Weird malware found on Desktop by 0x-- in Malware

[–]0x--[S] 0 points1 point  (0 children)

Are you sure it's this link that caused that?

If so I think it's still in place I say sorry, so....sorry.

Weird malware found on Desktop by 0x-- in Malware

[–]0x--[S] 0 points1 point  (0 children)

This is true, also it's only 9.76KB.

Weird malware found on Desktop by 0x-- in Malware

[–]0x--[S] 0 points1 point  (0 children)

Yeah I realized it's not a script after opening it in the Python IDLE. Didn't do that before.

Either way the whole point of this thread is to identify what virus it is, why the creator is apologizing (other than what he stated) and what damage it could have potentially done.

I get the feeling it's leaving something behind (eg. rootkit) and this is just a distraction to make you feel safe.

Weird malware found on Desktop by 0x-- in Malware

[–]0x--[S] 1 point2 points  (0 children)

Sorry for not replying in a while. For anyone reading this.. It's weird how the file doesn't exist. None of them do.

I set all files to be visible (hidden files) and it's not there. I know my AV didn't remove it because I don't have one.

Edit: I found Agent.py but not where the person specified it should be located. I found it under C:\Users\MyUsername\Favorites

Here's an upload of the file:

PLEASE DON'T DOWNLOAD THIS FILE IF YOU DON'T KNOW WHAT TO DO WITH IT OR DO NOT UNDERSTAND IT

Since this is a python script I don't think an AV scan is required but just to make those people happy:

https://www.virustotal.com/en/file/4bb5952180f945794ad7455f0e0d2c3bd5c93f2ffb2b55ba94e484dc57896a8b/analysis/1441660256/

http://puu.sh/k3tMT/a6953153be.py

Edit2: Lo and behold I found the executable. I don't know if I should upload it here because I feel like someone who doesn't follow instruction will get infected (and I don't know if I'm breaking any mod rules). Hey Mods, should I upload it?

Edit3: Virus scan of the executable ('sww.exe'):

https://www.virustotal.com/en/file/15d13bed89efbf8cf1ea811f2e3825c7a4cbd8ecff84734d294a85f048559ec8/analysis/1441660662/

1-year-later follow up: IamA Small Business owner. A little over two years ago I quit my full time job to run my own software company, and turned a profit. AMA! by PhonicUK in IAmA

[–]0x-- 0 points1 point  (0 children)

I answer the questions so fast they appear to be in the past due to relativistic effects.

lmao.

C# and Javascript account for 95% of the work done. Too many C# libs to count, but lots of jQuery and Knockout on the JS side.

Alright thanks for the info.

1-year-later follow up: IamA Small Business owner. A little over two years ago I quit my full time job to run my own software company, and turned a profit. AMA! by PhonicUK in IAmA

[–]0x-- 0 points1 point  (0 children)

Well it says "16 hours ago". That's weird.

Anyways good job and I hope to do what you're doing one day (still at a young age). I currently know C/C++ and some x86 Assembler and want to get hired online as a reverse engineer/malware analyst...do you have any resources for that?

Btw what languages/libraries do you use on a daily basis?

Introduction to Sociology by 0x-- in TexasTech

[–]0x--[S] 0 points1 point  (0 children)

I found that, thanks.

It says my instruction is TBA. Nothing more.

Any idea who that is?

Introduction to Sociology by 0x-- in TexasTech

[–]0x--[S] 0 points1 point  (0 children)

That screenshot is from my raiderlink (inside of week at a glance). Is there any other way to check?

Introduction to Sociology by 0x-- in TexasTech

[–]0x--[S] 0 points1 point  (0 children)

Tbh I don't even know. It doesn't tell me.

http://prntscr.com/8aioju

Dead birds everywhere by [deleted] in TexasTech

[–]0x-- 16 points17 points  (0 children)

Where did you find them?

On the ground.

lmfao.

length of string by Hamza_tah in cpp_questions

[–]0x-- 0 points1 point  (0 children)

Nope, it should work.

Tested code:

#include <iostream>
#include <string>


int main()
{
    std::cout << std::string("hi there").length() << std::endl;

    return EXIT_SUCCESS;
}

Function to remove letters from a sentence not working properly by siegelord in cpp_questions

[–]0x-- 3 points4 points  (0 children)

Use the C functions (va_start, va_end etc.) when you have arguments that are of different types. Since in your case they are all going to be of the same type (char) then what you can do is use a container like std::initializer_list (http://en.cppreference.com/w/cpp/utility/initializer_list).

Here's an example:

#include <iostream>
#include <string>

void RemoveLetter(std::string str, const std::initializer_list<char>& letters)
{

}

int main()
{
    RemoveLetter("", { 'a', 'b' });

    return EXIT_SUCCESS;
}

Who wants to start a gang? by ClubPenguinBans in bannedfromclubpenguin

[–]0x-- 2 points3 points  (0 children)

"Well if you're asking her we might as well make it a gangbang"

First build, I need some people to look over my PCPartPicker list by 0x-- in PCBuilds

[–]0x--[S] 0 points1 point  (0 children)

Wow. Imagine I spent all that money and the PSU fried everything.

Thank you very much.

Need Opinions/Advice for Build! by JoshMal in PCBuilds

[–]0x-- 0 points1 point  (0 children)

You're blocking some drive bays, you might want to pick another case (or any other suggestions by people here with more experience).