Windows 10 bug corrupts your hard drive on seeing this file's icon

Discussion in 'malware problems & news' started by zapjb, Jan 14, 2021.

  1. zapjb

    zapjb Registered Member

    Joined:
    Nov 15, 2005
    Posts:
    5,556
    Location:
    USA still the best. But barely.
    Windows 10 bug corrupts your hard drive on seeing this file's icon
    https://www.bleepingcomputer.com/ne...ts-your-hard-drive-on-seeing-this-files-icon/

    "An unpatched zero-day in Microsoft Windows 10 allows attackers to corrupt an NTFS-formatted hard drive with a one-line command.

    In multiple tests by BleepingComputer, this one-liner can be delivered hidden inside a Windows shortcut file, a ZIP archive, batch files, or various other vectors to trigger hard drive errors that corrupt the filesystem index instantly..."
     
  2. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    I read from people submiting bug reports to Microsoft's bug bounty that Microsoft is underestimating bugs on purpose and sometimes patching vulnerabilities just before processing bug reports so they don't have to acknowledge and pay for them.
     
  3. Floyd 57

    Floyd 57 Registered Member

    Joined:
    Mar 17, 2017
    Posts:
    1,296
    Location:
    Europe
    i mean if they already have the vulnerabilities fixed, assuming they didnt get em from the bug reports, then why not
     
  4. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    This sounds crazy, how can such a simple command corrupt the file system? I also wonder if you can perhaps block this with HIPS by denying direct access to disk.
     
  5. MisterB

    MisterB Registered Member

    Joined:
    May 31, 2013
    Posts:
    1,267
    Location:
    Southern Rocky Mountains USA
    This doesn't surprise me. And meanwhile, I've been writing and copying 100s of gigabytes in 1000s of files to NTFS volumes with Debian and after 8 months, not a single error.
     
  6. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    518
    Location:
    Bulgaria
    I thought the same thing but I guess it will not work since this is internal bug in the NTFS itself and not execution of a third-party code. It should be tested tho.
    Also if chkdsk fails to repair the MFT I am wondering if TestDisk would help here:

    Advanced NTFS Boot and MFT Repair
    https://www.cgsecurity.org/wiki/Advanced_NTFS_Boot_and_MFT_Repair

    At least MS is working on a fix.

    Microsoft to fix Windows 10 bug that can corrupt a hard drive just by looking at an icon
    https://www.theverge.com/2021/1/15/22232589/microsoft-ntfs-windows-10-bug-icon-file-flaw-vulnerability-comment

    I am not worried since I have a full system image with Macrium Reflect but it would be nice to have this annoying thing fixed.
     
  7. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes it depends if it needs ''direct access" to disk in the first place. For example SpyShelter does monitor this, I rarely get this alert though. Only system tools like SpeedFan and HWiNFO needed it on my system.
     
  8. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    My advice is read the posted comments in the bleepingcomputer.com article like this one:
    Appears only certain Win OS versions are adversely affected by this. Also appears SSD's versus HDD's are also more affected.
     
  9. B-boy/StyLe/

    B-boy/StyLe/ Registered Member

    Joined:
    Sep 19, 2012
    Posts:
    518
    Location:
    Bulgaria
    I know what you mean. I have Comodo Firewall which also monitoring for "Direct Disk Access" but if this access is requested by the OS itself I guess that I will not see a pop-up from Comodo. That's why I said this should be tested but I don't have VirtualBox/VMWare system at the moment.

    I have read it but in the comments section I noticed that even Windows XP with NTFS is affected as well but the results vary from system to system.
     
  10. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    It might be informative to note what :$i30:$bitmap is used for: https://www.osforensics.com/faqs-and-tutorials/how-to-scan-ntfs-i30-entries-deleted-files.html .

    What appears to be happening with this cd use of:$i30:$bitmap is the NTFS file index is being corrupted somehow. Now cd is the DOS command for change directory. What is a bit amazing is that the command would not give some type of access error or the like when tying to directly access the NTFS file index.
     
  11. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
  12. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    hi, plat. there's also this one in case you missed it too:
    https://www.wilderssecurity.com/thr...your-pc-when-you-access-this-location.435964/
     
  13. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Oh wow, OK thanks. My post is just a follow up to these articles, detailing a "temporary fix" by a third party on GitHub. Hopefully, no one around here would need it. :eek:
     
  14. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    yeah, i hope so too. thanks for your follow up.
     
  15. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
  16. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Installed this driver on Win 10 x(64) 20H2 w/o any issues. Rebooted to insure there were no additional issues.

    Note if looking for this driver when loaded, it is a File System driver. Also driver is both Microsoft and vendor signed. As such, there should be no problems w/Secure Boot.

    NTFS_Driver.png
     
    Last edited: Jan 26, 2021
  17. SouthPark

    SouthPark Registered Member

    Joined:
    Jun 13, 2012
    Posts:
    737
    Location:
    South Park, CO
    I also installed the OSR driver on Windows 10 x64 20H2 and restarted, no problems observed. (I use Microsoft Defender but haven't been able to determine if it has a detection for the malicious string.)
     
  18. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  19. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
  20. plat

    plat Registered Member

    Joined:
    Dec 19, 2018
    Posts:
    2,233
    Location:
    Brooklyn, NY
    Excellent, that's a load off. Thanks imdb. :)
     
  21. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    you're welcome. :thumb:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.