Removal of ProRat and attached Virusses

Anti-Virus Discuss, Removal of ProRat and attached Virusses at Tech Zone forum; Dear members, If you want to remove PROrat and its virusses you need not only need to edit your registery ...


Go Back   Gamerz Needs - For All Your Gaming Needs! > Technology Zone > Tech Zone > Anti-Virus
Forgot Password? | Sign Up!

Notices

Advertisement
   

Reply
 
Bookmark this Thread Tools Display Modes
  #1  
Old 08-27-2007, 05:07 AM
GameLordquest's Avatar
Mendelity Inc
 
Last Online: 12-03-2008 04:40 PM
Join Date: Mar 2006
Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Blog Entries: 6
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18
GameLordquest will become famous soon enoughGameLordquest will become famous soon enough
Points: 1,447.00
Bank: 204,314.07
Total Points: 205,761.07
Marked as kashin's property - kashin Property of Mufctreble - mufctreble WOOO IM THIRSTY... lol - GameLordquest A honorary member of the BleachNaruto fan club. - BleachNaruto 
Gold - GameLordquest Green - hotboy Black - hotboy 
Send a message via MSN to GameLordquest Send a message via Skype™ to GameLordquest
Removal of ProRat and attached Virusses

Dear members,

If you want to remove PROrat and its virusses you need not only need to edit your registery but start in Safe Mode too. So if you want to remove the virus print this page. I will also make an TXT file for those who dont have an printer.

Since i cant type backslashes replace every slash for a backslash

Here we go.

Windows 2000/NT/XP

for Windows 95/98/ME skip step number 11,12

Quote:
Step 1
Go to Start > Run

Step 2
type regedit and press enter ok click ok

Step 3
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run

Step 4
Delete this value MSNMESENGER"="%System%/Main.exe

Step 5
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/
Policies/Explorer/Run


Step 6
Delete this value DirectX for Microsoft Windows"="%System%/Fservice.exe

Step 7
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Active Setup/Installed Components/{5Y99AE78-58TT-11dW-BE53-Y67078979Y}


Step 8
Delete this value DirectX for Microsoft Windows"="%System%/Sservice.exe

Step 9
Navigate to this key HKEY_CURRENT_USER/SOFTWARE/Microsoft/Windows/CurrentVersion/Run

Step 10
Delete this value StubPath"="C:/Windows/system/Sservice.exe

Step 11
Navigate to this key HKEY_LOCAL_MACHINE/Software/Microsoft/Windows NT/CurrentVersion/Winlogon

Step 12
Modify this"Shell"="explorer.exe %System%/Fservice.exe" into this "Shell"="explorer.exe"

Step 13
Exit your Registry Editor and restart your PC in Safe mode with Command prompt (shut down then start up and hit and hold F8 untill and black screen with white letters appears)

Step 14
log on your own account and then you should see command prompt on the left and nothing else exept maybe some writing like Safe Mode Windows blahblahblah.

Step 15
type in cd/windows like that.

Step 16
type in erase services.exe

Step 17
Then type in cd/windows/system

Step 18
Type in erase sservice.exe like that. I did not misspelled it.

Step 19
Then type in cd/windows/system32

Step 20
Then type the following codes in
Code:
erase C:/windows/system32/reginv.dll
erase C:/windows/system32/fservice.exe
erase C:/windows/system32/winkey.dll
erase C:/windows/system32/wininv.dll 
Step 21
Then type in cd/ and then start explorer Note: you dont have internet

Step 22
Browse to your windows folder and check if the following files are deleted.
Code:
C:/windows/system32/reginv.dll
C:/windows/system32/fservice.exe
C:/windows/system32/winkey.dll
C:/windows/services.exe
C:/windows/system/sservice.exe
C:/windows/system32/wininv.dll 
Step 23
If you havent deleted it already delete PROrat without running it. the go to Start > Run again and if the following still exsist. If so delete/modify it again.
Code:
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run

