Undetected Virus? I study at College, and Now all of the school computers have paint.exe -autocheck
Posted
by Jeffy
on Super User
See other posts from Super User
or by Jeffy
Published on 2009-11-27T04:23:26Z
Indexed on
2010/05/12
6:44 UTC
Read the original article
Hit count: 166
virus
"C:\WINDOWS\system32\Paint.exe" -autocheck
is added to the registry every time its removed. This is like global. All the lab PCs(more than a hundred), personal laptops have this file. I really have no expert help to turn to.. as jotti says this file is clean.
Here's the dropped file [removed]
It seems that we all had this game cheating tool on our PCs called "Garena Maphack". Everytime it was run it would drop paint.exe into the system dir.
Paint.exe is diguised as the real paint.exe from windows. Having the same icon and such.
Check out threat expert's report at threatexpert.com/report.aspx?md5=176288f6f22a80c76329853f8535d45b
The game cheat that started this huge mess can be obtained from [removed]
What do I do? any experts care to take apart this file?
© Super User or respective owner