GeekPolice
Would you like to react to this message? Create an account in a few clicks or log in to continue.

GeekPoliceLog in

 


descriptionRAT infected (pretty sure) EmptyRAT infected (pretty sure)

more_horiz
Hey, I'm pretty sure I am RAT infected. It disables the security center in services.msc and It redirects sitws such as malwarebytes.org etc. Here is my Hijackthis log:

Spoiler :


Can someone please tell me how to fix this?

descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
Hi there MiniRadi!

I am Gabethebabe and I will be helping you with this issue. Before we start some general remarks/rules:
  • Whilst I´m helping you, please follow my instructions carefully and do not experiment on your own or accept help from other persons.
  • Feel free to ask questions! Especially if my instructions are not clear. I´m here to help, not confuse you.
  • I will try and respond quickly, but please understand I do have a real life (job, wife, 3 kids, kinky hobbies).
  • Stick with me till the end. If your computer starts running better, doesn´t mean it is clean yet!

====================

Please download OTL by OldTimer from here and save it to your desktop.
  • Close all windows and double click OTL.exe.
  • The Extra Registry setting should be Use Safelist
  • Copy and paste the following text into the Custom Scans/Fixes box:

Code:

%APPDATA%\Microsoft\*.*
%systemroot%\system32\config\systemprofile\*.dat /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\winn32\*.*
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%PROGRAMFILES%\Mozilla Firefox\*.exe
%ProgramFiles%\TinyProxy.
%systemroot%\system32\*.* /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.* /lockedfiles
%PROGRAMFILES%\*.
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
/md5start
netlogon.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
disk.sys
explorer.exe
userinit.exe
winlogon.exe
/md5stop
CREATERESTOREPOINT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs

  • Click the Run Scan button and allow it to run.
  • It will produce two logs for you, OTL.txt and Extras.txt. Please post both logs in this thread.
  • You may need multiple posts to get it all.

====================

Please download aswMBR by Alwil Software from here and save it to your desktop.

  • Double click aswMBR.exe to run the tool
  • Click the Scan button to start the scan
  • Don´t panic if you see any **Rootkit** entries. The tool sometimes produces false alarms
  • Once the scan finishes click Save log to save the log to your desktop
  • Copy and paste the contents of this log (aswMBR.txt) into your next reply.


descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
Hey Gabethebabe, Thanks.

Here are my logs from OLT by OldTimer:

OTL.txt:

Spoiler :

descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
Heres the rest of the OTL.txt log:

Spoiler :

descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
here is the Extra.txt log:

Spoiler :

descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
Here is the aswMBR.txt log:

Spoiler :

descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
Please download CKScanner by askey127 from here and save it to your desktop.

  • Doubleclick CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify that the file is saved.
  • Please copy the contents of the CKFiles.txt file on your desktop and paste it into your next reply.


descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
Alright, here is the log from CKScanner:

Spoiler :

descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
Keygen/crack warning!
There are keygens and/or cracks on your computer. Please be aware that these programs are generally used for illegal purposes. Software piracy is a crime that we at GeekPolice do not recommend or approve (but rest assured that we do not report it either).
Keygens and cracks form a very important distribution network of malware. It might be the reason of your present infection. Even if you use reknown security software, you can never be safe, as you might run into a fresh new variant (a so-called 0-day threat).

Example: Two VirusTotal reports of a keygen, that in reality was a trojan carrying a nasty infection called TDSS.
THIS is the report of the trojan just after release - 0/40 virusscanners detected the deadly load.
THIS is a report of the same file just five days later - 24/40 have updated their signature database to detect it.
If you would repeat the analysis today, it would probably be detected by even more scanners. Tough luck for the users that picked it up early. Make sure you are not among them.

Stay out of trouble: get free software instead! I provide some safe websites where you can pick up free software, often just as good as commercial software.

====================

I am sorry, but in the current state of your computer I will not help you to rid your computer of any malware infection. I recommend you cleanse your computer of pirated software first, by either completely uninstalling it or by purchasing legal copies of it.

descriptionRAT infected (pretty sure) EmptyRe: RAT infected (pretty sure)

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum