Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > Malware and Virus Removal

Malware and Virus Removal Problems removing malware/viruses? Get help from our Malware removal experts.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 16th August 2005   #1
Senior Member
 
Profile:
Join Date: Jan 2002
Location: Phoenix, Arizona
Posts: 126
Computer Experience:
intermediate
maureen Reputation Level


two .EXEs with same name, one good, one bad

Question about Zone Alarm:

We have a proprietary program at work using a sql database, whose executable is RB.exe. The latest update on ZA Pro has identified this program as a trojan, see description and blocked its activity with the error message that RB.exe was logging keystrokes and cursor movements.

I went into ZA's program control and saw that the path to this executable was indeed located in the appropriate folder for this program - so I gave it full permission as a super trusted program to do what it needs to do. No more error messages and everything is working fine.

However, my boss has asked me the question, If I have given full permission to this executable so that our program can work, what will happen if the real trojan (whose executable is also RB.exe) gets on the machine? Have I made the machine vulnerable to the trojan?

I of course said no, the executables are located in different paths, and if ZA found another RB.exe in another path, it would raise the question again about whether to give permission and that's when we would find the discrepancy. however, now I'm wondering......

Does anyone know how ZA would treat an intrusion of an illegitimate intruder, after having given full permissions to a legitimate executable with the same name?

Any help is much appreciated. TIA,

maureen

maureen is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 16th August 2005   #2
SuperGeek
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,308
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Hello maureen,

I've not installed v6.0 yet - using the last v5.5, so this is "informed" (I hope) speculation for now.

I do use an application firewall - System Safety Monitor, that does on a system wide basis what ZAP is doing, so do have experience with this kind of program.

SSM checks process execution based not only based on the path, but on something called MD Hash which is a unique identifier for anything that executes on the system. So if I've given permission for Notepad for instance, if a newer version is executed - as happened with SP2 - SSM will again ask permission.

I would ask at the ZL forums if this is indeed the case. I can't imagine that it wouldn't be though, otherwise this feature would be crippled. Sygate free has a feature that does the same thing (only for anything that wants to access the Net) and will spot a different version of an executable, same path or not.

If I think of a way to test this, I'll let you know.

Regards - Charles

charlesvar is offline   Reply With Quote
Old 16th August 2005   #3
Senior Member
 
Profile:
Join Date: Jan 2002
Location: Phoenix, Arizona
Posts: 126
Computer Experience:
intermediate
maureen Reputation Level


Thanks, Charles.

Guess I'll have to figure out where the ZL forum is, and post the question there.

Appreciate your help --

maureen

maureen is offline   Reply With Quote
Old 16th August 2005   #4
SuperGeek
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,308
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Hi maureen,

http://forums.zonelabs.com/zonelabs ZL forum

http://www.wilderssecurity.com/index.php Wilders forum - post in the "other firewall" section. This site is mostly about security issues and no registration required.

Regards - Charles

charlesvar is offline   Reply With Quote
Old 17th August 2005   #5
Senior Member
 
Profile:
Join Date: Jan 2002
Location: Phoenix, Arizona
Posts: 126
Computer Experience:
intermediate
maureen Reputation Level


Charles - you were so right about creating a hash ID file - ZA calls it a fingerprint.

I took your advice, registered for the forum and posted the same question. Here is the answer I got:
Zone Alarm creates a hash of files, in this case RB.exe. It stores a digital fingerprint of the file. If something were to erase RB.exe and then drop itself in the same directory and name itself RB.exe Zone Alarm would warn you that the program had changed. If a program named RB.exe was in another directory ZA would treat it as a new program, regardless of the name and even if it was the same exact RB.exe file that you allready have given permissions to. That's what I have found while playing around.

Different directory, same name = "New Program"
Same Directory, same name but different or altered file = "Changed Program"
Musashi

So I guess my first thought was kind of right, but the protection extends beyond that: it seems ZA is able to also recognize any substitution or secret infection in a file that has already been approved, and it will sound an alert. Nice.

Thanks for the help. I can sleep again and I think my boss will rest better too.

- maureen

maureen is offline   Reply With Quote
Old 17th August 2005   #6
SuperGeek
 
charlesvar's Avatar
 
Profile:
Join Date: Feb 2002
Location: New Jersey
Posts: 7,308
Computer Experience:
indeterminate
charlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Levelcharlesvar Reputation Level


Thanks maureen for the post back, appreciated

Regards - Charles

charlesvar is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Add/Remove Program has black vert. lines MinnesotaMike Windows XP 45 13th May 2005 05:53
Bad sectors on disk shortgal10 Hardware 30 29th March 2005 00:59


All times are GMT +1. The time now is 02:39.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]