Author Topic: New Poweliks variant  (Read 21574 times)

0 Members and 1 Guest are viewing this topic.

Reply #15September 19, 2014, 07:23:00 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: New Poweliks variant
« Reply #15 on: September 19, 2014, 07:23:00 AM »
can you look manually to see if you see the key above in regedit?

Reply #16September 19, 2014, 07:30:12 AM

Powdermnky007

  • Guest
Re: New Poweliks variant
« Reply #16 on: September 19, 2014, 07:30:12 AM »
I did, there was no weird java key there.  Just the normal C:\WINDOWS\system32\wbem\wmiprvse.exe

Reply #17September 19, 2014, 08:36:30 AM

Tigzy

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 957
  • Reputation:
    91
  • Personal Text
    Owner, Adlice Software
    • View Profile
    • Adlice Software
Re: New Poweliks variant
« Reply #17 on: September 19, 2014, 08:36:30 AM »
Ok, I think something fixed it before.
Maybe MBAM?