invitad0
24/07/07, 22:11:32
Hola, observo que en Anti-Malwares - Info Spyware (http://www.infospyware.com/Anti-Malwares.htm) se recomienda combofix. Tras una mala experiencia con este programa, me puse a indagar sobre esta herramienta y descubri que no se debería de recomendar su uso.
El caso es que mi ordenador fue infectado por el asqueroso totour.exe, un virus complejo y dificil de eliminar y que incluye varios troyanos. Consegui neutralizar los troyanos y el envio residente por smtp ,mientras me tomaba un tiempo para estudiar el tema con posterioridad..Luego,durante la ideación del proceso de limpieza total de mi disco duro (listando acciones de varios programas que me habia ido bajando), ejecute el combofix (en el foro de superantyspyware lo sugerian para un caso como el mio) para poder descartar o no su uso. No recordaba haber encontrado mucha informacion sobre la utilidad real de este programa y en la confianza de que tenia que tratarse de una herramienta segura, cometi la ligereza de ejecutarla.
Resultado: los varios troyanos que habia descargado el totour resucitaron del registro...No tarde mucho en arreglarlo, pero más tarde busque mas informacion sobre el programa combofix y lo que me habia sucedido. Encontre esto en foros en inglés (no traduzco las citas, pero se entiende bastante bien):
1)Herramienta no publica
En Anti-Malwares - Info Spyware (http://www.infospyware.com/Anti-Malwares.htm) se recomienda combofix. El enlace lleva a Bleeping Computer - Computer Help and Discussion (http://www.bleepingcomputer.com/), donde mora el creador de esta herramienta ..Hay que registrarse. Una vez hecho intentamos encontrar en la seccion de resources esta herramienta, pero no la encontramos de modo alguno.
En Help: MSNETAX.DLL Reinfected - PC Pitstop Forums (http://forums.pcpitstop.com/index.php?showtopic=135956&st=20&p=1336865&#entry1336865) , se lee en un mensaje de marzo:
"ComboFix was pulled out of public use. Do not run ComboFix!! If you have it in your system, please remove it." (esto se debio la existencia de versiones infectantes)
En Combofix-changed My Default Browser Settings? (http://www.bleepingcomputer.com/forums/topic80709.html) :
Feb 8 2007, 03:12 PM
"Do you know what to look for? Who asked you to download and run Combofix? What problems are you having that you needed to use it? This is an advanced tool normally used by experts who are helping others to investigate and remove malware infections in the Hijackthis forum. It is
intended to be used under the guidance and supervision of an expert, not for private use"
2)ANTIVIRUS, CAMBIOS EN EL REGISTRO NO DESEADOS Y VERSIONES PELIGROSAS
En Combofix-changed My Default Browser Settings? (http://www.bleepingcomputer.com/forums/topic80709.html):
Feb 8 2007, 10:46 AM
zorandjr:
"I have downloaded Combofix.exe from this address
http://download.bleepingcomputer.com/sUBs/combofix.exe (la C seria mayuscula)
I have scanned with it and got a report,nothing found I think- no indication in the report
But after scanning with it , IE icon showed up on Desktop and Firefox reported that it is not Default browser ,and my IE home page changed from Blank to MSN, and this is what I have discovered for now.
Is this normal or I did something wrong? [Esto tambien me sucedio a mi tras ejecutar durante unos instantes otra version buena de combofix al descubrir que la que habia ejecutado anteriormente era una version erronea e infectante con un rootkit, como veremos mas adelante]
(..)
Second question is- Do you know why I have this from UNA at Virustotal.com:
UNA -1.83 -01.30.2007 Trojan.Win32.Agent.BA1E (and today too) for DrWeb Cure-it?
