Install Steam
login
|
language
简体中文 (Simplified Chinese)
繁體中文 (Traditional Chinese)
日本語 (Japanese)
한국어 (Korean)
ไทย (Thai)
Български (Bulgarian)
Čeština (Czech)
Dansk (Danish)
Deutsch (German)
Español - España (Spanish - Spain)
Español - Latinoamérica (Spanish - Latin America)
Ελληνικά (Greek)
Français (French)
Italiano (Italian)
Bahasa Indonesia (Indonesian)
Magyar (Hungarian)
Nederlands (Dutch)
Norsk (Norwegian)
Polski (Polish)
Português (Portuguese - Portugal)
Português - Brasil (Portuguese - Brazil)
Română (Romanian)
Русский (Russian)
Suomi (Finnish)
Svenska (Swedish)
Türkçe (Turkish)
Tiếng Việt (Vietnamese)
Українська (Ukrainian)
Report a translation problem
It first kills any running instances of hl.exe or cstrike.exe. These are the main executable files for Half-Life and Counter-Strike respectively.
It then removes certain types of files (*.asi and *.bat), which could potentially be related to legitimate game modification files or other scripts.
A VBScript file (trash.vbs) is then created, which seems to be designed to download a file (ST*G_**_DE.exe) from a remote server and execute it on your machine.
The fact that you found a path to a PDB file (Program Database) in the binary suggests that the creator didn't bother to clean up after compiling the code, as these files are typically used for debugging and aren't needed in a final, released version of software. The username "emoto" might be related to the person who created this file, but it could also be a false flag or irrelevant.
In this case, you did the right thing by investigating the files and not running anything suspicious. It's very important to stay vigilant when gaming online, especially when joining servers or downloading mods from sources that aren't officially endorsed or otherwise trusted by the gaming community.
Here are a few additional steps you can take to protect yourself:
Scan your system for malware: Use an antivirus software to scan your computer for any malicious programs or files that may have been downloaded.
Change your passwords: If there's a chance that your information has been compromised, it's a good idea to change your passwords. This is especially true for any accounts that you logged into while you were potentially infected.
Update your software: Make sure all of your software, including your operating system, is up to date. Many updates include security fixes that can protect you from known vulnerabilities.
Enable a firewall: If you haven't already, enable a firewall on your computer. This can help protect your system by controlling incoming and outgoing network traffic based on predetermined security rules.
Be cautious: Be careful when joining unofficial servers or downloading mods. Always use trusted sources and verify the integrity of files where possible.
Remember, it's always better to err on the side of caution when it comes to online security.
They uploading rat to client with precache_generic.
Be careful.
I will probably wipe my OS... schizo is kicking in.
Also, I checked that script kiddie site; he keeps a public log of baited users. Server boosting?