Author Topic: Malware that can't be removed  (Read 15606 times)

0 Members and 1 Guest are viewing this topic.

Reply #15November 27, 2017, 09:24:40 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Malware that can't be removed
« Reply #15 on: November 27, 2017, 09:24:40 PM »
Hi xsilicon9,

You are welcome. However, there is still a leftover service from the infection.
Please use the attached fixlist.txt on normal mode to get rid of it.

It will be very valuable for the malware analysis community to get the initial source of this malware (dropper).
I highly suspect that it lies in a crack/keygen/hacktool you executed on November. So, could you please make an archive of all of them and send me a Private Message with the archive in attachment ?

Regards.

Reply #16November 27, 2017, 11:07:24 PM

xsilicon9

  • Newbie

  • Offline
  • *

  • 10
  • Reputation:
    0
    • View Profile
Re: Malware that can't be removed
« Reply #16 on: November 27, 2017, 11:07:24 PM »
I'm not the only one using the computer. But I think the culprit was Office 2016 Permanent Activator Ultimate 1.4 which my friend downloaded to use on his laptop.I deleted a lot of the other malware it installed but there was some leftover.

Reply #17November 27, 2017, 11:55:45 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2809
  • Reputation:
    100
    • View Profile
Re: Malware that can't be removed
« Reply #17 on: November 27, 2017, 11:55:45 PM »
Hi xsilicon9,

Thanks for your input.
You can now delete FRST and the files/folders it created.

Regards.