Very sneaky virus

Discussion in 'Help & Requests' started by Morally Skilled, Nov 4, 2011.

Very sneaky virus
  1. Unread #1 - Nov 4, 2011 at 3:11 PM
  2. Morally Skilled
    Joined:
    Jun 6, 2009
    Posts:
    894
    Referrals:
    0
    Sythe Gold:
    4

    Morally Skilled Apprentice
    Banned

    Very sneaky virus

    I've lost over 150m from a logger/RAT/something the past few days and all of the routes I've tried haven't worked in removing it..

    I've tried many different anti-virus programs like AVG, Malwarebytes and so on, individually and no progress has been made.

    It must be embedded into my System32 because after a restore to factory settings I'm still getting my bank stolen no matter what I do. (I'm in the process of putting in a pin, but wont matter if I can't get rid of it)


    So, computer wizards, advice?
     
  3. Unread #2 - Nov 4, 2011 at 3:16 PM
  4. Spy Tab
    Joined:
    Sep 10, 2011
    Posts:
    609
    Referrals:
    0
    Sythe Gold:
    0

    Spy Tab Forum Addict
    Banned

    Very sneaky virus

    I am not a computer wiz, but wouldn't it help if you moved the money to another acc.? Make sure to let someone trusted from another computer do the trade. That is if you have any money left. Just keep it safe until resolved.
     
  5. Unread #3 - Nov 4, 2011 at 3:23 PM
  6. Morally Skilled
    Joined:
    Jun 6, 2009
    Posts:
    894
    Referrals:
    0
    Sythe Gold:
    4

    Morally Skilled Apprentice
    Banned

    Very sneaky virus

    99% of it was lost when I first got it. I just put like 500k here and there to make sure I still have the virus.

    (Using my desktop.)
     
  7. Unread #4 - Nov 4, 2011 at 3:53 PM
  8. x339
    Joined:
    May 16, 2011
    Posts:
    3,223
    Referrals:
    0
    Sythe Gold:
    0

    x339 Grand Master
    Do Not Trade

    Very sneaky virus

    Not trying to insult you, but it sounds like you just need a new password on your RS account.
     
  9. Unread #5 - Nov 4, 2011 at 3:57 PM
  10. Morally Skilled
    Joined:
    Jun 6, 2009
    Posts:
    894
    Referrals:
    0
    Sythe Gold:
    4

    Morally Skilled Apprentice
    Banned

    Very sneaky virus

    You honestly think I haven't been changing it? In fact, I've been changing it from other sources.

    Some skinny Portuguese (According to the IP) kid is profiting off me and I just want it gone.
     
  11. Unread #6 - Nov 4, 2011 at 5:13 PM
  12. kill dank
    Joined:
    Mar 4, 2010
    Posts:
    6,471
    Referrals:
    2
    Sythe Gold:
    13
    St. Patrick's Day 2013

    kill dank Hero

    Very sneaky virus

    If you need someone to hold the gold, or to change your password from another computer, I'd do it.

    On another note, I assume all your information is getting stolen as soon as you enter it? As in, you change your rs password and he gets on right away without recovering it?
     
  13. Unread #7 - Nov 4, 2011 at 9:16 PM
  14. Morally Skilled
    Joined:
    Jun 6, 2009
    Posts:
    894
    Referrals:
    0
    Sythe Gold:
    4

    Morally Skilled Apprentice
    Banned

    Very sneaky virus

    Thanks but all of it's already gone lol.

    But yep. There's definitely a keylogger in there, according to RS they're logging in from 89.180.130.157 (Portugal)

    When I change it on my other computer, and check the last login it'll stay safe but as soon as I log in on my laptop, it will get robbed overnight.
     
  15. Unread #8 - Nov 4, 2011 at 10:25 PM
  16. hand breaded
    Joined:
    Oct 15, 2011
    Posts:
    196
    Referrals:
    0
    Sythe Gold:
    0

    hand breaded Active Member
    Banned

    Very sneaky virus

    Put on a PIN, unless they have a RAT, they cant access it.
     