This was something that happened once before when I accidentally emailed Stinger, Combofix and Vcleaner/grisoft/ to Virustotal - but from ESafe( -Trojan/Worm)"
Yo hize la prueba y me salian resultados similares:
zorandjr
Feb 8 2007, 02:00 PM
"and the almost the same for combofix.exe, as the last time
Complete scanning result of "combofix.exe", received in VirusTotal at 02.08.2007, 18:45:06 (CET)
AntiVir 7.3.1.34 02.08.2007 no virus found
Authentium 4.93.8 02.07.2007 no virus found
Avast 4.7.936.0 02.08.2007 no virus found
AVG 386 02.08.2007 no virus found
BitDefender 7.2 02.08.2007 no virus found
CAT-QuickHeal 9.00 02.08.2007 no virus found
ClamAV devel-20060426 02.08.2007 no virus found
DrWeb 4.33 02.08.2007 no virus found
eSafe 7.0.14.0 02.08.2007 suspicious Trojan/Worm
eTrust-InoculateIT 30.4.3378 02.08.2007 no virus found
eTrust-Vet 30.4.3378 02.08.2007 no virus found
Ewido 4.0 02.08.2007 no virus found
Fortinet 2.85.0.0 02.08.2007 no virus found
F-Prot 4.2.1.29 02.07.2007 no virus found
F-Secure 6.70.13030.0 02.08.2007 no virus found
Ikarus T3.1.0.31 02.08.2007 Trojan-Dropper.Win32.Delf.FZ
Kaspersky 4.0.2.24 02.08.2007 no virus found
McAfee 4959 02.08.2007 no virus found
Microsoft 1.2101 02.08.2007 no virus found
NOD32v2 2046 02.08.2007 no virus found
Norman 5.80.02 02.08.2007 no virus found
Panda 9.0.0.4 02.08.2007 Suspicious file
Prevx1 V2 02.08.2007 no virus found
Sophos 4.13.0 02.08.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.08.2007 no virus found
TheHacker 6.1.6.053 02.07.2007 no virus found
UNA 1.83 02.08.2007 Trojan.BAT.Small.BC0B
VBA32 3.11.2 02.08.2007 no virus found
VirusBuster 4.3.19:9 02.08.2007 no virus found "
(....)
zorandjr
Feb 20 2007, 02:48 PM
"Should I be worried about this:
QUOTE
The tool, ComboFix has been temporarily withdrawn.
The author discovered a rootkit infection that will intefere with ComboFix's running.
This will cause Combofix to be UNSAFE FOR USE on your machine.
Even if you manage to find a mirror for the tool, PLEASE DO NOT RUN THIS TOOL
Apologies for any inconvenience caused
and
QUOTE
I have just encountered a rootkit that will cause CF to recursively delete all files from
SystemDrive.
Pulling the tool till further notice.
Please inform your users not to use CF. Who knows if that rootkit is in there.
Please spread the word. Also have users delete their copies of CF
?
I have scanned recently, not with combofix.Nothing was found.
Everything was slower, mainly downloads, after my mistake with combofix."
En otro hilo (Combofix Question. (http://www.bleepingcomputer.com/forums/topic81560.html)), posteriormente:
Mar 8 2007, 11:03 PM
howard hopkinso
"Just to let everyone know. Combofix has now been fixed and is safe to use once more.
Regards Howard" [Aun asi se demuestra la existencia de versiones peligrosas]
En Combofix.exe (http://www.bleepingcomputer.com/forums/topic98878.html)
, miekiemoes dice que los resultados de los antivirus son falsos positivos
Jul 17 2007, 03:29 PM
"Yes, that are false positives. Most Vendors flag the NirCmd.exe that Combofix uses as suspicious.
Nothing wrong with nircmd.exe : NirCmd - Freeware command-line tool (http://www.nirsoft.net/utils/nircmd.html) "
3)FALLOS GRAVES DEL PROGRAMA
En Log Looks Dirty (http://www.bleepingcomputer.com/forums/topic98959.html), el usuario iblah presenta una serie de problemas.
d-trojanator responde,entre otras cosas:
Jul 7 2007, 09:53 AM
Please download Combofix to your desktop.
