Friday, 23 August 2013

Pursuing Malware

A few days ago I reported on BrowserDefender, malware already installed on my new laptop when I collected it.

A few days after uninstalling BrowserDefender I discovered that a bit had survived. There was a folder in ProgramData containing the executable, a dll file, and a collection of 'logging data' The date of the folder suggested it was created when I uninstalled the program. All the files in question resisted deletion, claiming they were 'used by another program'. Eventually I removed them by using Bullguard.

Incidentally the ProgramData folder is officially 'invisible' so it doesn't usually appear in listings. In the routine check on settings that I make when I get a new computer I'd chosen to restore visibility to invisible files. It's as well I did!



No comments :