Jump to content

A threat (msil/injector.fcd) was found in a file that microsoft teams tried to access


Go to solution Solved by Marcos,

Recommended Posts

hello

i built an app from youtube to enhance my game graphics and now i keep getting this every 1 min * a threat (msil/injector.fcd) was found in a file that microsoft teams tried to access *

its so annyoing and whenever eset tell me that it got rid of it it ask me to restart and it all happens again 

i have malwarebytes plus and eset smart security premium

both are detecting an outbound and blocking it but its so annoying because it happens every 30 sec to 1 min

please help anyone

Screenshot-2024-10-09-151356.png Screenshot-2024-10-09-150544.png

Link to comment
Share on other sites

  • Marcos changed the title to A threat (msil/injector.fcd) was found in a file that microsoft teams tried to access
  • Administrators

The malicious files were created by C:\Users\acer\AppData\Local\Programs\Common\OneDriveCloud\taskhostw.exe so most likely when syncing with your files in your OneDrive storage.  Log in to OneDrive in a browser and delete all suspicious files.

Link to comment
Share on other sites

  • Administrators
  • Solution

You must delete the suspicious files in the cloud, otherwise the OneDrive agent will download them again during a sync.

Link to comment
Share on other sites

  • Administrators

What if you temporarily rename C:\Users\acer\AppData\Local\Programs\Common\OneDriveCloud\taskhostw.exe in safe mode? Does it stop the detections from occurring?

Also you have quite many performance and detection exclusions. Please remove the performance exclusions and use only detection exclusions with a detection name set.

Link to comment
Share on other sites

just to let you know i deleted all the files in C:\Users\acer\AppData\Local\Programs\Common\OneDriveCloud

so its totally empty now

Edited by MasterMind6
Link to comment
Share on other sites

good thing is no more *A threat (msil/injector.fcd) was found in a file that microsoft teams tried to access*

but i got that address has been blocked thing every 2 seconds

Link to comment
Share on other sites

  • Administrators

Remove all performance exclusions as well as detection exclusions that have no detection name set, reboot the machine and see what happens.

Detection exclusions with no detection name:

C:\Users\acer\Desktop\KeyFlexor-v1\KeyFlexor v1\*
C:\Users\acer\Desktop\KeyFlexor-v1\KeyFlexor v1\KeyFlexor v1\STEP 2\*
C:\Program Files\keyflexor\Keyflexor.exe
C:\Program Files\keyflexor
C:\Program Files\keyflexor\Keyflexor.exe
C:\Program Files\keyflexor\Check_KF.exe
C:\Program Files\keyflexor\net8installer.exe
C:\Program Files\keyflexor\Keyflexor.exe.config

image.png

Link to comment
Share on other sites

  • Administrators
1 minute ago, MasterMind6 said:

ok i will reboot now i just removed all performance exclusions

Don't forget to remove also detection exclusions listed above that have no detection name set.

Link to comment
Share on other sites

  • Administrators

That should be all. The whole problem was that you had actual malware excluded from scanning which allowed it to execute. Subsequently various payload was subsequently detected in memory by Advanced memory scanner and Startup scanner, such as:
MSIL/AsyncRAT.A trojan
Win64/Injector.EM trojan
MSIL/Injector.FCD trojan
MSIL/ClipBanker.AIF trojan

 

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...