Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.



  • Please log in to reply
1 reply to this topic

#1 blablahbla


  • Members
  • 4 posts
  • Local time:06:12 AM

Posted 15 April 2017 - 02:19 AM

http://imgur.com/a/vXpNG (contents of 1.bat&1.vbs and 12.bat&12.vbs). Rarsfx1 contains the 12.bat and vbs, whereas all the other folders contain 1.bat and vbs.

In the temp folder, there are these folders rarsfx0-1056. They all contain 1.bat and 1.vbs. When I open my task manager, there are multiple cmd's opened, each taking 0.6 or 0.7mb. It eats up a lot of my memory. In either the bat or the vbs file, there is an email - roma98(dot)27@mail(dot)ru. At one point, I started deleting all the files, and successfully did so (after deleting the processes, manually deleting all vbs and bat files, then system files, then all the .dll files). Then, I restarted. A command prompt opened up (couldnt take a screenshot), that looked like it connected to the email address(email address was mentioned, and multiple files were being downloaded). I closed it, then went back to the folder, and saw that all the rarsfx0-rarsfx1056 (1057 folders in total) came back.

Used adwcleaner, malwarebytes(premium), kaspersky(premium), it doesnt do anything to the folder or the files at all. Need help, as it's slowing down my laptop, and my dad is superworried.

I used Everything program to delete all the vbs and bat files, and only then could I delete the system.exe file, then I deleted the folders.

!! DO NOT CLICK ON LINK!! This is the only website on google that contains the exact email words: https://www(dot)google(dot)com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&cad=rja&uact=8&ved=0ahUKEwio-a7J9KXTAhUSLlAKHRsuBicQFggkMAA&url=https%3A%2F%2Fvk(dot)com%2Fwall-93660645&usg=AFQjCNGaxIndpAipavAIXQeC75MxdZA5_A&sig2=y9fg80mwo7Sps0TkSuSL_w&bvm=bv(dot)152479541,d(dot)ZWM !! DO NOT CLICK ON LINK!!

Do not click on link said because I dont know what the bleep will happen to your pc.

safe Google search results: https://www.google.com/search?q=roma98.27&rlz=1C1CHBD_enAE739AE739&oq=roma98.27&aqs=chrome..69i57.4148j0j4&sourceid=chrome&ie=UTF-8#q=%22roma98.27%22 safe

The highlighted system.exe is the file, and as seen in the pictures, all those 32 bit cmd's are open (64 bit laptop). Thanks in advance :)


Posted the same thing on reddit: https://www.reddit.com/r/computerviruses/comments/65hwe7/rarsfx01056/

Edited by blablahbla, 15 April 2017 - 02:36 AM.

BC AdBot (Login to Remove)


#2 buddy215


  • Moderator
  • 13,410 posts
  • Gender:Male
  • Location:West Tennessee
  • Local time:08:12 PM

Posted 15 April 2017 - 04:37 AM

Please follow the instructions in the Malware Removal and Log Section Preparation Guide starting at Step 6.

  • If you cannot complete a step, then skip it and continue with the next.
  • In Step 6 there are instructions for downloading and running FRST which will create two logs.

When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.

Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.

After doing this, please reply back in this thread with a link to the new topic so we can close this one.


DO NOT bump your new topic. Wait for a response from one of the Team Members.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users