10-05-2010, 08:11 PM
Now listen, there is a new and undetectable virus if you have used the Activator for MS Office 2010... removal process... Read below.
"oh CodyX094Z (or whatever the Eff his name is) had said it will renew after 180 days"... Yeah, FKING LIES. Don't listen to him, read below.
Yes and No to that answer, I have decompiled his code and he had created the program to tweak all files for all versions of office to stay fully activated, he didn't lie about the activation, but he lied about the Executable File. If he told you that BS, and fell for it, you have a lot to learn. He has a malicious .exe put in your computer, thats all I know. And also, why the HELL would he put it in the C:\Windows directory. Exactly, infect your system files. Your gonna get PWND if you don't listen to me.
So guys, all of you are asking me whats the scoop about this file, lets have a technical run through. Not a RAT, no connections are being established. Not spyware because it didn't have any unsolicited pop-up advertisements and It didn't really even route HTTP requests to advertising sites. Not a virus, no connections established and wasn't automatically executed at all the second I used the activator. Its not a worm because active memory was perfectly fine, nothing loss and everything is up and running + No connections established. Most likely a Trojan because my AV's didn't detect any threats till it was finally ran until I rebooted my computer for that crappy activation, so it planned on being a destructive little bitch.
Detailed Virus Statistics and Sources:
Read the FULL Removal Process:
Navigate to C:\Windows\
Then you must find and delete AutoKMS.exe and Configuration settings file, KMSEmulator.exe, AutoKMS.exe and everything with the words KMS in it.
Now run regedit locate the following key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete everything you see with KMS in it. It, the VIRUS tries to get into your Startup, secretively.
Read the Statistics Above for Extra Detail from McAfee
Then your safe, it wanted to access my system but strangely my anti-virus didn't detect it... But Visual Studio 2010 Ultimate DID.
It wanted to debug itself at startup, which is really fcked up.
Just wanted everyone to know... be cautious... Undetectable...
"oh CodyX094Z (or whatever the Eff his name is) had said it will renew after 180 days"... Yeah, FKING LIES. Don't listen to him, read below.
Yes and No to that answer, I have decompiled his code and he had created the program to tweak all files for all versions of office to stay fully activated, he didn't lie about the activation, but he lied about the Executable File. If he told you that BS, and fell for it, you have a lot to learn. He has a malicious .exe put in your computer, thats all I know. And also, why the HELL would he put it in the C:\Windows directory. Exactly, infect your system files. Your gonna get PWND if you don't listen to me.
So guys, all of you are asking me whats the scoop about this file, lets have a technical run through. Not a RAT, no connections are being established. Not spyware because it didn't have any unsolicited pop-up advertisements and It didn't really even route HTTP requests to advertising sites. Not a virus, no connections established and wasn't automatically executed at all the second I used the activator. Its not a worm because active memory was perfectly fine, nothing loss and everything is up and running + No connections established. Most likely a Trojan because my AV's didn't detect any threats till it was finally ran until I rebooted my computer for that crappy activation, so it planned on being a destructive little bitch.
Detailed Virus Statistics and Sources:
Spoiler (Click to View)
Type Of Trojan: Generic.dx!tik
Extremely Detailed Statistics from McAfee
More Statistics at ThreatExpert
Extremely Detailed Statistics from McAfee
More Statistics at ThreatExpert
Read the FULL Removal Process:
Spoiler (Click to View)
Navigate to C:\Windows\
Then you must find and delete AutoKMS.exe and Configuration settings file, KMSEmulator.exe, AutoKMS.exe and everything with the words KMS in it.
Now run regedit locate the following key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and delete everything you see with KMS in it. It, the VIRUS tries to get into your Startup, secretively.
Read the Statistics Above for Extra Detail from McAfee
Then your safe, it wanted to access my system but strangely my anti-virus didn't detect it... But Visual Studio 2010 Ultimate DID.
It wanted to debug itself at startup, which is really fcked up.
Just wanted everyone to know... be cautious... Undetectable...