#Is there a way to know exactly what a piece of malware does and how to get rid of it?

1 messages ยท Page 1 of 1 (latest)

bleak lake
#

Like, sandboxing it and / or getting some log file of what it installs and does.

twilit crag
#

you get rid of it by making a fresh install

windows Pro got a developer feature for an simulated windows sandbox environment, but without code you can just guess what it does

bleak lake
#

Ok tnx, do you know what WMI provider host is and why it uses so much cpu

bleak lake
twilit crag
#

like you install a printer then you make a new wmi object

bleak lake
#

Ye ok, buy why did it randomly use 20% cpu

twilit crag
#

when you request a service from WMI , it will push up WMIs cpu usage, i wouldnt mind if it goes up

bleak lake
#

No normally i wouldn't but i just recoverd from some malware so im kina skeptical

twilit crag
#

there is no "recover" from malware when you didnt fresh install windows

bleak lake
twilit crag
#

a "virus" can do anything, like deleting important files, write stupid values, get passwords, anything

bleak lake
#

So? Resetting windows or just deleting the malware may work just as good... I just was (and still partially am) so paranoid that i did a clean install

bleak lake
#

@twilit crag

twilit crag
#

you cant just "delete" malware

#

a new fresh install of windows is the only way of getting rid of it

#

and most viruses are undetecable as they are for example keyloggers ( like tik tok search ) who dertect all key strokes and send them to a server somewhere, there they combine the strokes to search results and sell this data to companies, guess how you get always the correct ads ๐Ÿ™‚

#

selling > destroying
selling is worth more than encrypting and destroying a user

bleak lake
#

Nothing is undetectable

bleak lake
twilit crag
#

but seems like you are anyway a proffesional so you dont need help

bleak lake
bleak lake
blissful hatch
#

@bleak lake

#

i can help you

bleak lake
#

Ok...

blissful hatch
#

so what's your problem?

bleak lake
#

I just wanted to know if there is a way to tell exacly what a piece of malware does

blissful hatch
#

like trojan and bitcoinminner

#

and adware and spyware

#

and more of it

twilit crag
bleak lake
bleak lake
twilit crag
#

create a new file and delete the .txt from it then right click and open with editor => you can still write in it

#

for an OS anything is a file, even the folder is a file

#

the extension is just a hint for some programs, like windows got the setting to open .txt files with the editor, thats just for the program to simplify it for the user

bleak lake
#

Well yes but if i change the file extention form e.g. exe to dll the file became uselss

twilit crag
#

if you say in powershell ". fancyexe.dll" it will run it as a program

#

it just became "useless" because the program thought that it is an dll and treated it as that

bleak lake
#

Ik, that is kinda my point

#

Anyways, i doubt there are thath many malware going this far to remain on the system

twilit crag
bleak lake
#

I mean like... It is not the primary objective to keep the host infected

bleak lake
twilit crag
#

reinstall or reset?

bleak lake
#

Reinstall

twilit crag
#

oke then change the passwords as a virus can read the credential managers generic entries

bleak lake
#

Why? I reinstalled

twilit crag
#

yes but for example office makes a generic credential to make an "auto login"

#

but a process without adin privileges can access that credential manager and gather the password in nanoseconds

#

while you were infected

#

currently your OS is clean, but it could be that the virus stole your entries of passwords before you made the reinstall

bleak lake
#

In that case i would have noticed it... I have 2fa on everything

twilit crag
#

ah oke good, would recommend to look out for unexpected attempts on login

bleak lake
#

I have been for the past 3 weeks lol๐Ÿ˜‚

#

I became infected more than a month ago and am still a bit paranoid

twilit crag
#

and yes the reinstall was mandatory

bleak lake
twilit crag
#

you reinstalled and you got 2fa , nothing can happen anymore

bleak lake
#

Then it was not mandatory, just optionall

#

Otherwise i would have to live with the thought my device micht be infected

twilit crag
#

if the virus is a keylogger, it wont be detected by any anti virus

bleak lake
twilit crag
#

any program is a keylogger, for example games, they look out for keystroke events if you want to type texts

#

a antivirus cant detect if the intent is malicious or not

#

for example tik tok browser is a key logger with intend to gather what you search

#

afaik

bleak lake
#

Programs in the backgroud, in a currently not selected windows shouldn't be logging keys

twilit crag
#

bots do that, keepass ( most famous password safe )

bleak lake
twilit crag
#

im on 9gag ...

#

ยดso somehow yes

#

i made a powershell shell script which sends the windows shortcut ctrl alt a automatically to keepass, its not that hard

bleak lake
#

My understanding of english is good enough untill the point where people started using abbreviations.

twilit crag
#

for an attacker is the hard part on getting triggered, there malwarebytes could detect malicious software

bleak lake
#

I think i should switch to linux tbh... Les risk with malware... But what keeps me win are the games and so much software

twilit crag
#

did you download the virus?

bleak lake
#

Yes, and install it unfortunately

twilit crag
#

linux has same amount of problems but the range of targets is too small, until 2016 you could have unlocked sudo without a password

twilit crag
#

did you have an antivirus back then?

bleak lake
twilit crag
#

ahh, other anti viruses block the defender

bleak lake
#

Also the malware was a package installer (most likely)

bleak lake
twilit crag
#

yup thats good

twilit crag
bleak lake
twilit crag
#

yes, a destroying anti virus couldnt destroy anything on 8 as its allready destroyed without doing anything

bleak lake
#

Anyways, i should stop being paranoid and take some rest. Agreed?

twilit crag
#

nothing can happen anymore, reinstall + password secured, you are safe now

twilit crag
bleak lake
twilit crag
#

by the way

#

the windows sandbox feature was meant for that

bleak lake
twilit crag
#

it simulates a windows environment but when you close it it will delete it

bleak lake
#

I gotta go now btw

twilit crag
#

type in "activate windows features"

#

and search for "windows sandbox

#

idk if its available in home edition

#

it came with win10

#

but needs to be enabled

bleak lake
twilit crag
bleak lake
#

Ik

#

Just don't think home allows me to actually use it

twilit crag
#

can be

#

its sad that this is not available everywhere..