Windows 10: Tricking antivirus solutions into deleting the wrong files on Windows

Discus and support Tricking antivirus solutions into deleting the wrong files on Windows in Windows 10 News to solve the problem; Security research Or Yair discovered a method to trick antivirus and endpoint security solutions into deleting legitimate files on Windows systems.... Discussion in 'Windows 10 News' started by GHacks, Dec 11, 2022.

  1. GHacks
    GHacks New Member

    Tricking antivirus solutions into deleting the wrong files on Windows


    Security research Or Yair discovered a method to trick antivirus and endpoint security solutions into deleting legitimate files on Windows systems. Yair found out that he could manipulate endpoint detection and response and antivirus programs so that these programs would function as data wipers on Windows devices.

    Tricking antivirus solutions into deleting the wrong files on Windows file-wiper-security-threat-windows.png
    Prompt for Reboot. Source: SafeBreach Labs

    The discovered security issue can be exploited from unprivileged user accounts to delete system files and other files the user has no delete permissions for. The exploit could be used to remove important files from a system and this could result in an unbootable system or a system that lacks certain functionality.

    Classified as a data wiper, a class of malware designed to erase data on computer systems, its main purpose is destruction. Wipers are commonly used in cyber warfare, often to support physical aggression or to target the enemy's infrastructure.

    Wipers need to bypass certain protections, including those provided by a user permission system but also defenses that are in place to protect against unauthorized deletions of files. Additionally, to make sure that files can't be recovered, wipers need to overwrite file contents.

    Endpoint security and antivirus solutions would make excellent file wipers, if security issues could be exploited to use their privileges and capabilities. Yair had several ideas in this regard, but most were not practicable. Some required elevated privileges, others write access to the files in question.

    The main idea that he came up with was to create a malicious file in a temporary directory, and to redirect it to an important file on the system between the time the security solution detected the threat and deleted it. This method did not work out as planned initially, as some security solutions prevented access to detected files while others detected the deletion of the file and dismissed the pending action.

    Yair's solution was to keep the file open, so that it could not be deleted by the security solutions right away. The security programs would prompt for a reboot in that case so that the malicious file could be accessed and deleted. Files are added to a specific key in the Registry, so that Windows knows what to delete during the boot phase. Yair discovered that the deletion process would follow junctions, created to point the delete operation to a legitimate file.

    In other words, all it took to delete legitimate files on Windows was the following:

    1. Create a malicious file on the system using a special path.
    2. Hold it open so that security solutions can't delete it.
    3. Delete the directory.
    4. Create a junction that points from the deleted directory to another.
    5. Reboot.

    Yair tested 11 different security and endpoint solutions. Six of these were vulnerable to the file wiping exploit, including Microsoft Defender, Microsoft Defender for Endpoint, Avast Antivirus, SentinelOne EDR and TrendMicro Apex One. Microsoft, TrendMicro and Avast/AVG released updates already to address the issue.

    Now You: which security solution(s) do you use? (via Bleeping Computer)

    Thank you for being a Ghacks reader. The post Tricking antivirus solutions into deleting the wrong files on Windows appeared first on gHacks Technology News.

    read more...
     
    GHacks, Dec 11, 2022
    #1
  2. MohanC Win User

    windows 10 deleted my desktop files

    Step 1 - I upgraded to Win 10 and lost all my files on Desktop.

    Step 2 - Found the files in Network - USers- Desktop

    copied all files again to desktop.

    Step 3- Restarted my machine again and lost desktop files again.

    Step 4 - As suggested did the following as listed below but dont find my files.

    • Press “Windows + E”, open This PC/Computer
    • Open Local Disc C, open Windows.old
    • Click on Users, select your User name
    • Go to desktop folder
    Cant find my files. Why is Win 10 deleted files again and again from Desktop ?.
     
    MohanC, Dec 11, 2022
    #2
  3. Anusha Win User
    C windows installer folder - Delete?

    He can do symbolic link redirection and move the files in it to a different location. *Wink Tricking antivirus solutions into deleting the wrong files on Windows ;)
    Better try it out in a virtual of first. Just a suggestion.

