I’ve been pretty busy this week with malware appointments and thought I’d share this weeks “note to self stuff”…
A client calls me and says that they have a fake antivirus (internet security 2010 rogue) and now they can’t login to Windows
When I arrive I load my UBCD4WIN and immediately:
Replace Atapi.sys.
Replace Userinit.exe.
Load the host registry and [...]


