Register

If you already have an account with us, please use the login panel below to access your account.

Page 1 of 8 123 ... LastLast
Results 1 to 20 of 142
  1. #1
    1 Year Veteran 500 Posts KevinBlackburn's Avatar
    Join Date
    Sep 2012
    Location
    'MERICA
    Posts
    982
    In-Game Name(s)
    Kevin Blackburn
    Post Thanks / Like

    Protection from RAT's as well as UAE DM team (People attacking server and members)

    Me and Cody (Byt3) have found many of the ways a lot of the members have been getting infected. I will be writing a guide on how to stay protected.

    1. Go ahead and install a free antivirus. It is better then nothing. I recommend avast its a great antivirus. Located at this website http://www.avast.com/en-us/index

    2. The ways UAE DM team have been infecting members is through a Java Drive By (AKA: JDB). What a java drive by is, is a java message will pop up on your screen looking like this: if you push "Run" it will install a rat on your computer. RAT's is a tool that allows the person to have full control of your computer. NOTE: All things that look like the popup above is NOT a rat. For example when playing the game runescape it will pop up. Those are safe, but if someone sends you a random site, and that pops up DONT push run. It will infect you, which is how multiple of our members have gotten infected.

    3. One quick tool to use is this http://download.bshades.eu/download....detect.torrent
    It was made by a company that creates malware, but this tool detects any rats on your computer, yes it is created by someone that creates malware, but they also made a tool to detect any malware on your computer, dont worry it is 100% safe.



    Me and Cody have been looking into this for a while, we have traced the IP's of which the RAT's are resolving to enabling us to match them up on the forums, all members found ratting people will be found, banned and most likely reported. If anyone suspects themself of being infected, PLEASE feel free to contact me or Cody, we would like to take the program and reverse engineer it to trace the IP.

    PS:
    To get rid of a very common RAT going around SARP type this in
    Quote Originally Posted by Byte View Post
    By the way, if you think you were infected by this virus, run this command. It will remove this RAT, I've examined it quite closely.

    Code:
    taskkill /f /im "msdcsc.exe" & del %UserProfile%\Documents\MSDCSC\msdcsc.exe
    PSS:
    Another good tip only IF YOU KNOW WHAT YOU'RE DOING!!
    Quote Originally Posted by Jord View Post
    Another way to check you have one is to open Task Manager, hit "View" and "Select Colums" and make sure "PID" is showing.



    Then open command prompt (Start > cmd.exe) and type in:
    Code:
    netstat -ano


    Scroll up the command prompt a little and you'll see the list of IPs, and it will say "Established" or "Listening" or "Something_Wait" (Highlighted in Red), look for the ones that say Established, and the number next to it is their PID (Highlighted in Green).


    Then back on Task Manager, you can read the PID's from the cmd.exe and match them up with the processes running on your PC, by looking at the "Processes" and "Services" tab of Task Manager.

    Most of the IPs from the cmd.exe will return to things like Firefox, Chrome, Skype and whatnot, but if you find any IPs that definitely do not link up with a Process running, it could potentially be the IP of the RAT.
    Thank you.
    Last edited by KevinBlackburn; 4th July 2013 at 12:01 PM.


    Me owning a hitman:
    [spoiler]

    [/spoiler]



    Quote from the Wonderful John Wahl:


    Quote from the Wonderful Cody (Byt3):

  2. Thanks Todd Stark, Cranium™, Luka Hawthorne thanked for this post
    Likes Hollohan, Teodor, Harry_Thorne, , Jord and 5 others liked this post
    Dislikes Walter Greyson disliked this post
  3. #2
    10 Year Veteran 500 Posts500 Posts500 Posts500 Posts500 Posts Justin Fakie's Avatar
    Join Date
    Jul 2012
    Location
    /find
    Posts
    4,128
    In-Game Name(s)
     
    Post Thanks / Like
    I was RATted not long ago and I took care of it. It's freaky to know some fuck boy from who knows where can be watching you, especially when you talk to people about personal things on messengers. Good looks on this thread, Blackdick.

    I just want to say that the leader of Team UAE said he's going to jail LOL



  4. Thanks KevinBlackburn thanked for this post
    Laughed at SkrilleX, Klash, Hen C, Brad, Sabrina laughed at this post
    Likes Jackie_jack, Todd Stark, Sabrina liked this post
    Dislikes Walter Greyson disliked this post
  5. #3
    1 Year Veteran 500 Posts500 Posts Aldo's Avatar
    Join Date
    Oct 2012
    Age
    31
    Posts
    1,270
    In-Game Name(s)
    Aldo
    Post Thanks / Like
    Thanks for sharing not hard to do ot though.

