Share via

Windows Defender detects Trojan:Win64/TamperedChef.Z!MTB through malicious PDF Editor application

anton hård hed 0 Reputation points
2026-06-12T21:12:46.7033333+00:00

Hej.

En familjemedlem blev utsatt av ett falskt PDF Editor program. Vet ej hur länge sedan det var installerat.

Vi märkte ett par transparenta förmodligen PowerShell rutor som snabbt öppnades och stängdes. Tydligen har detta hänt någon gång ibland.

Då gjorde vi en Windows Defender full scanning och hittade fyra .exe program inom denna PDF Editor, och dom sattes direkt i karantän och sedan togs bort.

Trojan:Win64/TamperedChef.Z!MTB

C:\Users\Username\PDFEditor\resources\elevate.exe

Status: Borttaget

Trojan:JS\InfoStealer!MSR

C:\Users\Username\PDFEditor\resources\app\w-electron\bin\release\pdfeditor.js

Status: Borttaget

Trojan:Win32/InfoStealer!MSR

C:\Users\Username\AppData\Local\pdfeditor-updater\installer.exe

Status: Borttaget

Trojan:Win32/InfoStealer!MSR

C:\Users\Username\PDFEditor\PDFEditorSetup.exe

Status: I Karantän

Har även rensat webbläsarens alla sparade cache, cookies etc.

Tog bort PDF Editorns Mappen som skapades av programmet, tog också bort en PDF Editor mapp som var i Regedit

Min fråga är då, är datorn säker nu eller är det fortfarande i bakgrunden och fortsätter att fungera? Vad mer kan man göra och kan man se när programmet blev installerat?

Mvh Anton.

P.S. Datorn använder Windows 11 home.

P.P.S. Beklagar det ojämna radavståndet, mobilen ville inte riktigt samarbeta med mig i dag.

Microsoft Security | Microsoft Defender | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-06-12T21:13:04.3766667+00:00

    The malicious PDF editor behaved like a trojan and infostealer. Windows Defender has already detected and removed multiple related components, which is a good sign, but a few extra checks help ensure the device is clean and stays protected.

    Steps to take now:

    1. Run a full Microsoft Defender Antivirus scan again
      • Open Windows SecurityVirus & threat protection.
      • Make sure Microsoft Defender Antivirus is enabled.
      • Under Current threats, choose Scan optionsFull scan and run it.
      • Before scanning, select Virus & threat protection updatesCheck for updates to get the latest definitions, as recommended in the malware troubleshooting guidance.
    2. Turn on cloud-based protection and sample submission
      • In Windows SecurityVirus & threat protectionManage settings under Virus & threat protection settings.
      • Ensure Cloud-delivered protection and Automatic sample submission are set to On. This increases the chance of detecting any remaining or new variants of the malware.
    3. Run Microsoft Defender Offline
      • Microsoft Defender Offline scans outside of Windows and can detect rootkits or threats that try to hide from the normal OS.
      • In Windows Security, choose Virus & threat protection → look for Microsoft Defender Offline scan (or Scan optionsMicrosoft Defender Offline scan) and run it.
      • The PC will restart and perform a special scan before Windows loads.
    4. Remove any remaining unwanted software and browser add-ons
      • Go to Settings > Apps > Apps & features and uninstall any PDF editor or other software that is not recognized or needed, especially anything related to the fake PDF editor.
      • In each browser used on the PC, remove unknown or suspicious extensions/add-ons and reset unwanted changes (home page, search engine, etc.).
    5. If suspicious files remain
      • If Defender reports suspicious files that it cannot remove or that keep reappearing, submit them to Microsoft for analysis using the file submission portal referenced in the documentation.
    6. How to check when the program was installed
      • In Settings > Apps > Apps & features, locate any remaining entries related to the PDF editor. The Install date column (or by sorting by install date) shows when each app was installed.
      • If the app entry has already been removed, the exact install date may no longer be visible in this list, but checking other apps around the same install date can still give a rough timeframe.

    How to judge if the PC is likely clean now:

    • If:
      • All components of the fake PDF editor have been uninstalled and its folders deleted,
      • A fully updated Microsoft Defender Antivirus full scan shows no threats,
      • A Microsoft Defender Offline scan also shows no threats,
      • No new suspicious behavior appears (no unexpected PowerShell windows, no unknown apps, no browser changes),

    then the system is likely clean and protected by Defender.

    If new detections or suspicious behavior continue after these steps, consider backing up important data and consulting a professional technician or support channel for deeper investigation.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.