Important: Malware script on RatSkep

Please read...

Check here for news about the site.

Moderators: LIFE, kiore

Re: Important: Malware script on RatSkep

#141  Postby DoctorE » Sep 28, 2012 2:43 pm

I'm not convinced my computer is clean.. something happened when I entered the site and MSE said nothing, zero, no info at all; I find that spooky :)
User avatar
DoctorE
 
Posts: 10828
Age: 57
Male

Iceland (is)
Print view this post

Ads by Google


Re: Important: Malware script on RatSkep

#142  Postby james1v » Sep 28, 2012 3:34 pm

Ran Avast scan...Turned up a threat....Java:CVE-2012-4681-0(Expl).

Moved it to virus chest, do i just delete it now? Is it the one everyone else got?
"When humans yield up the privilege of thinking, the last shadow of liberty quits the horizon". Thomas Paine.
User avatar
james1v
 
Name: James.
Posts: 8907
Age: 59
Male

Country: UK
United Kingdom (uk)
Print view this post

Re: Important: Malware script on RatSkep

#143  Postby Ironclad » Sep 28, 2012 3:36 pm

byofrcs wrote:
Ironclad wrote:My main pc is still sick.
I've waited 30 mins and the thing is still unusable & won't fully boot, so again I'm starting in safe mode, running Mbytes & doing everything else on my phone or by tablet.
Mbytes isn't finding anything, Zone alarm isn't finding anything & I'm not sure what to do now.


I specialise in removing these and how it is done is more or less voodoo but as a quick start what I do is boot into safe mode (hit bash F8 when PC is starting) and then download and install Avira free version.

It is the bees knees in detecting malware. Run that and them PM me the report.


Still trying. Every time I try to run the downloaded for I get the message:
Installation of Microsoft runtime redist kit failed - please check to see if Windows update is running in parallel

Nothing is running in the background, I'm even offline when trying to install Avira.
"If there was no such thing as science, you'd be right " - Sean Lock

"God ....an inventive destroyer" - Broks

Image
User avatar
Ironclad
RS Donator
 
Name: Nudge-Nudge
Posts: 21065
Age: 14
Male

Country: Wink-Wink
Bahrain (bh)
Print view this post

Re: Important: Malware script on RatSkep

#144  Postby orpheus » Sep 28, 2012 7:29 pm

byofrcs wrote:
Ironclad wrote:My main pc is still sick.
I've waited 30 mins and the thing is still unusable & won't fully boot, so again I'm starting in safe mode, running Mbytes & doing everything else on my phone or by tablet.
Mbytes isn't finding anything, Zone alarm isn't finding anything & I'm not sure what to do now.


I specialise in removing these and how it is done is more or less voodoo but as a quick start what I do is boot into safe mode (hit bash F8 when PC is starting) and then download and install Avira free version.

It is the bees knees in detecting malware. Run that and them PM me the report.


You are a gentleman and a scholar, byofrcs.
Let's try for peace in 2017, shall we?
User avatar
orpheus
 
Posts: 7270
Age: 52
Male

Country: New York, USA
United States (us)
Print view this post

Re: Important: Malware script on RatSkep

#145  Postby orpheus » Sep 28, 2012 7:29 pm

byofrcs wrote:(I am now gathering chicken livers, feathers and magic herbs for the exorcism....)


And a rather scary dude.
Let's try for peace in 2017, shall we?
User avatar
orpheus
 
Posts: 7270
Age: 52
Male

Country: New York, USA
United States (us)
Print view this post

Re: Important: Malware script on RatSkep

#146  Postby byofrcs » Sep 28, 2012 7:45 pm

Ironclad wrote:
byofrcs wrote:
Ironclad wrote:My main pc is still sick.
I've waited 30 mins and the thing is still unusable & won't fully boot, so again I'm starting in safe mode, running Mbytes & doing everything else on my phone or by tablet.
Mbytes isn't finding anything, Zone alarm isn't finding anything & I'm not sure what to do now.


I specialise in removing these and how it is done is more or less voodoo but as a quick start what I do is boot into safe mode (hit bash F8 when PC is starting) and then download and install Avira free version.

It is the bees knees in detecting malware. Run that and them PM me the report.


Still trying. Every time I try to run the downloaded for I get the message:
Installation of Microsoft runtime redist kit failed - please check to see if Windows update is running in parallel

Nothing is running in the background, I'm even offline when trying to install Avira.

Now that is odd as I've not had Avira bork like that but others have,,,,

http://forum.avira.com/wbb/index.php?pa ... dID=110745

Go to http://www.avira.com/en/download/produc ... -antivirus and get the .ZIP version and unpack that and then run the setup.exe
In America the battle is between common cents distorted by profits and common sense distorted by prophets.
User avatar
byofrcs
RS Donator
 
Name: Lincoln Phipps
Posts: 7906
Age: 53
Male

Country: Tax, sleep, identity ?
European Union (eur)
Print view this post

Re: Important: Malware script on RatSkep

#147  Postby Globe » Sep 28, 2012 8:59 pm

byofrcs wrote:(I am now gathering chicken livers, feathers and magic herbs for the exorcism....)

You forgot tar and torches... :coffee:
"Justice will be served!
As soon as I can find you a piece that hasn't gone rotten." - Globe

I don't accept sexism, no matter what gender is being targeted with an -ism.
User avatar
Globe
 
Posts: 6659
Age: 49
Female

Country: Spain NOT Denmark
Spain (es)
Print view this post

Ads by Google


Re: Important: Malware script on RatSkep

#148  Postby Sgt Kelly » Sep 28, 2012 9:12 pm

Damn thing killed my work laptop.

Took about 8 hours to reinstall but fortunately I didn't lose anything.

It was a ZeroAccess rootkit, or something like that.
User avatar
Sgt Kelly
 
Posts: 365
Age: 44
Male

Belgium (be)
Print view this post

Re: Important: Malware script on RatSkep

#149  Postby LIFE » Sep 29, 2012 4:10 pm

Sgt Kelly wrote:Damn thing killed my work laptop.

Took about 8 hours to reinstall but fortunately I didn't lose anything.

It was a ZeroAccess rootkit, or something like that.


Ouch that's a particularly mean one.

Well I don't think everybody got the same malware, I guess whatever is loaded at that site is spawning random stuff.
"If you think education is expensive, try the cost of ignorance" - Derek Bok
"Words that make questions may not be questions at all" - Neil deGrasse Tyson
User avatar
LIFE
Site Admin
THREAD STARTER
 
Name: Bernhard
Posts: 7152
Age: 36
Male

Country: Germany
Germany (de)
Print view this post

Re: Important: Malware script on RatSkep

#150  Postby Ironclad » Sep 29, 2012 4:22 pm

My lappy is screwed, totally buggered. I can't follow byofrcs help because I can't open anything.

Would resetting to an earlier time actually help, or is my pc knackered regardless, if infected?
"If there was no such thing as science, you'd be right " - Sean Lock

"God ....an inventive destroyer" - Broks

Image
User avatar
Ironclad
RS Donator
 
Name: Nudge-Nudge
Posts: 21065
Age: 14
Male

Country: Wink-Wink
Bahrain (bh)
Print view this post

Re: Important: Malware script on RatSkep

#151  Postby byofrcs » Sep 29, 2012 4:34 pm

Ironclad wrote:My lappy is screwed, totally buggered. I can't follow byofrcs help because I can't open anything.

Would resetting to an earlier time actually help, or is my pc knackered regardless, if infected?


Could you boot to Safe Mode ?
In America the battle is between common cents distorted by profits and common sense distorted by prophets.
User avatar
byofrcs
RS Donator
 
Name: Lincoln Phipps
Posts: 7906
Age: 53
Male

Country: Tax, sleep, identity ?
European Union (eur)
Print view this post

Re: Important: Malware script on RatSkep

#152  Postby Ironclad » Sep 29, 2012 4:37 pm

I've tried a hundred times, buddy. I'm still trying to get avira running so I can get that report to you.
"If there was no such thing as science, you'd be right " - Sean Lock

"God ....an inventive destroyer" - Broks

Image
User avatar
Ironclad
RS Donator
 
Name: Nudge-Nudge
Posts: 21065
Age: 14
Male

Country: Wink-Wink
Bahrain (bh)
Print view this post

Re: Important: Malware script on RatSkep

#153  Postby Fallible » Sep 29, 2012 4:39 pm

:confused:
John Grant wrote:They say 'let go, let go, let go, you must learn to let go'.
If I hear that fucking phrase again, this baby's gonna blow
Into a million itsy bitsy tiny pieces, don't you know,
Just like my favourite scene in Scanners .
User avatar
Fallible
RS Donator
 
Name: Alice Pooper
Posts: 43958
Age: 44
Female

Country: Engerland na na
Canada (ca)
Print view this post

Re: Important: Malware script on RatSkep

#154  Postby Aern Rakesh » Sep 29, 2012 4:40 pm

+1
That's horrible, IC!
Image
User avatar
Aern Rakesh
RS Donator
 
Posts: 13582
Age: 68
Female

Country: UK (London)
United States (us)
Print view this post

Re: Important: Malware script on RatSkep

#155  Postby Ironclad » Sep 29, 2012 5:01 pm

I'm trying your earlier suggestion, Byof. I missed this. :)
"If there was no such thing as science, you'd be right " - Sean Lock

"God ....an inventive destroyer" - Broks

Image
User avatar
Ironclad
RS Donator
 
Name: Nudge-Nudge
Posts: 21065
Age: 14
Male

Country: Wink-Wink
Bahrain (bh)
Print view this post

Ads by Google


Re: Important: Malware script on RatSkep

#156  Postby Scarlett » Sep 29, 2012 5:05 pm

Ironclad wrote:My lappy is screwed, totally buggered. I can't follow byofrcs help because I can't open anything.

Would resetting to an earlier time actually help, or is my pc knackered regardless, if infected?


Oh no! I'd be buggered if that happened to me. I'd be useless in any attempts to right it :(
"The stupid bitch"

" ..the Scottish bitch.."

" Too much PC and stupid women."

"..Paula (who still thinks she is the forum pin-up)."


Prize for guessing who? :naughty2:
User avatar
Scarlett
 
Posts: 16046
Female

Scotland (ss)
Print view this post

Re: Important: Malware script on RatSkep

#157  Postby byofrcs » Sep 29, 2012 5:17 pm

You have to get to safe mode else stuff will never work. When it powers up after bios then just keep punching F8 until you get the safe mode questions that windows displays. Start safemode with networking enabled unless you have downloaded Avira free 2012 via another PC.

Why Avira ? because it has brilliant detection even if it is a cantankerous German package.
In America the battle is between common cents distorted by profits and common sense distorted by prophets.
User avatar
byofrcs
RS Donator
 
Name: Lincoln Phipps
Posts: 7906
Age: 53
Male

Country: Tax, sleep, identity ?
European Union (eur)
Print view this post

Re: Important: Malware script on RatSkep

#158  Postby Aern Rakesh » Sep 29, 2012 5:22 pm

byofrcs wrote:You have to get to safe mode else stuff will never work. When it powers up after bios then just keep punching F8 until you get the safe mode questions that windows displays. Start safemode with networking enabled unless you have downloaded Avira free 2012 via another PC.

Why Avira ? because it has brilliant detection even if it is a cantankerous German package.


I see they now make it for the Mac. But I'll have to upgrade to Snow Leopard first, which I'm about to do anyway.

(I already have Intego AV etc installed, will Avira conflict with that?)
Image
User avatar
Aern Rakesh
RS Donator
 
Posts: 13582
Age: 68
Female

Country: UK (London)
United States (us)
Print view this post

Re: Important: Malware script on RatSkep

#159  Postby Ironclad » Sep 29, 2012 5:24 pm

OK, i've finally gotten the .zip but I need a pointer, I always have trouble with these files even though I have 7zip.
When I extract the file I am getting a literal wall of folders, extensions, DAT files & text documents. What do I do now? Which of these blasted items do I click on? Even though the .zip was barely 100mb it is jam-packed.
"If there was no such thing as science, you'd be right " - Sean Lock

"God ....an inventive destroyer" - Broks

Image
User avatar
Ironclad
RS Donator
 
Name: Nudge-Nudge
Posts: 21065
Age: 14
Male

Country: Wink-Wink
Bahrain (bh)
Print view this post

Re: Important: Malware script on RatSkep

#160  Postby byofrcs » Sep 29, 2012 5:28 pm

You can't have two AV packages running at the same time without serious CPU chew and slowdown. No matter what people run I always add in Avira as a trial for the few hours it takes to clean up the infection no matter what they have installed.

What I'm after is not so much detected files but locked files. A locked file (other than hibernate/pagefile.sys) is usually where the virus is hiding and a running process is using it. You can't just delete it but must find how it is loading which usually means searching registry (regedit -> then F3 to search).
In America the battle is between common cents distorted by profits and common sense distorted by prophets.
User avatar
byofrcs
RS Donator
 
Name: Lincoln Phipps
Posts: 7906
Age: 53
Male

Country: Tax, sleep, identity ?
European Union (eur)
Print view this post

PreviousNext

Return to Announcements

Who is online

Users viewing this topic: No registered users and 1 guest