MSNMESENGER"="%System%/Main.exe

HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/WindowsCurrent/Version/
Policies/Explorer/Run

DirectX for Microsoft Windows"="%System%/Fservice.exe

HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Active Setup/Installed Components/{5Y99AE78-58TT-11dW-BE53-Y67078979Y}

DirectX for Microsoft Windows"="%System%/Sservice.exe

HKEY_CURRENT_USER/SOFTWARE/Microsoft/Windows/CurrentVersion/Run

StubPath"="C:/Windows/system/Sservice.exe

HKEY_LOCAL_MACHINE/Software/Microsoft/Windows NT/CurrentVersion/Winlogon

"Shell"="explorer.exe %System%/Fservice.exe" must be "Shell"="explorer.exe"
Step 24
Now restart your PC again and browse to your windows folder again to check if these files are gone. if not repeat from step 1.
Code:
C:/windows/system32/reginv.dll
C:/windows/system32/fservice.exe
C:/windows/system32/winkey.dll
C:/windows/services.exe
C:/windows/system/sservice.exe
C:/windows/system32/wininv.dll 
Step 25
Run your virusscanner to check for virusses. Now it should say nothing unless you have other virussses or hacks...

Congratulations. Your PC is now Good to Go again. Have a nice day.

Credits to:
Me for writing.
Symantec© for providing the Keys.
Toscane of PChelper.nl for helping me.
__________________


Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer
Dave Chappelle - What did the five fingers say to the Face
Make your PC Safer and Better! Visit this thread!
Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me.
Member of the BleachNaruto fan club!
The Following 5 Users Say Thank You to GameLordquest For This Useful Post:
Hornstar6969 (08-27-2007), howwie (10-03-2007), joriannn (04-10-2008), +touche_ (11-19-2007), YouKnowWho (08-27-2007)
  #2  
Old 08-27-2007, 06:02 AM
YouKnowWho's Avatar
Blue Dragon
 
Last Online: 10-26-2008 01:29 PM
Join Date: Aug 2007
Age: 20
Posts: 819
Blog Entries: 1
Thanks: 439
Thanked 75 Times in 45 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: The Girl
Rep Power: 5
YouKnowWho is on a distinguished road
Points: 6,382.01
Bank: 0.00
Total Points: 6,382.01
Thumbs up

i don't have any viruses but i'm sure this will help of i get a serious one .. thank you
  #3  
Old 08-27-2007, 06:27 AM
GameLordquest's Avatar
Mendelity Inc
 
Last Online: 12-03-2008 04:40 PM
Join Date: Mar 2006
Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Blog Entries: 6
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18
GameLordquest will become famous soon enoughGameLordquest will become famous soon enough
Points: 1,447.00
Bank: 204,314.07
Total Points: 205,761.07
Marked as kashin's property - kashin Property of Mufctreble - mufctreble WOOO IM THIRSTY... lol - GameLordquest A honorary member of the BleachNaruto fan club. - BleachNaruto 
Gold - GameLordquest Green - hotboy Black - hotboy 
Send a message via MSN to GameLordquest Send a message via Skype™ to GameLordquest
No problem im here to help... But this is actually only for the virus simular to the ProRat virus... you should check this list if you think your infected.
__________________


Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer
Dave Chappelle - What did the five fingers say to the Face
Make your PC Safer and Better! Visit this thread!
Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me.
Member of the BleachNaruto fan club!
  #4  
Old 10-03-2007, 04:46 PM
EnviousX's Avatar
Silver Dragon
 
