Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Short answer: “Firmware replying trojan that uses genuine Windows remoting to take over – Page 2” is not the name of a confirmed malware family or a published Malwarebytes threat report. It is the title of a Malwarebytes community malware-removal thread created on May 2, 2023. “Page 2” is simply the forum’s pagination.

The thread records one user’s theory about firmware persistence, Remote Desktop, PowerShell, DNS changes and Windows system files. Malwarebytes staff did not verify a firmware infection. They reported that the submitted files were not detected as threats and requested process and log evidence showing what had actually invoked them.

Where the claim came from

The source is a Malwarebytes Forums thread in the “Resolved Malware Removal Logs” section—not a Malwarebytes security bulletin, malware-family analysis or vendor advisory. The original title is “Firmware replying trojan that uses genuine windows remoting to take over.” The second URL page is a continuation of the same discussion, not a separate article or a second infection report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The thread was later closed after the poster stopped providing feedback. That closure does not confirm or disprove the proposed infection theory.

#1 Best Overall
Sale
Malwarebytes Standard, Premium Security| Amazon Exclusive | 18 Months, 2 Devices | Windows, Mac OS, Android, Apple iOS, Chrome [Online Code]
  • AWARD WINNING Antivirus, anti-malware, anti-spyware & more
  • 24/7 REAL TIME PROTECTION against emerging malware threats, including ransomware and viruses- without slowing you down.
  • PROTECTS YOUR DEVICES ON MULTIPLE PLATFORMS: Get cyber protection for your computers, smartphones, or tablets- Compatible with Windows, Mac, Android, iOS
  • DOWNLOAD AND INSTALL INSTANTLY
  • UNMATCHED THREAT DETECTION: We found malware on 40 percent of devices that already had a third-party antivirus installed.

What the poster alleged

The poster’s account included allegations that an attacker:

  • Abused genuine Windows components to avoid detection.
  • Created or used remote-control functionality, including Remote Desktop.
  • Used PowerShell extensively.
  • Changed DNS settings.
  • Replaced or copied files such as mstsc.exe and osk.exe.
  • Enabled or accessed the Guest account.
  • Used Xbox Game Bar or Microsoft-account-related mechanisms.
  • Persisted through firmware, Windows Recovery or Windows installation processes.
  • May have involved Nvidia or Realtek device firmware.

These are claims made by the forum poster. The available discussion does not provide independent firmware analysis, a firmware image showing unauthorized changes, or a reproducible demonstration that the suspected behavior survived replacement of the operating system and storage.

What Malwarebytes actually established

Malwarebytes staff reported that the uploaded items were not detected as threats by the security vendors checked. The discussion included files such as:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • KnownGameList.bin, reported with a 0/58 VirusTotal detection result.
  • mbamchameleon.sys, identified as a Malwarebytes driver and reported with a 0/70 result.
  • RunExeActionAllowedList.dat, reported with a 0/58 result.

A zero-detection result is not proof that a file is harmless. Conversely, a behavior label in a sandbox is not proof that a firmware implant exists. Malwarebytes also pointed out that the .dat material was text or JSON-like configuration content. Such a file cannot independently execute; an investigator needs to identify the process that read it and determine what that process did.

Rank #2
Malwarebytes Premium 4.5 Latest Version Antivirus Software | 12 Months, 10 Devices (Windows, Mac OS, Android, Apple iOS, Chrome) [software_key_card]
  • PROTECTS YOUR DEVICES ON MULTIPLE PLATFORMS: Compatible with Windows, Mac, Android devices.
  • UNMATCHED THREAT DETECTION: We found malware on 29 percent of devices that already had a third-party antivirus installed. That’s the power of our innovative technology. We block sophisticated cyberthreats that other programs miss, providing an effective way to secure your devices and data.
  • INCREDIBLY EASY TO USE: Our simple user interface enables you to fully control your protection to meet your needs without requiring technical expertise. You can schedule scans, adjust protection layers, and choose your desired scan mode. Protecting your devices shouldn’t be complicated.
  • ADVANCED MALWARE, RANSOMWARE PROTECTION: Helps protect you from websites that download ransomware, steal login credentials, or run scams. Reduces your exposure to hackers and cyberthreats while protecting your devices and data.
  • PROACTIVE EXPLOIT, AND VIRUS PROTECTION: Protection from the financial and reputational risk posed by a ransomware attack. Shields your device and data from vulnerable and unpatched software until it can be updated. Malwarebytes finds more threats compared to traditional antivirus programs so you can restore your device quickly to its pre-infection state.

This distinction is central. A suspicious filename, an unusual configuration file or a sandbox observation is an investigative lead—not a complete infection chain.