  6. Thanks KevinBlackburn thanked for this post
    Dislikes Walter Greyson disliked this post
  7. #4
    1 Year Veteran 500 Posts KevinBlackburn's Avatar
    Join Date
    Sep 2012
    Location
    'MERICA
    Posts
    982
    In-Game Name(s)
    Kevin Blackburn
    Post Thanks / Like
    Quote Originally Posted by Aldo™ View Post
    Thanks for sharing not hard to do ot though.
    If you know what your doing, my guess it is your first timing seeing a JDB? Those things are tricky.


    Me owning a hitman:
    [spoiler]

    [/spoiler]



    Quote from the Wonderful John Wahl:


    Quote from the Wonderful Cody (Byt3):

  8. Dislikes Walter Greyson disliked this post
  9. #5
    Benjamin_Williams
    Guest
    The only way back from getting ratted is to completely reformat your hard disk and re-install your operating system. If you are getting ratted by things like this and visiting these dodgy sites then all the antiviruses won't protect you from your self. You could have a completely secure system and an unknowing user. Everyone should not be using Internet Explorer and instead be using Firefox or Chrome with extensions NoScript and Adblock.

  10. Dislikes byt3, KevinBlackburn disliked this post
    Hated byt3, KevinBlackburn hated this post
    WTF'd Ryan Crowley WTF'd this post
  11. #6
    Banned
    Join Date
    May 2013
    Location
    Aint nobody got time for that
    Posts
    190
    In-Game Name(s)
    Daniel Hayawrd Gavin Hayward
    Post Thanks / Like
    Thanks man.

  12. Thanks KevinBlackburn thanked for this post
    Dislikes Walter Greyson disliked this post
  13. #7
    1 Year Veteran 500 Posts KevinBlackburn's Avatar
    Join Date
    Sep 2012
    Location
    'MERICA
    Posts
    982
    In-Game Name(s)
    Kevin Blackburn
    Post Thanks / Like
    Quote Originally Posted by Benjamin_Williams View Post
    The only way back from getting ratted is to completely reformat your hard disk and re-install your operating system. If you are getting ratted by things like this and visiting these dodgy sites then all the antiviruses won't protect you from your self. You could have a completely secure system and an unknowing user. Everyone should not be using Internet Explorer and instead be using Firefox or Chrome with extensions NoScript and Adblock.
    Please dont post false things, this is completely not true at all. All you need to do is end the proccess and delete the main exe installed on your computer and also remove it from msconfig startup.


    Me owning a hitman:
    [spoiler]

    [/spoiler]



    Quote from the Wonderful John Wahl:


    Quote from the Wonderful Cody (Byt3):

  14. Thanks Timmy_Jimmy thanked for this post
    Dislikes Walter Greyson disliked this post
  15. #8
    Benjamin_Williams
    Guest
    Quote Originally Posted by KevinBlackburn View Post
    Please dont post false things, this is completely not true at all. All you need to do is end the proccess and delete the main exe installed on your computer and also remove it from msconfig startup.
    You're wrong in the fact that you accuse my post of being incorrect. Most RAT's don't have a process you can end and hook on to already running windows processes and services like svhost.exe. The average user probably won't even be able to locate the main executable as when the infected file is run it usually infects the windows process then when that windows process is run (on startup) so is the virus.

    All RATs and viruses are different so it is difficult to speak generally.

  16. Dislikes byt3 disliked this post
    Hated byt3, KevinBlackburn hated this post
  17. #9
    1 Year Veteran 500 Posts KevinBlackburn's Avatar
    Join Date
    Sep 2012
    Location
    'MERICA
    Posts
    982
    In-Game Name(s)
    Kevin Blackburn
    Post Thanks / Like
    Quote Originally Posted by Benjamin_Williams View Post
    You're wrong in the fact that you accuse my post of being incorrect. Most RAT's don't have a process you can end and hook on to already running windows processes and services like svhost.exe. The average user probably won't even be able to locate the main executable as when the infected file is run it usually infects the windows process then when that windows process is run (on startup) so is the virus.

    All RATs and viruses are different so it is difficult to speak generally.
    The fact that I am even arguing this right now is crazy. 1. All fucking programs have a process, so hence, they can be ended. Second, they dont "hook" onto another service, you will just see a extra svhost.exe in your processes. And third the exe is very easy to find as you open file location of the unknown process as well as using wireshark, please stop posting false info on the thread.


