Register for your free account! | Forgot your password?

Go Back   elitepvpers > Popular Games > Silkroad Online > SRO Private Server
You last visited: Today at 04:36

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Attention] Ddos Attacks through the virus Ramnit.A

Discussion on [Attention] Ddos Attacks through the virus Ramnit.A within the SRO Private Server forum part of the Silkroad Online category.

Reply
 
Old 12/18/2012, 21:04   #16
 
_HouseMusicx3's Avatar
 
elite*gold: 100
Join Date: Dec 2007
Posts: 12,305
Received Thanks: 5,307
Funny to see that almost every client in the advertising section got this virus in it :d
_HouseMusicx3 is offline  
Thanks
1 User
Old 12/18/2012, 21:26   #17
 
elite*gold: 62
Join Date: Mar 2011
Posts: 602
Received Thanks: 2,952
Ramnit - Wikipedia, the free encyclopedia

G.T.F.O.


Probably, false positive. Or.. there is still a possibility i were infected with it.
Chernobyl* is offline  
Thanks
2 Users
Old 12/18/2012, 21:58   #18
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,307
Received Thanks: 6,469
Quote:
Originally Posted by Chernobyl* View Post
Ramnit - Wikipedia, the free encyclopedia

G.T.F.O.


Probably, false positive. Or.. there is still a possibility i were infected with it.
remember your impostor months ago?
maybe it was that, cuz your current exe is clean(btw, any issue if you could share the source with me, i want to take a look at it and be sure[no publication will be made. dont worry])
PortalDark is offline  
Old 12/18/2012, 22:00   #19
 
elite*gold: 62
Join Date: Mar 2011
Posts: 602
Received Thanks: 2,952
PortalDark, might be it. Well, why don't you just disassemble it with .net reflector, and compile back ?
Chernobyl* is offline  
Old 12/18/2012, 23:06   #20
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,307
Received Thanks: 6,469
Quote:
Originally Posted by Chernobyl* View Post
PortalDark, might be it. Well, why don't you just disassemble it with .net reflector, and compile back ?
you didn't obscured the code?
wow, i thought it was


Edit: current SrPatcher is clean
use a .net decompiler to check it yourself
PortalDark is offline  
Old 12/21/2012, 21:54   #21
 
theross's Avatar
 
elite*gold: 0
Join Date: Mar 2007
Posts: 364
Received Thanks: 592
releasing a beasty virus which would spread easily, and because the "latest" tool is clean the accused one is not guilty anymore?

cool. I'll rape a dog and later I'll NOT rape a dog. it's like i have never raped a dog =)

I kill someone at the park, and go home. as there are people passing by me on my way home, which didn't get killed by me, I'm not a killer. YAY!
theross is offline  
Old 12/21/2012, 22:33   #22
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,307
Received Thanks: 6,469
Quote:
Originally Posted by theross View Post
releasing a beasty virus which would spread easily, and because the "latest" tool is clean the accused one is not guilty anymore?

cool. I'll rape a dog and later I'll NOT rape a dog. it's like i have never raped a dog =)

I kill someone at the park, and go home. as there are people passing by me on my way home, which didn't get killed by me, I'm not a killer. YAY!
some time ago, cherno got hacked by this same virus and the hacker spread over cherno's tools the virus(i think that was one of the reasons cherno got demoted at RZ. I can confirm that it was indeed a guy spreading the virus, but i can assure Cherno(the real one) wasn't the responsible for that
as for the virus, it is not very dangerous. The real danger is the virus that is based over this one, which is identified by other names
PortalDark is offline  
Old 12/21/2012, 22:51   #23
 
elite*gold: 0
Join Date: Mar 2012
Posts: 81
Received Thanks: 22
told you days ago, all clients are infected
boOoO0oris is offline  
Old 12/21/2012, 22:53   #24
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,307
Received Thanks: 6,469
Quote:
Originally Posted by boOoO0oris View Post
told you days ago, all clients are infected
not mine at least
scanned with 4 different AV(home) and VirusTotal
but good for me that I always run SRO files(client too) on sandbox
PortalDark is offline  
Old 12/21/2012, 22:56   #25
 
naty48's Avatar
 
elite*gold: 0
Join Date: Mar 2009
Posts: 337
Received Thanks: 474
yeah , i found out that one day all my files&clients were infected with that.

installed malewarebytes + ESET = they got deleted.

also this **** caused my entire stuff wiped.