What “genuine Windows remoting” might mean

The phrase is technically ambiguous. It could refer to several different Windows features or legitimate tools:

Technology What it does Evidence needed
Remote Desktop Services Provides graphical remote sessions, commonly associated with mstsc.exe. RDP logons, source addresses, authentication events and service or firewall changes.
WinRM Microsoft’s implementation of WS-Management for remote administration. WinRM service activity, authentication records, source IPs and command execution logs.
PowerShell remoting Runs PowerShell commands through remoting technologies such as WinRM. PowerShell operational events, Script Block Logging, command lines and process ancestry.
Remote-support software Allows legitimate help-desk or administrator access. Installed software, account ownership, connection history and provider records.

Microsoft documents WinRM as Windows Remote Management. The winrs command is a command-line client for executing commands remotely through WinRM. WinRM, RDP and PowerShell remoting are related but distinct. Nothing in the forum title alone proves that WinRM was used.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why legitimate Windows files can appear in an attack

Attackers sometimes abuse trusted Windows tools through malicious command-line arguments, injected code, DLL search-order hijacking, unsafe file replacement, scheduled tasks, services, WMI subscriptions or stolen credentials. But the filename alone cannot show whether that happened.

Rank #3
Sale
Malwarebytes Standard, Premium Security + VPN Software | 1 Year, 2 Device | Windows, Mac OS, Android, Apple iOS, Chrome [Online Code]
  • Malwarebytes Premium: Available for Windows, Mac, iOS, Android and Chromebook. 24/7 real-time protection against emerging threats
  • Malwarebytes Browser Guard: Available for Chrome, Edge, Firefox and Safari. Removes annoying ads that follow you around. Blocks third-party ad trackers that collect your data. Helps protect against tech support and online scams. Blocks malicious web pages, stops in-browser cryptojackers.
  • Malwarebytes Privacy: Available for Windows, Mac, iOS, Android. Next-gen, no-log VPN to protect your online digital footprint. Secure public Wi-Fi connections. One-click, intuitive UI to manage your online privacy. 500+ servers in 40+ countries.

For a file such as mstsc.exe, osk.exe, msdt.exe or svchost.exe, collect:

  • Its complete path.
  • SHA-256 hash.
  • Authenticode signature and signer.
  • File version and timestamps.
  • Parent process and complete command line.
  • Loaded modules.
  • Network connections.
  • User account and integrity level.
  • Relevant Windows event records.

A signed Microsoft executable is not automatically safe: trusted tools can be abused. But a signed filename is also not evidence that the file was replaced. Hash, path, signature, process context and timeline must be examined together.

Why the firmware theory remains unproven

Firmware persistence is a much stronger claim than ordinary Windows malware. A credible firmware investigation would normally require some combination of:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • A vulnerable or compromised device-flashing path.
  • A firmware image or dump showing unauthorized modifications.
  • Reproducible reinfection after a clean operating-system reinstall.
  • Persistence that survives secure reinitialization or storage replacement.
  • Hardware-specific indicators.
  • Vendor or independent reverse-engineering analysis.

Several different persistence layers can be confused with firmware:

Rank #4
Malwarebytes Standard, Premium Software | 5 Device 1 Year (Windows, Mac OS, Android, Apple iOS, Chrome) [software_key_card]
  • AWARD WINNING Antivirus, anti-malware, anti-spyware & more
  • 24/7 REAL TIME PROTECTION against emerging malware threats, including ransomware and viruses- without slowing you down
  • PROTECTS YOUR DEVICES ON MULTIPLE PLATFORMS: Get cyber protection for your computers, smartphones, or tablets- Compatible with Windows, Mac, Android, iOS devices
  • DOWNLOAD AND INSTALL INSTANTLY
  • UNMATCHED THREAT DETECTION: We found malware on 40 percent of devices that already had a third-party antivirus installed
  1. UEFI or boot persistence: code that runs before Windows.
  2. Recovery-partition persistence: tampering with Windows Recovery or installation media.
  3. Malicious-driver persistence: a Windows driver that starts early in the operating system.
  4. Compromised installer or update: malicious software introduced during setup or updating.
  5. Ordinary Windows malware: persistence through services, tasks, registry keys or scripts.
  6. Account or network compromise: stolen credentials, router changes or malicious DNS.

The forum discussion does not distinguish these possibilities conclusively. It therefore should not be used to claim that Nvidia or Realtek firmware was infected, that reinstalling Windows cannot remove the threat, or that a new firmware-rootkit family was discovered.

How to interpret VirusTotal behavior reports

VirusTotal can provide useful reputation and analysis signals, but its results require context.

