Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 17th, 2004, 07:26 AM
tomteeth tomteeth is offline
Regular Poster
 
Join Date: May 2002
Location: filthydelphia
Posts: 153
Default NetSlayer(RAT)

Hello Everyone: I may not be at the right place here, but here goes. I have the NetSlayer(RAT) on my pc and I cannot get rid of it. Can anyone tell me how to find out what program is launching this and how to permanently get rid of it? I am Using windowsXP, with Spyware Blaster, Outpost firewall, and a pretty good antivirus (always updated) Now I do have FlashGet and I kow that has Cydoor (I got rid of that) and I do have VCatch (I know associated with some spyware which I deleted, and I dont think this NetSlayer is from them! any idea's on how to fined out what service is putting this on my pc? Thanks, Tom
  #2  
Old September 17th, 2004, 07:35 AM
Don Pelotas's Avatar
Don Pelotas Don Pelotas is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 2,257
Default Re: NetSlayer(RAT)

Hi Tom

A Link to manual removal. You might want to try Ad-Aware and Spybot, both free.

Regards
__________________
Errare humanum est

Last edited by Don Pelotas : September 17th, 2004 at 08:41 AM.
  #3  
Old September 17th, 2004, 09:32 AM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: NetSlayer(RAT)

As well as above, I would suggest following the instructions found in post number 2 here

Let us know how you go...

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #4  
Old September 17th, 2004, 01:20 PM
tomteeth tomteeth is offline
Regular Poster
 
Join Date: May 2002
Location: filthydelphia
Posts: 153
Default Re: NetSlayer(RAT)

Ok Guys, I ran spybot, hijack this, and my antivirus, and none of them are picking it up. The only thing picking this up is my Yahoo Companion AntiSpy toolbar. Every time I have the program remove it, it comes back again! I cannot even find it in the registry. What do you think?
  #5  
Old September 17th, 2004, 01:30 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,183
Default Re: NetSlayer(RAT)

You could try Ewido also.

http://www.ewido.net/en/?section=download
  #6  
Old September 17th, 2004, 01:35 PM
snapdragin's Avatar
snapdragin snapdragin is offline
Administrator
 
Join Date: Feb 2002
Location: Southern Ont., Canada
Posts: 8,415
Default Re: NetSlayer(RAT)

Hi tomteeth,

You can also try TDS-3, which has a 30-day free trial.

Before you open and run the program you must bring it up-todate. Download the latest radius database file from here: Radius td3 update. Right-click on the link shown on the updates page, and choose "Save target as" and save it to your TDS install directory (say "yes" to overwriting the one that is there). Reboot your computer after installing.

Then open TDS and press the "Scan Control" and tick all the boxes in the bottom part of the window. Press "Save configuration" and then close the window by pressing the red x in the top right corner. Now select "System Testing" and choose the 'Full system Scan" and scan your local drives.

Once the scan is finished, TDS3 will display what it finds in the lower screen. It will show "Positive Identification" or "Suspicious File". Right-click on anything found as "Positive Identification" and choose Delete. For the "Suspicious" files, right-click on those and choose "Save to Text". Since most suspicious files are harmless, we would want to see the scandump.txt for them before deciding what to do with them. Go to the TDS-3 folder (usually C:\Program Files\TDS3) and find the scandump.txt file. Open it and copy & paste the contents here in your next reply.

Please disable your antivirus before running TDS3 so it will not interfere with the scan.

Regards,

snap
__________________
@-`-,--
  #7  
Old September 17th, 2004, 01:37 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,601
Default Re: NetSlayer(RAT)

I will agree with snapdragin, A friend of mine had several (rat) pieces of malware on his comp and the trial version of TDS3 removed them all.

bigc
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #8  
Old September 17th, 2004, 03:18 PM
tomteeth tomteeth is offline
Regular Poster
 
Join Date: May 2002
Location: filthydelphia
Posts: 153
Default Re: NetSlayer(RAT)

Ok, I tried Ewido, and it did not find it. So maybe I will try Snapdragin's way, but it looks complicated?
  #9  
Old September 17th, 2004, 04:16 PM
tomteeth tomteeth is offline
Regular Poster
 
Join Date: May 2002
Location: filthydelphia
Posts: 153
Default Re: NetSlayer(RAT)

I was wrong, Ewido did find One spyware, I accidentally removed it by mistake before reading the whole app. it must have been the NetSlayer that it removed, because I just ran the Yahoo companion AntiSpy and it was gone. I will see if it comes back again by tomorrow when I turn on the pc again, thats the first thing I will check. If you dont hear from me, then Ewido, did it. Thank you all for your help, Tom
  #10  
Old September 17th, 2004, 04:39 PM
snapdragin's Avatar
snapdragin snapdragin is offline
Administrator
 
Join Date: Feb 2002
Location: Southern Ont., Canada
Posts: 8,415
Default Re: NetSlayer(RAT)

Hi tomteeth,

It may well be that Ewido caught it and removed it. I've not used Ewido myself as I use both TDS-3 and TrojanHunter (which also has a 30-day free trial.)

TDS-3 really is not complicated to use, I just like to put more information there on the first few steps so the person will be sure and use the most recent database.

Hope Ewido did catch the trojan for you. Please let us know what the results are when you turn your computer back on again.

Regards,

snap
__________________
@-`-,--
  #11  
Old January 4th, 2005, 10:45 PM
??rnbw?or?*****?
 
