[ATTACH] Now he's trying to get rid of it. Glad i found this report first, or i might have ended up with a tag myself.
Thanks to advicebanana we now have the full configuration of that malware: [INI file] 0x63b2e9fd [Client] _present=1 DisableChat=1...
Alright, i analyzed the executable. It is indeed mumble, but with a nasty surprise appended, a malicious Microsoft Javascript file: [ATTACH]
Accused of Hijacking | steamname: Fat German Pigletzzz | steam3ID: [U:1:38254412] | steamID32: STEAM_0:0:19127206 | steamID64:...
Separate names with a comma.