Malware that possible ?bypassed SBIE

Discussion in 'other anti-malware software' started by aigle, Jul 8, 2008.

Thread Status:
Not open for further replies.
  1. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Yes, you are right as I think the dll names are randomly selected. I tried it twice now and dll in system32 folder was diffrent ineach time. Also in above snapshots we can see that when dll was denied to be created in system 32 folder, malware tried n tried to create the dll with so many diffrenet random names.


    Anyway I can confrim that on my system too nothing seems to excape SBIE.
    Sorry guys for all this thread.
     
  2. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    You are just emotional with a software. Otherwise I stated every thing very clear. There is a big Q mark on the thread title.

    Noway i am against SBIE. I do like it.
     
  3. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    I performed a search for: *.dll; created: today; in: \windows\system32

    Search result: 0 files found.
     
  4. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    It creates a single dll in system32 foider actually but it is contained by SDIE. Name of this dll is randomly slected.
     
  5. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    So it might be true that jfiehayd.dll = qoMEuSJY.dll and the volume in bytes might be the same. :)
     
  6. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Could not check it.
     
  7. Franklin

    Franklin Registered Member

    Joined:
    May 12, 2005
    Posts:
    2,517
    Location:
    West Aussie
    I can tell how much you like it by the million or so screenshots of Geswall you've posted all over the place.:D
     
  8. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    So, bottom line: both tests (mine and aigle's) show that SBIE succesfully contains this threat.

    Are screenshots still needed?
     
  9. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Hi guys thanks for testing!
    It is a win win whatever the results are so thankyou for the confirmation!
    As you can watch from the link from aigles first post
    or just trust the screen shots I'm having a leak.
    another screen showing startup entries and files.
     

    Attached Files:

  10. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    That's weird. Have you asked at SBIE forums?
    What version of SBIE do you have?
     
  11. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Sandboxie 3.26 when I first noticed and yet to update - I emailed tzuk twice with all information and screens.
     
  12. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    Maybe then it's possible that the malware actually bypassed SBIE. I tested v3.28
     
  13. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    I don't know but here it is as malware23.avi and the rest show.
     
  14. nomarjr3

    nomarjr3 Registered Member

    Joined:
    Jul 31, 2007
    Posts:
    502
    Sandboxie has nothing to do with this malware.
    With all the years of using Sandboxie, never once has an infection 'escaped' from the sandbox.

    This is just another tale of stupidity.:cautious:
     
  15. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    ....lol
     
  16. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    Malware can evolve, you know...
    Malware writers get sneakier every day.

    I rely almost only in SBIE, but to think that it will be always invincible...that would be just another tale of stupidity...
     
    Last edited: Jul 9, 2008
  17. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I wouldn't think it would matter inside the sandbox, it's what's outside that matters. I will run some tests myself tomorrow.
     
  18. Huupi

    Huupi Registered Member

    Joined:
    Sep 2, 2006
    Posts:
    2,024
    Hi worried guys i see no any mention of this bypasser on Tsuk forums recently,How serious and honest are you. take the guess out and post on his forum.
     
  19. innerpeace

    innerpeace Registered Member

    Joined:
    Jan 15, 2007
    Posts:
    2,121
    Location:
    Mountaineer Country
    Are all of you testing with "default" sandbox settings in Sandboxie?

    Also, when installing SBIE, you may need to reboot for the driver to install. It's probably best to reboot anyways. I'm aware the installation tells you this, but it may be the variable in the results.
     
  20. Meriadoc

    Meriadoc Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    2,642
    Location:
    Cymru
    Thanks for your comment innerpeace, yes I always reboot after an install.
    I think the problem is specific to me somehow.
     

    Attached Files:

    Last edited: Jul 9, 2008
  21. HURST

    HURST Registered Member

    Joined:
    Jul 20, 2007
    Posts:
    1,419
    No default setting here. Tweaked as much as I could.
    But I don't think it was that.
    \System32\ protection is by default in SBIE.

    I will try again later, with default settings.
     
  22. CogitoErgoSum

    CogitoErgoSum Registered Member

    Joined:
    Aug 22, 2005
    Posts:
    641
    Location:
    Cerritos, California
    For those who are interested,

    I personally tested this sample against both DefenseWall(DW) and Primary Response SafeConnect(PRSC) "without" the protection of Returnil's "session lock". The former was successfully able to block and contain it while the latter was not. Before "rolling back" the malicious files and registry tracks that were created and marked as "untrusted", I took note and have listed them below.

    C:\Users\Owner\AppData\Local\Temp\IXP000.TMP\
    C:\Users\Owner\AppData\Local\Temp\install14564.exe
    C:\Users\Owner\AppData\Local\Temp\setup.exe
    C:\Users\Owner\AppData\Local\Temp\install17446.exe
    C:\Users\Owner\AppData\Local\Temp\install6857.exe
    C:\Users\Owner\AppData\Local\Temp\install48586.exe
    C:\Users\Owner\AppData\Local\Temp\install2503.exe
    C:\Users\Owner\AppData\Local\Temp\install19995.exe
    C:\Windows\system32\vtUILFyy.dll
    C:\wupdate.exe

    Lastly, after performing the "rollback" which was accomplished within DW, I was able to confirm that my system was clean with the use of CureIt!, MBAM, Prevx CSI+ and SAS.


    Peace & Gratitude,

    CogitoErgoSum
     
    Last edited: Jul 9, 2008
  23. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    Nice testing folks:thumb:Now how about some classic hips tested or comodo D+ and spyware terminator hips.:D
     
  24. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    I gave it a play and I'd say it was well contained.

    First I tried it in my browser and outlook sandboxes, and it never got off the ground as those sandboxes are restricted.

    Then I tried it in my default box, I use for testing "none of the above". Anything can run in it, but no network access. It threw up a lot of errors trying to run there.

    I feel pretty confident SBIE is doing it's job.
     
  25. Dark Shadow

    Dark Shadow Registered Member

    Joined:
    Oct 11, 2007
    Posts:
    4,553
    Location:
    USA
    I do not doubt sandboxie at all.off topic but I really love sandboxie but it kills my browser speeds on vista with IE7 badly.Never had that with XP:'( :oops:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.