Need some help with RAT virus.

Draeren

Beta member
Messages
1
Location
borl
Hey there, I figured some of you guys might be able to help me, or at least point me in the right direction about my issue.

Some time a few weeks ago(?) I must have picked up a RAT, the person behind it I've managed to figure out somewhat. He's Brazilian, uses my computer for personal use, not to sell, plays with my Minecraft account among other things, and likes shaking my mouse and typing things whilst I'm playing games. Now that's not much to go off, as I don't have his IP or any real useful information on him yet.

I ran MalwareBytes and it picked up about 9 trojan clickers, although that seems to have failed, even after it dealt with the ones found, he's still alive and kicking. I've checked netstat -a and -ano, not being able to locate him from there.

I will happily supply any information you may need to solve this problem of mine, just let me know what info is relevant and I can take screenshots and/or post it here. I hope you can help me, thanks!
 
Well I would suggest using peerblock to start and see who is connecting to you at the moment. It will give you source and destination IPs run it for a day and post the log. Be sure to include the times at which they mess with you.
 
im curious about what gave you all of these conclusions 2 start with. e.g Brazilian, rat.
 
If he is actively accessing your pc while you are on it could he not turn off peerblock or even delete it before he can be traced? I don't know anything about this kind of stuff so disregard if I said anything stupid.

How do you know he is Brazilian? Does he leave terrifying Portuguese threats or something? If it's like a guy who lives next door and he is a brazilian computer geek then just kick his butt. Not really.
 
Last edited:
I figured that but I was not sure. I sometimes imagine getting remotely hijacked and the hijacker defeating my attempts to block them because they are already inside. Would this be possible?
 
he is asking can the person stop peerblock from blocking him since he is already in the guys comp and has control, I say yes, reason being if he is a hacker, it isn't hard to change your IP address he could just keep changing it and jump on while the guys not there.
 
Last edited:
I would say a quick solution would be to format your disc. I'm surprised he hasn't done more damage...
 
Back
Top Bottom