Posts: n/a
Thumbs up Re: NetSlayer(RAT)

Everyone Everyone calm down! their are many programs that can remove these.
but it's simple if you have a bad virus or some thing. first of all you guys are talking about this rat which is a (remote administation tool), you can get expesive programs to get rid of these things,but i say do it free, you guys are just finding nibbled off wood and putting out the posion for a rat that can just be shot in the head with a shot gun, re load your whole system,> regular guy:But I have all my pictures saved and word docs ill lose all of those.me>save them to a cd by burning them.regular guy>But i dont have a cd burner.me>Buy one if you really wunt to be perfectly virus, rat free,,, connect it to a USB port(the cd/rw drive) that you buy and get blank disk.regular guy>but im too lazy to go out and get a seperate drive and buy blank cd's.me>then live with the annoying virus or RAT your whole damn life;which will suck.regular guy>fine.
***********************************************************
once you do that and burn all your infromation>>>>>>>you must have or look for>>>>>>>>System recovery disk of some sort<any disk that came with iit> that came with your computer>>>>>now is the tricky [part]>
*turn of your computer>> turn it back on and hurry put in the disk(system recovery disk)
*follow the instructions on the screen.
dont worry if it comes to a dision that might delete stuff on your comp you got all your info on disk.

make wise choses>>>>>>>>>>READ CAREFULLY<<<<<<<<<<<<<<<<<<<<

%^&*if nothing happens when you put in the disk and you computer just normaly turns on>>>than turn it off again and on put in the disk quick and continuously press >ctrl+alt+delete until a screen comes up.
<follow instrucions on screen>

remember your doing all these instructions right when the comp turns on and is loading.

if you get it all done or when you get it done. you have a brand new computer like it came strait from the factory just like you bought it brand new virus trojon rat free><,,once you get here all your info that you burned on disk load on your comp and it's good as new.

there somthing i forgot to say hmmmmmm.
email if problems come up.

help or probelms email at: ~snip~ @yahoo.com - email removed to prevent it being harveted - snap

Last edited by snapdragin : January 4th, 2005 at 10:53 PM. Reason: removed email for security reasons.
  #12  
Old January 5th, 2005, 06:51 PM
S!x's Avatar
S!x S!x is offline
Regular Poster
 
Join Date: Jan 2005
Location: Ohio, USA
Posts: 51
Default Re: NetSlayer(RAT)

you guys are just finding nibbled off wood and putting out the posion for a rat that can just be shot in the head with a shot gun

A prime example of why guests shouldn't be allowed to post. (WOW)

Reformatting a PC everytime you get a trojan is like cutting off your head to cure a headache ... And any system restore disk only has drivers for the original hardware that came with that PC ... and takes away all Windows Updates and you lose all your files.

Using that mentality why run a firewall or AV at all? ... A virus that may destroy your computer is no worse than what your doing by constantly reformatting ... not too mention decreasing the life of your hard drive.

Last edited by S!x : January 5th, 2005 at 08:35 PM.
  #13  
Old January 5th, 2005, 07:32 PM
tomteeth tomteeth is offline
Regular Poster
 
Join Date: May 2002
Location: filthydelphia
Posts: 153
Default Re: NetSlayer(RAT)

S!x: Your right, I did not have the heart to say it!
  #14  
Old January 23rd, 2005, 11:09 AM
Steve Castle
 
Posts: n/a
Default Re: NetSlayer(RAT)

Midrosoft

http://www.microsoft.com/

download

http://www.microsoft.com/downloads/s...displaylang=en

Window Anti Spyware (Beta) free and free updates for 6 months.

http://www.microsoft.com/downloads/d...displaylang=en

Worked for me. ~snipped email to prevent it's being harvested - snap~

Last edited by snapdragin : January 24th, 2005 at 10:30 PM. Reason: removed personal email for security reason
  #15  
Old January 23rd, 2005, 11:15 AM
Steve Castle
 
Posts: n/a
Default Re: NetSlayer(RAT)

Explains the details of manual removal.

http://www.pestpatrol.com/PestInfo/n/netslayer.asp
  #16  
Old March 9th, 2005, 07:41 PM
Bullroarer
 
Posts: n/a
Question Re: NetSlayer(RAT)

None of this works, Microsoft antispyware picks it up everytime no matter what you do.

Somewhere there is a trigger reinstalling it.
  #17  
Old March 9th, 2005, 07:50 PM
tomteeth tomteeth is offline
Regular Poster
 
Join Date: May 2002
Location: filthydelphia
Posts: 153
Default Re: NetSlayer(RAT)

Bullroarer, I agree with you, there is a trigger somewhere, but who knows where?
  #18  
Old March 11th, 2005, 07:21 AM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,268
Default Re: NetSlayer(RAT)

well gollie!!!!!!!!!

some of us don't have any important pictures or files on our computers. All we do in our free time is try help the world by comming to forums like this LOL
SO reformating was no problem till Feb 28th. Then is became just a tiny bit more
cumbersome.

Like the guy said, save your stuff to CD or another drive.
and um so what if you don't have all the updates when you reformat.
If you are like me you ordered the FREE SP2 CD.
The only other thing you need to make sure of is that you DO have all the drivers you need saved on a CD or floppy hehe is you have one.

I aggree that we shouldn't have to depend on a million different apps
trying to defend us against all the nasties these days but the fact is we do & program makers the fact.

I used to preach using imaging software such as drive image or ghost and that is fine too. Using a program such as deep freeze is another way.

Don't get me wrong, I am a software junkie just like the rest of you are.
We get bored easly. That is why i reformat mostly. AHHHH BETA'S

Anyway I just didn't like the fact someone would compare another to a moran for posting and preaching FORMAT !!!

I know for a fact that some od the people that have posted here and are even mods, never learned how to reformat their computers. It is almost like being affraid of the dark LOL
And so in closing, I commend anyone that knows how.

Bruce
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:35 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums