Microsoft banishes Trend Micro code at center of driver 'cheatware' storm from Windows 10, rootkit detector product pulled from site
- Reference: 1590563651
- News link: https://www.theregister.co.uk/2020/05/27/trend_micro_driver_banned_windows/
- Source link:
Late last week, Trend removed downloads of its [1]Rootkit Buster from its [2]website . And last night it emerged the kernel-level driver at the heart of the software, tmcomm.sys , was just added to Windows 10's list of banned drivers – preventing it from loading and Rootkit Buster from running.
Windows internals guru Alex Ionescu discovered the blockade, and [3]highlighted it on Twitter, while investigating [4]research by computer security undergrad Bill Demirkapi that revealed not only shortcomings in the driver's code but also an effort to detect Microsoft's QA test suite.
"Well done, Microsoft Security, for banning these drivers," said Ionescu, noting that up to version 8.x of tmcomm.sys is now toast on Windows 10.
This comes after Demirkapi, [5]as we reported last week , discovered tmcomm.sys altered the way it allocated memory to pass Microsoft's Windows Hardware Quality Labs ( [6]WHQL ) certification tests.
Passing these tests is highly desirable: if a driver meets the grade, it can be digitally signed by Microsoft, is trusted by Windows, and potentially can be distributed via Windows Update and similar mechanisms.
Tech's Volkswagen moment? Trend Micro accused of cheating Microsoft driver QA by detecting test suite [7]READ MORE
One of the requirements is that, for security reasons, the driver requests memory only from the operating system's non-executable non-paged pool of available RAM. By doing this, exploits that attempt to run malicious code injected into a driver's memory allocations via a vulnerability are hampered.
If the Trend Micro driver detects it's running on a computer undergoing WHQL testing, it requests from this specific non-executable pool as expected. However, if it doesn't detect the presence of Microsoft's driver verifier software, it draws from the executable non-paged pool, which is insecure and would cause it to fail the certification test. It is not clear why Trend's software does this; it may be because using the non-executable pool triggers bugs within its code.
Deep dive
The Register has verified Demirkapi's findings by reverse-engineering the driver code, specifically version 7.0.0.1160 that shipped with Rootkit Buster.
By default, it sets a variable at 0x18005aa4c to zero. This variable holds the pool type: zero being the executable non-paged pool. This variable is passed to the kernel whenever the driver allocates memory. Thus, the driver by default allocates from the executable non-paged pool, which would fail the certification test.
The function IsVerifierCodeCheckFlagOn() at 0x180030b23 checks the value of the registry key VerifyDriverLevel , which indicates whether Microsoft's driver certification test is running. If it cannot detect the verifier, it returns the value zero.
Then at 0x180035efa , the driver checks to see if it is running on Windows 10 or higher, and if IsVerifierCodeCheckFlagOn() returns a non-zero result, meaning the verifier was detected. If it was detected, and we're on Windows 10 or higher, the pool type variable is changed to 512 (0x200), which is the identifier for the non-executable non-paged pool. Thus all subsequent allocations are made from the non-executable pool, aka the NonPagedPoolNx , as expected by the verifier.
Otherwise, the driver continues using its default: the executable non-paged pool, which is against Microsoft's rules.
[8]
Reconstructed C from driver's machine code by Hopper, showing the check for Windows 10, or higher, and the verifier detection call. If successful, it changes the pool type for the driver to 0x200, or 512, which is the non-executable pool. By default, it uses the executable pool ... Click to enlarge
We note that while the driver appears in other Trend Micro products, they may not necessarily be using the banned driver versions, or may have received a hot fix, and thus will continue working on Windows 10. Older Trend Micro products – those released before 2019 – may be prevented from running due to the driver blockade. If your Trend Micro Antivirus+ 2018, Trend Micro Internet Security 2018, Trend Micro Maximum Security 2018, or Trend Micro Premium Security 2018 have suddenly stopped working on Windows 10, this is probably why.
Trend Micro has ignored our repeated requests for an explanation as to why its software altered its operation specifically while under test, though it insisted "at no time was the Trend Micro team avoiding certification requirements." A spokesperson for Trend was not available for immediate comment on Microsoft's decision to ban the driver on Windows 10.
'A potential medium-level security issue'
Before the weekend, and after we noticed the Rootkit Buster software had disappeared from its website, a Trend spokesperson told us it removed the product after discovering an unidentified vulnerability: "While investigating claims in [Demirkapi's] blog, our development teams identified a potential medium-level security issue and are working to ensure it is properly and quickly resolved. Out of an abundance of caution, we have taken down the current version of the tool from our site while we evaluate and remediate.
