Share via

Help with removing a complex rat

Anonymous
2024-05-22T04:30:38+00:00

I'm currently on Windows 10 and there's a process running, which I only noticed due to Process Hacker. It's unsigned and packed, with a thread running. In Process Hacker I can view the file location, but there's nothing there. However, when I list all directories in CMD, it's there, but I can't delete it. I've tried giving myself access to it, and some user named "logon" has access. When I leave the folder and try to find it in Explorer, it doesn't exist. No antivirus can pick it up, and if I do a factory reset or use a USB, it's back. What can I do? Also, I can't remove the remote user because when I open any window related to users, it crashes, and that's after I suspended their .exe file. No antivirus can detect it im guessing it was from a binded rar file most advanced rat ive seen in a good while. The rat is suppose to look like a edge updater but you can tell its unlegit due to file not existing according to explorer and the fact its unsigned like most or not all windows programs. Closing rat doesnt help either in 5 mins its back theirs also nothing in task scheduler or startup and its starts when i boot. only ideas on what i can do to help my self? Also if i may include that taskmgr cant see it i was only able to notice it with Process Hacker when i hid all signed processes.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-05-22T04:55:02+00:00

    Hi, please scan with Farbar Recovery Scan Tool (FRST) and share logs.

    https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

    • If your computer language is not English, rename FRST64.exe to FRST64English.exe
    • Run FRST and press "Scan"
    • Two logs are created in the folder that FRST is run from, FRST.txt and Addition.txt
    • Upload the logs to OneDrive, Google Drive or any file sharing service and post the share link

    Note: If you are downloading FRST with Edge, smartscreen may initially block it.

    Click on the 3 dots next to the warning and select Keep-> Show more-> Keep anyway.

    Share OneDrive files and folders - Microsoft Support

    Was this answer helpful?

    0 comments No comments