Pop Quiz #2

What command should be typed to get to the Desktop?

  • Bitsadmin

    Votes: 0 0.0%
  • Cacls

    Votes: 0 0.0%
  • Endlocal

    Votes: 0 0.0%
  • Ksetup

    Votes: 0 0.0%

  • Total voters
    7
  • Poll closed .

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,151
A real easy one today, but important to know.

Scenario:

You use Windows 7 and are checking your email; you see a message with the heading Sexy Girls that comes with an attachment "sexy-girls.jpg.exe". Being male you have a Genetic Imperative to explore further, so you run the file. Surprise! Instead of images you now have a variety of FBI ransomware that locks you out. No problem, right? Boot into safe mode and remove it. However when either Safe Mode or Safe Mode with networking are tried you still are presented with the nasty ransom screen.

Being a member of MT this presents no issue to you as you know that Ransomware won't prevent you from using Safe Mode with Command Prompt. So you Safe Boot to the Command prompt, get presented with the Command box (C:\Windows\System32) and type a command. Your Desktop now appears behind the Command Window. You now get to work and remove the malware.

What Command did you type?
 
D

Deleted member 21043

"sexy-girls.jpg.exe" - Yes, the title is making me unable to resist exploring! :oops::rolleyes:... However, if I saw a file with a extension added into the name and then a second extension I would be pretty cautious about it. I would insist running it in a Virtual Machine or Sandbox before using it properly... Unless im feeling crazy of course :eek:

Anyway, as for the command, I would say explorer is the closest (for the desktop)... In fact, I don't even know the other ones. Are they faked? Either way, me and CMD doesn't match very well... :D:p
 
Last edited by a moderator:

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
Explorer, what else?

Dang double extensions sexy-girls.jpg.exe. First, chances that I'll read this email is remote because these types gets directly to my Spam folder, in case this one was able to squeeze in, I'll just ignore it. Or maybe out of curiosity download the file and play with it. Okay change of plan, PC won't boot in Safe Mode for some unknown reasons, heard the saying "when it rains it pours". Next course of action is to boot with Linux and trash the FBI, NSA, CIA, IRS whatever ransomware. After that I'll reward myself by watching Ransom by Mel Gibson. What a way to start a day.
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
I don't think it's any of them, if it's one, it's explorer. However, I would simply type in rstrui.exe in the cmd prompt and restore my system...

What if System Restore is disabled, not by the FBI Ransomware but by something else. An what if you have known that the email came from a cow? hypothetically speaking of course.
 
  • Like
Reactions: FreddyFreeloader

Chromatinfish 123

Level 21
Verified
May 26, 2014
1,051
"sexy-girls.jpg.exe" - Yes, the title is making me unable to resist exploring! :oops::rolleyes:... However, if I saw a file with a extension added into the name and then a second extension I would be pretty cautious about it. I would insist running it in a Virtual Machine or Sandbox before using it properly... Unless im feeling crazy of course :eek:

Anyway, as for the command, I would say explorer is the closest (for the desktop)... In fact, I don't even know the other ones. Are they faked? Either way, me and CMD doesn't match very well... :D:p
I think the exe won't be displayed so it will only say jpg, as Windows automatically takes away the extension. Thats their way of cheating. I've seen filed that say .jpg or .gif that are really .7z/.zip/.exe files...
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
I have show extensions of known file type on by default
 
D

Deleted member 21043

I think the exe won't be displayed so it will only say jpg, as Windows automatically takes away the extension. Thats their way of cheating. I've seen filed that say .jpg or .gif that are really .7z/.zip/.exe files...
Yeah, that's true. But, I don't "run". I save the files. Then I check the extension before running.
 

McLovin

Level 76
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,224
I'm just gonna say that I wish I didn't run that file.

If I ever get that sort of emails that get past Trend's Antispam, I add it to the block list and just delete it. For one single click can turn into, hours, maybe even weeks of restoration. :)
 

Thingol

Level 1
Verified
Aug 9, 2014
32
I think the answer is Explorer. Can't see what help the others would be in that scenario.

Most on the forums would not be fooled I hope ;) but it's a good example of why I use SBIE and AppGuard though. IMO you need to restrict threat-gates like browsers/mail clients. AG would have blocked it and SBIE would likely not let it run either in my set-up but if it did likely contain it and flushed it away. :cool:

In the real world if anything got passed my security stuff I'd likely boot into the IFW recovery consul or use the bootable media to restore a back-up. No telling if the ransomware also dropped something that will cause you further issues later.

Cheers
 

cruelsister

Level 42
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,151
You guys are smart- the answer is indeed “Explorer”. This will bring up the Desktop behind the Command Prompt Window and analysis and removal of the malware can be done. Assuming that you hadn't uninstalled Malwarebytes and/or HMP to make room for the Porno, malware remediation can be done with either of these with efficiency; but even if you didn't have either installed, a quick look at what is scheduled to start with Windows (via MSCONFIG or similar) will lead you to the malware which could be manually deleted (further registry changes can be corrected after this),

Notice that I specified Window 7 in the original question. The reason I didn't include Windows 8 is that getting into the Boot Menu in 8 can present problems. As the startup routine is more RAM intensive than with previous builds of Windows, the ease at which the F8 will lead to the Boot menu is inversely proportional to the speed of your computer (basically no way). So to make things easier there is a tweak that can be done in Windows 8.1 restore the legacy boot menu; at the command prompt type:

bcdedit /set {default} bootmenupolicy legacy

to reverse the above change:

bcdedit /set {default} bootmenupolicy standard
 

Behold Eck

Level 15
Verified
Top Poster
Well-known
Jun 22, 2014
724
What about the porn do we get that back as well ?:D

Great quiz this could be the very thing if called upon to remedy my sons computer with.

Love it.

Regards Eck:)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top