Infopost | 2010.04.02

John McAfee MP5

I had to de-virus a computer today and since casual googling didn't turn up any results I thought I'd share the fix with the interwebs. It came from some hulu-ish site, I'm not sure the details on how it passed as innocuous.

It installs an app that appears to be a generic looking antivirus program. It continuously prompts you to purchase the full version from a domain called pc-fortress or something. Trying to run anything from word to regedit results in the window being killed with a kind dialog, 'this executable is infected, want to purchase the full version?'

Bleh. That's why WinMo programmers have it so easy, MS apis must be full of great stuff, like an interface to kill whatever OS app you feel like.

So basically you just restart in safe mode cause the malware author sucks and needed Windows to start it. For me, the startup tab of msconfig had sknqxoufx, an exe located in one of the user data/app data hidden folders. The name could be randomly generated (again, no google results). With the autostart box unchecked and the directory removed, problem solved.

Other news in brief: lots of work... Malaysia GP - not a good RBR track still excited... still need lawnmower... Shred The Gnar won 3-2 on Thursday... Arthur coming into town soon... Resto Hardware duvee rather nice... header bolt fell off Duc...

tags: virus


Comments

osx ftw


osx ftw

Chris

Hate mac fanboys so much...



Related - internal

Some posts from this site with similar content.

Post
2007.12.19

Spoken

So there's the front turbo. And I put the HID assembly on the Duc (thanks to Connie). The bulb replacement was exact, the ballast was easily tucked in front of the gauge cluster. It's whiter, brighter, and uses something like 35W versus 55W. So a HI...
Post
2022.06.03

The decline of user data storage

Trying to find out how many files are in a Google Drive directory precipitates a short rant about the big picture.
Post
2010.08.01

Starcraft

Initial thoughts on Starcraft II.I and photographing paintball from the trenches.

Related - external

Risky click advisory: these links are produced algorithmically from a crawl of the subsurface web (and some select mainstream web). I haven't personally looked at them or checked them for quality, decency, or sanity. None of these links are promoted, sponsored, or affiliated with this site. For more information, see this post.

blog.yadutaf.fr

Anatomy of a virus: iTunesHelper.vbe 1/2 | Yet another enthusiast blog!

404ed
blog.securityonion.net

Security Onion: Quick Malware Analysis: ICEDID BOKBOT infection pcap from 2023-07-25

Thanks to Brad Duncan for sharing this pcap from 2023-07-25 on his malware traffic analysis site! Google currently has a warning for the sit...
ohio.araw.xyz

The Old Computer Challenge

Researcher's log

Created 2024.03 from an index of 146,332 pages.