 01:36 PM
Alcyon's Avatar
Alcyon Alcyon is offline
Frequent Poster
 
Join Date: Jan 2008
Location: Earth
Posts: 363
Default Re: Hmm... still another rootkit bypassing CFP?

Code:
HKLM\SYSTEM\ControlSet001\Services\(?..)\msliksurserv.sys
Unless this is intentional!
__________________
~ϡ Win7 / Avira Antivir / Proxomitron / A² / W7FC / LUA / WRT54G ϡ~
  #11  
Old August 3rd, 2008, 01:56 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Re: Hmm... still another rootkit bypassing CFP?

Quote:
Originally Posted by Alcyon
Code:
HKLM\SYSTEM\ControlSet001\Services\(?..)\msliksurserv.sys
Unless this is intentional!
From where u took the two paths?
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #12  
Old August 3rd, 2008, 02:18 PM
Alcyon's Avatar
Alcyon Alcyon is offline
Frequent Poster
 
Join Date: Jan 2008
Location: Earth
Posts: 363
Default Re: Hmm... still another rootkit bypassing CFP?

Just by looking at the pics you posted, isn't the path supposed instead to be something like HKLM\SYSTEM\ControlSet001\Services\ServiceName\ImagePath\msliksurserv.sys ?

Btw, I'm planning to try CFP with D+ soon. I haven't tested D+ since MANY months.
__________________
~ϡ Win7 / Avira Antivir / Proxomitron / A² / W7FC / LUA / WRT54G ϡ~

Last edited by Alcyon : August 3rd, 2008 at 02:45 PM.
  #13  
Old August 3rd, 2008, 02:46 PM
zopzop's Avatar
zopzop zopzop is offline
Frequent Poster
 
Join Date: Apr 2006
Posts: 565
Default Re: Hmm... still another rootkit bypassing CFP?

good job on these tests aigle, they should be paying you for all this work

quick question though, which eqsecure are you using? 3.41 or 4.0 beta?
__________________
Current Security Apps -
Desktop/Laptop : SRP + LUA + KAFU, Antivir (free - on demand)

LUA+SRP+KAFU = WIN!!!111
  #14  
Old August 3rd, 2008, 04:20 PM
Coolio10's Avatar
Coolio10 Coolio10 is offline
Very Frequent Poster
 
Join Date: Sep 2006
Posts: 1,066
Default Re: Hmm... still another rootkit bypassing CFP?

I am guessing this isn't going to be fixed in CFP, but in CIS when it comes out in 3-4 weeks.
  #15  
Old August 3rd, 2008, 06:16 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Re: Hmm... still another rootkit bypassing CFP?

Quote:
Originally Posted by zopzop
good job on these tests aigle, they should be paying you for all this work

quick question though, which eqsecure are you using? 3.41 or 4.0 beta?
Thanks zopzop.

I was using EQS 3.41.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #16  
Old August 3rd, 2008, 06:18 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Re: Hmm... still another rootkit bypassing CFP?

Quote:
Originally Posted by Alcyon
Just by looking at the pics you posted, isn't the path supposed instead to be something like HKLM\SYSTEM\ControlSet001\Services\ServiceName\ImagePath\msliksurserv.sys ?

Btw, I'm planning to try CFP with D+ soon. I haven't tested D+ since MANY months.
Hmmm... I think only Comodo people can tell about this.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #17  
Old August 3rd, 2008, 07:23 PM
trjam's Avatar
trjam trjam is offline
Massive Poster
 
Join Date: Aug 2006
Location: North Carolina USA
Posts: 5,784
Default Re: Hmm... still another rootkit bypassing CFP?

Kudos to Eset. See.....

How did GW do against it.
__________________
Kaspersky Internet Suite
  #18  
Old August 4th, 2008, 11:41 AM
HURST's Avatar
HURST HURST is offline
Very Frequent Poster
 
Join Date: Jul 2007
Posts: 1,420
Default Re: Hmm... still another rootkit bypassing CFP?

Just tested SBIE 3.28 against it.
Rootkit safely contained in the sandbox.
Click image for larger version

Name:	sbie.JPG
Views:	9
Size:	100.8 KB
ID:	201964
__________________
I SandboxIE
  #19  
Old August 4th, 2008, 01:47 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Re: Hmm... still another rootkit bypassing CFP?

Thanks for the testing!
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #20  
Old August 5th, 2008, 11:56 AM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,838
Default Re: Hmm... still another rootkit bypassing CFP?

Hi,

I´ve tested this malware on two VM´s and I got strange results. First of all both SSM Pro and NG pass the test. However, on one of my machine I saw the strangest thing, it looked like Windows Installer was sort of infected by this rootkit, because everytime I tried to launch a .msi file, it was trying to infect my machine with the msliksurserv.sys rootkit!

So this means that if you didn´t pay any attention (and even if you did) you could end up infecting your system when executing a harmless app. I never saw this before, seems to be very advanced malware. Rootkit Unhooker also reported seeing stealth code on the system, it also detected a parasite inside itself. The question is how to stop this rootkit from modifying/infecting Win Installer, NG couldn´t do it, but I didn´t get to see this behavior when I tested SSM Pro.
  #21  
Old August 5th, 2008, 06:11 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,051
Default Re: Hmm... still another rootkit bypassing CFP?

Quote:
Originally Posted by trjam
How did GW do against it.
GW stops it but ATM there is a small problem. U mighht fail to launch trusted applications untill u reboot or kill the malware process manually.

In any way system is not compromized at all. I hope that the minor issue will be fixed as it is being investigated.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
 

Wilders Security Forums > Security Software > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 12:23 PM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums