• XSS.stack #1 – первый литературный журнал от юзеров форума

CMLauncher.exe

SafearR

floppy-диск
Пользователь
Регистрация
06.03.2024
Сообщения
6
Реакции
1
hey guys, I just downloaded this cs source launcher from a russian site named clientmod.ru. I want to ask if this file is safe because when I uploaded it to VirusTotal, it said the file was a trojan. I know it's a silly question because I uploaded it to VirusTotal, so there's no need to ask. However, this is a launcher with many users, so I wanted to get your opinion. real noob ish :)))
 

Вложения

  • Screenshot 2024-06-29 050301.png
    Screenshot 2024-06-29 050301.png
    37.1 КБ · Просмотры: 85
  • Screenshot 2024-06-29 050346.png
    Screenshot 2024-06-29 050346.png
    125.6 КБ · Просмотры: 86
  • Screenshot 2024-06-29 051215.png
    Screenshot 2024-06-29 051215.png
    54.6 КБ · Просмотры: 85
hey guys, I just downloaded this cs source launcher from a russian site named clientmod.ru. I want to ask if this file is safe because when I uploaded it to VirusTotal, it said the file was a trojan. I know it's a silly question because I uploaded it to VirusTotal, so there's no need to ask. However, this is a launcher with many users, so I wanted to get your opinion. real noob ish :)))
There might be false positive results, also trojan is very basic detection, also there are adware etc... Thus it might indicate that there is nothing specific and these detections are false positive, but at this point I would rather check behaviors tab, this is vm check on many sandboxes, might tell more about this file, post SS from this tab, it will help a lot, because looking only at detections is stupid approach, won't tell us much in this case.
 
unfortunately, I ran CMLauncher.exe on my main OS not vm. But I deleted it and the Counter Strike Source folder it downloaded, so is my computer safe now?
Oh no... You don't know what is it, since it was loader. It could download and execute anything, the only thing I would recommend is fresh windows install, and also change all passwords ASAP, and logoff from all important sessions so cookies will be expired, also if you have any crypto cold wallets, be sure you have unique password that was not leaked! Here I assume that there could be a stealer, probably the worst scenario for you.
 
so is my computer safe now?
in case that link i provided tells that this loader has rootkit persistence - you are not, at all.
1 - turn on 2fa and terminate all sessions on sensitive sites
2 - fully reinstall windows with full wipe of all your drives
3 - after windows reinstalled log in to your accounts of sensitive sites and change password
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх