[Attention] Ddos Attacks through the virus Ramnit.A

12/18/2012 13:59 Raptursh#1
In those days , i discovered something , which is a virus spread in almost every machine of a server . its called (Ramnit.A) .
What is a Ramnit.A ?
Thats how an attacker can shutdown servers easily , if u scan the vsro files or those new programs that are released , u can see there is a Ramnit virus in it , the biggest example of such programs is Srpatcher made by Cherno .
So please all scan your files to prevent these attacks , i recommend to use Avira (avira.com) , there is a version of it for windows server too . so please take care .
12/18/2012 14:06 Zodiao#2
why DDoS attacks as a title?
12/18/2012 14:18 Raptursh#3
mm , because it causes ddos attacks i guess ? :facepalm:
12/18/2012 14:27 Zodiao#4
Virus causes DDoS attacks,that's new, and where's the text at the thread that says it causes DDOSes?
12/18/2012 14:32 Raptursh#5
google what is a Ramnit and u'll see . dont come to comment while u dont know what a virus will do

and no , i didnt say that the virus itself attacks , the virus is used as a backdoor to infect other machines and are standby waiting for an order from the attacker .
12/18/2012 14:36 Zodiao#6
define the meaning of :
Quote:
mm , because it causes ddos attacks i guess ?
or
Quote:
its one of the reasons for DDoS attacks
please...
12/18/2012 14:50 JuliaRocks*#7
Goddamn,I had this kind of sh*t xD
12/18/2012 14:59 GroundRave#8
thanks alot Ahmad , That virus is added to Vsrofiles and his Patchs by Chernobyl , he use every machine as Bot-net to hack other machines =)
12/18/2012 15:04 Legacy2#9
yea that shit tried to infect my home pc too. He use the local port 1434. My kaspersky blocked it. 5 different IPs attacked me.

srPatcher_1.0.6 didnt had any virus in it. My kaspersky reported nothing about it.

ups sry wrong virus :D

my network attack had the name > Win.MSSQL.Worm.Helkern
12/18/2012 15:05 Failwell#10
I can confirm this. And i guess it was done by the hackers which where leeching the files - or the one who postet the files after the first release. They put the backdoor in it - to get access to the servers.

With this backddor they create a bot-net. And with this bot-net they can start ddos attacks. Also there is another worm which installs a little later - we found that drop.agent.ab installs a short while after ramnit. On some installations it took a few weeks. Seems like the ramnit - security hole is used for that.

drop.agent infects html, htm and some other files with a web-browser script.
This Script tries to infect desktop-machines. Especially Microsoft Windows ones.
DropAgent is destructive - it can delete files..
12/18/2012 15:50 M4n1ak#11
Cuz, right, my ESET NOD32 rescued my pc from this xd

[Only registered and activated users can see links. Click Here To Register...]

Some time ago...
12/18/2012 18:22 PortalDark#12
well, i have lots of files infected by this, a no network change
there are virus that cause a connection to a botnet, but a virus that DDOS is really hard to believe
btw, chernos patcher was once INFECTED. he lost his account and the hacker start spreading his work infected. that may by the cause as mine, was scanned already and
Quote:
[Only registered and activated users can see links. Click Here To Register...]
[Only registered and activated users can see links. Click Here To Register...]
Quote:
Originally Posted by Failwell View Post
Especially Microsoft Windows ones.
sorry to point that out but, is there a potential virus for any other OS?(MacOS has virus, but i assume they have less that WinOS)
12/18/2012 20:32 Shane¸#13
that's why I use newest official br files lol!
12/18/2012 20:51 Veteran1337#14
Quote:
Originally Posted by ~ Shane View Post
that's why I use newest official br files lol!
vsro files aren't infected atleast those I got
12/18/2012 20:52 PortalDark#15
Quote:
Originally Posted by ~ Shane View Post
that's why I use newest official br files lol!
that's why i have vSRO-3-R
i can tell yours are crap compared to that