Conversation

Jarkko Sakkinen

Removed the malware after one month of suffering.

#microsoft #malware
1
2
9
@miiko exactly 💝
0
0
1
I learned WinDbg kernel mode, sysmon, WMI events, how to setup virtofs shares and how to gain SSH access to a Windows VM.

For the next run I know how to take servercore docker image, extract is tarball, turn that into qcow2, and finally patch that into a Windows image that boots by "fake recovering" it with Windows ISO.

Thus, at least this is the last time I go full-on Windows 11. For the Docker artifacts, look up https://mcr.microsoft.com/.
0
0
1