 |
Removal of ProRat and attached Virusses
| Anti-Virus Discuss, Removal of ProRat and attached Virusses at Tech Zone forum; Dear members,
If you want to remove PROrat and its virusses you need not only need to edit your registery ... |
| Notices | Welcome to the Gamerz Needs forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact contact us. |  | | 
08-27-2007, 05:07 AM
|  | Mendelity Inc | | | Last Online: 12-03-2008 04:40 PM Join Date: Mar 2006 Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18 Points: 1,447.00 Bank: 204,314.07 Total Points: 205,761.07 | | | Removal of ProRat and attached Virusses
Dear members,
If you want to remove PROrat and its virusses you need not only need to edit your registery but start in Safe Mode too. So if you want to remove the virus print this page. I will also make an TXT file for those who dont have an printer.
Since i cant type backslashes replace every slash for a backslash
Here we go. Windows 2000/NT/XP for Windows 95/98/ME skip step number 11,12 Quote: Step 1
Go to Start > Run Step 2
type regedit and press enter ok click ok Step 3
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run Step 4
Delete this value MSNMESENGER"="%System%/Main.exe Step 5
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/
Policies/Explorer/Run Step 6
Delete this value DirectX for Microsoft Windows"="%System%/Fservice.exe Step 7
Navigate to this key HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Active Setup/Installed Components/{5Y99AE78-58TT-11dW-BE53-Y67078979Y} Step 8
Delete this value DirectX for Microsoft Windows"="%System%/Sservice.exe Step 9
Navigate to this key HKEY_CURRENT_USER/SOFTWARE/Microsoft/Windows/CurrentVersion/Run Step 10
Delete this value StubPath"="C:/Windows/system/Sservice.exe Step 11
Navigate to this key HKEY_LOCAL_MACHINE/Software/Microsoft/Windows NT/CurrentVersion/Winlogon Step 12
Modify this"Shell"="explorer.exe %System%/Fservice.exe" into this "Shell"="explorer.exe" Step 13
Exit your Registry Editor and restart your PC in Safe mode with Command prompt (shut down then start up and hit and hold F8 untill and black screen with white letters appears) Step 14
log on your own account and then you should see command prompt on the left and nothing else exept maybe some writing like Safe Mode Windows blahblahblah. Step 15
type in cd/windows like that. Step 16
type in erase services.exe Step 17
Then type in cd/windows/system Step 18
Type in erase sservice.exe like that. I did not misspelled it. Step 19
Then type in cd/windows/system32 Step 20
Then type the following codes in Code: erase C:/windows/system32/reginv.dll
erase C:/windows/system32/fservice.exe
erase C:/windows/system32/winkey.dll
erase C:/windows/system32/wininv.dll Step 21
Then type in cd/ and then start explorer Note: you dont have internet Step 22
Browse to your windows folder and check if the following files are deleted. Code: C:/windows/system32/reginv.dll
C:/windows/system32/fservice.exe
C:/windows/system32/winkey.dll
C:/windows/services.exe
C:/windows/system/sservice.exe
C:/windows/system32/wininv.dll Step 23
If you havent deleted it already delete PROrat without running it. the go to Start > Run again and if the following still exsist. If so delete/modify it again. Code: HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run
MSNMESENGER"="%System%/Main.exe
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/WindowsCurrent/Version/
Policies/Explorer/Run
DirectX for Microsoft Windows"="%System%/Fservice.exe
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Active Setup/Installed Components/{5Y99AE78-58TT-11dW-BE53-Y67078979Y}
DirectX for Microsoft Windows"="%System%/Sservice.exe
HKEY_CURRENT_USER/SOFTWARE/Microsoft/Windows/CurrentVersion/Run
StubPath"="C:/Windows/system/Sservice.exe
HKEY_LOCAL_MACHINE/Software/Microsoft/Windows NT/CurrentVersion/Winlogon
"Shell"="explorer.exe %System%/Fservice.exe" must be "Shell"="explorer.exe"
Step 24
Now restart your PC again and browse to your windows folder again to check if these files are gone. if not repeat from step 1. Code: C:/windows/system32/reginv.dll
C:/windows/system32/fservice.exe
C:/windows/system32/winkey.dll
C:/windows/services.exe
C:/windows/system/sservice.exe
C:/windows/system32/wininv.dll Step 25
Run your virusscanner to check for virusses. Now it should say nothing unless you have other virussses or hacks...
|
Congratulations. Your PC is now Good to Go again. Have a nice day.
Credits to:
Me for writing.
Symantec© for providing the Keys.
Toscane of PChelper.nl for helping me.
__________________  Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer Dave Chappelle - What did the five fingers say to the Face Make your PC Safer and Better! Visit this thread! Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me. Member of the BleachNaruto fan club! | | The Following 5 Users Say Thank You to GameLordquest For This Useful Post: | | 
08-27-2007, 06:02 AM
|  | Blue Dragon | | | Last Online: 10-26-2008 01:29 PM Join Date: Aug 2007 Age: 20
Posts: 819
Thanks: 439
Thanked 75 Times in 45 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: The Girl
Rep Power: 5 Points: 6,382.01 Bank: 0.00 Total Points: 6,382.01 | |
i don't have any viruses but i'm sure this will help of i get a serious one .. thank you | 
08-27-2007, 06:27 AM
|  | Mendelity Inc | | | Last Online: 12-03-2008 04:40 PM Join Date: Mar 2006 Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18 Points: 1,447.00 Bank: 204,314.07 Total Points: 205,761.07 | | |
No problem im here to help... But this is actually only for the virus simular to the ProRat virus... you should check this list if you think your infected.
