Results 1 to 8 of 8
  1. #1
    Fraggykidd's Avatar
    Join Date
    Jan 2012
    Gender
    male
    Posts
    39
    Reputation
    10
    Thanks
    72
    My Mood
    Amazed

    Exclamation I Got RATTED :( Any Help?

    I KNOW i have been ratted, MSConfig deleted/hid all the startup programs, processes in task manager got deleted instantly and got refreshed.
    Ran in safe-mode and checked startup manager, and i removed all suspicious programs, not sure if its gone yet. I want to be 100% sure so if there is a way too clean your pc from RAT's? Please Help.


    <3 From Frag.

    ---------- Post added at 02:54 PM ---------- Previous post was at 02:52 PM ----------

    HEhe, just saw the anti-malware subforum xD

    @Ravallo It's solved. Close please ? :3

    Thanks all! <3 From Frag =)
    Last edited by Fraggykidd; 12-27-2012 at 10:49 AM. Reason: Solved

  2. #2
    Ravallo's Avatar
    Join Date
    Jun 2008
    Gender
    male
    Location
    The Netherlands
    Posts
    17,093
    Reputation
    2134
    Thanks
    5,750
    My Mood
    Angelic
    Would start out by scanning your PC with ComboFix
    Otherwise reformatting your PC would be the best option


     

    MSN: woutervvelsen@live.nl
    Timezone: GMT +1



    Middleman since: April 13th, 2011
    Marketplace minion since: April 18th, 2011
    Runescape minion since: June 6th, 2011
    Moderator since: September 28th, 2011
    General Moderator since: November 2nd, 2011
    Global Moderator since: April 29th, 2012
    Super User since: November 1st, 2013

  3. #3
    luka186's Avatar
    Join Date
    Feb 2011
    Gender
    male
    Posts
    187
    Reputation
    10
    Thanks
    15
    My Mood
    Angelic
    RATs can't be removed by AV's (RARELY, you will get VERY lucky and remove it), so the only option you have is to install a clean new windows.

    I also suggest you don't backup anything since it can contain parts of the RAT spread. If it's a text file, upload it to pastebin, etc.


    Goodluck

  4. #4
    Solo's Avatar
    Join Date
    Jul 2010
    Gender
    male
    Posts
    2,133
    Reputation
    64
    Thanks
    383
    My Mood
    Cold
    First disconnect your PC from the internet so the attacker can not damage your computer further. Then proceed to scan with you A/V (I would recommend Malwarebytes). If nothing is found and you still think the RAT is present on your system, go seek professional assistance.
    Nipples

  5. #5
    Fraggykidd's Avatar
    Join Date
    Jan 2012
    Gender
    male
    Posts
    39
    Reputation
    10
    Thanks
    72
    My Mood
    Amazed
    Quote Originally Posted by Solo View Post
    First disconnect your PC from the internet so the attacker can not damage your computer further. Then proceed to scan with you A/V (I would recommend Malwarebytes). If nothing is found and you still think the RAT is present on your system, go seek professional assistance.
    This is what i had in mind, so i tried and nothing suspicious since.

  6. #6
    DєfKOniK's Avatar
    Join Date
    Apr 2012
    Gender
    male
    Posts
    3,262
    Reputation
    234
    Thanks
    425
    My Mood
    Cynical
    Quote Originally Posted by Fraggykidd View Post
    This is what i had in mind, so i tried and nothing suspicious since.
    okay do as i say.



    - Go to taskmanager
    - Go to the "view" tab
    - Go to select columns
    - Check PID (Process ID)
    - Now close all programs that access the internet (chrome, itunes and what not)
    - Go to CMD (Window key + r; type cmd; hit enter)
    - type "netstat -ano"
    - now look for all established connections and check the PID for the established ones and compare them to the PID's in taskmanager
    - If you notice anything weird, open its file location and check it!


    hope this helps

    Tell me your skype if you need further help ^^

  7. #7
    Fraggykidd's Avatar
    Join Date
    Jan 2012
    Gender
    male
    Posts
    39
    Reputation
    10
    Thanks
    72
    My Mood
    Amazed
    Quote Originally Posted by ℒεℬøss View Post
    okay do as i say.



    - Go to taskmanager
    - Go to the "view" tab
    - Go to select columns
    - Check PID (Process ID)
    - Now close all programs that access the internet (chrome, itunes and what not)
    - Go to CMD (Window key + r; type cmd; hit enter)
    - type "netstat -ano"
    - now look for all established connections and check the PID for the established ones and compare them to the PID's in taskmanager
    - If you notice anything weird, open its file location and check it!


    hope this helps

    Tell me your skype if you need further help ^^
    Thanks for trying too help me i appreciate it.
    But i removed it ^_^ closed my internet connection when i noticed the stupid idiot started remote desktop <.< if he didnt, i would never have noticed.
    Ran a scan and found it, wasnt even hidden.. Amateurs :P

  8. #8
    chocolate_1995's Avatar
    Join Date
    Dec 2012
    Gender
    male
    Location
    In your closet
    Posts
    19
    Reputation
    10
    Thanks
    1
    My Mood
    Busy
    Quote Originally Posted by Fraggykidd View Post
    I KNOW i have been ratted, MSConfig deleted/hid all the startup programs, processes in task manager got deleted instantly and got refreshed.
    Ran in safe-mode and checked startup manager, and i removed all suspicious programs, not sure if its gone yet. I want to be 100% sure so if there is a way too clean your pc from RAT's? Please Help.


    <3 From Frag.

    ---------- Post added at 02:54 PM ---------- Previous post was at 02:52 PM ----------

    HEhe, just saw the anti-malware subforum xD

    @Ravallo It's solved. Close please ? :3

    Thanks all! <3 From Frag =)
    Don't just take stuff from people without running in sandboxie first. :/ Have them show you proof (teamviewer, join.me ect) that the program ect is legit.

    Need to contact me? Email me here: contact@chocolatemods.com
    My website | Cod Research

Similar Threads

  1. [Help Request] Can any help me with this Cheat engine code?
    By vinvin148 in forum Alliance of Valiant Arms (AVA) Help
    Replies: 0
    Last Post: 07-17-2012, 12:48 PM
  2. [Help Request] GOT BAN pls help
    By ShOoKeR in forum Alliance of Valiant Arms (AVA) Help
    Replies: 3
    Last Post: 07-17-2012, 08:33 AM
  3. [Help Request] Appreciate any help I can get
    By holytits in forum Vindictus Help
    Replies: 4
    Last Post: 08-11-2011, 01:53 AM
  4. Well... any help is welcome
    By Koto in forum Combat Arms Hacks & Cheats
    Replies: 9
    Last Post: 08-11-2008, 06:31 PM
  5. Hi i want to make a trainer but need any help
    By Jeffrey1993 in forum WarRock - International Hacks
    Replies: 4
    Last Post: 06-11-2007, 02:21 PM