Quote:
|
It continued running ok until ComboFix rebooted Windows. I assumed at that point that it was done so I entered my user id under the Windows logon screen. This resulted in 16 lines of 'access denied'. Also, my firewall, COMODO turned back on. (I'm not sure how I could have prevented this unless logging on with my id was responsible). I then got a series of error messages such as 'nircmd.com not recognizable as an internal or external command and a couple of other similar errors.
|
Nircmd is tool which is embedded into ComboFix. It's a freeware command-line utility published by Nirsoft (
website). Google has many hits of
articles about it. Nircmd has multiple features & some malicous software of past has misused it. Thus, some security vendors has listed Nircmd as 'riskware' (potentially unwanted tool). I submitted Nircmd to a comprehensive online scan performed by 36 security vendors. This was the report >
http://www.virustotal.com/analisis/3...4e0f0cdfd18275 . 9/36 detected it but 2 falsely identified it as a trojan.
I don't really know how to say this without sounding disparaging. Comodo is
supposed to be a protection program. It's akin to rearing a large dog to safeguard the home. While it's good that my large scary dog will deter would-be burglars, it's bad when this 'appointed protector' doesn't listen to it's master's instructs.
ComboFix is a malware removal tool. It's one of the most powerful file removers out there. That's the reason why we don't advocate users running ComboFix on their own initiative. When a user runs ComboFix, it's a bit like launching a nuclear missile in the system. If this missile finds, targets & destroys malware files, then all is well and good. If something messes with the missile's guidance system, we wont know what it will detect/target. ComboFix does have the ability to render machines to doorstops.
Quote:
|
I then logged on using an administrative id and repeated the whole process. Same result. Here's the error message received. PS, I disabled COMODO, my security package both times.
|
This is a good example depicting how the guard dog doesn't obey instructs. It hasn't been able to deal with infection currently on the machine but it interferes with another tool from trying to do so. For us to safely continue running ComboFix on this machine, I must request that Comodo be temporarily be uninstalled. I cannot take the risk that Comodo may cause ComboFix to perform a series of false deletions.
Please let me know if you're agreeable to the idea.
__________________
Question - what have you done for the community today?