__________________  Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer Dave Chappelle - What did the five fingers say to the Face Make your PC Safer and Better! Visit this thread! Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me. Member of the BleachNaruto fan club! | 
10-03-2007, 04:46 PM
|  | Silver Dragon | | | Last Online: 11-30-2008 09:48 PM Join Date: Oct 2006 Location: Can- why do you wanna know?
Posts: 1,260
Thanks: 328
Thanked 144 Times in 102 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 10 Points: 25,384.39 Bank: 131,693.89 Total Points: 157,078.28 | | |
Well thanks, ive been proratted before by somebody (cough cough)
But yeah i had kaspersky on luckily, so it killed it after my system reboot.
I also had a parite which was odd, every file was infected.
__________________ If i helped you, kindly press the thanks button or +rep me. --->> | | The Following User Says Thank You to EnviousX For This Useful Post: | | 
10-28-2007, 10:45 AM
|  | Silver Dragon | | | Last Online: Yesterday 03:20 PM Join Date: May 2007 Location: In Matt's Porno Collection
Posts: 1,205
Thanks: 210
Thanked 251 Times in 113 Posts
Nominated 2 Times in 2 Posts TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 8 Points: 3,487.60 Bank: 356,254.16 Total Points: 359,741.76 | | |
hmm oke 1 thing what thus that virus do to your pc ?
i got and virus
and now i dont got permision to my system that mean i can't edit my pc or remove software
ore look in windows conf
and i can't change my desktop image :'(
| 
04-09-2008, 09:32 AM
|  | Mendelity Inc | | | Last Online: 12-03-2008 04:40 PM Join Date: Mar 2006 Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18 Points: 1,447.00 Bank: 204,314.07 Total Points: 205,761.07 | | |
lol i got thanked by hornstar...
ProRAT is an keylogger that grants access to several programs where normally access is denied... so infact is ProRAT handy but it has a flip side...
__________________  Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer Dave Chappelle - What did the five fingers say to the Face Make your PC Safer and Better! Visit this thread! Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me. Member of the BleachNaruto fan club! | 
04-09-2008, 10:43 AM
|  | Registered Users + | | | Last Online: Yesterday 10:47 AM Join Date: Aug 2007 Location: ██████████████
Posts: 1,046
Thanks: 134
Thanked 68 Times in 42 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 6 Points: 1,209.80 Bank: 0.00 Total Points: 1,209.80 | |
prorat doesnt have a virus. atleast my one didnt. | 
04-10-2008, 11:31 AM
|  | Mendelity Inc | | | Last Online: 12-03-2008 04:40 PM Join Date: Mar 2006 Location: GunZ/GzN ((F)) FEYENOORD ((F))
Posts: 3,581
Thanks: 145
Thanked 332 Times in 218 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: sixth seventh and eight day
Rep Power: 18 Points: 1,447.00 Bank: 204,314.07 Total Points: 205,761.07 | | |
ok... have it your way... let me put it like this. ProRAT is a keylogger that manifest in your PC the moment you installed it. you can play "smartass" all you want but you know im right.
__________________  Hall of respect: Hornstar6969, BleachNaruto, Kanon, Joriannn, Flamee, Kamil077, Bam, zone1992, +CrackKing1, +Demonite, +killah4eva, +kmaster22, +xslayer Dave Chappelle - What did the five fingers say to the Face Make your PC Safer and Better! Visit this thread! Wanna be 1337 just like me??? Buy Premium+ Now and PWN just like me. Member of the BleachNaruto fan club! | 
04-10-2008, 12:33 PM
|  | | | | Last Online: Today 12:44 AM Join Date: Oct 2006 Location: Utrecht, The Netherlands Age: 17
Posts: 6,533
Thanks: 333
Thanked 536 Times in 434 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog: Rappelz ftw!
Rep Power: 26 Points: 463.50 Bank: 537,056.01 Total Points: 537,519.51 | | Quote:
Originally Posted by N_E_O_N prorat doesnt have a virus. atleast my one didnt.  | If there's a free version of it, it most likely does. The name only already freaks me out, I'd never download something like that
__________________ Rule 1: I'm always right.
Rule 2: When I'm not, or when in doubt, refer to rule 1. | 
04-10-2008, 12:44 PM
|  | Chris < Big Nubzor | | | Join Date: Jan 2007 Location: Canada,Eh?
Posts: 1,762
Thanks: 320
Thanked 372 Times in 183 Posts
Nominated 0 Times in 0 Posts TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 10 Points: 773.10 Bank: 0.00 Total Points: 773.10 | | Quote:
Well thanks, ive been proratted before by somebody (cough cough)
But yeah i had kaspersky on luckily, so it killed it after my system reboot.
I also had a parite which was odd, every file was infected.
| Ehhh this was me lol. xD *cough* What?
|  | | |
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | | | | |