Bootstrapper.exe attempted to delete a Volume Shadow Snapshot as reported by Crowdstrike - is this a ransomware or a false positive?

Anonymous
2025-01-16T03:32:20+00:00

Crowdstrike Falcon has reported a medium level vulnerability Bootstrapper.exe attempted to delete a Volume Shadow Snapshot on a Windows 11 laptop. The operation was blocked by Crowdstrike.

The question is if this is a security incident/vulnerability or a false positive?

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

6 answers

Sort by: Most helpful
  1. Anonymous
    2025-01-16T07:21:58+00:00

    Hi ankhilesh, welcome in community

    I'm Alvise, an independent consultant and i'm eager to support you today

    Strange, Can you run other scans with other software such as malwarebytes or similar?

    In what path does this executable turn out? This is usually a trusted file used by the operating system

    Let me know

    Elvis

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2025-01-17T00:29:25+00:00

    Thanks Rob for sharing this. I reviewed some searches but wasn't very clear. It looks like this is standard practice to delete the old backups once space becomes an issue but also saw that in some cases ransomware is the one trying to delete this backup. Wanted to understand how can I be sure and if any file (like in my case Bootstrapper and Optionalfeatures) are doin this and if it should be treated as false postive or not.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2025-01-16T23:21:28+00:00

    Rather than try to provide this via the forums directly, I'll include the following search done via DuckDuckGo, since it lists not only the Microsoft Community forums threads I recall having seen, but also some on reddit that may aid in your understanding.

    Bootstrapper.exe attempted to delete a Volume Shadow Snapshot as reported by Crowdstrike at DuckDuckGo

    Rob

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2025-01-17T07:27:51+00:00

    The two paths are trusted, do you use the computer in a business or home environment?

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2025-01-17T00:21:58+00:00

    Thank you Alvise for your response

    This is the command line : "C:\ProgramData\Package Cache{df1acfd4-fb47-4cdf-97da-b140c3663d74}\Bootstrapper.exe" -q -burn.elevated BurnPipe.{98278422-AA26-4ED8-B5A5-45530595BF7B} {ACF8A50E-E71C-475D-A55A-9D56234B5A9F} 18064

    Filepath : \Device\HarddiskVolume3\ProgramData\Package Cache{df1acfd4-fb47-4cdf-97da-b140c3663d74}\Bootstrapper.exe

    I found another file trying to do the same and was blocked by Crowdstrike

    Comand Line: "C:\WINDOWS\system32\OptionalFeatures.exe".

    Filepath : \Device\HarddiskVolume3\Windows\System32\OptionalFeatures.exe

    Was this answer helpful?

    0 comments No comments