Post: How to prevent getting RATted/How to Remove one
08-10-2014, 06:54 PM #1
Dacoco
I void warranties.
(adsbygoogle = window.adsbygoogle || []).push({}); Hey everybody, I've recently seen alot of rats being posted on the forums, so im going to post a thread on how to prevent them from being executed/removing one.

What is a RAT?


Well RAT has many names, the most common being Remote Administrative Tool/Trojan. A RAT basically allows some ****** that is using DarkComet to control your PC without you even knowing. Some features of rats include them being able to turn your webcam on, see all your saved passwords, controlling your mouse and keyboard, opening random pages, they even have the ability to delete your system32 Files, the list goes on. I know it sounds scary, thats why i want people to try to be safe, I ratted a while back and now that im looking at it, it was a dick move.


How to Prevent getting RATted


Okay there are many things you can do to NOT get ratted, simply just dont download anything at all, dont click random links, there done you wont get ratted if you do that. But this is a modding community, we have to download stuff, so lets check a program to see if its a rat or not. For this part you will need Sandboxie (You must login or register to view this content.). I know, ironic how i told you just to not download things, but this helps, trust me. Once you install Sandboxie, you now have the option to open anything sandboxed, which basically means that when that program is open, it can only stay in the sandbox, it cant spread to your computer. If it is a rat though, it will still run, so they will have access to things that dont involve files, like being able to turn your webcam on, I usually put a piece of paper taped to the webcam so that way even if they turn it on, they cant see me.

Run the rat in a Virtual Machine, i dont have much knowledge on this topic, but from hearing people talk about it, I believe that all you need is to download a Virtual Machine (You must login or register to view this content.), and install an OS on it, then you can run all your programs on this machine, so that way even if one slips through, its still on a machine that only has an OS on it.


How to Remove Rats

Okay, i know that RATs can be harsh, they can disable task manager making it a pain to remove, but there is one thing that no rat can stay on your PC from, a system Restore, no rat can make it through this, unless you restore to a point when the rat was already on your PC, so if you dont have that much important data on your PC, go ahead and do a system restore so that all data is wiped, along with the RAT.

Okay i recently came across a program that is in my opinion way better than task manager, its called Process Hacker(You must login or register to view this content.). This allows you to see what your programs are doing where they came from etc. One reason i really like this program, is because when you cant end a task in task manager, it just says something along the lines of Process cannot be stopped. But if you try to end it in Process Hacker, it tells you the actual reason why it cant be stopped.

Two more things and then we are done, Okay, RATs need an internet connection, so if you arent connected to the internet, they cant do anything about it. Try to avoid connecting to the internet as much as possible. Now that we are not connected to the internet, hit the windows key and R at the same time or just open up run, and type 'regedit' no quotes, say yes to the admin stuff, then navigate to HKEY_Current_User>Software>Microsoft>Windows>Current Version>Run. This will show you the processes, and their file location, if there is something suspicious, check it out my googling the processes name, and going to that file location. When you go there, and there isnt a folder but iRegEdit says there is, you have to turn on Hidden Folders(You must login or register to view this content.).

Last thing Happy. Okay now open up Run again, and type 'msconfig' no quotes, then click the startup and open task manager through that, this will tell you all the apps that run on startup. If you dont know what it is, i suggest googling it, then if there isnt much on the topic, disable it. Now go to the services tab, and make sure Hide all Microsoft services is checked, then it will tell you all the services running that arent microsoft, again if you dont know what it is, i suggest googling it, then if there isnt much on the topic, disable it.


Thanks for reading my tutorial Happy Check these often, for the love of god, please.

Useful Programs

IOBit Unlocker(Can Unlock files/folders making them easy to delete) - You must login or register to view this content.

The following 21 users say thank you to Dacoco for this useful post:

ALI ALHILFI, BossManAbz, Creepzoid 0___0, djbackwardss, Dominator666, Geo, iAmRishi, Im Not Boobdidas, MORPHEUS__2142, Notorious, quack_QUACK, QuantumDev, RealzHax, Sammmmmy, sittinlower, Swifter, Taylors Bish, Tee1945, Trojan041, Zambie

The following 2 users groaned at Dacoco for this awful post:

Toke, Number
03-01-2015, 09:24 PM #20
Dacoco
I void warranties.
Originally posted by HD View Post
Dark Comet RAT Remover

Only removes unencrypted dark comet rats
04-15-2015, 11:17 PM #21
Nic ethatnks for heads up
04-20-2015, 08:17 PM #22
nice thanks its helped Smile
04-20-2015, 08:18 PM #23
wow so smart and cool!
04-21-2015, 05:26 PM #24
Just saying there are crypters allowing you to bypass vmware, sandboxie and anubis!
I recommend getting autoruns to remove rats even tho crypters can allow for more advance spreading...
05-07-2015, 02:02 AM #25
i just removed one thanks soo much i never new what a rat was thought it was just a rodent xD
05-10-2015, 08:45 AM #26
05-12-2015, 03:51 AM #27
Nice, tutorial man.

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo