How to prevent RATs?

DarkFlare69

Well-Known Member
OP
Member
Joined
Dec 8, 2014
Messages
5,147
Trophies
2
Location
Chicago
XP
4,749
Country
United States
Reset the BIOS again by removing the CMOS battery. Go back into the BIOS before doing anything else, change the boot order so that USB devices boot first. Wipe your hard drive completely. Use fdisk or whatever relevant tool needed to reinitialize the drive. Don't attempt to boot into the drive until it has been wiped and reinitialized. Once that's done, reinstall Windows or Linux or whatever on it.
I did that and the bios still fails to load. I tried unplugging my SATA ports too and still blackscreen when going into bios.

--------------------- MERGED ---------------------------

I dont know if this matters but I have an MSI 970a-g46 and an FX 8320 CPU. It says it will need a bios update on pcpartpicker before using this cpu.
 

twocows

Well-Known Member
Newcomer
Joined
Feb 2, 2013
Messages
50
Trophies
0
Location
Michigan
XP
243
Country
United States
If it loaded once, it should load again unless something's seriously screwed up. Is the connection between your monitor and your device secure?
 

DarkFlare69

Well-Known Member
OP
Member
Joined
Dec 8, 2014
Messages
5,147
Trophies
2
Location
Chicago
XP
4,749
Country
United States
If it loaded once, it should load again unless something's seriously screwed up. Is the connection between your monitor and your device secure?
Thats what I thought, too, but it's not working. i unplugged my pc, removed battery for 60 seconds, put battery in, plugged it in, and booted up. nothing.

yes im using geforce gtx 960 hdmi to my tv.
 

twocows

Well-Known Member
Newcomer
Joined
Feb 2, 2013
Messages
50
Trophies
0
Location
Michigan
XP
243
Country
United States
At this point, I'd take it into a local computer shop. Don't go to Best Buy or a big name store, they'll rip you off. Look for local PC repair shops with decent online reviews.
 

Sono

cripple piss
Developer
Joined
Oct 16, 2015
Messages
2,820
Trophies
2
Location
home
XP
9,309
Country
Hungary
When I spam F12, it goes to a blackscreen forever.

when idont, it blackscreens for about 30 seconds and goes straight to the windows screen where i enter my password, completely skipping this screen: http://media.askvg.com/articles/images3/Windows_7_Boot_Screen.png

Is there a blinking cursor in the top-left corner? There should be.
(Currently I can't access my PC, so I'm writing this from top of my head)
Open "msconfig", goto the "boot order" tab, click on Windows 7, and I think it should be obvious what to enable/disable to enable the bootlogo.
Also, didn't that monster reflash/infect your BIOS by chance? It sounds like your BIOS got corrupted/infected.
 
Last edited by Sono,

Sono

cripple piss
Developer
Joined
Oct 16, 2015
Messages
2,820
Trophies
2
Location
home
XP
9,309
Country
Hungary
Okay, I analyzed the txt file.

What is "Akamai NetSession Interface"? It looks suspicious to me. It's at "%userprofile%\AppData\Local\Akamai\netsession_win.exe". Guessing from the service list, it came bundled with your Autodesk product installation.

"BrYNSvc" service. Do you have a "Brother industries" hardware in/plugged into your PC? Or have you used one? Like a printer or something?

"dot3svc"/"Wired AutoConfig". Unless you have a crazy home setup with Windows, this looks a bit suspicious to me.

Others aren't worth mentioning, since those are just normal Windows services. Okay, the one above IS a Windows service, but it can be suspicious.
 

DarkFlare69

Well-Known Member
OP
Member
Joined
Dec 8, 2014
Messages
5,147
Trophies
2
Location
Chicago
XP
4,749
Country
United States
I installed windows 10 just for the fuck of it, and then the bios worked fine. I reflashed my BIOS to ensure he didnt do anything to them, and then I formatted my entire HDD twice.There was a 2nd partition i didnt make, but that could just be windows doing that and not a virus.

im going to look around this thread again after i set up my stuff. i set my networks as public as the first step.
 
  • Like
Reactions: Sono

KashiToxicBlood

how2hakpls
Banned
Joined
Jan 30, 2015
Messages
385
Trophies
0
Age
23
Location
same place as Huntereb
Website
www.youtube.com
XP
209
Country
United States
This is the 4th time I've had a RAT. 3 different PCs.

Here's how it happened, someone sent me this info: http://prntscr.com/abe0v6

In my AppData, I had this: http://prntscr.com/abe05b

I can remove it. That's not a problem. The problem is how do I prevent future ones? My PC has been taking a long time to log on lately...

If someone can help I'll pay you $10.
install a linux distro, done
 
  • Like
Reactions: Deleted User

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: Hello @realtimesave.