Last Online: 11-30-2008 09:48 PM
Join Date: Oct 2006
Location: Can- why do you wanna know?
Posts: 1,260
Thanks: 328
Thanked 144 Times in 102 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 10
EnviousX will become famous soon enoughEnviousX will become famous soon enough
Points: 25,384.39
Bank: 131,693.89
Total Points: 157,078.28
B33R - EnviousX APPL3 - EnviousX BURG3R - EnviousX BON3R - EnviousX Here yo go monkey =D - Gamerz7 
got meat? - EnviousX DUNG!!!!111 - EnviousX apple a day keeps the diarhyea away! - EnviousX this is to hold my pants up! - EnviousX 
Gold - Dominic001 Gold - Dominic001 Green - Hezekiah Burgundy - EnviousX Lavender - EnviousX 
Send a message via MSN to EnviousX
Well thanks, ive been proratted before by somebody (cough cough)
But yeah i had kaspersky on luckily, so it killed it after my system reboot.
I also had a parite which was odd, every file was infected.
__________________



If i helped you, kindly press the thanks button or +rep me. --->>
The Following User Says Thank You to EnviousX For This Useful Post:
misterpt (06-09-2008)
  #5  
Old 10-28-2007, 10:45 AM
Samurai_Mo's Avatar
Silver Dragon
 
Last Online: Yesterday 03:20 PM
Join Date: May 2007
Location: In Matt's Porno Collection
Posts: 1,205
Thanks: 210
Thanked 251 Times in 113 Posts
Nominated 2 Times in 2 Posts
TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 8
Samurai_Mo is on a distinguished road
Points: 3,487.60
Bank: 356,254.16
Total Points: 359,741.76
Find the code :P!! - Ken No Message - BAKKA why did i do this? - BAKKA 
Burgundy - hotboy Lavender - lifestyles 
hmm oke 1 thing what thus that virus do to your pc ?

i got and virus
and now i dont got permision to my system that mean i can't edit my pc or remove software
ore look in windows conf

and i can't change my desktop image :'(
__________________
ThE bEsT mEmBeR of The BleachNaruto Fan Club!

Click here for Kissing Advice
GzN Video click here to watch it
Rakion account for $13 it has lvl41 archer lvl33 ninja lvl21 warrior
  #6  
Old 04-09-2008, 09:32 AM
GameLordquest's Avatar
Mendelity Inc
 
Last Online: 12-03-2008 04:40 PM
Join Date: Mar 2006
Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Blog Entries: 6
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18
GameLordquest will become famous soon enoughGameLordquest will become famous soon enough
Points: 1,447.00
Bank: 204,314.07
Total Points: 205,761.07
Marked as kashin's property - kashin Property of Mufctreble - mufctreble WOOO IM THIRSTY... lol - GameLordquest A honorary member of the BleachNaruto fan club. - BleachNaruto 
Gold - GameLordquest Green - hotboy Black - hotboy 
Send a message via MSN to GameLordquest Send a message via Skype™ to GameLordquest
lol i got thanked by hornstar...

ProRAT is an keylogger that grants access to several programs where normally access is denied... so infact is ProRAT handy but it has a flip side...
__________________


Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer
Dave Chappelle - What did the five fingers say to the Face
Make your PC Safer and Better! Visit this thread!
Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me.
Member of the BleachNaruto fan club!
  #7  
Old 04-09-2008, 10:43 AM
iio's Avatar
Registered Users +
 
Last Online: Yesterday 10:47 AM
Join Date: Aug 2007
Location: ██████████████
Posts: 1,046
Thanks: 134
Thanked 68 Times in 42 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 6
iio is on a distinguished road
Points: 1,209.80
Bank: 0.00
Total Points: 1,209.80
Gold - flyff1987 Black - Spo0onMan Gold - Spo0onMan Black - Spo0onMan Gold - Spo0onMan 
Black - Spo0onMan Gold - Spo0onMan Black - Spo0onMan Gold - Spo0onMan Black - Spo0onMan 
prorat doesnt have a virus. atleast my one didnt.
  #8  
Old 04-10-2008, 11:31 AM
GameLordquest's Avatar
Mendelity Inc
 
