{"id":100,"date":"2012-01-06T23:33:18","date_gmt":"2012-01-07T07:33:18","guid":{"rendered":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/?p=100"},"modified":"2012-01-17T18:00:17","modified_gmt":"2012-01-18T02:00:17","slug":"malware-never-sleeps","status":"publish","type":"post","link":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/2012\/01\/06\/malware-never-sleeps\/","title":{"rendered":"Malware never sleeps"},"content":{"rendered":"<p>Malware and Trojans and Viruses, oh my! <\/p>\n<p>Oh geez, again?  This crap is really annoying.<\/p>\n<p>So I just launched a new web presence for Engineer LLC (my new encompassing venture for business).  I set up a WordPress blog on the site.  So I was checking out the &#8220;official&#8221; themes on the &#8220;official&#8221; WordPress website a bit later and I saw one that looked interesting.  Curious to see more I selected the hyperlink for the theme Author&#8230;<\/p>\n<p>!!! AHHHRGH !!!  Malware Attack  !!! AHHHRG !!!<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/sandbox.dev.vernonjohnson.net\/wordpress\/wp-content\/uploads\/Malware_01062012.JPG\" alt=\"Malware\" \/><\/p>\n<p>Luckily, Microsoft Security Essentials trapped it right away.  However, it had apparently left the tentacles.  Next day&#8230;  OK the computer starts fine, but wait there&#8217;s more!  Now my browsers (all of them) keep getting the home page hijacked to some Spanish language Movie website?  Gimme a break!<\/p>\n<p>(Update 01\/07\/2012)  The annoyance took a bit of work to get rid of, but now it&#8217;s gone.  While the anti malware stuff caught and killed the threats immediately, it left behind 2 executables in the temporary and program data folders, set to run on startup and lurk until a browser was run.  Then the registry was overwritten with the offending url over and over again.  Narrowing it down was a hassle.  Shut down all the browser add-ons, nope.  Run msconfig and deselect all suspected interlopers and possibly compromised legit apps.  OK that stopped it.  reactivate the browser add-ons one by one, nothing there.  Delete the startup items that are not recognizable and enable the suspected legit apps.  Restart again and it&#8217;s still OK.  OK then it was one or more of those unrecognizable .exe files.  Stinky malware&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Malware and Trojans and Viruses, oh my! Oh geez, again? This crap is really annoying. So I just launched a new web presence for Engineer LLC (my new encompassing venture for business). I set up a WordPress blog on the &hellip; <a href=\"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/2012\/01\/06\/malware-never-sleeps\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[39,32,19,20],"tags":[50],"class_list":["post-100","post","type-post","status-publish","format-standard","hentry","category-idiocracy","category-malware","category-tech","category-windows-7","tag-punks"],"_links":{"self":[{"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/posts\/100","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/comments?post=100"}],"version-history":[{"count":10,"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/posts\/100\/revisions"}],"predecessor-version":[{"id":111,"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/posts\/100\/revisions\/111"}],"wp:attachment":[{"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/media?parent=100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/categories?post=100"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.sandbox.dev.vernonjohnson.net\/wordpress\/wp-json\/wp\/v2\/tags?post=100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}