Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
RAT
#1
Hello all,

Bit of a situation here...I'm about 95% sure someone installed a RAT onto my laptop. I've done all the scans out there, including a few of the manual techniques off YouTube. My best guess is someone from my Steam friends list as I generally practice the use of common sense( Tongue ) when web browsing. Steam was actually my first clue, when I noticed during my CS:GO games I would almost always have "1 viewer", including a couple times I did a personal server. Since then I've noticed little system tweaks here and there that I know were not my doing. Ill admit the lad isn't malicious (knock wood) which is nice, but I do think he has me chained up to his train of hacked PCs, used for DDOS or some other sort.

I'm assuming he's somewhere in my registry to make coming and going swift, as well as some sort of restore function. I ran Tweakings.com Windows Firewall repair, and was successful for all of 5-7 minutes until it was shifted back to "his" version, which allows separate VPN clients to be run as well as specific guidelines for my network ports. Can't forget constantly being denied access to multiple different file locations(usually TrustedInstaller), even though I'm running the admin account.

Also I'll point out this laptop use to belong to my roommate months ago, I've done a full system reset since then but figured it was worth the shout? Maybe he's on the HDD?

Thanks and hope to hear back soon
P.S. Britec-can't thank you enough for the YouTube videos!!
-Kompany

#2
Kompany in my opinion if you think someone is able to vpn into your laptop at will then I would back up your important data and re-install Windows from scratch. No telling what changes this person made to your registry.
Tim's Computer Repair (TCR) 
1503 Kings Way, Savannah, GA 31406, US
912-220-0765
https://www.TimsComputerFix.net 


#3
[Image: FRST.png]Scan with Farbar Recovery Scan Tool


Please download Farbar Recovery Scan Tool x64 and save it to your Desktop.
  • Right-click on [Image: FRST.png] icon and select [Image: RunAsAdmin.jpg] Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • When the tool opens click Yes to disclaimer.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please copy and paste their content into your next reply.
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 

#4
Post Close due to lack of interest from poster.
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 



Forum Jump:


Users browsing this thread:
1 Guest(s)

Powered By MyBB, © 2002-2024 Melroy van den Berg.