Possible CF bug again? Overzealous quarantine!
#1
Posted 21 May 2011 - 04:19 PM
Today I was doing doing a few scans on a friend's x86 XP SP3 PC (the joys of being an IT professional, these things tend to land in your lap) and my suspicions led me to run, amongst other things, ComboFix on the machine in question*. Now usually this tool behaves itself quite well but today it seems to have gone a little awry: After copying across and launching the version that resides on my USB stick (which was last manually updated perhaps a week ago) it began updating itself then proceeded to install the recovery console and begin scanning. During the scan, It decided that the entire contents of the Program Files folder required deletion and procedeed to quarantine the lot. Not a big problem really, it's easily enough restored (though I'll have to boot into linux as my batch scripting is awful, no idea how to mass rename!) but I was just wondering if perhaps the bug that popped up in January had made a reappearance? I couldn't find anything on the site that would indicate this and felt that if it had, it might be worth bringing it to the attention of the author and community.
Thanks in advance!
Ross
*Log on request, if I'm not mistaken they're not allowed in here!
#2
Posted 21 May 2011 - 08:56 PM
To compound my woes, I can't get the unquarantine script to work. I tried to do it like this:
<script removed>
Is that incorrect? I want to unquarantine everything.
This post has been edited by elise025: 22 May 2011 - 03:26 AM
Reason for edit: script removed for security reasons ~Elise
#3
Posted 22 May 2011 - 03:32 AM
Do NOT post any Combofix logs here, they will be removed. Instead, if you need help removing malware, follow the steps in the Preparation Guide.
#4
Posted 22 May 2011 - 09:06 AM
elise025, on 22 May 2011 - 03:32 AM, said:
Do NOT post any Combofix logs here, they will be removed. Instead, if you need help removing malware, follow the steps in the Preparation Guide.
Thanks for the confirmation Elise. I've restored everything on my end, but confirmation of the method Falcon was attempting would be appreciated for future reference.
#5
Posted 22 May 2011 - 09:34 AM
Quote
#6
Posted 22 May 2011 - 10:03 AM
elise025, on 22 May 2011 - 09:34 AM, said:
Fairy snuff, it's easy enough to remedy without the script anyway.
Thanks again!
#7
Posted 22 May 2011 - 03:06 PM
Quote
It would be incredibly nice to know if I was at least on the right track. I have since used Linux to restore the files, so it's no longer crucial. However, I would far rather not disassemble the application and experimentally determine how to restore mistakenly quarantined files; could I at least know whether the commands I was using were syntactically correct? I am not terribly worried about damaging windows installations as I have a test environment.
How does one determine if CF is even running the script? Does it intentionally appear to be doing the exact same thing it would if you had not run the script, or does it give an indication?
#8
Posted 22 May 2011 - 03:35 PM
Safeguarding ComboFix from malware writers is necessary and important so that we can continue to use it without attackers having knowledge how to defeat it. Everything we discuss can be read by the bad guys. Yes, they read forum topics looking for clues on how to circumvent our tools. We don't want to provide any information they can use against us so we deliberately limit discussion which sometimes may appear vague or not fully address a specific question.
As such, the developer does not want his tool discussed outside of private forums and therefore we cannot answer specific questions.

Member of UNITE, Unified Network of Instructors and Trusted Eliminators
#9
Posted 22 May 2011 - 07:44 PM
Sorry to drag this so far off topic, though. It seems the bug has not shown its face again...
#10
Posted 22 May 2011 - 08:57 PM
This post has been edited by quietman7: 22 May 2011 - 09:01 PM

Member of UNITE, Unified Network of Instructors and Trusted Eliminators
#11
Posted 26 May 2011 - 08:45 PM
I ran the supposed solution only find it did nothing...
I've been pulling my hair out for the last 3 days. Luckily it isn't my main computer.
All my files have been mover to the quarantined folder with the vir extension.
#12
Posted 27 May 2011 - 07:47 AM
hamluis has already responded in your other thread here. If you have further questions, please continue in there. Please do not start new threads or duplicate topics as this causes confusion and makes it more difficult to get the help you need to resolve your issues. Further, it necessitates staff spending time with housecleaning to remove or close those duplicate postings...time which could have been provided to others needing assistance.

Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Help

Back to top










