This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

"Generic" (non-)detection, alerting and automatic cleanup

Over the last two weeks a few users "contracted" some pieces of malware. Initially there was no specific detection but (see the link for details). Later it was HIPS/ProcInj-001 and HIPS/RegMod-014 alerts. Identities were created or updated (within hours) for various Troj/Agent-xxx, Troj/FakeAV-xxx and several others.

On Monday I had again two reports and looking a the computer details I found that there had been a few detections but no outstanding alerts. Inspecting the computers the already known problems were found: executables in the users Application Data folder started from HKCU\....\Windows\...\Run, mgrls32.exe located in the RECYCLER started from HKCU\...\Windows NT\...\Winlogon,  executables with three-digit names and so on. Quite easy for a human (like me) to detect but no alerts even with paranoid scanning turned on.

Given that this junk is "visible" I wonder how it evades (generic) detection (and Windows' security BTW) - I think that for example something started from the RECYCLER should always be suspicious. But I'm sure Sophos is working on it.

Second thought: As obviously the "payload" consisted of several items and some of them had been detected and cleaned up I might have been alerted earlier (although it wouldn't have made much difference) without automatic cleanup and deny access only.

Christian

:2797


This thread was automatically locked due to age.
  • To avoid any misunderstanding - it is not a complaint at all, labs are doing a great job identifying threats and rolling out detection as soon as possible. It is more curiosity on my part. To the untrained eye :smileywink: these things look pretty similar.

    In summary it went quite well and it was beneficial for both my ('cause I found the shstuff) and Sophos' ('cause they dealt with really fast) reputation. But as for me - I could do well without it.

    Christian 

    :2801