Anti-nuisance lawsuit warning: The purpose of these notes is to remind me, Zoegond, of stuff or to help me work stuff out. They may contain mistakes.

Quick

  • ($a, $b....) = unpack("A2A7...", $packed)
  • push( array, list )

Saturday, May 11, 2013

GoogleUpdate malware

Suppose you want to install some useful Google application like Earth or Chrome, but don't want GoogleUpdate downloading gigabytes of crap behind your back afterwards. Notes toward preventing a GoogleUpdate infestation...
  • Once the app installation has finished and you've tested it, immediately kill off any lingering msiexec.exe and GoogleUpdater.exe threads.
  • Check Scheduled Tasks - there'll be two tasks to run GU, delete them.
  • Check Services - there isn't usually anything Google-related here but it's worth checking.
  • Use msconfig to check Startup - there will be at least one Google-related startup item, disable it. This is important, if you don't, GU will install all the other malware above again next time you reboot.
These steps have been enough for me so far. But you may also want to do a dir google*.exe /s on your Windows installation drive, because in %appdata%\Google and subdirectories, you'll find the GU executables (and other related programs which appear to try and do a Robin Hood-Little John routine to keep GU going if you kill it off).

It seems odd that this sort of warning is necessary for applications openly distributed by a legitimate business company. And also that the installation process doesn't offer a tick box for 'Do NOT install a whole raft of crap, just the application please, I'll update it myself manually as necessary.'

Followers

Blog Archive