Programs being deleted from C:\Program Files (x86)

Page 4 of 5 FirstFirst ... 2345 LastLast

  1. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #31

    Hi,

    Its likely the malware was contracted through the VMWare keygen - avoid cracked software if you don't want these problems.

    Is malware still flagged on your system, or does it show up clean now?

    Regards,
    Golden
      My Computer


  2. Posts : 111
    Windows 7 HP x64 SP1
    Thread Starter
       #32

    Well as far as I know, it should be clean now since I quarantined and deleted the exploits shown up by microsoft security essentials, and deleted VirTool:Win32/DelfInject.gen!X shown up by defender offline. I don't think it was vmware as I haven't used it for a long time, I've been using virtual box since, and this issue has only cropped up over the last few days. I didn't keep my windows XP AV updated and didn't scan on the few times I loaded XP environment within vbox, so I'm wondering whether I let the exploits through because of that.
      My Computer


  3. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #33

    Hi,

    Its possible, but I was looking specifically at this item:
    Resource Path:\$RECYCLE.BIN\S-1-5-21-1716146104-364351621-1683301092-1001\$RYRILHJ\VMWare.Workstation.v6.5.3.185404.Incl.Keygen-DI\keygen.exe
    None-the-less you have deleted that. How is the system now?

    Regards,
    Golden
      My Computer


  4. Posts : 111
    Windows 7 HP x64 SP1
    Thread Starter
       #34

    Golden said:
    Hi,

    Its possible, but I was looking specifically at this item:
    Resource Path:\$RECYCLE.BIN\S-1-5-21-1716146104-364351621-1683301092-1001\$RYRILHJ\VMWare.Workstation.v6.5.3.185404.Incl.Keygen-DI\keygen.exe
    None-the-less you have deleted that. How is the system now?

    Regards,
    Golden
    Well, the only virus flagged by defender offline was the VirTool:Win32/DelfInject.gen!X which is deleted. The keygen files are deleted but they didn't flag a virus. But I won't know how the system is until I reinstall a couple of programs back to c:/program files (x86) and see if they disappear or not.
      My Computer


  5. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #35

    Hi,

    Keygens can behave as what are known as 'droppers' - they carry the malware payload, which then typicallly infects other files. So whilst the keygen is strictly speaking not malware, it was in all probability the source of the malware.

    Let us know how your system is once you get everything sorted.

    Regards,
    Golden
      My Computer


  6. Posts : 111
    Windows 7 HP x64 SP1
    Thread Starter
       #36

    True, but those keygens have been on my system for years, so unless they were benign lying dormant and suddenly became active and dropping the malware payload, I honestly don't believe they're responsible.
      My Computer


  7. Posts : 111
    Windows 7 HP x64 SP1
    Thread Starter
       #37

    To add, the fact that malwarebytes disappeared from both my desktop AND laptop, AND both from program files x86, AND both computers had the same java exploit blacole, that's where I put my money.
      My Computer


  8. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #38

    Roman5 said:
    Tso unless they were benign lying dormant and suddenly became active and dropping the malware payload
    Thats exactly how some droppers work.

    Regards,
    Golden
      My Computer


  9. Posts : 111
    Windows 7 HP x64 SP1
    Thread Starter
       #39

    Golden said:
    Roman5 said:
    Tso unless they were benign lying dormant and suddenly became active and dropping the malware payload
    Thats exactly how some droppers work.

    Regards,
    Golden
    Ah, well in that case, having deleted them will hopefully stop the exploit returning, if it was the keygens that dropped them. Thanks for the tips, I am learning my lessons the hard way.
      My Computer


  10. Posts : 19,383
    Windows 10 Pro x64 ; Xubuntu x64
       #40

    Its all good

    Let us know how you get on and if you need any more help.

    regards,
    Golden
      My Computer


 
Page 4 of 5 FirstFirst ... 2345 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 01:08.
Find Us