Normal
Kaspersky, ESET and Avast! continue to detect it after your modification, which is in line with my theory: they have performed a Hexa detection on the malware.