Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 29th, 2010, 12:44 PM
taleblou taleblou is offline
Frequent Poster
 
Join Date: Jan 2010
Posts: 302
Thumbs down a TDL rootkit passed through time freeze

Hi:
I am disappointed at time freeze. I got it on the free giveaway and it failed for me to protect the pc I used it from malwares (eventhough I used optimum setting). I had to format to be sure all is clean and back to the shadow defender on that pc. In my openion time freeze is not worth it. I got infected with a TDL rootkit that passed through time freeze and deeply infected my windows xp sp2 pc.

P.S. I got infected with the malware also in my test pc with time freeze on and using malwaredomainlist malwares. It seems only rootkits made through??
  #2  
Old June 29th, 2010, 01:53 PM
Leach Leach is offline
Regular Poster
 
Join Date: May 2010
Posts: 84
Default Re: Wondershare Time Freeze - Giveaway

taleblou,

Thanks for warnings although I made a massive amount of tests since I installed it including malwarebytes domains. Possibly I haven't got the malware which could pass through WTF but any program can be bypassed sooner or later, Shadow Defender is not an exсeption, have a look at Deep Freeze thread. I would still use Shadow Defender but at the time I tested Defense Wall it had a conflict with SD - sporadic slowdowns on startup. WTF can make drives ReadOnly, a possibility which I find very usefull and haven't seen free. It suits me quite well - I use a clone of a real system more often than a fresh and clean VM installation. Besides it won't slow down the system at all which happens when you use VM or sandbox. Haven't seen any signs of vulnerabilities but I'll have a closer look into it.

Last edited by Leach : June 29th, 2010 at 02:07 PM.
  #3  
Old June 29th, 2010, 03:52 PM
taleblou taleblou is offline
Frequent Poster
 
Join Date: Jan 2010
Posts: 302
Default Re: Wondershare Time Freeze - Giveaway

Hi:

Yeah I was shocked too. From all the positive reading I done and demos I seen I thought time-freeze was bullet proof and even has boot protection feature but I was surprised when I got infected and I only noticed it when I ran hitman pro 305 and it was the only one out of the 5 antimalware programs I used to scan that detected the TDL rootkit. By the way before installing the time freze I had scanned the pc with all 5 anti-mlawares incl. hitman pro and all was clean. Therefore the infection happened after time freeze was protecting.

If you want to test time freeze I suggest try malwaredomainlist links, specialy the TDL rootkits and see for yourself.

By the 5 anti-malwares I use for scanning are: a-square free, malwarebyte, superantispyware, hitman pro, Comodo.

P.S. I have e-mailed wondershare about this and waiting for their reply.
  #4  
Old June 30th, 2010, 09:36 AM
Leach Leach is offline
Regular Poster
 
Join Date: May 2010
Posts: 84
Default Re: Wondershare Time Freeze - Giveaway

Hi taleblou,

Made some research and got interesting results about TDSS TDL you mentioned. I got a bunch of critters of the TDSS serie
and tried them against Time Freeze v1.0.0.1 and then against Shadow Defender v1.1.0.325, both are configured to
reset the original state of the OS after reboot. XP sp3 x32 has been used installed on VirtualPC, the latest updates
applied. To check if the system is infected or not I used a special utility TDSSKiller by Kaspersky Lab. No antivirus were
installed, only shadowing systems and Delfi 7 with some libs.

The procedure is rather simple -
a) The system is checked with TDSSKiller and shadow mode is turned on
b) Samples are launched directly from the desktop one at a time to avoid "self false positive detection" of a rootkit and
thus refusing to install. Smart viruses are checking their presence in a system before trying to infect it.
c) After a short downtime the system is rebooted and checked with TDSSKiller again after a short downtime. A delay
is needed to let the rootkit initialize / start normally after reboot because some versions use a short delay after system
restart before initialising to avoid detection by anti-rootkit programs.

I have tested it twice to be sure and the results are identical. The fact is this sample of TDSS trojan is detected by AV
programs, two of them I used at least - MBAM and SuperAntiSpyware. You were right - WTF has been compromised,
and so was I - Shadow Defender is not an exception. The second sample has bypassed Time Freeze as well as Shadow
Defender later. In both cases the OS has been infected with a rootkit after reboot and the shadowing systems supposedly
cleaned OS.
Here are some screen shots:

Name:  MBAM_state.jpg
Views: 3311
Size:  13.8 KB

Name:  InitialState.jpg
Views: 3310
Size:  29.7 KB

Name:  WTF_infected.jpg
Views: 3308
Size:  59.9 KB

Name:  SD_infected.jpg
Views: 3310
Size:  59.4 KB

Mods, Sorry, I didn't expect such a mess. Can it be cured?

