Quote:
Originally Posted by lnf3ct3d
So.. Some people are having issues? Does it work or..?
|
Before somebody else will try to DL this s***, Ill warn :
It doesnt work, really, and I
DONT recommend you to try this out, here is why :
1. In archive there are two files that both are useless. One is infected, even VT wont show it up.
2. After a short period of time (i happend to restart my PC) my antivirus started to say that vbc.exe (MS .net framework component, dupe that virus created) is infected with
trojan fynloski.a. This fake MS component will launch when you next time turn on you PC. The source of this present is in 2nd file (it just disappears if you click on it) in this archive, it creates this infected file
Note : if you will try to scan it, it wont make any effect. Virus will blow its cover if you will run LOL or APPs, that require .net framework
as
Blessdown said - fake+keylogger, 100%
Backdoor Win32/Fynloski.A also known as DarkComet is a repackaged version of a remote access tool (RAT). Backdoor Win32/Fynloski.A allows unauthorized access and control of an affected computer. It is capable of downloading and executing other malicous files. Besides that the “Backdoor Win32/Fynloski.A” trojan wil also collect system information, record keystrokes and is able to steal passwords from known applications and websites. - from malwareremovalguides
Incase, if you already DLed this, then :
1. Permanently delete archive with these file and files from it.
2. Task manager > Rclick on vbc.exe process > Open containing folder
Note : Windows wont allow you simply to delete it, it will ask for a permission from TrustedInstaller to delete this file.
3. Rclick on vbc.exe > click "propereties" > click "security" > Click on group "TrustedInstaller", then lower, under the table with ticks, click "Additionally"
4. You will see a window that has 4 tabs. Open 3rd tab, called "Owner". Lower you will see button "Change", click on it and select "Admins group". After doing this, you will be warned, that you need to close "Propereties window" for this file, in order apply changes. Apply+Ok+Close, same for "Properties window".
5. After doing that, Rclick on vbc.exe's properteties, then go to security. You need to set permissions, lower click "Change", then click on "Admins" and set "Full access". Apply+Ok+Close. Now you can delete the infected file.
6. Run a full antivirus scan for your PC
7. Change Passwords on your accounts ( aim might be not only your LOL account, but private info, cards number, etc ). Change Passwords from another PC/laptop/smth else, if possible.
Hope it helps somebody
-Wyatt
-----------------------------------
#vote4close ; #vote4ban