Navigate to your %appdata% folder by typing in run or windows search bar %appdata%
Once in your appdata folder go under Roaming if not already there.
Delete main.exe and chrtmp and of course delete the original file you ran called something like xRadar.
It most likely will not let you delete main.exe as it was also a process created and that is now running. (probably keylogger) So you may have to first stop main.exe and then delete it.
Next Steps:
If you save passwords in firefox or any other browser I'd HIGHLY suggest changing your passwords as this file due to high evidence steals passwords and keylogs you. So make sure to change passes after this!
What else might it have done?
It may have modified some of your internet explorer settings. It for sure looked at internet, history and cookies. A good idea would be to totally change EVERY password for your sites.
Good Luck everyone I'm sorry for this file being approved.
If you ran this, I'd suggest you get rid of the virus first and change ALL of your passwords.
I think I've recovered my accounts and such, but after reinstalling battlefield 3 I can't launch the game, simply gives me an error
"Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item..."
Originally Posted by nmeseth
I think I've recovered my accounts and such, but after reinstalling battlefield 3 I can't launch the game, simply gives me an error
"Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item..."
Run as admin. If that doesn't work maybe check the install folder and see if the exe file has full permissions (right click file > properties > security)
mozsqlite3.dll is the dll that the hack did something with btw
Here is a simple cleanup batch file:
Code:
@EcHo off
echo ----------------
set /p t=Cleaning up mess.... < NUL
del /q %appdata%\main.exe 2> NUL
del /q %appdata%\chrtmp 2> NUL
echo DONE!
echo.
echo Please do a full scan with your AV software to cleanup any further traces
echo as it still maybe hiding somewhere in the system or modified some
echo important files/registry values. A quick scan with
echo Malwarebytes Anti-Malware (free) is also recommended.
echo ----------------
pause
Open Notepad and then copy and paste everything in the box. Click File > Save and change the Save as type to All Files (*.*) and then browse to your desktop. Name the file cleanup.bat and then click Save. Double click on the file on your desktop and that's it.
A reminder, if we (--removed--) did some free trials (which is most unlikely unless you are a customer) we won't advertise it on other forums and only on our own. People use our name to spread their shit (viruses, trojans, RAT's, etc) use common sense.
i have the ip and everything else of the guy.
he also tried to hack my fb!
rape this guy! -his battlefield 3 origin name is --r0nnyy
Unbenannt.png
he'll cry cuz he's on my shitlist now
Originally Posted by Bull56
i have the ip and everything else of the guy.
he also tried to hack my fb!
rape this guy! -his battlefield 3 origin name is --r0nnyy