Server hanging on login after infected with variant of MSIL/Injector.FWX trojan

Rene

New Member
Thread author
Oct 21, 2014
2
Hey guys,

Here is my issue. End user opened infected attachment and ran it.

You can login to Safe Mode with Networking. When running Windows in Normal Mode as long as you do not login as a user the server will run OK. Once you login these screen will freeze (but server looks like it is running. Only cold boot will fix.

Scanned with ESET Online Scanner and it removed most of Trojan except for one exe. Scanned with Malwarebytes and no detection. Currently running another full scan with Malwarebytes and eSET. Also did a SFC.exe /scannow and no damaged files were detected.
 

Attachments

  • Addition.txt
    34.2 KB · Views: 79
  • AdwCleaner[R1].txt
    12 KB · Views: 50
  • aswMBR.txt
    1.4 KB · Views: 37
  • eset scan.txt
    1.5 KB · Views: 79
  • FRST.txt
    28.6 KB · Views: 71

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top