Marty Posted November 21, 2010 Share Posted November 21, 2010 http://www.threatexpert.com/report.aspx?md...9a6ec672ec63a88 i'll probably make a tool to check if your infected & do all this for you at a later time Start up in Windows Safe Mode Open up Task Manager and kill any processes running under your user(not system) with the following name(s): explorer.exe, iexplorer.exe, server.exe Run the Windows Registry Editor and delete any registry values referring to "%RootDrive%\directory\CyberGate\install\server.exe": HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{X3345FLR-12IQ-3C01-1K75-CU1KOA37JVG1} HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\msvideo HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MediaResources\msvideo HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings HKEY_CURRENT_USER\Software\ZXZ [*]Go to your root drive(probably c:\) and delete the folder "directory" and its contents. [*]Go to your appdata folder and delete a file that is named "<your computer username>log.dat" and then your probably free from that scum :) some known youtube channels that he posts his trash on: http://www.youtube.com/user/woopssafty http://www.youtube.com/user/shadowgod170 (i think?) Link to comment Share on other sites More sharing options...
vanish pk Posted November 21, 2010 Share Posted November 21, 2010 Don't click that link its a keylogger. The few kids who come on their zerks to our trip either lost their pure or are old school and only get on for trips. These kids are in mith or addy... >pure world Link to comment Share on other sites More sharing options...
Alex Posted November 21, 2010 Share Posted November 21, 2010 Don't click that link its a keylogger. LOL Epidemic forever<3 Link to comment Share on other sites More sharing options...
Marty Posted November 21, 2010 Author Share Posted November 21, 2010 Don't click that link its a keylogger. very funny Link to comment Share on other sites More sharing options...
Josh-- Posted November 21, 2010 Share Posted November 21, 2010 Thanks but i wasn't that stupid to go onit like most people :) hiooooooooooooo Link to comment Share on other sites More sharing options...
Solo Posted November 22, 2010 Share Posted November 22, 2010 Give this guy Admin. NO ONE LIKES US, WE DON'T CARE. Click the link below to go beyond the limits. eop-rs.com/forums/ Link to comment Share on other sites More sharing options...
King Of Asian Posted November 22, 2010 Share Posted November 22, 2010 Looks good. http://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idxhttp://rs-fi.com/index.php?act=idx Link to comment Share on other sites More sharing options...
Corrupt3d Posted November 22, 2010 Share Posted November 22, 2010 First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup? You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about. Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory? I suggest you do some real research before attempting to inform people of something you know nothing about. Link to comment Share on other sites More sharing options...
AndyIbeat Posted November 22, 2010 Share Posted November 22, 2010 drama Link to comment Share on other sites More sharing options...
Nibo Posted November 22, 2010 Share Posted November 22, 2010 No idea what your talking about....lol Leader of #Tryhard|Ex-Member of #Haste #Nibo @ Swiftirc *Retired from RS. Link to comment Share on other sites More sharing options...
Codie Posted November 22, 2010 Share Posted November 22, 2010 james ripped that kid lol. HI JUSTIN!^ Link to comment Share on other sites More sharing options...
Alessandro Posted November 27, 2010 Share Posted November 27, 2010 lmfao destroyed by corrupted Link to comment Share on other sites More sharing options...
Hugh Posted November 27, 2010 Share Posted November 27, 2010 Does this work with you as well? Link to comment Share on other sites More sharing options...
Owen Posted November 27, 2010 Share Posted November 27, 2010 lmfao destroyed by corrupted [99/99] [99/99] [99/99] [99/99] [99/99] [95/95] Link to comment Share on other sites More sharing options...
dotfire Posted November 28, 2010 Share Posted November 28, 2010 i still like marty more Link to comment Share on other sites More sharing options...
Am0n Posted November 28, 2010 Share Posted November 28, 2010 Lets go fishing =] Yes fishing For turtles. "Practice + Determination isn't coincidence." Retired Link to comment Share on other sites More sharing options...
trib Posted November 28, 2010 Share Posted November 28, 2010 or just pm him if your friends with him =] you will never know my true identity Link to comment Share on other sites More sharing options...
P0ke N Die Posted November 28, 2010 Share Posted November 28, 2010 I clicked link, am I keylogged? Joined the Pure Community March 2006 Link to comment Share on other sites More sharing options...
Ryan- Posted November 28, 2010 Share Posted November 28, 2010 ur all **** grow the hell up Link to comment Share on other sites More sharing options...
Evan Posted November 29, 2010 Share Posted November 29, 2010 First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup? You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about. Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory? I suggest you do some real research before attempting to inform people of something you know nothing about. Oh god Link to comment Share on other sites More sharing options...
Corrupt3d Posted December 4, 2010 Share Posted December 4, 2010 First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup? You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about. Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory? I suggest you do some real research before attempting to inform people of something you know nothing about. Oh god wat. Link to comment Share on other sites More sharing options...
Darker Posted December 4, 2010 Share Posted December 4, 2010 gf elvy ^_^ Proud Co-Leader Of Chaotic!Current Proud Elite of Intense Redemption! Link to comment Share on other sites More sharing options...
Martin Posted December 15, 2010 Share Posted December 15, 2010 First of all why would you go through the registry looking for elvys Rat when it doesn't just add to HKLM and HKCU it also saves to the startup-folder as well as uses Active-Startup? You obviously lack knowledge of such a topic and would like to act as if you know what you're talking about. Last of all, you specified the default directory that CBG would save to, why would he have it save to the default directory? I suggest you do some real research before attempting to inform people of something you know nothing about. Oh god wat. inb4 skiddie Link to comment Share on other sites More sharing options...
Mich-ae-l Posted December 16, 2010 Share Posted December 16, 2010 Thanks for helping me get rid of the virus!!11!11!11one11!1! Proud Ex-Member of NMEProud Ex-Leader of Brave Theoryretired. Supporting Epidemic Link to comment Share on other sites More sharing options...
Omni Posted December 16, 2010 Share Posted December 16, 2010 You kids and your computer chats, it's so adorable. Maybe if you all actually knew what you were talking about it wouldn't be about RuneScape and you'd actually be on a real Forum. Link to comment Share on other sites More sharing options...
Recommended Posts