Register for your free account! | Forgot your password?

Go Back   elitepvpers > Coders Den > General Coding
You last visited: Today at 10:13

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



Help please ;)

Discussion on Help please ;) within the General Coding forum part of the Coders Den category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Jan 2013
Posts: 4
Received Thanks: 0
Help please ;)

Hey, can anyone find out the code of this program, and find out what it does? I would appreciate it a lot!


jaudaa is offline  
Old 01/08/2013, 16:09   #2
 
omer36's Avatar
 
elite*gold: 0
Join Date: Mar 2009
Posts: 2,317
Received Thanks: 1,255
lol..
yeah..sure...
omer36 is offline  
Old 01/08/2013, 16:11   #3
 
Chanolan's Avatar
 
elite*gold: 0
Join Date: Feb 2010
Posts: 1,030
Received Thanks: 393
Seems legit ~
Chanolan is offline  
Old 01/08/2013, 16:16   #4
 
elite*gold: 0
Join Date: Jan 2013
Posts: 4
Received Thanks: 0
please! think my pc is part of a botnet...
jaudaa is offline  
Old 01/08/2013, 16:29   #5
 
Dr. Coxxy's Avatar
 
elite*gold: 0
Join Date: Feb 2011
Posts: 1,206
Received Thanks: 736
virus.

anubis is down, so virustotal:


several typical registry keys:
Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon
Software\\Microsoft\\Windows\\CurrentVersion\\Run

paths:
drivers\\etc\\hosts

100% infected, you should reinstall.

Quote:
Opened files...

\\.\PIPE\lsarpc (successful)
C:\2a6b41e6a7c612f597955a080ddf87bd98b167a3d331522 5e63472f2e006b29f (successful)
C:\Documents and Settings\<USER>\My Documents\MSDCSC\msdcsc.exe (successful)

Read files...

C:\2a6b41e6a7c612f597955a080ddf87bd98b167a3d331522 5e63472f2e006b29f (successful)

Copied files...

SRC: C:\2a6b41e6a7c612f597955a080ddf87bd98b167a3d331522 5e63472f2e006b29f
DST: C:\Documents and Settings\<USER>\My Documents\MSDCSC\msdcsc.exe (successful)

Registry activity
Set keys...

KEY: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run\MicroUpdate
TYPE: REG_SZ
VALUE: C:\Documents and Settings\<USER>\My Documents\MSDCSC\msdcsc.exe (successful)

KEY: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
TYPE: REG_SZ
VALUE: C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\<USER>\My Documents\MSDCSC\msdcsc.exe (successful)
Dr. Coxxy is offline  
Thanks
1 User
Old 01/08/2013, 17:47   #6
 
elite*gold: 0
Join Date: Jan 2013
Posts: 4
Received Thanks: 0
so it's a botnet or what? ...

btw thx
jaudaa is offline  
Old 01/08/2013, 19:48   #7
 
»Cirruzz«'s Avatar
 
elite*gold: LOCKED
Join Date: Dec 2010
Posts: 74
Received Thanks: 32
Have u the Virus Warning ignored? You're infected.
»Cirruzz« is offline  
Old 01/08/2013, 20:59   #8
 
elite*gold: 0
Join Date: Jan 2013
Posts: 4
Received Thanks: 0
yh put it on ignore for a few secs 2 open this app...
jaudaa is offline  
Old 01/08/2013, 21:12   #9
 
Kraizy​'s Avatar
 
elite*gold: 0
The Black Market: 471/0/0
Join Date: Apr 2010
Posts: 9,696
Received Thanks: 1,811
DarkComet RAT
Well, better change all your passwords etc (on a new computer or after installing Windows again)
Kraizy​ is offline  
Thanks
1 User
Reply




All times are GMT +1. The time now is 10:15.


Powered by vBulletin®
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2026 elitepvpers All Rights Reserved.