More Malware Endeavors With Mrs. Windows.
Posted by TrevelynFeb 25
I didn’t think I would have to come back to this subject so soon, but I have to share this story because this is something I see everyday at my job. I am a technical support / Systems Admin / Software Developer for a University. My Job title is smaller than that and my duties reach far beyond that, at the same time. Anyways, I get systems that are virus ridden. I see broken machines, systems with huge loads on CPU/RAM/(I/O), smashed laptops..you name it, I see it. Today I encountered a Vista Virus called Vista AntiVirus Pro 2010 or as I see it: av.exe This little bugger was deeply embedded. I am going to go over a few reasons in order as to why I hate dealing with Windows and why I believe it to be only made for one purpose: World of Warcraft.
The first thing I saw was that I couldn’t stop it via TaskManager. This is normal. usually malware can make their own svchost.exe or even splice themselves or a rogue file with one that is already running. TaskManager, is a grandiose title for such an application in Windows. It should be renamed to TaskEmployee.
Next I downloaded Malwarebyte’s AntiMalware tool. This tool is absolutely amazing. This tool is free. This tool is NOT part of Microsoft Windows. Why? Well, I guess they know that they can make more money by being so fragile. I am sure their genius developers could have thought up an anti-Malware tool they could build right into their OS by now? Pshh.. Anyways, this tool didn’t work. Each time I would run the tool, TaskEmployee would tell me that I ran av.exe! Oh no!
I boot into “SafeMode.” What makes this “Safe?” Well, they stop all things from starting automatically for you, similar to you un-checking everything in msconfig that is not from Microsoft. As I double clicked on mbam-setup.exe (MalwareBytes) in SafeMode, I realized that av.exe opened up again! This isn’t good, this could only mean one thing!
I opened “Windows Explorer” in SafeMode and did a search for “av.exe” in the top right search bar. Well, nothing turned up as the file av.exe usually resides in the AppData folder of the current user – which is a hidden folder. Then I noticed that there was no menu for Windows Explorer! I couldn’t even change the setting to view “hidden” files and folders! (I think I will try a real OS that handles files like a real OS should.)
I boot into WeakNet Linux Text Only Mode. I mount the drive and run find on the users folder for ‘av\.exe’ This finds it immediately and I remove it. I reboot. Hrmm, why couldn’t the Windows OS do this for me? Because it’s made for playing MMO’s NOT file management. The name “Windows” is still a good name for this OS, I give it that. Only because it can handle MMO windows that are open pretty easily.
Now I try to run mbam-setup.exe and guess what happens? Yeah, Windows has no idea what an exe file is! In fact, it’s so lame that it actually asks me to use another exe file to open it! Guess which one! Go ahead! Yeah, Adobe Acrobat. Something NOT EVEN MADE BY MICROSOFT. So I click “search online for an appropriate application” and I find something that I think is a gem. Go to this page, and make “EXE” your file type: (I already did by adding it into your URL)
http://shell.windows.com/fileassoc/0409/xml/redir.asp?EXT=EXE
This is priceless, like a gem. Like a gem that sits away hiding from the world and once found glows so beautifully that it opens up peoples’ eyes to new perspectives. Yeah it says and I quote:
“Description: Windows does not recognize this file type.”
And then has a few sponsored links below it that contain Malware themselves. Okay so right now, I can clearly see that the “OS” has no idea what a Windows native binary is and Neither do the developers of the aforementioned support site. This is what happens. This is were people end up being cattle. You get herded around the internet by redirect sites and wind up with a virus that completely destroys your registry and “OS.” At the same time, you don’t even know it’s a virus because it looks similar to and says that it is a legitimate Antivirus Client for Microsoft Windows. To me that is just a huge kick in the balls to the company who made such a lame “OS” (I use OS in quotes because they [ Microsoft ] accidentally named their buggy software an “operating system”). But Microsoft likes that. They like making money from it. They like the fact that others’ are making money from it as well, like for instance Symantec.
Speaking of Symantec:
Wanna see something hilarious? Well, you’re reading my article so I will show you anyways!

That is an “Antivirus Client.” Or so Symantec says so. See how it’s green? That means that everything is fine and dandy according to the “Antivirus Client.” You have no viruses or Malware! (Except for the one in the HUGE WHITE SPEAKING BUBBLE ABOVE THE SYMANTEC ICON.) Here are a few more shots of this in action:


This is tremendous. We have these HUGE software developers who make software under the wrong names! Windows isn’t an “operating system.” Symantec Norton AV, is NOT an “AntiVirus Client (Even if you have Malware protection through them, it’s useless).” These are sad times. Linux and the Linux kernel gets stronger everyday. Millions upon millions of dedicated SMART individuals are working together on the security, hardware support, and simple softwares for this OS. Windows is a lame cow. Or as Stewie once said on Family Guy “Lamer than FDR’s legs.”
Now I try to fix the registry with a .REG file. This file contains the lines:
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithList]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids]
"exefile"=hex(0):
As instructed by Microsoft and many Microsoft support technicians. It did nothing. Once again, Windows asked me to open all EXE files with Adobe Acrobat as a suggestion. This happens everyday. Rogue antivirus clients should be the death of the fake OS. Malware should be the death of the Fake OS. For Malware truly shows how strong UNIX and Linux can actually be.
~Douglas.

