Softwaresoftlay.net

 

Press Ctrl+Enter to quickly submit your post
Quick Reply  
 
 
  
 From:  graphitone  
 To:  CHYRON (DSMITHHFX)      
41996.2 In reply to 41996.1 
I can get you a kosher image of (some flavours of) Windows 7 - what version are you looking for?
0/0
 Reply   Quote More 

 From:  CHYRON (DSMITHHFX)   
 To:  graphitone     
41996.3 In reply to 41996.2 
home premium 32-bit
“Canadians can’t agree on what makes our country great, and one-third even hate hockey”
0/0
 Reply   Quote More 

 From:  CHYRON (DSMITHHFX)   
 To:  ALL
41996.4 
so I ran an SFC from a known good (purchased) installer dvd (but Pro version) from work, and it returned "Windows Resource Protection did not find any integrity violations".

Still only boots into Safe Mode. Hmph.

Gonna burn the softlay iso next and might essay a scan from that. Probly looking at the oem nuke & reinstall thingy though. :-(
“Canadians can’t agree on what makes our country great, and one-third even hate hockey”
0/0
 Reply   Quote More 

 From:  CHYRON (DSMITHHFX)   
 To:  ALL
41996.5 
OK, so after going through msconfig and setting it to boot normally it... booted normally. I'm guessing dickwad mcfuckface on the phone had set for safe mode and then wanted a hundred bucks to unset it.

I also disabled remote desktop connection in msconfig.

Fuck you, mcfuckface.

I may test out the softlay offering in a virtual machine at work next week. Glad I didn't have to use it.
“Canadians can’t agree on what makes our country great, and one-third even hate hockey”
0/0
 Reply   Quote More 

 From:  CHYRON (DSMITHHFX)   
 To:  ALL
41996.6 
A fresh softlay-sourced Windows 7 install in virtualbox passed a MS Malicious Software Removal Tool scan, so I installed Firefox (which Mrs.D uses) and opened the site she said was the last one she browsed before the attack: http://arizonamountaineeringclub.org.

Nothing happened. I suppose it's possible another malware-infected web site she had browsed earlier was the culprit.

I also opened the actual web page the attack apparently came from, based on her ff history:
http://187679863776586953687908945.win/?a=10012294&offer_key=d26a2baaa128ee148b74161dcfb52443&nrid=3

which (unsurprisingly) returned a 404 not found

Another scan with the Microsoft tool after browsing these sites also turned up nothing.

Conclusion: attack vector unknown.
“Canadians can’t agree on what makes our country great, and one-third even hate hockey”
0/0
 Reply   Quote More 

Message 41996.7 deleted 28 Feb 2018 09:13 by MILKO

Reply to All    
 

1–7

Rate my interest:

Adjust text size : Smaller 10 Larger

Beehive Forum 1.5.2 |  FAQ |  Docs |  Support |  Donate! ©2002 - 2024 Project Beehive Forum

Forum Stats