    Me owning a hitman:
    [spoiler]

    [/spoiler]



    Quote from the Wonderful John Wahl:


    Quote from the Wonderful Cody (Byt3):

  18. Dislikes Walter Greyson disliked this post
  19. #10
    Benjamin_Williams
    Guest
    Quote Originally Posted by KevinBlackburn View Post
    The fact that I am even arguing this right now is crazy. 1. All fucking programs have a process, so hence, they can be ended. Second, they dont "hook" onto another service, you will just see a extra svhost.exe in your processes. And third the exe is very easy to find as you open file location of the unknown process as well as using wireshark, please stop posting false info on the thread.
    It's called an injection. There is no false info. I don't know why you're so determined to say this info is false, I suspect you have other motives.

    I'll just agree to disagree with you because clearly we both have a different idea of how things work.
    Last edited by dsfsdfdsfsdfds; 3rd July 2013 at 07:52 PM.

  20. Hated KevinBlackburn hated this post
  21. #11
    1 Year Veteran 500 Posts KevinBlackburn's Avatar
    Join Date
    Sep 2012
    Location
    'MERICA
    Posts
    982
    In-Game Name(s)
    Kevin Blackburn
    Post Thanks / Like
    Quote Originally Posted by Benjamin_Williams View Post
    It's called an injection. There is no false info. I don't know why you're so determined to say this info is false, I suspect you have other motives.

    I'll just agree to disagree with you because clearly we both have a different idea of how things work.
    Becasue it is wrong, all programs have processes, you are giving out false info to SARP... Also injection doesnt stop the program from having a process unless it has access to ring0, which no rat does at the moment.


    Me owning a hitman:
    [spoiler]

    [/spoiler]



    Quote from the Wonderful John Wahl:


    Quote from the Wonderful Cody (Byt3):

  22. Dislikes Walter Greyson disliked this post
  23. #12
    Benjamin_Williams
    Guest
    Quote Originally Posted by KevinBlackburn View Post
    Becasue it is wrong, all programs have processes, you are giving out false info to SARP... Also injection doesnt stop the program from having a process unless it has access to ring0, which no rat does at the moment.
    Ok. I am not giving out false info. You seem determined to disprove everything I say. Please consult http://en.wikipedia.org/wiki/Rootkit .

    Bootkits

    A kernel-mode rootkit variant called a bootkit is used predominantly to attack full disk encryption systems, for example as in the "Evil Maid Attack", in which a bootkit replaces the legitimate boot loader with one controlled by an attacker; typically the malware loader persists through the transition to protected mode when the kernel has loaded. For example, the "Stoned Bootkit" subverts the system by using a compromised boot loader to intercept encryption keys and passwords. More recently, the Alureon rootkit has successfully subverted the requirement for 64-bit kernel-mode driver signing in Windows 7 by modifying the master boot record.
    The only known defenses against bootkit attacks are the prevention of unauthorized physical access to the system—a problem for portable computers—or the use of a Trusted Platform Module configured to protect the boot path.
    Quick google search revealed:

    https://www.underground.org.mx/index.php?topic=28482.0
    http://c0decstuff.blogspot.co.uk/201...-and-dkom.html
    Last edited by dsfsdfdsfsdfds; 3rd July 2013 at 08:07 PM.

  24. Laughed at Walter Greyson laughed at this post
    Likes Percy_Peterson liked this post
    Hated KevinBlackburn hated this post
  25. #13
    ~skeggers
    Retired Administrator
    500 Posts500 Posts500 Posts500 Posts500 Posts Luke Shiels's Avatar
    Join Date
    Jun 2011
    Location
    England, Kent
    Age
    29
    Posts
    3,431
    In-Game Name(s)
    lufe helf
    Post Thanks / Like
    R@t alerts~
    "I'm searching you mate
    Your jaw is all over the place"

  26. Laughed at Ryan Crowley, KevinBlackburn laughed at this post
  27. #14
    10 Year Veteran
    Join Date
    Sep 2011
    Location
    Heaven
    Posts
    1,500
    In-Game Name(s)
    Chin®
    Post Thanks / Like
    Who still opens mail attachments from unknown senders at this age of time? Ugh..., if only there was a patch for human stupidity.

    PS: This doesn't explain how they get our e-mail addresses? Either the admin team is handing out e-mail addresses as they were handing out ip's a while back, or i call this false. Nice try though.


