[OUTDATED / UNSUPPORTED] RemoveWAT

Discussion in 'Windows 7' started by Hazar, Oct 15, 2009.

Thread Status:
Not open for further replies.
  1. Ashq

    Ashq MDL Novice

    May 3, 2010
    9
    0
    0
  2. tod

    tod MDL Novice

    Aug 11, 2010
    29
    0
    0
    :eek: You have to prove that
    i switched to win7loader yesterday
    ie8 is unsafe i don't use it
    i use firefox especially for logins and passwords.
     
  3. Ashq

    Ashq MDL Novice

    May 3, 2010
    9
    0
    0
    #3203 Ashq, Sep 3, 2010
    Last edited: Sep 3, 2010
    Fix:

    1.Open RemoveWAT, close all programs and then click "Restore WAT"/"Remove WAT" - let it reboot (auto).
    2.Open RemoveWAT and repeat once again untill you get "Remove WAT" then execute it as the final one.

    NOTE:while doing this your anti-virus will prompt access permissions to the internet for removeWAT.exe, allow it temporarily then block it's access from the internet so that the embedded trojan will be useless.

    [or]

    just block it completely via windows firewall

    it connects to 96.28.136.171 on port 49916..that must be the trojan's server..who cares anyway.

    Reason for this problem:Windows media player's automatic update, which cannot be disabled physically.Disable windows media center if possible(wont be a problem for now).
     
  4. timesurfer

    timesurfer MDL Developer

    Nov 22, 2009
    8,524
    4,112
    270
    Hazar doesn't add trojans to his builds :eek:...lol
     
  5. ollie

    ollie MDL Novice

    Sep 15, 2008
    13
    1
    0
    #3205 ollie, Sep 3, 2010
    Last edited: Sep 3, 2010
    you know for sure? ;) he could be caught red-handed now :p

    PS. Although I have NOT witnessed removewat itself, windows is accessing something or other over the internet, which cannot be turned off unless u want your internet cut off as well
     
  6. timesurfer

    timesurfer MDL Developer

    Nov 22, 2009
    8,524
    4,112
    270
    #3206 timesurfer, Sep 3, 2010
    Last edited: Sep 3, 2010
    He is a moderator here and it think it's shunned on for moderators to include trojans in their win 7 solutions...lol

    Have some respect he was the first guy to activate win 7 I believe so even though RW has some uninstall issues it does work as an solution

    p.s. I believe RW dl's the WAT update then disables it buy patch or deletion of some files. I'm uncertain exactly but there's no trojan
     
  7. BigFatLiar

    BigFatLiar MDL Novice

    Nov 28, 2009
    17
    0
    0
    ........the tool has been modified by many unscrupulous people.....
     
  8. timesurfer

    timesurfer MDL Developer

    Nov 22, 2009
    8,524
    4,112
    270
    But I would "assume" this first page link is Hazar's build no kittie script included right? :eek:
     
  9. BigFatLiar

    BigFatLiar MDL Novice

    Nov 28, 2009
    17
    0
    0
    I think you're right ...
    At that moment, I use this tool downloaded from here and I have not had problems.
     
  10. Hazar

    Hazar MDL Guru

    Jul 29, 2009
    2,507
    458
    90
    I'm a bit offended.

    I would never include a trojan of any sorts in my work :(
     
  11. cee12

    cee12 MDL Junior Member

    May 4, 2010
    57
    2
    0
    ashq = m$ agent?
     
  12. MadSheep!

    MadSheep! MDL Junior Member

    Jul 12, 2009
    72
    23
    0
    your stupidity have no borders, this tool is clean if you extract it you will find that the contents is a fake update "KB971033" to protect you from Micr0soft and the WSUSSCAN.cab for installing the update no virus no Trojan nothing

    @Ashq
    Try more next time and learn to use computers
     
  13. Ashq

    Ashq MDL Novice

    May 3, 2010
    9
    0
    0
  14. cee12

    cee12 MDL Junior Member

    May 4, 2010
    57
    2
    0
    Ah.

    ashq ≠ m$ agent,

    ashq = idiot.
     
  15. MasterDisaster

    MasterDisaster MDL Expert

    Aug 29, 2009
    1,255
    675
    60
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. Hazar

    Hazar MDL Guru

    Jul 29, 2009
    2,507
    458
    90
    Hi all.

    With regards to this issue, I never put anything malicious in my programs. I will investigate if something has snuck into the server, but this is incredibly unlikely considering the security behind the system and the competence and awareness of the admin.
     
  17. FreeStyler

    FreeStyler MDL Guru

    Jun 23, 2007
    3,563
    3,848
    120
    Maybe add MD5 or SHA hash to first post, so people can verify if they have the real deal
     
  18. Ashq

    Ashq MDL Novice

    May 3, 2010
    9
    0
    0
    so he admits that the executable file is packed with a trojan ?

    use ur heads, why would removeWAT require an internet connection - this proof is more than enough.
     
  19. Ashq

    Ashq MDL Novice

    May 3, 2010
    9
    0
    0
    i doubt he will do that, coz he will have to edit the executable if he changes his mind by removing the virus ?

    [or]

    he could had just added those hashes in the first place when he started the thread?why didn't he?think abt it.