Last edited by LowWaterMark : June 30th, 2010 at 06:41 PM. Reason: adjusted display of screenshots
  #5  
Old June 30th, 2010, 11:51 AM
taleblou taleblou is offline
Frequent Poster
 
Join Date: Jan 2010
Posts: 302
Smile Re: Wondershare Time Freeze - Giveaway

Hi;
Thanks for the test. I appreciate it. ALso can you test comodo time machine and returnil against these tdss tdk rootkits and please let me know if they pass the test or not. Please tell me so if any of them passes the test then I will use that software for protection. Thanks in advance.

Looking forward to your test result on comodo time-machine and returnil.
  #6  
Old June 30th, 2010, 05:29 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Wondershare Time Freeze - Giveaway

Hi Leach, what version of ShadowDefender were you using and what is the md5 or sha1 hash of the tdl/tdss (dogma.exe) you were using, thanks.

latest
md5 : 55A16DB3018A69A7D27F0DEAF632273F
sha-1 : 1B1B5AF63CB048FCF47BDCE96CCFEA1301034137
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld

Last edited by Meriadoc : June 30th, 2010 at 10:11 PM.
  #7  
Old June 30th, 2010, 08:03 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Thumbs up Re: TDL/TDSS trojan series bypassing isolation software

Well i tried to get a new thread going MBR bypass thread http://www.wilderssecurity.com/showthread.php?t=276136 as i felt it would be useful in many ways.

As you can see it's been locked rather early on But the reasons for that, and why this one has been started in it's place, have been explained to me, and i understand and agree

So we're good to go
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #8  
Old June 30th, 2010, 08:50 PM
Serapis Serapis is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 241
Default Re: TDL/TDSS trojan series bypassing isolation software

How does Cleanslate 6.5 fare against these rootkits?
  #9  
Old June 30th, 2010, 09:50 PM
Kid Shamrock's Avatar
Kid Shamrock Kid Shamrock is offline
Regular Poster
 
Join Date: Apr 2007
Posts: 169
Default Re: TDL/TDSS trojan series bypassing isolation software

Hi Leach,

Please test DefenseWall 3.03 against these rootkits. You can download it here:
DefenseWall_Personal_Firewall V 3.03
__________________
Laptop: Win7 x64 | AppGuard 3.4.2 | Rollback Rx | Macrium Reflect

Last edited by BlueZannetti : June 30th, 2010 at 10:00 PM. Reason: Edited direct exe download link to location from which download can be initiated
  #10  
Old June 30th, 2010, 10:37 PM
acuariano acuariano is offline
Frequent Poster
 
Join Date: Nov 2005
Posts: 786
Default Re: TDL/TDSS trojan series bypassing isolation software

did it pass sandboxie?...since it did to sd and tf
  #11  
Old July 1st, 2010, 12:40 AM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: a TDL rootkit passed through time freeze

Quote:
Originally Posted by taleblou
I got infected with a TDL rootkit that passed through time freeze and deeply infected my windows xp sp2 pc.
Can you explain how the infection occurred? Drive-by download? P2P?, etc.

Thanks,

-rich
  #12  
Old July 1st, 2010, 01:23 AM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by acuariano
did it pass sandboxie?...since it did to sd and tf
I've tested hundreds of TDL/TDSS samples using Sandboxie and none have touched the real system.
__________________
Nick
  #13  
Old July 1st, 2010, 01:39 AM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: TDL/TDSS trojan series bypassing isolation software

Sandboxie doesn´t allow installing drivers, that´s why Sandboxie can not be bypassed that way.

Leach: You got a PM.
__________________
http://bsa.isoftware.nl
  #14  
Old July 1st, 2010, 01:46 AM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by Buster_BSA
Sandboxie doesn´t allow installing drivers, that´s why Sandboxie can not be bypassed that way.
Indeed. Permitting driver install is a recipe for disaster.
__________________
Nick
  #15  
Old July 1st, 2010, 01:55 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by Kid Shamrock
Please test DefenseWall 3.03 against these rootkits. You can download it here:
The dogma.exes seem to be VM aware?

Tested Bufferzone, Sandboxie and Defensewall 3.03 against SafeSys.exe.

