Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Use SEP application control to block these:

Updated: 26 Sep 2010 | 4 comments
ShadowsPapa's picture
+4 4 Votes
Login to vote

(see my article on using SEP app control to block bad BHOs and fake AV apps)
Here are some paths that a SINGLE threat attempted to exploit - this is a common one:
This is part of my policy here - I NOW block this since it was successful in getting in to this area - I'd left a hole...........

%userprofile%\templates\*.exe

Check these log entries below to see all the ways this one threat was trying to get in!

------------------------------------
Attempt #1:
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/av.exe
User name:
 
----------------------------------------------------------
Attempt #2
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Templates/av.exe
User name:
 
----------------------------------------------------
Attempt #3
 
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/mtg/mtg.exe
User name:
 
 
------------------------------------------------------
Attempt #4
 
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/mtg/MSASCui.exe
User name:
 
 
-----------------------------------------------------
Attempt #5
 
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/mtg/av.exe
User name:
 
 
--------------------------------------------------
Attempt #6
 
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/Microsoft/Windows Defender/mtg.exe
User name:
 
 
-----------------------------------------------------
Attempt #7
 
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/Microsoft/Windows Defender/MSASCui.exe
User name:
 
 
--------------------------------------------------------
Attempt #8
 
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/Microsoft/Windows Defender/av.exe
User name:
 
 
-------------------------------------------------------
Attempt #9
 
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/mtg.exe
User name:
 
 
---------------------------------------------------------------
Attempt #10
 
Caller Process Name:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Temp/cxmaon.exe
Target:
C:/Documents and Settings/Jami.Schwickerath/Local Settings/Application Data/MSASCui.exe
User name:
 
 
--------------------------------------------------------------------

Comments

Aniket Amdekar's picture
19
Mar
2010
0 Votes 0
Login to vote

Nice analysis of the

Nice analysis of the logs.

Aniket

Brian81's picture
19
Mar
2010
0 Votes 0
Login to vote

Thanks for sharing, certainly

Thanks for sharing, certainly will be a big help.

snekul's picture
22
Mar
2010
0 Votes 0
Login to vote

In our most secure areas, we

In our most secure areas, we let nothing run from any part of the user's profile!  This would be why.

Eric C. Lukens IT Security Policy and Risk Assessment Analyst University of Northern Iowa

ShadowsPapa's picture
22
Mar
2010
0 Votes 0
Login to vote

My article on using SEP's

My article on using SEP's application control basically blocks nearly everything from running under user profile areas. I have a group that does allow things, if an install is needed, we move PC to that group, run the install, then move it back.
If it's a mass need, I create a specific exclusion.
It irritates some, but we've cut down big on the rogue av and such.............