

Mspaint.exe (Paint) devmgmt.msc (Device Manager)Īfter a while, the trojan will start randomly moving the mouse slightly, and messages taunting the user appear (see image), getting more violent and rapid as time progresses.

It may also open one of the following Windows applications: (redirects to as Club Penguin and Club Penguin Island have shut down) read/watch-this-malware-turn-a-computer-into-a-digital-hellscape Skrillex scay onster an nice sprites midiĪ/en-us/protect/forum/protect_other-protect_scanning/memz-malwarevirus-trojan-completely-destroying/268bc1c2-39f4-42f8-90c2-597a673b6b45 My computer is doing weird things wtf is happenin plz halp The following can appear:įacebook hacking tool free download no virus working 2016 The first payload inside of Windows is opening random websites, as well as Google searches at .ck (.ck is the country code top-level domain for the Cook Islands). If the installed system uses an EFI bootloader, "Nyan Cat" does not appear on startup due to different booting schemes, but the computer will still fail to boot as the EFI system partition will be impossible to find due to the partition table being broken. The MBR payload written while note.txt gets opened is a "Nyan Cat" animation running as a custom bootloader, and this write is likely to break your partition table. MEMZ Destructive launches multiple instances of itself - one renders the payloads, while the other guard each other and trigger killWindows(), which creates a rain of message boxes and crashes the PC as elaborated further down. The payloads are meant to work on Windows XP and up, failing on all previous versions of Windows due to missing API calls. This means your computer will not start up again. Trying to kill MEMZ will cause your system to beĪt the same moment, the computer's Master Boot Record is overwritten by MEMZ.

YOUR COMPUTER HAS BEEN FUCKED BY THE MEMZ TROJAN. At the same time, it will leave a note titled note.txt for the user saying that they will not be able to use the computer anymore after rebooting it: If the user answers Yes to both warning messages, MEMZ will run. Newer versions of MEMZ Destructive, 4.0 and up, warn the user not to run it on a physical machine as it will damage it and advise the user to run the trojan on a virtual machine. Hi, because of some complaints I will give a complete In-depth overview of what the memz will do to your computer and some of the payloads it can do.