All three seemed to contain or cannot run fully and delete all dregs, or at least that's what TDSSKiller and Malwarebytes scans are showing.
  #16  
Old July 1st, 2010, 02:00 AM
acuariano acuariano is offline
Frequent Poster
 
Join Date: Nov 2005
Posts: 786
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by nick s
I've tested hundreds of TDL/TDSS samples using Sandboxie and none have touched the real system.

great,thanks
  #17  
Old July 1st, 2010, 02:05 AM
AvinashR's Avatar
AvinashR AvinashR is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: New Delhi Metallo β-Lactamase 1
Posts: 2,060
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by acuariano
great,thanks

Read this for more information....

http://www.wilderssecurity.com/showthread.php?t=276023
__________________
∆√♪ηάکђ
ℓєтک υηcσммpℓιcαтє
http://www.adminus.net
http://technonxt.wordpress.com
  #18  
Old July 1st, 2010, 02:16 AM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: TDL/TDSS trojan series bypassing isolation software

@Franklin I had to reboot the vm (vmware 7.0.1) to get it to work so could not test ShadowDefender in vmware.

dogma.exe md5 : 55A16DB3018A69A7D27F0DEAF632273F

retrieved config.ini from tdl3 rootkit
Quote:
[main]
quote=Tempers are wearing thin. Let's hope some robot doesn't kill everybody
version=3.273
botid=
affid=
subid=
installdate=1.7.2010 6:6:56
builddate=29.6.2010 11:50:23
rnd=602162358
[injector]
*=tdlcmd.dll
[tdlcmd]
version=3.82
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #19  
Old July 1st, 2010, 02:18 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by Meriadoc
@Franklin had to reboot the vm (vmware 7.0.1) to get it to work.
dogma.exe md5 : 55A16DB3018A69A7D27F0DEAF632273F
Thanks Meriadoc, will give it a go.
  #20  
Old July 1st, 2010, 02:26 AM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by AvinashR
Whatever demonstrated Sandboxie bypasses that existed last year have been addressed. None of those bypasses had the ability to successfully install a driver on the real system.
__________________
Nick
  #21  
Old July 1st, 2010, 02:30 AM
Kid Shamrock's Avatar
Kid Shamrock Kid Shamrock is offline
Regular Poster
 
Join Date: Apr 2007
Posts: 169
Default Re: TDL/TDSS trojan series bypassing isolation software

Thanks for the testing Franklin.
__________________
Laptop: Win7 x64 | AppGuard 3.4.2 | Rollback Rx | Macrium Reflect
  #22  
Old July 1st, 2010, 02:34 AM
AvinashR's Avatar
AvinashR AvinashR is offline
Very Frequent Poster
 
Join Date: Dec 2009
Location: New Delhi Metallo β-Lactamase 1
Posts: 2,060
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by nick s
Whatever demonstrated Sandboxie bypasses that existed last year have been addressed. None of those bypasses had the ability to successfully install a driver on the real system.

Read it again...I am not talking about SandboxIE, i am talking about Avast Sandbox...
__________________
∆√♪ηάکђ
ℓєтک υηcσммpℓιcαтє
http://www.adminus.net
http://technonxt.wordpress.com
  #23  
Old July 1st, 2010, 02:45 AM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by AvinashR
Read it again...I am not talking about SandboxIE...
I know, but others were. I was just clarifying the situation regarding Sandboxie.
__________________
Nick
  #24  
Old July 1st, 2010, 03:02 AM
acuariano acuariano is offline
Frequent Poster
 
Join Date: Nov 2005
Posts: 786
Default Re: TDL/TDSS trojan series bypassing isolation software

Quote:
Originally Posted by AvinashR

hey thanks for the link,,,good to know sbie is stronger.,effective.
  #25  
Old July 1st, 2010, 04:28 AM
Leach Leach is offline
Regular Poster
 
Join Date: May 2010
Posts: 84
Default Re: Wondershare Time Freeze - Giveaway

Quote:
Originally Posted by Meriadoc
Hi Leach, what version of ShadowDefender were you using and what is the md5 or sha1 hash of the tdl/tdss (dogma.exe) you were using, thanks.

latest
md5 : 55A16DB3018A69A7D27F0DEAF632273F
sha-1 : 1B1B5AF63CB048FCF47BDCE96CCFEA1301034137
md5: 55a16db3018a69a7d27f0deaf632273f *dogma.exe

Good you found the sample - I just wanted to ask for a help.

Shadow Defender with full DEP enabled has been tested by request - no changes except the targeted .DLL, system remains infected.
Attached Images
 
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:53 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums