Jump to content

Trojan.Crypt & Spyware.PasswordStealer & Spyware.AgentTesla


AlexLeadingEdge

Recommended Posts

Are these false positives? Three detection types for the same program. I believe Native Images is a Microsoft .NET program.

 

2022-01-02 09:43:58 AM    Trojan.Crypt    REDACTED    Malware    file    C:\Windows.old\WINDOWS\assembly\NativeImages_v4.0.30319_32\FSharp.Lang8152be21#\40b5a56f150011d0c51fa11bfbc6e1ee\FSharp.LanguageService.Base.ni.dll

2022-01-02 09:43:58 AM    Spyware.PasswordStealer    REDACTED    Malware    file    C:\Windows.old\WINDOWS\assembly\NativeImages_v4.0.30319_32\NuGet.Commands\f154ae2115190e7d3d955cd4b7ca51ff\NuGet.Commands.ni.dll

2022-01-02 09:43:58 AM    Spyware.PasswordStealer    REDACTED    Malware    file   C:\Windows.old\WINDOWS\assembly\NativeImages_v4.0.30319_32\FSharp.Projc0b0e1ec#\41ac35f187be0c6809aab3fce1e98c13\FSharp.ProjectSystem.PropertyPages.ni.dll

2022-01-02 09:43:58 AM    Trojan.Crypt    REDACTED    Malware    file C:\Windows.old\WINDOWS\assembly\NativeImages_v4.0.30319_32\Microsoft.V159eb141#\68e338c8fd741854bf0c872f0349b630\Microsoft.VisualStudio.TestWindow.Host.ni.dll

2022-01-02 09:43:58 AM    Spyware.AgentTesla    REDACTED    Malware    file    C:\Windows.old\WINDOWS\assembly\NativeImages_v4.0.30319_32\fsc\c7885f835f4d68bc4a8f20a3da0d4a54\fsc.ni.exe

Edited by AlexLeadingEdge
Link to post
Share on other sites

  • AlexLeadingEdge changed the title to Trojan.Crypt & Spyware.PasswordStealer & Spyware.AgentTesla

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.