These virus (I think) have been existed on my computers for few years now, and I had gone through different versions of Windows, (XP,7,8.1,10) and it's still be able to run. It's disguised as explorer.exe , spoolsv.exe and icsys.icn.exe, and live in C:\Windows\Resources . It's tend to use a lot of disk and usually fill up my "C:" partition. Sometimes, when I execute a program, It pops-up as explorer.exe or icnsys.icn.exe and require me to hit yes in order to run the program , if not , the program won't launch. I remembered it was constantly showing error when I reached the peak point of my system memory , It showed a message box with "Project1" in the title and "Out of Memory" inside the box. And there was lots of that box, I had to use Task Manager to kill all of them . It's also tried to copy it's code in other .exe files. It's infect my game executable, which I've scanned right here.
http
/
And I tried to scan icnsys.icn.sys and got the same result
http
/
Every program that it's infected usually have their icon pixelated and their description in "Details" altered. I once tried to change a infected program's description in Resource Hacker and from that point , every program that's it infect have the same description as the one I've changed. Funny thing is the infected program still running fine. It's original description said that it's program name is "Tjprojmain.exe". I think it's written in VB.
I tried to use MBAM , It does clean the virus and detected some reg key that virus inserted .but it can't detect infected files. Even on VirusTotal,Malwarebyte didn't recognize it as a virus.
I also used Hijackthis , and clean them, but it's the same case as MBAM
http

And I tried to scan icnsys.icn.sys and got the same result
http

Every program that it's infected usually have their icon pixelated and their description in "Details" altered. I once tried to change a infected program's description in Resource Hacker and from that point , every program that's it infect have the same description as the one I've changed. Funny thing is the infected program still running fine. It's original description said that it's program name is "Tjprojmain.exe". I think it's written in VB.
I tried to use MBAM , It does clean the virus and detected some reg key that virus inserted .but it can't detect infected files. Even on VirusTotal,Malwarebyte didn't recognize it as a virus.
I also used Hijackthis , and clean them, but it's the same case as MBAM