i can confirm it has nothing to do with the tools of chernobyl since i never downloaded any of those.

it was inside the original vsro 1.188 server files (which shown has clean a few days ago).

this virus will infect your website and everyone who get inside it will get infected too also it's infecting dlls , .exes , .ico , .png , .php ,.html files .

really nice spreader , didn't looked about what this one actually does.

and i dont really care since it was cleared by malewarebytes.

just beware and make sure your servers are SAFE and you got AV/MLB Installed there!!.

so yeah , chernobyl has nothing to do with that as far as i know.
naty48 is offline  
Old 12/21/2012, 23:18   #26
Chat Killer In Duty


 
PortalDark's Avatar
 
elite*gold: 5
Join Date: May 2008
Posts: 16,307
Received Thanks: 6,469
Quote:
Originally Posted by naty48 View Post
yeah , i found out that one day all my files&clients were infected with that.

installed malewarebytes + ESET = they got deleted.

also this **** caused my entire stuff wiped.

i can confirm it has nothing to do with the tools of chernobyl since i never downloaded any of those.

it was inside the original vsro 1.188 server files (which shown has clean a few days ago).

this virus will infect your website and everyone who get inside it will get infected too also it's infecting dlls , .exes , .ico , .png , .php ,.html files .

really nice spreader , didn't looked about what this one actually does.

and i dont really care since it was cleared by malewarebytes.

just beware and make sure your servers are SAFE and you got AV/MLB Installed there!!.

so yeah , chernobyl has nothing to do with that as far as i know.
no doubt many servers have the favicon.png infected on their websites
vSRO files virus is just a false positive, nothing to do with the real one
good thing im not infected
PortalDark is offline  
Reply


Similar Threads Similar Threads
[Security Release]Stop the recent attacks(That are not ddos attacks.)
12/04/2012 - Shaiya PServer Guides & Releases - 1 Replies
Hi everyone here is a little tutorial on the recent attacks as i've seen and were i played on servers which have gotten attacked, so to prevent this issue here is the tutorial below. Get the program called rKill, which i have provided below And block in firewall this IP *fetching ip* Range: xxx.xxx.xxx.x - xx.xx.xxx.xxx Range: xx.xxx.xxx.x - xxx.xxx.xxx.xxx Range: xx.x.xxx.x - xx.x.xxx.xx As far as rKill, use it only under attack, It may block you out for a few seconds, and make players...
[VIRUS] Warrock Virus.Ramnit.X infinziert
07/31/2012 - WarRock Guides, Tutorials & Modifications - 2 Replies
Hallo Liebe Warrock Com. Als ich Heute mein Computer mit Malwarebytes scannte fande der einen Virus versteckt in der Warrock Launcher.exe. Dieser Virus nennt sich Ramnit, Ramnit ist ein Virus der andere Anwendungsdatein also *.exe infiziert. Ich empfehle euch da ihr noch ca. 1-2 std. Zeit wegen der Maintance habt euer System zu Prüfen. HKCR\NXCOM.NxGameControl.EU.2 (Virus.Ramnit) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Nexon\Common\dbghelp.dll (Virus.Ramnit)...
[VIRUS] Warrock Virus.Ramnit.X infinziert
07/26/2012 - WarRock - 11 Replies
Hallo Liebe Warrock Com. Als ich Heute mein Computer mit Malwarebytes scannte fande der einen Virus versteckt in der Warrock Launcher.exe. Dieser Virus nennt sich Ramnit, Ramnit ist ein Virus der andere Anwendungsdatein also *.exe infiziert. Ich empfehle euch da ihr noch ca. 1-2 std. Zeit wegen der Maintance habt euer System zu Prüfen. HKCR\NXCOM.NxGameControl.EU.2 (Virus.Ramnit) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Nexon\Common\dbghelp.dll (Virus.Ramnit)...
Attention: Hackers attacks from Cabal Rider!
03/10/2009 - Cabal Online - 22 Replies
Forget I posted this, no I do not go to porn sites and to get hi jacked by hackers! Also I do not use IE cuz it sucks and I actually use Mozilla. I'm not really the type of nerd person but I heard you can change your IP by unplugging your modem router? I did that but my IP is the same and my Internet Files in local settings is infected by the Trojan horse PSW.OnlineGames. So from now on I will not blame anymore because I quit hacking and another reason is because I get flamed. Now someone tell...



All times are GMT +2. The time now is 04:36.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.