Think I have a RAT

Discussion in 'Windows Support' started by LmfaoBen, Feb 28, 2011.

Thread Status:
Not open for further replies.
  1. LmfaoBen Minecraft Guru / Cat Daddy

    Message Count:
    1,851
    Likes Received:
    298




    So I recently received a very suspicious file from someone via AIM, I made sure not to run it but neglected to delete it before other people got their hands on the computer so it may have been run. After examining the file in HxD I saw a bit about the window style being transparent, it also came up as infected in both McAfee and MalwareBytes. Although I currently have no symptoms I need to make sure I have privacy and security. If needed I can provide a copy of the file as well.

    Virus Total Results


    Symptoms:
    So far only paranoia about my computer's security. lol

    MalwareBytes Log:
    Show Spoiler


    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5904

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    2/28/2011 9:54:21 AM
    mbam-log-2011-02-28 (09-54-21).txt

    Scan type: Quick scan
    Objects scanned: 1
    Time elapsed: 11 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\Users\**********\downloads\Zombe.exe (Backdoor.Fynloski) -> Quarantined and deleted successfully.




    What's been done already:
    CCleaner stuff done.
    McAfee "Quick Scan" though I couldn't completely finish it.
    MalwareBytes "Quick Scan" completed.
    Verified virus in Virus Total.

    What I need:
    To make sure I haven't been affected by it.
  2. Capito Banned

    Message Count:
    1,804
    Likes Received:
    139
    You should not be infected now, please post a HJT scan, or send it to me on aim: [email protected]
    1 people like this.
Thread Status:
Not open for further replies.