    Like:
    First move everything in c:\windows\installer to d:\installercache
    Then delete c:\windows\installer folder
    Then type this in command mode as admin
    mklink /d c:\windows\installer d:\installercache

    Removing those installer files is a bad idea. it might prevent you from updating or uninstalling apps.
     
    Anusha, Dec 11, 2022
    #3
  4. Alden Rey Win User

    Tricking antivirus solutions into deleting the wrong files on Windows

    deleting hard drive files

    Hi,

    May we know what type of file are you trying to delete? Would it be Office documents, media files, or picture files? If you're trying to delete files for free some space on your device. We suggest to perform a Disc Cleanup. Kindly follow the steps below to
    perform the task:

    • Type in Cortana Disc Cleanup
    • Choose the files to delete
    • Click on "Clean up system files"
    • Click on Ok

    For any concerns, don't hesitate to get back to us.

    Regards.
     
    Alden Rey, Dec 11, 2022
    #4
Thema:

Tricking antivirus solutions into deleting the wrong files on Windows

Loading...
  1. Tricking antivirus solutions into deleting the wrong files on Windows - Similar Threads - Tricking antivirus solutions

  2. Is it possible to use a cleaner program as an antivirus solution?

    in Windows 10 Gaming
    Is it possible to use a cleaner program as an antivirus solution?: Is it feasible to utilize a cleaner as an alternative to an antivirus program?Why and why not? https://answers.microsoft.com/en-us/windows/forum/all/is-it-possible-to-use-a-cleaner-program-as-an/67476635-47c1-4c0c-9663-4e80ae072b35
  3. Something went wrong with no solution

    in Windows 10 Gaming
    Something went wrong with no solution: Trying to finish the set up on my computer however when I open store and download anything it says something went wrong. I cant finish since I cant download anything even im using Microsoft account for log in and in store....
  4. Something went wrong with no solution

    in Windows 10 Software and Apps
    Something went wrong with no solution: Trying to finish the set up on my computer however when I open store and download anything it says something went wrong. I cant finish since I cant download anything even im using Microsoft account for log in and in store....
  5. Something went wrong with no solution

    in Microsoft Windows 10 Store
    Something went wrong with no solution: Trying to finish the set up on my computer however when I open store and download anything it says something went wrong. I cant finish since I cant download anything even im using Microsoft account for log in and in store....
  6. Something is wrong with the Microsoft Defender Antivirus.

    in AntiVirus, Firewalls and System Security
    Something is wrong with the Microsoft Defender Antivirus.: It detects Utorront as PUA Potential Unwanted App while it is not. https://answers.microsoft.com/en-us/protect/forum/all/something-is-wrong-with-the-microsoft-defender/10f32442-4568-4669-b0ea-82c50b97749c
  7. Antivirus deletion

    in Windows 10 Installation and Upgrade
    Antivirus deletion: Sir how to delete SysWOW64/msi.dll from my windows 10 https://answers.microsoft.com/en-us/windows/forum/all/antivirus-deletion/461c37d1-1ae2-4096-a37c-485292e25b4e
  8. [Solution] How to delete other file on Windows 10

    in Windows 10 Network and Sharing
    [Solution] How to delete other file on Windows 10: i Solved other file hidden file storage on windows 10 issue as per below image Download https://www.jam-software.com/treesize_free Run as administration-select C drive Locate -$GetCurrent-right clickdelete this folder & solved the issue for me [ATTACH]...
  9. Avast antivirus solution

    in Windows 10 Network and Sharing
    Avast antivirus solution: How Can I Fix Avast Antivirus Error 7? https://answers.microsoft.com/en-us/windows/forum/all/avast-antivirus-solution/9cef230e-4f8d-45ca-ab3e-dc847220bc28
  10. can't delete files in the wrong place

    in Windows 10 Support
    can't delete files in the wrong place: two files have appeared inside my lifelock program and i can't delete them. other ways to delete than using the delete button? ETA: sorry. the program is folderlock. 68303