RCC - check your system's trusted root certificate store

Discussion in 'other anti-malware software' started by svenfaw, Feb 28, 2015.

  1. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    Any news on the Symantec certificate? (this version still reports it)
     
  2. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    No news so far. However I plan to approve the cert in the next build, based on the following facts:

    - By all accounts it appears to be part of a default Win10 install

    - Verified to be a legit Symantec cert as per
    https://knowledge.symantec.com/support/code-signing-support/index?page=content&id=SO20770

    - Windows already trusts other Symantec root certs

    - Can be used for Code Signing only

    To me the above is sufficient justification to whitelist it in RCC.
    Of course if there are any thoughts about this please chime in.
     
    Last edited: Dec 1, 2015
  3. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Strange things are going on..

    Today I scanned my office machine again, and RCC found no "interesting" certificates.

    I took a notebook, that was never used for any experiments and that is running WIN7, office, chrome and AVIRA
    Scanned with RCC, last build, and found no interesting certificates
    Scanned with Zemana Antimalware 2.18.2.519 portable, no detection.
    Scanned again with RCC and TADA: 90 interesting certificates, inserted a minute ago, all the same that I had on my office machine.

    Any opinion whats going on here?
     
  4. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    I'm not familiar with Zemana... Does it touch certificates in any way? Did you also have it running on your office machine at some point?
     
  5. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    I had Zemana portable run from time to time on my office machine.
    It scans for bad certificates, but only found my self signed certificate.
    So yes, it touches the certificate store, but should not alter it, or even insert certificates. Did it?
     
  6. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    Too early to tell. We would need more information to be sure.

    Does Zemana require admin rights to run?

    If you really want to be sure, one good way would be to repeat the test on a clean system and monitor registry accesses during the Zemana scan.
    Using ProcessMonitor if you're experienced with that, for instance.
     
    Last edited: Dec 3, 2015
  7. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Yes, Zemana opens a UAC prompt.
    All certificates are in the certificate store.

    I will setup a WIN7-64 system, that doesn't take long for me, because I have a setup stick with all updates included.
    I will do a reg shot and start Zemana, while running ProcessMonitor.

    But I can't do it right now, because of limited time.
     
  8. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    The architect of Zemana Antimalware is active on this forum (see the topic dedicated to this software); you might ask him.

    (I have a lifetime license and run ZAM in portable mode on my system; during my last RCC check only 2 certificates where reported: the Symantec one plus one other)
     
  9. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    Bevor I blow the whistle,
    can anyone confirm, or deny, that 90 "interesting" certificates appear in the certificate store, after running ZAM ?

    Today I tried on 5 machines and 4 of them had the dirty ninety, after running ZAM portable
     
  10. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    Just tried after ZAM portable scan and no 90 here. I had the 90 before, not sure why, but none lately.
     
  11. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    Thanks, I have asked Emre to have a look into this.
     
  12. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
    I ran ZAM portable, latest stable and latest beta, on several more random picked machines.

    Out of 9 machines, 7 where affected.

    So I pulled the trigger and asked in ZAM thread.
     
  13. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Just tried RCC for the first time now.
    Got the following 'interesting item': '4D18231F020E7A3E66B2B5B60DB5458FAFB6DE78: WinPrivacy 2 Time of insertion: 2015-09-12 09:28:13 UTC'
    WinPrivacy is a program from the WinPatrol stable - I believe it is an FP.
    Can it be whitelisted?
     
  14. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    I unfortunately don't have enough time to investigate it now, but basic support for whitelisting will be added into RCC soon.
     
  15. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    No response yet.
     
  16. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    It's really weird; I have seen it on one PC (32 bits, non-English), but not on another (64 bits, English).
     
  17. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    Emre gives an explanation in the ZAM topic: #1474
     
  18. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    I'm afraid that explanation is incorrect. I've posted a reply over there.
     
  19. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
    Thanks.

    What would be the easiest way to remove those old certificates?
     
  20. Hiltihome

    Hiltihome Registered Member

    Joined:
    Jul 5, 2013
    Posts:
    1,131
    Location:
    Baden Germany
  21. girioni

    girioni Registered Member

    Joined:
    Mar 31, 2015
    Posts:
    13
    Probably time for a little apology? :)
     
  22. XIII

    XIII Registered Member

    Joined:
    Jan 12, 2009
    Posts:
    1,383
  23. haakon

    haakon Guest

    @ svenfaw

    Thank you for RCC.

    I think I've got all the stuff squared away between this and the ZAM threads. I the past six or so months I've run several versions of ZAM portable and installed trials with one about 10 days ago with real-time enabled. All were fully uninstalled.

    I've just run RCC 1.55.246, Baseline RCC1_STD_MSCTL, 2015-11-28 which returned: [ OK ] No unusual root certificates found.

    So, my understanding is that RCC is THE test in this assessment and my system did not suffer from Zemana's "oops" - Correct??
     
  24. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    @haakon Yes, your system appears to be unaffected.
     
  25. svenfaw

    svenfaw Registered Member

    Joined:
    May 7, 2012
    Posts:
    291
    Hi, there is not much information available about this certificate yet. I have no Windows 10 system at hand but if you have time for that, you could try using Microsoft's Sigcheck utility to check if any system files are signed with this certificate.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.