Jump to content
View in the app

A better way to browse. Learn more.

Tuts 4 You

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

Posted

Is this a real malware?

C:\Users\UserName\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
that file was renamed to Internet Explorer.vir
It just a shortcut:
"C:\Program Files\Internet Explorer\iexplore.exe" http://hi.ru/?dk71

It is detected by some antiviruses:
https://www.virustotal.com/gui/file/9f9002954be80252c9cd7c73114ac2805343b14259619c08bbda50402899c8b4?nocache=1

InternetExplorer.vir

I don't see how, unless the site itself is somehow linked to malware delivery.

Hi @CodeExplorer

that shortcut will cause internet explorer (iexplore) to open that website (ofc you already know this).

Now, I used https://www.url2png.com/ to take a look at the content of that URL without visiting it and it seems like there is nothing important there at the moment.

Googling the domain name, I found out that it is quite famous because it has been used by hijackers in the past.

It is possible that you have been infected by a very old and quite silly hijacker (targeting the now-discontinued iexplorer); a simple vir scan should be enough to resolve the situation (or you can search the process yourself).

As a side note, current browsers won't auto-allow a NON-HTTPS (443) connection. You could use the tool Fiddler (or similar) to see if a payload is downloaded. From there, you dissect it (of course).

Edited by Stuttered

of course it is :)

alert rate > 50%

the summary is clear - dont install russion SW

43 minutes ago, CodeExplorer said:

if this actually a malware

Define "actual malware" :) 

 

Judging from that old VT analysis it's an old pay-per-install adware/browser hijacker.
Back in the old days, this type of software was used to hijack Internet Explorer homepage, inject some ads, run some ad referral/click scams, and/or grab personal information from IE.

Will it destroy your machine today, steal your creditcards and encrypt all your porn collection for a ransom? Unlikely.
Would I personally want such activity on my real machine? Hell, no.

 

  • Author

Besides that strange Internet Explorer.lnk I've noticed that portable Firefox doesn't work any more: can't load any website. I also noticed that something is installed as stand alone program (in uninstall) - I can't remember what.
I restored my OS from backup.
I've reinstalled SuperMariotySetup.exe and is not the source of shortcut Internet Explorer.vir
 

Edited by CodeExplorer

have you checked AUtoruns?

  • Author
1 hour ago, jackyjask said:

have you checked AUtoruns?

I restored my OS from backup. My system is now clean.
 

how exaclty did you restore your OS?

some super advanced virii might even jump into BIOS
 

  • Author
1 hour ago, jackyjask said:

how exaclty did you restore your OS?

I have a backup of C:\ partition with "Paragon Backup and Recovery 14 Free"
I just restored C:\ partition from backup.
 

4 hours ago, CodeExplorer said:

I restored my OS from backup

HUGE respect to you for actually having a backup. :thumbsup:

But given that VMWare Workstation is now free for personal use, why aren't you using it to test the weird and suspicious software you encounter? :wacko:

I saw some adv about "Selling Shortcut .lnk Downloader Builder" in some russian hacking forums.

they sell this app or builder for make undetectable malware downloader.

So be aware ...

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.