November 29, 2022
November 29, 2022, Another Malware alert BBWC (not From HP, which has a BBWC Module) is among the newest and most sophisticated released on the net. The second system on my network got infected. Unfortunately, it's the one my wife uses. It wanted to update drivers. I looked on the net because I was like, cool, there is a fix. None worked for me. So I restarted the computer when it came up again with the error saying it couldn't update drivers. I ran task manager, and right on the program with the error, open to file locate, look at the configuration file. This told me where the uninstall pathway both were in C:\Users\Whatever\AppData\Local I copied and pasted the location of the unistall.bat, and it uninstalled
Comments
Seems odd that a malware trojan would not only provide an uninstaller but make it easy to find on the infected system.
I would have anyone that uses that system change all their passwords very soon.
I use hers like a honey pot. She cruises the net, Always finding something on it or wrong with it. She finds them, then I uninstall or wipe them out. Some are very hard to find. I think I found it accidentally because it wants to update some driver for itself, then thru an error. It was set for a silent run in the configuration file.
Good training when you have to hunt them down.
ahh, ok, I follow you now.
It was going to download the "Driver" then try to cover it's tracks by quietly uninstalling the downloader front end once it had the payload installed with admin privileges.
Good catch.