We are working closely with our partners at Microsoft to ensure that our code is in compliance with their rigorous standards
"As for the allegation that Trend Micro is somehow trying to work around Microsoft’s certification process, we want to again make clear that this is indeed not the case and we are working closely with our partners at Microsoft to ensure that our code is in compliance with their rigorous standards."
That would suggest Trend Micro didn't intend to deliberately swerve Microsoft's certification checks. Demirkapi, and your humble vultures, remain puzzled, though, as to any reasonable explanation to why the Rootkit Buster would need this WHQL detection code in the first place, even for testing or debugging purposes.
"It just doesn't make sense that they would add extra code and go out of their way to check for it," Demirkapi told The Register . "Why not use NonPagedPoolNx all the time for systems that support it? There is no reason I can think of.
"Trend Micro must be held accountable for their extremely questionable code. Trend Micro continues to deny my claims that they are cheating Microsoft's certification standards, but their lack of an explanation only reaffirms my position. The evidence has shown that Trend Micro designed their driver to specifically detect testing environments, including Microsoft's own testing platform for WHQL certification." ®
Reverse-engineering by [9]Chris Williams .
[1] https://www.trendmicro.com/en_us/forHome/products/free-tools/rootkitbuster.html
[2] https://downloadcenter.trendmicro.com/index.php?clk=tbl&clkval=355®s=NABU&lang_loc=1
[3] https://twitter.com/aionescu/status/1265481087544893440
[4] https://billdemirkapi.me/How-to-use-Trend-Micro-Rootkit-Remover-to-Install-a-Rootkit/
[5] https://www.theregister.co.uk/2020/05/20/trend_accused_microsoft_cheating/
[6] https://docs.microsoft.com/en-us/windows-hardware/drivers/install/whql-release-signature
[7] https://www.theregister.co.uk/2020/05/20/trend_accused_microsoft_cheating/
[8] https://regmedia.co.uk/2020/05/27/hopper_trend_micro_code.png
[9] https://www.theregister.co.uk/Author/Chris-Williams/
"Took liberties"
Well, if that did happen and it was not caught, that wouldn't give you much confidence that their code was secure or able to detect attacks.
Ah yes, the ol' rogue engineer excuse.
Dieselgate 2.0?
[Comment is optional]
Re: Dieselgate 2.0?
At least VW's cheat software had to try a bit. The cars don't have a registry entry that says "We are now performing a test."
Hanlon's Razor does not apply today...
Normally, I would pull out the old Hanlon's Razor "Never attribute to malice that which is adequately explained by stupidity". BUT this is definitely not something slipped in by accident. You dont put a check for something that then defines further behaviour by accident - a) because its more lines of code that you really dont need if you were doing things above board, and b) who needs the hassle of then spending the time to test that works under two different behaviour scenarios.
This was put in deliberately. The question is why?
Re: Hanlon's Razor does not apply today...
I wonder if there is any possibility this part of the code was bought in and hence not written by the trend micro team (and not audited, ugh)?
Re: Hanlon's Razor does not apply today...
This is supposedly the product of an expert security company.
Oh they're experts all right. Just not for your security.
Re: Hanlon's Razor does not apply today...
Trend have performed poorly in independent testing over the last 18 months or so. I would bet this is an extension of that since they've been reluctant to allow independent testing of their software being widely published since they started to perform poorly
> "at no time was the Trend Micro team avoiding certification requirements."
Well then who wrote that code? The code is definitely there and someone had to write it so Trend's statement implies hackers are changing their code without their knowledge - an even worse situation than trying to fool certification tests!
I will believe them when they can provide some credible and convincing explanation as to why it was there, why the software only changed its behaviour to what it should have been when the software recognised it was being tested.
I'm not holding my breath but I've put £5 on a long-shot of the excuse being 'safeguarding a child'.
Kettle calling
As if MS would never do this. Bit like being fine with sexism while being appalled at racism.
"It is not clear why Trend's software does this"
I don't care if it's clear or not, it should not be done, period.
Good on Borkzilla for reacting on this and pulling the driver. Now Trend is going to have to submit another one, and I'll bet it will get a lot more scrutiny the next time around.
A reputation takes years to build, but only a day to trash. Trend Micro has now trashed its reputation.
Maybe a programmer of theirs took liberties to meet deadlines. And it flew through reviews, and management knows nothing. ;)