  28. Laughed at Walter Greyson laughed at this post
  29. #15
    1 Year Veteran 500 Posts KevinBlackburn's Avatar
    Join Date
    Sep 2012
    Location
    'MERICA
    Posts
    982
    In-Game Name(s)
    Kevin Blackburn
    Post Thanks / Like
    Quote Originally Posted by Benjamin_Williams View Post
    Ok. I am not giving out false info. You seem determined to disprove everything I say. Please consult http://en.wikipedia.org/wiki/Rootkit .



    Quick google search revealed:

    https://www.underground.org.mx/index.php?topic=28482.0
    http://c0decstuff.blogspot.co.uk/201...-and-dkom.html
    Clearly you have no idea what you're talking about. I said ring0. ring0 = rootkit, there is not rat right now that has ring0, case closed.


    Me owning a hitman:
    [spoiler]

    [/spoiler]



    Quote from the Wonderful John Wahl:


    Quote from the Wonderful Cody (Byt3):

  30. Dislikes Walter Greyson disliked this post
  31. #16
    Soldier 500 Posts500 Posts500 Posts500 Posts500 Posts Emily Grey's Avatar
    Join Date
    Nov 2012
    Location
    A corn field
    Age
    34
    Posts
    3,140
    In-Game Name(s)
    Emily Grey
    Post Thanks / Like
    How did yall manage to turn this one into an argument
    big changes are here, more soon stay tuned

  32. Thanks Moke_Clark thanked for this post
    Laughed at KevinBlackburn laughed at this post
    Likes Timmy_Jimmy liked this post
    Dislikes Walter Greyson disliked this post
  33. #17
    1 Year Veteran 500 Posts KevinBlackburn's Avatar
    Join Date
    Sep 2012
    Location
    'MERICA
    Posts
    982
    In-Game Name(s)
    Kevin Blackburn
    Post Thanks / Like
    Quote Originally Posted by Emily Grey View Post
    How did yall manage to turn this one into an argument
    Its not really a argument, its more false info from a member, but he refuses to notice it. Just ignore it lol.


    Me owning a hitman:
    [spoiler]

    [/spoiler]



    Quote from the Wonderful John Wahl:


    Quote from the Wonderful Cody (Byt3):

  34. Dislikes Walter Greyson disliked this post
  35. #18
    3 Year Veteran 500 Posts Kanji's Avatar
    Join Date
    Oct 2010
    Posts
    570
    In-Game Name(s)
    Kanji_Yakamura Haruko_Yakamura
    Post Thanks / Like
    Good job Blackburn, good job...

  36. Thanks KevinBlackburn thanked for this post
    Dislikes Walter Greyson disliked this post
  37. #19
    10 Year Veteran 500 Posts500 Posts500 Posts500 Posts500 Posts Justin Fakie's Avatar
    Join Date
    Jul 2012
    Location
    /find
    Posts
    4,128
    In-Game Name(s)
     
    Post Thanks / Like
    Quote Originally Posted by Benjamin_Williams View Post
    The only way back from getting ratted is to completely reformat your hard disk and re-install your operating system. If you are getting ratted by things like this and visiting these dodgy sites then all the antiviruses won't protect you from your self. You could have a completely secure system and an unknowing user. Everyone should not be using Internet Explorer and instead be using Firefox or Chrome with extensions NoScript and Adblock.
    Not true. Find the location of the process, close the process, disable it on startup, delete the file in the location of the process containing the RAT, and problem solved. Many rats are made by skids and people who use tuts or some bootleg crap.



  38. Likes Dylan., KevinBlackburn liked this post
    Dislikes Walter Greyson disliked this post
  39. #20
    1 Year Veteran 500 Posts KevinBlackburn's Avatar
    Join Date
    Sep 2012
    Location
    'MERICA
    Posts
    982
    In-Game Name(s)
    Kevin Blackburn
    Post Thanks / Like
    Quote Originally Posted by Justin Fakie View Post
    Not true. Find the location of the process, close the process, disable it on startup, delete the file in the location of the process containing the RAT, and problem solved. Many rats are made by skids and people who use tuts or some bootleg crap.
    Bout time someone else posts stating he is wrong. My guess is he is going to come back and still argue it but what ever.


    Me owning a hitman:
    [spoiler]

    [/spoiler]



    Quote from the Wonderful John Wahl:


    Quote from the Wonderful Cody (Byt3):

  40. Dislikes Walter Greyson disliked this post
 

 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Click to connect to Discord (San Andreas Roleplay)Click to go to the official San Andreas Multiplayer websiteDownload Teamspeak