Last Online: 12-03-2008 04:40 PM
Join Date: Mar 2006
Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Blog Entries: 6
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18
GameLordquest will become famous soon enoughGameLordquest will become famous soon enough
Points: 1,447.00
Bank: 204,314.07
Total Points: 205,761.07
Marked as kashin's property - kashin Property of Mufctreble - mufctreble WOOO IM THIRSTY... lol - GameLordquest A honorary member of the BleachNaruto fan club. - BleachNaruto 
Gold - GameLordquest Green - hotboy Black - hotboy 
Send a message via MSN to GameLordquest Send a message via Skype™ to GameLordquest
ok... have it your way... let me put it like this. ProRAT is a keylogger that manifest in your PC the moment you installed it. you can play "smartass" all you want but you know im right.
__________________


Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer
Dave Chappelle - What did the five fingers say to the Face
Make your PC Safer and Better! Visit this thread!
Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me.
Member of the BleachNaruto fan club!
  #9  
Old 04-10-2008, 12:33 PM
joriannn's Avatar
 
Last Online: Today 12:44 AM
Join Date: Oct 2006
Location: Utrecht, The Netherlands
Age: 17
Posts: 6,533
Blog Entries: 1
Thanks: 333
Thanked 536 Times in 434 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: Rappelz ftw!
Rep Power: 26
joriannn will become famous soon enough
Points: 463.50
Bank: 537,056.01
Total Points: 537,519.51
chocolate beer - Ken Property of Mufctreble .... got to him 1st Kashin...XD.....oh an joriann u need it....espeically if u dont wash XD(jk) - mufctreble Marked as kashin's property. (Spearmen's Raiding Trainer and Leader) - kashin Did I say you can have this? I'll Need it back LATER! Merry Christmas, Cuz you'll need it, on Christmas, I'mma impregnanting you... - kaswar =p - magikman 
teh nicest in all of GzN - - - apple 4 good health LONG LIVE JORIANNN!!! - Session Burger - _MaSTeR_ AV ITTTT!! lol.. - Adamaniac No Message - Bottes :D - Dominic001 
dud this is the only way u get things up - ducaduca gift 1 - chaosnite192 gift 2 - chaosnite192 gift 3... - chaosnite192 gift 4... - chaosnite192 
gift 4... - chaosnite192 gift 5... - chaosnite192 
Gold - Dominic001 Lavender - Yondaime Lavender - MysticWeaver Lavender - VietBoiHiep 
Send a message via MSN to joriannn Send a message via Skype™ to joriannn
Quote:
Originally Posted by N_E_O_N View Post
prorat doesnt have a virus. atleast my one didnt.
If there's a free version of it, it most likely does. The name only already freaks me out, I'd never download something like that
__________________
Rule 1: I'm always right.
Rule 2: When I'm not, or when in doubt, refer to rule 1.
  #10  
Old 04-10-2008, 12:44 PM
stormer320's Avatar
Chris < Big Nubzor
 
Join Date: Jan 2007
Location: Canada,Eh?
Posts: 1,762
Donation Award 
Thanks: 320
Thanked 372 Times in 183 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 10
stormer320 has much to be proud ofstormer320 has much to be proud of
Points: 773.10
Bank: 0.00
Total Points: 773.10
tnx for editing my thread :) - Kojack510 Better we share this beer xD - SkoolGurl Banana is more better than burger - SkoolGurl Marked as kashin's property. (Part of the Spearmen's Offencive force,  trained and led by sir Joriannn) - kashin merry christmas to all !! - Kojack510 
Did I say you can Have this? I'll Need it back later! You can puke can't you? - kaswar ok dude use this to hold up ur pants - EnviousX you're hungry xD - ChrisxD put this in between your boobs - choad Happy Birthday Alex--Frank - Franky 
Happy Late B-Day xD - ChrisxD 
Green - Yondaime Lavender - VietBoiHiep 
Send a message via MSN to stormer320
Quote:
Well thanks, ive been proratted before by somebody (cough cough)
But yeah i had kaspersky on luckily, so it killed it after my system reboot.
I also had a parite which was odd, every file was infected.
Ehhh this was me lol. xD *cough* What?
__________________
GzN Anime Site
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools