Skip to main content

New version of malware uses ‘God Mode’ to hide from Windows users

new version of malware uses god mode to hide from users
Many PC users will have a ‘God Mode’ folder sitting on their desktop — it’s a neat Windows tweak that allows immediate access to a whole host of different controls that come in handy every now and again. However, new information from McAfee suggests that malware could be taking advantage of the same functionality.

Dynamer is a piece of malware that’s been around for several years, but a new version riffs on “God Mode” to hide away on your system. A few devious tricks have been used in an attempt to prevent users from getting rid of the problem.

The malware installs itself in the AppData directory, creating a registry run key value so that it can survive a reboot. However, when users click on the folder created by Dynamer during this process, they’ll simply be redirected to an unrelated area of the control panel.

Worse yet, the folder uses a ‘com4’ string in its name to gain some extra protection from Windows. This tricks the OS into treating the folder like a device, which prevents the user from deleting it as they might normally, according to a report from Extreme Tech.

However, Dynamer’s defenses are thankfully not completely impervious. Users can rid themselves of the malware by first ending the associated process via Task Manager, before opening up a command prompt and entering the following string, specially crafted by the security experts at McAfee:

rd “\\.\%appdata%\com4.{241D7C96-F8BF-4F85-B01F-E2B043341A4B}” /S /Q

That should remove the offending malware from your computer and return your system to its previous state. This fix will be a huge help for anyone who has been targeted by Dynamer, but anyone already protected by McAfee products can safely ignore it — according to the company, its antimalware defenses won’t be fooled by this particular trick.

Editors' Recommendations

Brad Jones
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
New version of Microsoft Edge could save you from using bad passwords online
microsoft edge gets startup boost feature take on chrome new

Microsoft's Edge web browser just got a new feature that ensures you're a bit safer when browsing the web.

Now rolling out in version 92 of Edge is a new password health dashboard, to help you decide if the password you've saved is strong enough, or used on another website.

Read more
Microsoft warns Windows users of another unpatched printing vulnerability
A digital depiction of a laptop being hacked by a hacker.

Microsoft might have patched PrintNightmare in Windows, but for the second time this month, there's yet another printer-themed vulnerability in the wild.

Just detailed is a new vulnerability in the Windows Print Spooler service that could allow hackers to install programs; view, change, or delete data; and create new accounts on your PC.

Read more
Windows has a print vulnerability that hackers are actively using
Brother's L8360 is a great color laser printer for small offices.

Microsoft has updated its documentation around the "PrintNightmare" vulnerability that is impacting Windows PCs across the world. The company now says it is aware of the issue, which officially involves cases where the Windows Print Spooler service may perform privileged file operations and allow hackers into your device.

Though it's not clear if all versions of Windows are impacted by this vulnerability, Microsoft says that the print spooler code that has the vulnerability is in all versions of Windows. The print spooler is what usually handles print jobs in Windows. Specifically, hackers can exploit that code to run arbitrary code with system privileges.

Read more