Is SPK views bot a virus?

dekadent30

Elite Member
Joined
Nov 10, 2008
Messages
1,910
Reaction score
1,036
Since i run it on my dedi yesterday i can't log in to my remote desktop, i submit ticket to support, they rebooted my server and it didn't help. I tried to log in from other PC and still can't. Did mods ban spk for spreading virus? Virustotal shows 2/43 scan result
 
Nope, I used it yesterday and it's all good. He has a service here for goodness sake, he wouldn't try to infect all of us only to risk his entire business and reputation.
 
Well since yesterday, i am also getting problem logging into my VPS. Is it really a keylogger of some kind maybe?
 
Nope, I used it yesterday and it's all good. He has a service here for goodness sake, he wouldn't try to infect all of us only to risk his entire business and reputation.

He's banned
 
If you saw the thread before it was deleted SpK explained everything about it being a virus or trojan.

You can even decompile the program and look at the whole code yourself, which he suggested you do if you're concerned.
 
If you saw the thread before it was deleted SpK explained everything about it being a virus or trojan.

You can even decompile the program and look at the whole code yourself, which he suggested you do if you're concerned.

So it really is a virus?
 
don't think so, otherwise there would already be a stickied thread about it alerting users made by Wiz
but yea, run it in VM
 
Here's the posts from the thread:

ByteHero is a heuristics detection system, Emsisoft clearly says "Riskware", and Ikarus states VirTool. What do these mean? Well ByteHero means they think its a virus, because of its behavior, but it is not a confirmed virus. Riskware means it is software that could be a risk, but is not confirmed to be dangerous, and VirTool means it is a tool that can be used like a virus. If this software can potentially spam youtube videos, then yes, it is a VirTool, Riskware, and potentially dangerous. Not dangerous for the user, but for the target: youtube in this case.

You just confirmed for us that it is a clean file
Also don't forget to mention the file's source is totally visible as I have not obfuscated the .NET RTSP.exe file. Stupidity amazes me
 
It's not a virus. He was probably banned for another reason, and will probably return soon. I guess it's just a temporary ban - but not sure.

If it was a virus, Wiz or Blackhit would have DEFINITELY got onto it and posted a sticky warning others. The virus that appears on the virus scan is probably one that comes on all bots created in the language he used.

I don't think he will risk his business here for a simple bot he made.
 
Just like all keygens are considered a virus just because what they do.. when they are not a virus at all.
 
It is not a virus, I got a problem with my server but that was caused by windows.

I read that he got banned because he manipulated the youtube section of BHW forum.
Oh the irony
 
It is not a virus, I got a problem with my server but that was caused by windows.

I read that he got banned because he manipulated the youtube section of BHW forum.
Oh the irony
No thats not the reason. He actually got banned for bumping his BST. Dont make stuff up.
 
No thats not the reason. He actually got banned for bumping his BST. Dont make stuff up.

He did say that he "read" it somewhere, therefore he wasn't making it up himself.
 
Issue with windows Vps???



Dear Customer,
This is a notice of an active security alert which could pose a threat
to your server with operating system of Microsoft Windows.

Please see the alert below:

"Yesterday, during Microsoft's Patch Tuesday they announced a patch
for a critical vulnerability in Windows Remote Desktop. If exploited,
the vulnerability would allow anyone to remotely run commands on your
server.

This bug affects all versions of Windows (XP - 7/2008 R2)
If you have a server or workstation running RDP please patch it now.
There currently is no known exploit, but Microsoft believes there will
be one in the next 30 days. However, it is very likely there will be
something sooner.

A temporary fix is to enable NLA (Network Layer Authentication). This
would require the attacker to have valid login credentials, however if
successfully exploited the remote commands would run as the SYSTEM
user and not the user authenticated."

The patch is available from Windows Update and there are manual
patches linked below.

http://technet.microsoft.com/en-us/security/bulletin/ms12-020

http://blogs.technet.com/b/srd/arch...closer-look-at-ms12-020-s-critical-issue.aspx

*

Regards


Thrust::VPS
 
Back
Top