RE: [Tutorial] How to remove a RAT for beginners. 04-11-2013, 02:52 AM
#11
(04-11-2013, 02:48 AM)Odissea Wrote:And I'm sure since you also RAT that it's easy to remove the msconfig file or change the files permissions. Which is another flaw in your tutorial. Nonetheless, removing it from that start up won't do anything against persistence as you have to kill the process first, then remove the base file, then remove the keys from the registry/start up folder. And you should also know most people also disable the task manager or make it so the process is closed every time it's executed.(04-11-2013, 02:29 AM)Soup Wrote:Yes and most of the time is hides itself in explorer.exe ._. I also rat.(04-11-2013, 02:22 AM)Odissea Wrote:(04-11-2013, 01:59 AM)Soup Wrote: I suggest to clear your temp file after you clean up the virus issue. And also, a lot of viruses don't use those icons. Most of them melt on execution and hide themselves in various locations with persistence on. This will only remove some obvious infections.You have to run the virus for it to embed itself in the first place. Unless it's a java drive by so get it right
Also it's easy to disable persistence by removing all permission from the stub. If it is a crypted stub it WILL be visible in you task manager. You can also go into your register to look for a start up key from the stub. I know what i'm talking about.
Well of course you have to run it unless it's a JDB. How else would it infect your system .__.;?
I don't think you understand some features that crypters have nowdays. I know what I'm talking about. I RAT. I have my own installs and my own infections. Honestly, I doubt you know what you're talking about.
You do realize that your registry will most likely be disabled, right? The crypted stub will be visible in the task manager, yeah. But you do know it hides itself and clones a process right?


![[Image: rYBC5OE.gif]](http://i.imgur.com/rYBC5OE.gif)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)