  • A file can have no antivirus detections and still deserve investigation.
  • A sandbox can observe actions caused by its test environment rather than normal host behavior.
  • A domain or IP seen in a behavior report is not automatically attacker infrastructure.
  • A signed Windows executable may legitimately access files, registry keys, PowerShell or network services.
  • Behavior tags are leads, not independent forensic proof.

The poster cited behavior involving PowerShell, keylogging, clipboard access, registry discovery and file enumeration. The thread does not establish that these actions came from a confirmed firmware implant rather than a diagnostic tool, test harness or unrelated process. Analysts should correlate the exact sample hash, execution context, command line and timestamps with host telemetry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Safe triage for a suspected compromise

1. Contain the system

If active compromise is plausible, disconnect the computer from networks. Avoid logging into sensitive accounts from it. If evidence may be needed, do not immediately wipe the machine before preserving relevant records.

Best Value
Sale
McAfee+ Premium 2026 Antivirus Software, Unlimited Devices | Auto-Renews
  • ALL-IN-ONE PROTECTION – award-winning antivirus, total online protection, works across compatible devices, Identity Monitoring, Secure VPN
  • SCAM DETECTOR - We'll automatically identify risky texts, emails, and videos that attempt to steal your personal or financial information. You can even use our mobile app to check social messages and QR codes for scams on-demand, without missing a beat.
  • SECURE VPN – Secure and private browsing, unlimited VPN, privacy on public Wi-Fi, protects your personal info, fast and reliable connections
  • PERSONAL DATA SCAN - Scans for personal info, finds old online accounts and people search sites, helps remove data that’s sold to mailing lists, scammers, robocallers
  • SOCIAL PRIVACY MANAGER - helps adjust more than 100 social media privacy settings to safeguard personal information

2. Record the environment

Note the computer make and model, Windows edition and build, BIOS/UEFI version, recent firmware updates, symptoms, first-seen date, recent installers and connected external devices.

3. Preserve useful evidence

  • Windows Event Logs.
  • Security-product detection and quarantine logs.
  • Autoruns, scheduled-task and service inventories.
  • Network and DNS configuration.
  • Relevant file hashes and signature results.
  • RDP, WinRM and PowerShell logs.

Redact usernames, IP addresses, tokens, email addresses and other sensitive information before posting logs publicly.

4. Check the likely persistence points

  • Unexpected local users, new administrators and the Guest account state.
  • RDP or WinRM configuration changes.
  • New scheduled tasks, services and drivers.
  • PowerShell Script Block Logging events.
  • Unusual outbound connections.
  • DNS settings on both the Windows computer and the router or DHCP server.

5. Validate Windows files safely

Use trusted Microsoft repair and verification mechanisms rather than manually deleting or replacing system binaries. A system file should be assessed by path, signature, hash and process context—not by its name alone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Escalate persistent cases

If suspicious behavior returns after a properly performed clean reinstall, or if firmware tampering remains a credible possibility, contact the device manufacturer, a professional incident-response provider or a reputable local technician. Hardware and firmware analysis is outside the scope of ordinary consumer malware scanning.

What not to do

  • Do not run a forum repair script written for another computer.
  • Do not manually delete Windows executables because their names appear in a report.
  • Do not treat one VirusTotal result as a complete diagnosis.
  • Do not assume a DNS change came from the endpoint; inspect the router and DHCP path.
  • Do not publish unredacted diagnostic logs.

Malwarebytes staff specifically warned that the Farbar fix procedure in the thread was machine-specific and could damage another system. It should not be copied as a generic cleanup recipe. The Malwarebytes Support Tool can be used as a vendor-supported diagnostic route, but collecting logs does not prove that the alleged firmware infection exists.

Evidence thresholds for common conclusions

Conclusion Responsible minimum evidence
Windows remoting was used RDP, WinRM or PowerShell-remoting logs linked to a process and network timeline.
A Windows binary was replaced Hash mismatch against a trusted baseline, invalid signature or verified malicious binary.
The malware came from firmware Firmware-image evidence or reproducible persistence across operating-system and storage replacement.
DNS was hijacked Resolver, router, DHCP or packet-capture evidence showing the change and its timing.
The Guest account was abused Account state, authentication records and a matching timeline.
VirusTotal confirmed malware The exact sample hash plus corroborating analysis; behavior labels alone are insufficient.

The Bottom Line

Bottom line: The Malwarebytes thread documents suspicious activity and an unverified firmware-persistence theory. It does not establish a named “firmware replying trojan,” prove that WinRM or RDP was used, or demonstrate that Nvidia, Realtek or Windows firmware was infected. Treat the discussion as a starting point for evidence-based Windows and network triage—not as confirmation of a new malware threat.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.