ISSUE 18.17 โข 2021-05-10 SAFETY By Ben Myers Things are not always as they seem. What might appear to be a devastating, PC-destroying piece of malware
[See the full post at: Anatomy of a malware]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Anatomy of a malware
Home » Forums » Newsletter and Homepage topics » Anatomy of a malware
- This topic has 11 replies, 8 voices, and was last updated 4 years ago.
AuthorTopicViewing 6 reply threadsAuthorReplies-
erbkaiser
AskWoody PlusMay 10, 2021 at 1:57 am #2363815For the record, the ‘new’ way to get to the Folder Options and make it so that Windows shows hidden files and extensions is to click File on top of a file explorer window, then selecting Change folder and search options.
This will bring up the same Folder Options dialog where you can opt to show everything.
I also recommend turning at least Hide protected operating systems back on after it is no longer needed for any casual user, as otherwise they will see multiple files and folders they cannot and should not interact with.1 user thanked author for this post.
-
anonymous
Guest -
anonymous
GuestMay 10, 2021 at 8:07 am #2363863This isย theย infamousย ย Micro Soft Tech Supportย scam.ย ย ย One of many internet scams outย of India.ย ย For more information please go to You Tube and searchย ย Scam Baiting,ย ย also see:ย ย Jim Browning, Kitboga, scammer payback.ย ย Yes,ย there is a group of people fighting back.ย ย Also see:ย ย Scammer.info .ย ย ย Billions have been lost to these scammers.
-
RetiredGeek
AskWoody_MVPMay 10, 2021 at 9:20 am #2363885You forgot to mention the No. 1 tool (IMHO) in the fight against malware/ransomeware Image Backups. You never have to fear if you have recent Images of your drives. Just boot from a USB drive and restore the C: drive done! HTH ๐
-
Ben Myers
AskWoody PlusMay 13, 2021 at 9:07 am #2364700As in many cases when a client’s system shows up here, they did not ever do any backup.ย And, doing regular image backups are often beyond the abilities of many people who simply think of their computers as appliances to do what they need to do and no more.ย To put it less delicately, the level of know-how for many computer owners is pretty low.
2 users thanked author for this post.
-
bmeacham
AskWoody Plus-
PKCano
ManagerMay 10, 2021 at 10:14 am #2363899If you can get to it with Admin privileges in the Command Prompt, and you can’t get to it with File Explorer using your ID, I have to ask – Is your ID a Standard User or a member of the Administrators Group?
If you right click on Explorer and “Run as Admin,” can you access it?
1 user thanked author for this post.
ve2mrx
AskWoody PlusMay 10, 2021 at 12:56 pm #2363948WARNING: Improperly editing file rights can trash your system, make sure you have a backup or other recovery methods before doing the following!
One tip for harder to remove malware processes: Remove SYSTEM rights from the bad files after adding your user full rights. Reboot!
After booting, Windows won’t have access to the bad files, but you can go back and then delete them! I’ve used this trick a few times in the past.
Today, I prefer to wipe the system as what you see could only be the tip of the security iceberg: There could be multiple layers of malware installed and you can’t always see all of them. Technology makes it easy to make custom malware on-the-fly, making such malware undetected by normal security software.
I prefer to see security malware as an alarm system: If you see something, the system is now compromised and under someone else’s control. Only a complete forensic analysis can reveal the extent of the compromise, something most users can’t do.
So, if you find something, burn it and start over!
Martin
-
This reply was modified 4 years ago by
ve2mrx. Reason: Clarity
1 user thanked author for this post.
anonymous
GuestMay 10, 2021 at 3:40 pm #2364007Thank you for this post. I’d be more cautious about using Select All and deleting the files that appear after searching for %temp% files. I found many music and other files with the “temp” string in them (Word files, music files like “la Tempesta di Mare”…)
1 user thanked author for this post.
