Comodo Defence Plus Bypassed by Zeroaccess rootkit

Discussion in 'other anti-malware software' started by aigle, Dec 4, 2011.

Thread Status:
Not open for further replies.
  1. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,047
    Location:
    Saudi Arabia/ Pakistan
    Interesting scenario with zeroaccess rootkit. Tested with Comodo HIPS and GesWall

    Comodo Defence plus SAFE mode, sandbox enabled, firewall safe mode, AV turned off

    1.jpg
    2.jpg
    3.jpg
    4.jpg
    5.jpg
     
    Last edited: Dec 4, 2011
  2. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,047
    Location:
    Saudi Arabia/ Pakistan
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    GesWall- passed with

    - only dll isolated or
    - dll and flashplayer.exe both isolated.

    a.jpg b.jpg c.jpg d.jpg
     
  3. LoneWolf

    LoneWolf Registered Member

    Joined:
    Jan 2, 2006
    Posts:
    3,408
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Nice to see GesWall nail this. :thumb:
     
  4. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,954
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Very nice info, thanks. Any chance you could try DefenseWall or Sandboxie against this?
     
  5. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
  6. Brocke

    Brocke Registered Member

    Joined:
    Mar 16, 2008
    Posts:
    2,191
    Location:
    USA,IA
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    oh now try with sandboxie :) haha

    no bypass :argh:
     
  7. Boost

    Boost Registered Member

    Joined:
    Feb 2, 2007
    Posts:
    1,293
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    :thumb:
     
  8. cheater87

    cheater87 Registered Member

    Joined:
    Apr 22, 2005
    Posts:
    3,125
    Location:
    Pennsylvania.
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    I'm pretty sure this is because of limited rights for the sandbox. What if you had it set to restricted or untrusted? I know blocked would well block it. :p
     
  9. Noob

    Noob Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    6,468
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Could be this as he said, you should try it as untrusted :D
     
  10. icebela

    icebela Registered Member

    Joined:
    Dec 5, 2011
    Posts:
    2
    Location:
    china
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Can provide samples, please?
     
  11. constantine76

    constantine76 Registered Member

    Joined:
    Dec 18, 2010
    Posts:
    178
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Very nice there aigle :)

    If sandbox is disabled will D+ pop-up an alert?
     
  12. Technical

    Technical Registered Member

    Joined:
    Oct 12, 2003
    Posts:
    471
    Location:
    Brazil
  13. Ranget

    Ranget Registered Member

    Joined:
    Mar 24, 2011
    Posts:
    846
    Location:
    Not Really Sure :/
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    what version of comodo

    and can you plz try it when comodo sandbox is disabled

    also can you try OA
     
  14. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,148
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Was this the automatic sandbox or fully virtualized sandbox?
     
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    17,060
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Icebela it is against TOS rules to request malware samples here. Member who have them for the most part know this and won't respond.

    Pete
     
  16. NSG001

    NSG001 Registered Member

    Joined:
    Jul 14, 2006
    Posts:
    617
    Location:
    Wembley, London
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    The OP could do this at the Comodo forum.
    Comodo will nail this ;)
     
  17. icebela

    icebela Registered Member

    Joined:
    Dec 5, 2011
    Posts:
    2
    Location:
    china
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    I do not know what is the significance of such tests? No sample so much, what is the significance? It's like the manufacturers say me how good, but not used how do you know what's good or bad?
     
  18. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,047
    Location:
    Saudi Arabia/ Pakistan
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    i did testing with win 7 in VBox in ubuntu host. CIS on default settings but AV was not installed.

    Tried on XP under cover of CTM with same settings but strange thing appeared. Day before yesterday, it was giving a pop up alert that flash...exe wants to get unlimited access, it's signed but not white listed by comodo, do you want to allow, or sandbox or block. If sandboxed, all is ok but if allowed rootkit is installed. Yesterday i tried again and strangely it says that this eye wants unlimited access but it's unsigned. That is strange really. I am not able to get previous alert at all.

    No such alert on win 7 or may be it's due to vbox. Can any one test on real win 7 system or vmware?

    Also tried with proactive mode with sandbox off. It gives many pop up alerts and is a pass for comodo. I wil post screenshots later.
    OA doesn't give any alert at all but i need to confirm this as i think i trusted every thing on the computer as trusted. I wil post later.

    Sorry that i could not test DW and SBIE but i see no reason for them to pass this test.
     
    Last edited: Dec 6, 2011
  19. treehouse786

    treehouse786 Registered Member

    Joined:
    Jun 6, 2010
    Posts:
    1,388
    Location:
    Lancashire
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    would running under under a standard user account protect you from this nasty or does it bypass that aswel?
     
  20. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,047
    Location:
    Saudi Arabia/ Pakistan
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    not sure but i think it should protect. UAC also protects.
     
  21. Technical

    Technical Registered Member

    Joined:
    Oct 12, 2003
    Posts:
    471
    Location:
    Brazil
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Thanks aigle.
    Maybe you can submit the file (sample) to the Comodo team.
     
  22. cruelsister

    cruelsister Registered Member

    Joined:
    Nov 6, 2007
    Posts:
    977
    Location:
    Paris
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Aigle- can you please post the MD5 of the sample?

    There have been 2 that have been floating around this week:

    0fc7456a17a43983d55488fcf548410e and
    998cb14ac738a8cceefd0ef29017d12f

    Running these under CIS where Execution Control was set as Restricted did not produce the same results that you had (both were blocked).

    Also, what was your EC setting when you ran the malware?
     
  23. NSG001

    NSG001 Registered Member

    Joined:
    Jul 14, 2006
    Posts:
    617
    Location:
    Wembley, London
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    Excellent work fellas, let's get this nailed :)
     
  24. Zyrtec

    Zyrtec Registered Member

    Joined:
    Mar 4, 2008
    Posts:
    534
    Location:
    USA
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit


    Not to be seen as disrespectful to Aigle and his tests, but the way some people are testing CIS [a security suite that includes AV + FW + HIPS [D+]/Sannbox] is kind of flawed to me.

    It's like telling a guy to run a 10 miles marathon in 1 hour but sawing off his two legs before the competition starts.

    The same applies to CIS. They disable the AV, then setup D+ with the weakest settings and also setup the Sandbox to Partially Limited instead of Untrusted/Restricted, and even sit down and wait for it to pass those “tests” :rolleyes: .


    Honestly, I don't know what to think.


    Thanks.
     
  25. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,047
    Location:
    Saudi Arabia/ Pakistan
    Re: Comodo Defence Plus Byapssed by Zeroaccess rootkit

    I used default settings.
     
Loading...
Thread Status:
Not open for further replies.