ratiofaker virus killing my system (help please)

Discussion in 'ESET NOD32 Antivirus' started by guest, Mar 28, 2008.

Thread Status:
Not open for further replies.
  1. guest

    guest Guest

    Hi i went to this website: {snip}
    and downloaded the ratiofaker program found here: {snip}

    but it ended up being a virus and putting my system in safe mode. I cannot do system restore or anything. Eset does not detect anything on scans.I have a paper endline and my pc is messed now.
    when windows starts up it is fine but after 2 mins or so my start menu bar gets removed and so does the status and task bar and my desktop icons.
    I checked in safemode and it runs a .dll at start up that is called MServer, i delete it from start up but it just comes back again under a different .dll name.

    thanks for your time and i look forward to your reply.

    EC edit: Removed possibly unsafe links
     
    Last edited by a moderator: Mar 28, 2008
  2. lucas1985

    lucas1985 Retired Moderator

    Joined:
    Nov 9, 2006
    Posts:
    4,047
    Location:
    France, May 1968
    It looks like a dropper/downloader for a backdoor or a bot. You'll have to contact ESET support with a log of ESET's SysInspector.
     
  3. Kosak

    Kosak Registered Member

    Joined:
    Jul 25, 2007
    Posts:
    711
    Location:
    Slovakia
    Hi, I wouldn't write to ESET tech support for this simple problem. Better will be contact some forum specialized on malware removing.

    Yes, the base downloaded file can be trojan downloader/dropper, but loaded files will be written in registry and loaded in processes.
     
  4. guest

    guest Guest

    I was able to log into windows and look at nod32's log and i found out that the following happened....

    C:\Users\Raul\AppData\Local\Temp\wr-1-1645.exe
    Win32/TrojanDownloader.Small.IAW trojan quarantined - deleted RaulCrainic-PC\Raul Crainic Event occurred on a new file created by the application: C:\Users\Raul Crainic\Downloads\ratiofaker1.75-setup.exe. The file was moved to quarantine. You may close this window.

    C:\Users\Raul\AppData\Local\Temp\setupb.exe probably a variant of Win32/TrojanDownloader.Small.NZM trojan quarantined - deleted Event occurred on a new file created by the application: C:\Users\Raul Crainic\Downloads\ratiofaker1.75-setup.exe. The file was moved to quarantine. You may close this window.

    C:\Users\Raul Crainic\AppData\Local\Temp\wr-1-1645.exe Win32/TrojanDownloader.Small.IAW trojan quarantined - deleted RaulCrainic-PC\Raul Crainic Event occurred on a new file created by the application: C:\Users\Raul Crainic\Downloads\ratiofaker1.75-setup.exe. The file was moved to quarantine. You may close this window.

    what should i do next? i searched the internet for some fixes to these viruses but no luck.
     
  5. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,873
    Location:
    SW. Oklahoma
    I think you should follow up on your post at CastleCops and let their malware experts help you out.
     
  6. guest

    guest Guest

    nevermind i got sick of looking for "so called" solutions and just formatted my comp.
    case closed
     
  7. swami

    swami Registered Member

    Joined:
    Mar 24, 2006
    Posts:
    167
    No honour amongst the thieves. Double pirate?
     
  8. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    Extracted the undetected trojan and chucked it ESET's way. Looks like a Virtumonde trojan to me.
     
  9. solcroft

    solcroft Registered Member

    Joined:
    Jun 1, 2006
    Posts:
    1,639
    Excerpts from the website the guy was trying to download his free software from.

    Now excuse me while I go and laugh my arse off.
     
Thread Status:
Not open for further replies.