Login to ZARP
Username: Password: Remember me

TOPIC: A gr8 l8 PSA

A gr8 l8 PSA 9 years 11 months ago #80515

Have you ever seen something similar to this?

And I mean almost identical, if so. Wipe your PC.
This is Betabot, betabot is a fucking crazy ass botnet designed not to be removed.


What does betabot do?
It runs, hides it's files using a userkit/ring3 rootkit (Fancy way of saying FUCK YOU Anti-viruses and any prying eyes)
It then forces admin using that prompt you saw
Then it kills all AVs (Anti-viruses) on your system.
You are now stuck with a hectic botnet, designed to steal Passwords and Credit cards from you. GLHF.

Getting rid of it can be a pain, finding a file hidden by a root kit is kinda hard. Since rootkits affect only system api calls, reading directly from hardware is one way to do it. Try finding programs against it.

The positives of betabot are as follows, it stops most malware from running as its root kit hooks functions used by most malware and renders them unusable. Once a bot kill has been completed your machine would be cleaner then if you had run a Virus Scan.

Why your AV can't help you. Making it undetected by all anti viruses is easy, once its run it then has a foothold and can beat the AVs.

If you need help removing it just ask.
  • kristofferson
  • kristofferson's Avatar
  • Offline
  • Gold Boarder
  • ZARP VIP
  • 420 Blaz It Son
  • Posts: 2664
  • Thanks received: 627
  • Karma: -39
I'm EMP's only friend
"Do you have to wear lip stick" - RedPowder 2016
Unable to display Google Map.
[spoiler=throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]]'throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13][/spoiler][quote=throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]][code=throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]...
Last Edit: 9 years 11 months ago by kristofferson.
Login or register to post a reply.
The following user(s) said Thank You: Blocked, Luxor

A gr8 l8 PSA 9 years 11 months ago #80559

Malwarebytes Chameleon
  • DarthVader
  • DarthVader's Avatar
  • Offline
  • Expert Boarder
  • ZARP VIP
  • EX-SSRP ADMIN
  • Posts: 1393
  • Thanks received: 285
  • Karma: 3


AKA Victor
Login or register to post a reply.
The following user(s) said Thank You: Tettra

A gr8 l8 PSA 9 years 11 months ago #80567

Good thing soxey is back telling us this information. Don't understand most of it, but still hey, he's helping :)
  • Studio Banter
  • Studio Banter's Avatar
  • Offline
  • Marvelous Boarder
  • ZARP VIP
  • ❤️
  • Posts: 14009
  • Thanks received: 5849
  • Karma: -60
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80569

gr8 to heer i hav not encconterd this befor thank for shering.

In reality, I've only suffered from one major virus. I can't remember it's name. All it did was stop me from opening any program and saying it's infected. I just rolled my PC back. it fixed that twat.
  • BigNoobUsername
  • BigNoobUsername's Avatar
  • Offline
  • User is blocked
  • ZARP VIP
  • Posts: 1708
  • Thanks received: 274
  • Karma: -4
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80577

>makes botnet
>warns everyone about botnet
  • Section
  • Section's Avatar
  • Offline
  • Junior Boarder
  • ZARP VIP
  • Posts: 194
  • Thanks received: 40
  • Karma: 1

''Its always darkest before the dawn''
i got 99 bots and soxey is one.
Login or register to post a reply.
The following user(s) said Thank You: Zer0nix

A gr8 l8 PSA 9 years 11 months ago #80582

It is not actually always a virus if you see that pop up. I had it recently, because my HDD was dying. I did multiple S.M.A.R.T. scans on my harddrive and it was actually my harddrive failing, not a virus.

So how can you tell the difference?

I found some more detailed information
  • Ruben
  • Ruben's Avatar
  • Offline
  • Fresh Boarder
  • Posts: 63
  • Thanks received: 6
  • Karma: 2
You don't know the man, nor his history
Last Edit: 9 years 11 months ago by Ruben.
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80584

Ruben wrote:
It is not actually always a virus if you see that pop up. I had it recently, because my HDD was dying. I did multiple S.M.A.R.T. scans on my harddrive and it was actually my harddrive failing, not a virus.

So how can you tell the difference?

I found some more detailed information

Viruses that display error messages like this are designed to be the same as the real ones. from my experience, there is no 'real' way to tell...The best way is to not rush into thinking its legit, just because its says its from 'windows' dont mean it true.
look on the internet, google is your best friend. always.
  • Section
  • Section's Avatar
  • Offline
  • Junior Boarder
  • ZARP VIP
  • Posts: 194
  • Thanks received: 40
  • Karma: 1

''Its always darkest before the dawn''
i got 99 bots and soxey is one.
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80585

Yeah, the virus tries to gain permission through command prompt.

So, that means, if you get this pop-up without command prompt (while you have UAC enabled), it is legit.
  • Ruben
  • Ruben's Avatar
  • Offline
  • Fresh Boarder
  • Posts: 63
  • Thanks received: 6
  • Karma: 2
You don't know the man, nor his history
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80586

Section wrote:
Ruben wrote:
It is not actually always a virus if you see that pop up. I had it recently, because my HDD was dying. I did multiple S.M.A.R.T. scans on my harddrive and it was actually my harddrive failing, not a virus.

So how can you tell the difference?

I found some more detailed information

Viruses that display error messages like this are designed to be the same as the real ones. from my experience, there is no 'real' way to tell...The best way is to not rush into thinking its legit, just because its says its from 'windows' dont mean it true.
look on the internet, google is your best friend. always.

Done.
  • Studio Banter
  • Studio Banter's Avatar
  • Offline
  • Marvelous Boarder
  • ZARP VIP
  • ❤️
  • Posts: 14009
  • Thanks received: 5849
  • Karma: -60
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80592

Ruben wrote:
Yeah, the virus tries to gain permission through command prompt.

So, that means, if you get this pop-up without command prompt (while you have UAC enabled), it is legit.

NONONONO!!!!!!! CMD has nothing to do with this. It tricks you into giving it Admin rights or smthn like that if you have UAC enabled...

usa.kaspersky.com/internet-security-center/definitions/beta-bot
  • DarthVader
  • DarthVader's Avatar
  • Offline
  • Expert Boarder
  • ZARP VIP
  • EX-SSRP ADMIN
  • Posts: 1393
  • Thanks received: 285
  • Karma: 3


AKA Victor
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80595

If you read the article I posted, you could clearly see that the virus USES the command prompt to ask for permission. If you start up command prompt with elevated permissions, processes started through that instance of the command prompt inherit the permissions and thus have elevated permissions as well.

So the virus starts cmd.exe with admin rights, you are prompted with a pop-up to ask if you want to give permission. If you don't click "More details" you won't be able to see WHAT it is running, thus you won't see any harm in accepting it. As soon as you accept it, it opens, runs a command, closes the command prompt. Virus is now up and running.

If you don't have UAC enabled, it can do this without even asking for permission.

So if you see a pop-up about a corrupt folder or files, without being prompted with a command prompt asking for admin permissions and you have UAC enabled, you can almost surely say that it is not a virus, but a legitimate warning.
  • Ruben
  • Ruben's Avatar
  • Offline
  • Fresh Boarder
  • Posts: 63
  • Thanks received: 6
  • Karma: 2
You don't know the man, nor his history
Last Edit: 9 years 11 months ago by Ruben.
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80753

Ruben wrote:
If you read the article I posted, you could clearly see that the virus USES the command prompt to ask for permission. If you start up command prompt with elevated permissions, processes started through that instance of the command prompt inherit the permissions and thus have elevated permissions as well.

So the virus starts cmd.exe with admin rights, you are prompted with a pop-up to ask if you want to give permission. If you don't click "More details" you won't be able to see WHAT it is running, thus you won't see any harm in accepting it. As soon as you accept it, it opens, runs a command, closes the command prompt. Virus is now up and running.

If you don't have UAC enabled, it can do this without even asking for permission.

So if you see a pop-up about a corrupt folder or files, without being prompted with a command prompt asking for admin permissions and you have UAC enabled, you can almost surely say that it is not a virus, but a legitimate warning.

If you have actually seen the botnet in action you'll notice it does not always use CMD. The virus runs w/wo admin priv.

Once clicked, it spams UAC, and you cannot use your PC without wiping. So you know, poor programming = fun for me.

An easy way to tell is that it'll always say Documents, always 3 and many other things like the lack of a close, min, or max controls.



Section wrote:
>makes botnet
>warns everyone about botnet
<3 you section. they don't know what I have on my site.



DarthVader wrote:
Malwarebytes Chameleon
I do believe that it even kills that, not entirely sure, but BB was released after this so i'd assume so.


DarthVader wrote:
Ruben wrote:
Yeah, the virus tries to gain permission through command prompt.

So, that means, if you get this pop-up without command prompt (while you have UAC enabled), it is legit.

NONONONO!!!!!!! CMD has nothing to do with this. It tricks you into giving it Admin rights or smthn like that if you have UAC enabled...

usa.kaspersky.com/internet-security-center/definitions/beta-bot

What it does is it executes CMD with arguements to execute itself with admin privileges.



Extra information:
A single build (A binary/executable like .exe designed for 1 site) costs $50 even after the program was leaked and cracked. Builders can go for $200 and are not easy to come across. I may have one.
  • kristofferson
  • kristofferson's Avatar
  • Offline
  • Gold Boarder
  • ZARP VIP
  • 420 Blaz It Son
  • Posts: 2664
  • Thanks received: 627
  • Karma: -39
I'm EMP's only friend
"Do you have to wear lip stick" - RedPowder 2016
Unable to display Google Map.
[spoiler=throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]]'throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13][/spoiler][quote=throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]+a[13]][code=throw/a/,Uncaught=1,g=alert,a=URL+0,onerror=eval,/1/g+a[12]+[1337]...
Last Edit: 9 years 11 months ago by kristofferson.
Login or register to post a reply.

A gr8 l8 PSA 9 years 11 months ago #80761

Section wrote:
>makes botnet
>warns everyone about botnet

Yep.
  • The Gamer Guy
  • The Gamer Guy's Avatar
  • Offline
  • Diamond Boarder
  • ZARP VIP
  • ...
  • Posts: 3895
  • Thanks received: 749
  • Karma: 20


SSRP - Ex-Super Admin
Minecraft - Ex-Admin
TeamSpeak - Ex-Staff

Login or register to post a reply.
Time to create page: 0.150 seconds

270 PLAYERS ONLINE

Connect to server View Gametracker DarkRP 1
7/127
online
Connect to server View Gametracker Deathrun
1/40
online
Connect to server View Gametracker TTT
0/47
online
Connect to server View Gametracker Bhop
0/32
online
Connect to server View Gametracker Surf
1/32
online
Connect to server View Gametracker Prop Hunt
0/42
online
Connect to server View Gametracker Sandbox
0/42
online
Connect to server Discord
261/905
online
Top