| View previous topic :: View next topic |
| Author |
Message |
homer_simpson Grandmaster Cheater
Reputation: 0
Joined: 25 Feb 2007 Posts: 596
|
Posted: Sun Nov 14, 2010 12:41 pm Post subject: [Help] CyberGate RAT |
|
|
| Well It seems I've been scammed with a CyberGate RAT. It has been crypted with a FUD Crypter and I was wondering how can I remove it? It seems to have attached itsself to chrome.exe. It kept creating some files in C:\Users\Alex\AppData\Local\Temp called xxxyyyzzz.dat and Alex6,Alex7, Alex10.Alex10 containing "Messenger|<myusername>|<mypassword>", so yeah I'm a bit concerned. Yes I've thought of System Restore but I'd like to know an option.
|
|
| Back to top |
|
 |
OhAndyOh Expert Cheater
Reputation: 0
Joined: 16 Feb 2009 Posts: 236
|
Posted: Sun Nov 14, 2010 1:34 pm Post subject: |
|
|
| Full sweep, reformatt.
|
|
| Back to top |
|
 |
homer_simpson Grandmaster Cheater
Reputation: 0
Joined: 25 Feb 2007 Posts: 596
|
Posted: Sun Nov 14, 2010 2:54 pm Post subject: |
|
|
I've got rid of it manually. Since other people might have this problem, here's what I did:
This RAT is user customizable so a user chooses which path to store the main executable and a user can choose to make it hook into Google Chrome. First of all terminate chrome.exe's task. Then you can find the path of this executable by going on regedit/regedt32. Just browse to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run and you will find a key that contains the path. Delete this key (make sure to write down the path it contained). Now you will have to delete the executable. Go to Control Panel, chose View by: "Small icons" and click Folder Options. Now on the view tab tick "Show hidden files, folders and drives" and untick "Hide Protected operating system files". Now simply go to the path mentioned earlier and delete the executable. Done!
|
|
| Back to top |
|
 |
Falc0n Expert Cheater
Reputation: 1
Joined: 04 Apr 2009 Posts: 104
|
Posted: Tue Nov 16, 2010 3:49 pm Post subject: |
|
|
Persistancy will kill you.
Dissect the RAT and look for all the places it has initiated and set itself. Then remove it.
|
|
| Back to top |
|
 |
|