Doubleclick combofix.exe to launch the application.
iblah responde que tiene problemas con el combofix:
Jul 7 2007, 06:28 PM
"I did all but combofix. I let it run for 30 mins and got impatient so I closed it, restarted my computer, ran it again and took off for a few hours. When I came back it was still scanning so I just closed it.(...)combofix also reset my time settings to 24hours "
Mas tarde:
d-trojanator:
Jul 10 2007, 02:37 PM
"Ok let's try that. Delete combofix from your desktop, along with the "C:\ComboFix" folder.
Redownload combofix from the above link, and rerun it a per previous instructions..
If it doesn't work, don't worry - I will get the tool author to have a look."
(..a iblah le sigue sin furular...)
d-trojanator:
Jul 12 2007, 06:36 PM
"Sorry for the delay in getting back to you, I've been in contact with the author of combofix and it's been a struggle trying to find what's wrong with the tool.
I'm going to need to get a couple of samples off you before we continue with the fix, please bear with me."
(...d-trojanator sigue tratando el problema....)
Jul 13 2007, 03:45 PM
iblah:
"Okay I deleted ~.exe and let combofix run for about an hour and still got nothing. =S "
En Log Looks Dirty (http://www.bleepingcomputer.com/forums/topic98959-15.html) , ya llega Subs, el creador del programa y Se disculpa por crear esa "estupida herramienta":
Jul 13 2007, 03:54 PM
Subs:
"Hello, I'm sUBs. I apologise for making that stupid tool, ComboFix that's currently tormenting you" y explica una serie de acciones con un programa creado por él que mientras corre ejecutan el combofix parcheandolo y con otro programa en caso de que falle el primero.
Posteriormente subs le recomienda otro programa mas que ha creado para reportar los fallos del combofix, que iblah consigue ejecutar no sin problemas..
IMPORTANTE:
Jul 15 2007, 04:49 PM
Subs:
"iblah, how are things on your side? Still getting ComboFix hangs?
If it still persist, I will have to make you a special copy of ComboFIx that'll skip that subroutine. "
En resumen: Es una herramienta NO PUBLICA,que produce cambios en el registro que pueden no ser deseados, con bugs de programacion actualmente y con versiones existentes que infectan el ordenador.
Me parecio de interés (además de obligado) dar a conocer estas informaciones,ya que infospyware recomienda este programa.
SAludos
El caso es que mi ordenador fue infectado por el asqueroso totour.exe, un virus complejo y dificil de eliminar y que incluye varios troyanos. Consegui neutralizar los troyanos y el envio residente por smtp ,mientras me tomaba un tiempo para estudiar el tema con posterioridad..Luego,durante la ideación del proceso de limpieza total de mi disco duro (listando acciones de varios programas que me habia ido bajando), ejecute el combofix (en el foro de superantyspyware lo sugerian para un caso como el mio) para poder descartar o no su uso. No recordaba haber encontrado mucha informacion sobre la utilidad real de este programa y en la confianza de que tenia que tratarse de una herramienta segura, cometi la ligereza de ejecutarla.
Resultado: los varios troyanos que habia descargado el totour resucitaron del registro...No tarde mucho en arreglarlo, pero más tarde busque mas informacion sobre el programa combofix y lo que me habia sucedido. Encontre esto en foros en inglés (no traduzco las citas, pero se entiende bastante bien):
1)Herramienta no publica
En Anti-Malwares - Info Spyware (http://www.infospyware.com/Anti-Malwares.htm) se recomienda combofix. El enlace lleva a Bleeping Computer - Computer Help and Discussion (http://www.bleepingcomputer.com/), donde mora el creador de esta herramienta ..Hay que registrarse. Una vez hecho intentamos encontrar en la seccion de resources esta herramienta, pero no la encontramos de modo alguno.
