TigerKing
Wise Old Owl
Most of the "steps" in this script tool I can do or maybe done by me in past.For Enthusiasts a must watch
Is it safe to run?
I like to try this on laptop.
Last edited:
Most of the "steps" in this script tool I can do or maybe done by me in past.For Enthusiasts a must watch
Okay^^Yes you can try. Take a backup of your system first.
This is what baffles me-the files are clearly malicious,otherwise they wouldn't have reappeared at their original locations upon reboot (despite having been deleted previously).And during startup i can see multiple instances of update.exe running in the background for no apparent reason-they disappear after sometime.I dont think any legit app would behave this way.^^Scanned using Bitdefender & Malwarebytes. Nothing detected. Files are clean
Can you post the taskmanager screenshot running these malicious exe ? It could be the exe is being invoked by some other infected program/app.This is what baffles me-the files are clearly malicious,otherwise they wouldn't have reappeared at their original locations upon reboot (despite having been deleted previously).And during startup i can see multiple instances of update.exe running in the background for no apparent reason-they disappear after sometime.I dont think any legit app would behave this way.
I wonder why none of the popular antivirus programs can detect them as malware.Even in virustotal,only one obscure av product called ikarus or something detects the update.exe as a malicious file out of several others listed there,which include some popular a/vs like kaspersky,eset and bitdefender.This is a major disappointment to say the least!!
Post screenshot of details tab, go to the location of that exe and also check for its services.here it is
Some screenshots taken using process explorer...although i couldn't figure what was really going on.It didn't show any info regarding which utility/app/service was spawning the processes.
The malware infection might have been removed from the system. And it could be just a zombie process lurking there.Tried Kaspersky free antivirus but it couldn't detect the malware, neither could bitdefender free.
Haven't tried it in vm yet.