[New Virus ?]

07/25/2013 19:18 鳳凰城#16
It is not ramnit nor trojan. it's new kind of virus which duplicates itself when you're running DEP for such application.


Ex on crossfire ps: [Only registered and activated users can see links. Click Here To Register...]
07/25/2013 19:36 LastThief*#17
Quote:
Originally Posted by Phoenix 1337 View Post
It is not ramnit nor trojan. it's new kind of virus which duplicates itself when you're running DEP for such application.


Ex on crossfire ps: [Only registered and activated users can see links. Click Here To Register...]
SRV is ramnit >.>
07/25/2013 19:56 PortalDark#18
Quote:
Originally Posted by Phoenix 1337 View Post
It is not ramnit nor trojan. it's new kind of virus which duplicates itself when you're running DEP for such application.


Ex on crossfire ps: [Only registered and activated users can see links. Click Here To Register...]
in fact, Rammit does duplicate as well
and this virus behavious is not new, any AV should do fine
07/28/2013 04:07 Unrealx420#19
There is another virus that does this same exact thing its called "Jeefo" it will infect all of your .exe, .dll, html files over time, creating the duplicate file in this case sro_client and create sro_clientSrv.
07/30/2013 15:02 sarkoplata#20
yep, ramnit
ps. im back bitchez
07/30/2013 15:27 Haxor#21
Quote:
Originally Posted by Unrealx420 View Post
There is another virus that does this same exact thing its called "Jeefo" it will infect all of your .exe, .dll, html files over time, creating the duplicate file in this case sro_client and create sro_clientSrv.
I got infected by Jeefo too.. and guess what the virus was in private server client..
[Only registered and activated users can see links. Click Here To Register...]
The solution for jeefo is formatting..
07/30/2013 19:23 鳳凰城#22
Quote:
Originally Posted by Haxor View Post
I got infected by Jeefo too.. and guess what the virus was in private server client..
[Only registered and activated users can see links. Click Here To Register...]
The solution for jeefo is formatting..
The solution for jeefo is getting 1 hour free from your time, start deleting srv extra exes and after then, get a good registry fixer and wash your pc. and or use good antivirus.
'except for kaspersky, however, if it was cracked or you've used fake serial it will fuck up your windows'
Forgot to mention that srv might be caused from many viruses. because I have srv shit in crossfire fantasy gaming client and it is not even infected. which means it's duplication process only. depends!
07/30/2013 21:40 LastThief*#23
Quote:
Originally Posted by Phoenix 1337 View Post
The solution for jeefo is getting 1 hour free from your time, start deleting srv extra exes and after then, get a good registry fixer and wash your pc. and or use good antivirus.
'except for kaspersky, however, if it was cracked or you've used fake serial it will fuck up your windows'
Forgot to mention that srv might be caused from many viruses. because I have srv shit in crossfire fantasy gaming client and it is not even infected. which means it's duplication process only. depends!
SRV is ramnit if you've ramnit it's infection not "duplicated process" only
07/30/2013 22:18 鳳凰城#24
Quote:
Originally Posted by LastThief* View Post
SRV is ramnit if you've ramnit it's infection not "duplicated process" only
[Only registered and activated users can see links. Click Here To Register...]
08/01/2013 04:12 Glorious Online#25
i dont have that too, maybe just something u extracted from your pk2 files
08/06/2013 20:48 xXHaoshiXx#26
Well funny thing is, I downloaded an ECSRO Client based Server and started it, BAM SilkroadSrv.exe.
Read about 3 hours about Ramnit, infected Exes duplicate themselves and put the word "mgr" or "srv" infront or after the .exe ending.
Worst thing about this is that it also infects all external HDDs connected to your Computer, which raped my external HDD.
The infected filetypes are .exe .dll .htm and .html.
All other files can be put on your ext HDD by restarting into Safe Mode.
You can only be sure by reformating, I let 3 virusscans run and repair the infected files, but they had to delete nearly anything and left Trojans on my PC.
Reformated my ext HDD and my whole HDD before making a copy of the not infected File Extension (e.g. .rar of old clients, music and pics).
So there's no real solution but reinstalling your system, it infected 4473 on my system + ext. HDD.
Also if you open your Taskmanager while you're infected after starting your browser (even if it's Mozilla or Chrome) it will show about 15-20 "iexplorer.exe" processes that restart after closing them.

Use this method to protect yourself, LastThief is my hero:
[Only registered and activated users can see links. Click Here To Register...]