Need Info about structure of Symantec Quarantine Files (*.vbn)
Created: 28 Oct 2010 | 3 comments
Hi all,
I am working on an incident where th suspect might have used some sort of trojan.
For whatever reason the quarantine folder was touched. If I try to extract the suspicious file out of the quarantine archive with QEXTRACT I only get error messages.
I started to analyze the vbn-files and was able to decrypt the XOR.
However I can not see where the quarantined file itself starts inside the vbn-data.
I would REALLY appreciate if someone could give me a hint, if there is an offset stored to the file-data and where to find it
Thanks in advance!
regards
Marc
Discussion Filed Under:
Comments 3 Comments • Jump to latest comment
Thanks & Regards Sandip C Sali
to extract the file
you can use the sep interface
click on quarentine; you will see the list of files which are quarantined
you can restore the file ,,,,
is that why u r looking for ?
Please don't forget to mark your thread solved with whatever answer helped you : ) Rafeeq
thanks for your replies...
as I mentioned, the quarantine-folder seems to be corrupted (either by the suspect or an admin...).
There are only the {session-id}-folders, the {session-id}.vbn-files are missing.
Thus I can not recover the quarantined files neither with SEP nor QEXTRACT.
Due to internal regulations I can NOT just submit the vbn-files to Symantec for extraction.
For forensic reasons I have to show that the vbn-contents are the files we're looking for.
Sorry for Symantec, but I already was able to "decrypt" the vbn-file contents with some test-viruses.
But I can't see where exactly the encrypted virus-file is stored in the vbn-file - it seems to change every time...
thats why I am asking for some insider-information regarding the vbn-file structure.
(if needed, it can be sent to my official email-account, additionally I assure non-disclosure!!)
best regards
Marc
Would you like to reply?
Login or Register to post your comment.