-
Ben Myers
AskWoody PlusMay 13, 2021 at 9:10 am #2364702The temp string is not an issue.ย I cannot ever recall an issue with doing a Select All followed by a Delete from the %temp% folder.ย If a file is in use, the Delete function will tell you and you can skip its deletion.
Further, one needs to ask how music, Word, Excel or other files have found their way into %temp%, and whether or not there are more permanent files elsewhere.ย After all, the %temp% folder is for files and folders that are temporary.
-
b
AskWoody_MVPMay 13, 2021 at 9:32 am #2364707Iโd be more cautious about using Select All and deleting the files that appear after searching for %temp% files. I found many music and other files with the โtempโ string in them
It’s not a filename search. %temp% is a folder, as the article explains.
Viewing 6 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
DBOS Advanced Network Analysis
by
Kathy Stevens
1 hour, 42 minutes ago -
Microsoft Edge Launching Automatically?
by
healeyinpa
2 hours, 25 minutes ago -
Google Chrome to block admin-level browser launches for better security
by
Alex5723
4 hours, 23 minutes ago -
iPhone SE2 Stolen Device Protection
by
Rick Corbett
5 hours, 5 minutes ago -
Some advice for managing my wireless internet gateway
by
LHiggins
1 hour, 34 minutes ago -
NO POWER IN KEYBOARD OR MOUSE
by
HE48AEEXX77WEN4Edbtm
6 hours ago -
A CVE-MITRE-CISA-CNA Extravaganza
by
Nibbled To Death By Ducks
13 hours, 52 minutes ago -
Sometimes I wonder about these bots
by
Susan Bradley
10 hours, 9 minutes ago -
Does windows update component store “self heal”?
by
Mike Cross
12 minutes ago -
Windows 11 Insider Preview build 27858 released to Canary
by
joep517
1 day, 3 hours ago -
Pwn2Own Berlin 2025: Day One Results
by
Alex5723
1 day, 3 hours ago -
Windows 10 might repeatedly display the BitLocker recovery screen at startup
by
Susan Bradley
28 minutes ago -
Windows 11 Insider Preview Build 22631.5409 (23H2) released to Release Preview
by
joep517
1 day, 6 hours ago -
Windows 10 Build 19045.5912 (22H2) to Release Preview Channel
by
joep517
1 day, 6 hours ago -
Kevin Beaumont on Microsoft Recall
by
Susan Bradley
19 hours, 7 minutes ago -
The Surface Laptop Studio 2 is no longer being manufactured
by
Alex5723
1 day, 14 hours ago -
0Patch, where to begin
by
cassel23
1 day, 8 hours ago -
CFPB Quietly Kills Rule to Shield Americans From Data Brokers
by
Alex5723
2 days, 4 hours ago -
89 million Steam account details just got leaked,
by
Alex5723
1 day, 16 hours ago -
KB5058405: Linux – Windows dual boot SBAT bug, resolved with May 2025 update
by
Alex5723
2 days, 12 hours ago -
A Validation (were one needed) of Prudent Patching
by
Nibbled To Death By Ducks
2 days, 3 hours ago -
Master Patch Listing for May 13, 2025
by
Susan Bradley
1 day, 14 hours ago -
Installer program can’t read my registry
by
Peobody
7 hours, 45 minutes ago -
How to keep Outlook (new) in off position for Windows 11
by
EspressoWillie
2 days, 1 hour ago -
Intel : CVE-2024-45332, CVE-2024-43420, CVE-2025-20623
by
Alex5723
2 days, 8 hours ago -
False error message from eMClient
by
WSSebastian42
2 days, 23 hours ago -
Awoke to a rebooted Mac (crashed?)
by
rebop2020
3 days, 9 hours ago -
Office 2021 Perpetual for Mac
by
rebop2020
3 days, 10 hours ago -
AutoSave is for Microsoft, not for you
by
Will Fastie
7 hours, 50 minutes ago -
Difface : Reconstruction of 3D Human Facial Images from DNA Sequence
by
Alex5723
3 days, 13 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.