  17. Unread #9 - Nov 4, 2011 at 10:35 PM
  18. Morally Skilled
    Joined:
    Jun 6, 2009
    Posts:
    894
    Referrals:
    0
    Sythe Gold:
    4

    Morally Skilled Apprentice
    Banned

    Very sneaky virus

    Thanks for the advice.

    But that wont remove the virus...

    notsureifsrs
     
  19. Unread #10 - Nov 5, 2011 at 12:10 AM
  20. Ivy Bridge
    Joined:
    Aug 5, 2011
    Posts:
    1,206
    Referrals:
    0
    Sythe Gold:
    0

    Ivy Bridge Guru
    Banned

    Very sneaky virus

    Honestly if AVG isn't picking it up I'd say this is no amateur. I've used AVG for years and never had anything it couldn't pick up AFAIK lol, and I torrent a lot of shit... My advice to you would be nuke the hard drive and reinstall Windows. I wouldn't take any chances with that kinda personal info.
     
  21. Unread #11 - Nov 5, 2011 at 12:40 AM
  22. Paralysisâ„¢
    Joined:
    Sep 16, 2011
    Posts:
    1,033
    Referrals:
    1
    Sythe Gold:
    0

    Paralysisâ„¢ Guru
    Banned

    Very sneaky virus

    Try this:

    Ctrl + Alt + Delete > Task Manager > Processes Tab > End any processes that aren't famaliar.
     
  23. Unread #12 - Nov 5, 2011 at 5:21 AM
  24. Fruity Lex
    Joined:
    Oct 14, 2011
    Posts:
    654
    Referrals:
    0
    Sythe Gold:
    0

    Fruity Lex Apprentice
    Banned

    Very sneaky virus

    As long as you log onto our account from the infected computer you're in danger, he can get your bank pin and password.
     
  25. Unread #13 - Nov 5, 2011 at 6:12 AM
  26. just un dude
    Joined:
    May 27, 2005
    Posts:
    5,331
    Referrals:
    5
    Sythe Gold:
    2

    just un dude Hero
    Do Not Trade

    Very sneaky virus

    I can help via teamviewer, if you're sure you still have it?

    Could be someone else just recovering your account ofcourse.
     
  27. Unread #14 - Nov 5, 2011 at 10:45 AM
  28. Morally Skilled
    Joined:
    Jun 6, 2009
    Posts:
    894
    Referrals:
    0
    Sythe Gold:
    4

    Morally Skilled Apprentice
    Banned

    Very sneaky virus

    I don't even understand how I got it. The last thing I torrented was from 2006 lol. But, I'm glad it's not destroying my machine at least.

    It had to have been a drive-by of some sort, but without requiring me to hit run.

    edit; How would I 'nuke' my hard-drive? I've reset to factory settings which is what a lot of people refer to that as.

    The password doesn't change, so that's not happening.

    I'd rather not do it over teamviewer, MSN or something sure.


    I've been doing that a couple times a day. Lots of Asus software but after a google searching everything that could be there, nothing. :\





    *
    Edit: Here's one of the IP's: http://tinypic.com/r/29o2ty8/5
     
  29. Unread #15 - Nov 5, 2011 at 11:37 AM
  30. just un dude
    Joined:
    May 27, 2005
    Posts:
    5,331
    Referrals:
    5
    Sythe Gold:
    2

    just un dude Hero
    Do Not Trade

    Very sneaky virus

    It's impossible for me to help you without teamviewer, sorry,
    but obviously I am offering this to actually help you.

    I've worked at several helpdesks and have come across every kind of virus you can imagine.
     
  31. Unread #16 - Nov 5, 2011 at 9:10 PM
  32. SyntheticX
    Joined:
    Sep 17, 2011
    Posts:
    183
    Referrals:
    0
    Sythe Gold:
    0

    SyntheticX Active Member

    Very sneaky virus

    If nothing works, back up all music,videos,pictures. What evers important(preferably not programs, because if it's a virus it's likely to hidden in one), and reformat and re-install windows.
     
< Need help with a picture | Where can I get Reloadable Prepaid Card >

Users viewing this thread
1 guest


 
 
Adblock breaks this site