En Help: MSNETAX.DLL Reinfected - PC Pitstop Forums (http://forums.pcpitstop.com/index.php?showtopic=135956&st=20&p=1336865&#entry1336865) , se lee en un mensaje de marzo:
"ComboFix was pulled out of public use. Do not run ComboFix!! If you have it in your system, please remove it." (esto se debio la existencia de versiones infectantes)
En Combofix-changed My Default Browser Settings? (http://www.bleepingcomputer.com/forums/topic80709.html) :
Feb 8 2007, 03:12 PM
"Do you know what to look for? Who asked you to download and run Combofix? What problems are you having that you needed to use it? This is an advanced tool normally used by experts who are helping others to investigate and remove malware infections in the Hijackthis forum. It is
intended to be used under the guidance and supervision of an expert, not for private use"
2)ANTIVIRUS, CAMBIOS EN EL REGISTRO NO DESEADOS Y VERSIONES PELIGROSAS
En Combofix-changed My Default Browser Settings? (http://www.bleepingcomputer.com/forums/topic80709.html):
Feb 8 2007, 10:46 AM
zorandjr:
"I have downloaded Combofix.exe from this address
http://download.bleepingcomputer.com/sUBs/combofix.exe (la C seria mayuscula)
I have scanned with it and got a report,nothing found I think- no indication in the report
But after scanning with it , IE icon showed up on Desktop and Firefox reported that it is not Default browser ,and my IE home page changed from Blank to MSN, and this is what I have discovered for now.
Is this normal or I did something wrong? [Esto tambien me sucedio a mi tras ejecutar durante unos instantes otra version buena de combofix al descubrir que la que habia ejecutado anteriormente era una version erronea e infectante con un rootkit, como veremos mas adelante]
(..)
Second question is- Do you know why I have this from UNA at Virustotal.com:
UNA -1.83 -01.30.2007 Trojan.Win32.Agent.BA1E (and today too) for DrWeb Cure-it?
This was something that happened once before when I accidentally emailed Stinger, Combofix and Vcleaner/grisoft/ to Virustotal - but from ESafe( -Trojan/Worm)"
Yo hize la prueba y me salian resultados similares:
zorandjr
Feb 8 2007, 02:00 PM
"and the almost the same for combofix.exe, as the last time
Complete scanning result of "combofix.exe", received in VirusTotal at 02.08.2007, 18:45:06 (CET)
AntiVir 7.3.1.34 02.08.2007 no virus found
Authentium 4.93.8 02.07.2007 no virus found
Avast 4.7.936.0 02.08.2007 no virus found
AVG 386 02.08.2007 no virus found
BitDefender 7.2 02.08.2007 no virus found
CAT-QuickHeal 9.00 02.08.2007 no virus found
ClamAV devel-20060426 02.08.2007 no virus found
DrWeb 4.33 02.08.2007 no virus found
eSafe 7.0.14.0 02.08.2007 suspicious Trojan/Worm
eTrust-InoculateIT 30.4.3378 02.08.2007 no virus found
eTrust-Vet 30.4.3378 02.08.2007 no virus found
Ewido 4.0 02.08.2007 no virus found
Fortinet 2.85.0.0 02.08.2007 no virus found
F-Prot 4.2.1.29 02.07.2007 no virus found
F-Secure 6.70.13030.0 02.08.2007 no virus found
Ikarus T3.1.0.31 02.08.2007 Trojan-Dropper.Win32.Delf.FZ
Kaspersky 4.0.2.24 02.08.2007 no virus found
McAfee 4959 02.08.2007 no virus found
Microsoft 1.2101 02.08.2007 no virus found
NOD32v2 2046 02.08.2007 no virus found
Norman 5.80.02 02.08.2007 no virus found
Panda 9.0.0.4 02.08.2007 Suspicious file
Prevx1 V2 02.08.2007 no virus found
Sophos 4.13.0 02.08.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.08.2007 no virus found
TheHacker 6.1.6.053 02.07.2007 no virus found
UNA 1.83 02.08.2007 Trojan.BAT.Small.BC0B
VBA32 3.11.2 02.08.2007 no virus found
VirusBuster 4.3.19:9 02.08.2007 no virus found "
(....)
zorandjr
Feb 20 2007, 02:48 PM
"Should I be worried about this:
QUOTE
The tool, ComboFix has been temporarily withdrawn.
The author discovered a rootkit infection that will intefere with ComboFix's running.
