Just a question (probably already answered thousand times).
What does exactly that Combofix do? I saw much fuss around it but never saw any post explaining how to use or what it does or how it does that. Maybe it's a nice tool to have
Is there any tutorial, documentation or something about it? Any where to download it?
There is a lot of documentation on it, 162 A4 pages to be precise and ever growing as malware continues to develop. But this information is locked deep within the realms of the malware removal universities who allow their students (including me

) to access them. It is heavily controlled because it is a very powerful tool that is highly effective against a lot of today's malware - revealing how it works to the general public isn't the best of ideas as we'd see malware adapt very quickly to avoid detection by CF. Other, less intrusive, malware removal tools, however, have public tutorials:
HijackThis Tutorial - How to use HijackThis to remove Browser Hijackers & Spyware
There is further information held privately by the universities, but most of it is in that tutorial.
If you are interested in learning to use CF, and other malware removal tools (OTL, DDS, GMER etc.) then drop me a message and I'll tell you about how to enrol with a malware removal university.
I've never had any training with it. I have used it on several machines to recover from bad virus intrusion where the AV just wasn't enough to fix it. I wouldn't send that kind of warning out unless you are referring to a network situation. Then I would let the HMIC take care of it. On your own machine, I wouldn't use it unless it was a last resort but I wouldn't be sending fear out like the OP did.
Why wouldn't you send that warning out unless the computer was networked? I've quoted it before, and I'll quote it again:
ComboFix is a very powerful tool which when improperly used may render your machine to a doorstop.
We first need to verify if there are any rootkits present and how they could affect our tools. Thus, we use preliminary scans like DDS and GMER and their logs to map our strategy for attack.
With these logs, we can determine the infections present and decide whether to deploy ComboFix
Written by sUBs, the author of CF. If you wish to ignore our opinions (which I personally think would be an absurd thing to do seeing as the warning was written by an MVP), then surely you'll agree that the author of CF might just have a point here - after all, he did make the thing.
I've never had any training with it. I have used it on several machines to recover from bad virus intrusion where the AV just wasn't enough to fix it. I wouldn't send that kind of warning out unless you are referring to a network situation. Then I would let the HMIC take care of it. On your own machine, I wouldn't use it unless it was a last resort but I wouldn't be sending fear out like the OP did.
The OP is a Security expert, and a MVP. I can't get over people saying, "I used it myself, and had no problems". As if that means that will be the case for everyone. The original warning was for a valid reason, and it still applies. A Guy
You will note that in my post I said "I wouldn't send that kind of warning out unless you are referring to a network situation. Then I would let the HMIC take care of it." HMIC = Head man in charge. That would be the expert. on your own PC, you should be fine. I also said that I have used it on several machines as a last resort. Which makes me an expert on personal use of the program. I've used it on everything from 98SE to 7 and have never had an issue when used at default settings.
I think that's a very bold statement to make seeing as you don't know how to use CF properly. CF isn't designed to be a one size fits all style of program, it's designed to be used under supervision of a trained expert as they will know what to look for, and do, with a log. Tell us, how do you know that your computer is fully clean?
on your own PC, you should be fine.
False. On your own PC you
MAY be fine. I am amazed that you disagree with trained windows security experts, and feel the need to continue to belabor the issue.
I also said that I have used it on several machines as a last resort. Which makes me an expert on personal use of the program. I've used it on everything from 98SE to 7 and have never had an issue when used at default settings.
False. It means you have used it with no apparent issues, at least so you say. It in no way makes you an expert of any kind. We have hundreds of thousands of visitors here. We do not want to condone using Combofix on your own. Everyone has the right to do so if they please. But we will still warn them of the dangers!
A Guy
Tom