![]() |
|
#1
|
||||
|
||||
|
I tried this rootkit installer detected as Win32/TrojanClicker.Agent.BCI by NOD32 on VT( the only detection on VT for it). It installs a hiddden driver via windows installer, so I removed pre-defined rules for windows installer in CFP, marking it as untrusted. I used max paranoid settings.
Hope some one can confirm my findings. I allowed all pop up alerts. Here are my settings.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
Last edited by aigle : August 2nd, 2008 at 03:30 PM. |
|
#2
|
||||
|
||||
|
Here are the popups by CFP, no pop up about driver install/ loading though there is pop up about a new sys file craetion and services registry modification( probably showing ne service install but it must be more obvious like other HIPS). Even no popup alert about SCM access alert.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
Last edited by aigle : August 2nd, 2008 at 03:31 PM. |
|
#3
|
||||
|
||||
|
Alerts by EQS about driver install/ loading.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#4
|
||||
|
||||
|
They have repsponded to all other queries and in all cases it was a real bug, nothing wrong on my side.
Only this issue is not addressed so far and I am almost sure that again here it,s a bug in CFP.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#5
|
|||
|
|||
|
It is a bug of cfp, I just want it be fixed as soon as possible
|
|
#6
|
|||
|
|||
|
But if you block the new file creation, I suppose the driver gets blocked? But yes it should give the alert about driver loading anyway. I think the problem with CFP is that it´s giving way too many alerts, it should get smarter.
|
|
#7
|
|||
|
|||
|
For those who are interested,
I can personally confirm that DefenseWall v2.45 successfully blocks and contains install.exe's rootkit driver, dll's and malicious new program installation. I have attached both my DW events log and rollback list as proof. Peace & Gratitude, CogitoErgoSum
__________________
Current Vista 32 SP2 Resident Security Arsenal: (DefenseWall Personal Firewall v3.00 Beta - KeyScrambler Pro - Proxomitron) DefenseWall HIPS(http://www.softsphere.com/) *Loyal & diehard DefenseWall user since 1/06!* ~Living dangerously without a resident antivirus since late 2/07!~
|
|
#8
|
||||
|
||||
|
Code:
|
|
#9
|
|||
|
|||
|
Quote:
__________________
Windows 7 Ultimate 32-bit - UAC: Enabled - AppLocker: Disabled - Hardware-DEP: Enabled
Realtime: Norton Internet Security 2010 On-demand: Hitman Pro + Malwarebytes' Anti-Malware + Sandboxie Backup: Windows Backup |
|
#10
|
||||
|
||||
|
Code:
|
|
#11
|
||||
|
||||
|
Quote:
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#12
|
||||
|
||||
|
Just by looking at the pics you posted, isn't the path supposed instead to be something like HKLM\SYSTEM\ControlSet001\Services\ServiceName\ImagePath\msliksurserv.sys ?
Btw, I'm planning to try CFP with D+ soon. I haven't tested D+ since MANY months. Last edited by Alcyon : August 3rd, 2008 at 02:45 PM. |
|
#13
|
||||
|
||||
|
good job on these tests aigle, they should be paying you for all this work
quick question though, which eqsecure are you using? 3.41 or 4.0 beta?
__________________
Current Security Apps - Desktop/Laptop : SRP + LUA + KAFU, Antivir (free - on demand) LUA+SRP+KAFU = WIN!!!111 |
|
#14
|
||||
|
||||
|
I am guessing this isn't going to be fixed in CFP, but in CIS when it comes out in 3-4 weeks.
__________________
Kaspersky Internet Security 2009 Kaspersky Fan Club Kaspersky Lab Forum
|
|
#15
|
||||
|
||||
|
Quote:
I was using EQS 3.41.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#16
|
||||
|
||||
|
Quote:
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#17
|
||||
|
||||
|
Kudos to Eset. See.....
How did GW do against it.
__________________
Kaspersky Internet Suite |
|
#18
|
||||
|
||||
|
__________________
I ♥ SandboxIE
|
|
#19
|
||||
|
||||
|
Thanks for the testing!
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#20
|
|||
|
|||
|
Hi,
I´ve tested this malware on two VM´s and I got strange results. First of all both SSM Pro and NG pass the test. However, on one of my machine I saw the strangest thing, it looked like Windows Installer was sort of infected by this rootkit, because everytime I tried to launch a .msi file, it was trying to infect my machine with the msliksurserv.sys rootkit! So this means that if you didn´t pay any attention (and even if you did) you could end up infecting your system when executing a harmless app. I never saw this before, seems to be very advanced malware. Rootkit Unhooker also reported seeing stealth code on the system, it also detected a parasite inside itself. The question is how to stop this rootkit from modifying/infecting Win Installer, NG couldn´t do it, but I didn´t get to see this behavior when I tested SSM Pro. |
|
#21
|
||||
|
||||
|
Quote:
In any way system is not compromized at all. I hope that the minor issue will be fixed as it is being investigated.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|