This will cause Combofix to be UNSAFE FOR USE on your machine.
Even if you manage to find a mirror for the tool, PLEASE DO NOT RUN THIS TOOL
Apologies for any inconvenience caused
and
QUOTE
I have just encountered a rootkit that will cause CF to recursively delete all files from
SystemDrive.
Pulling the tool till further notice.
Please inform your users not to use CF. Who knows if that rootkit is in there.
Please spread the word. Also have users delete their copies of CF
?
I have scanned recently, not with combofix.Nothing was found.
Everything was slower, mainly downloads, after my mistake with combofix."
En otro hilo (Combofix Question. (http://www.bleepingcomputer.com/forums/topic81560.html)), posteriormente:
Mar 8 2007, 11:03 PM
howard hopkinso
"Just to let everyone know. Combofix has now been fixed and is safe to use once more.
Regards Howard" [Aun asi se demuestra la existencia de versiones peligrosas]
En Combofix.exe (http://www.bleepingcomputer.com/forums/topic98878.html)
, miekiemoes dice que los resultados de los antivirus son falsos positivos
Jul 17 2007, 03:29 PM
"Yes, that are false positives. Most Vendors flag the NirCmd.exe that Combofix uses as suspicious.
Nothing wrong with nircmd.exe : NirCmd - Freeware command-line tool (http://www.nirsoft.net/utils/nircmd.html) "
3)FALLOS GRAVES DEL PROGRAMA
En Log Looks Dirty (http://www.bleepingcomputer.com/forums/topic98959.html), el usuario iblah presenta una serie de problemas.
d-trojanator responde,entre otras cosas:
Jul 7 2007, 09:53 AM
Please download Combofix to your desktop.
Doubleclick combofix.exe to launch the application.
iblah responde que tiene problemas con el combofix:
Jul 7 2007, 06:28 PM
"I did all but combofix. I let it run for 30 mins and got impatient so I closed it, restarted my computer, ran it again and took off for a few hours. When I came back it was still scanning so I just closed it.(...)combofix also reset my time settings to 24hours "
Mas tarde:
d-trojanator:
Jul 10 2007, 02:37 PM
"Ok let's try that. Delete combofix from your desktop, along with the "C:\ComboFix" folder.
Redownload combofix from the above link, and rerun it a per previous instructions..
If it doesn't work, don't worry - I will get the tool author to have a look."
(..a iblah le sigue sin furular...)
d-trojanator:
Jul 12 2007, 06:36 PM
"Sorry for the delay in getting back to you, I've been in contact with the author of combofix and it's been a struggle trying to find what's wrong with the tool.
I'm going to need to get a couple of samples off you before we continue with the fix, please bear with me."
(...d-trojanator sigue tratando el problema....)
Jul 13 2007, 03:45 PM
iblah:
"Okay I deleted ~.exe and let combofix run for about an hour and still got nothing. =S "
En Log Looks Dirty (http://www.bleepingcomputer.com/forums/topic98959-15.html) , ya llega Subs, el creador del programa y Se disculpa por crear esa "estupida herramienta":
Jul 13 2007, 03:54 PM
Subs:
"Hello, I'm sUBs. I apologise for making that stupid tool, ComboFix that's currently tormenting you" y explica una serie de acciones con un programa creado por él que mientras corre ejecutan el combofix parcheandolo y con otro programa en caso de que falle el primero.
Posteriormente subs le recomienda otro programa mas que ha creado para reportar los fallos del combofix, que iblah consigue ejecutar no sin problemas..
IMPORTANTE:
Jul 15 2007, 04:49 PM
Subs:
"iblah, how are things on your side? Still getting ComboFix hangs?
If it still persist, I will have to make you a special copy of ComboFIx that'll skip that subroutine. "
En resumen: Es una herramienta NO PUBLICA,que produce cambios en el registro que pueden no ser deseados, con bugs de programacion actualmente y con versiones existentes que infectan el ordenador.
Me parecio de interés (además de obligado) dar a conocer estas informaciones,ya que infospyware recomienda este programa.
SAludos