Rat.Rads.Gen infction

Discussion in 'Trojan Defence Suite' started by Jim C, Jul 14, 2004.

Thread Status:
Not open for further replies.
  1. Jim C

    Jim C Guest

    All,

    I've got this little bleeder on my system. Removing the file with either TDS, Taskmanager or Process Explorer (gawd bless sysinternals) simply causes a child process to be invoked before closing down the original trojan process.

    Does anyone have any good tips on how to get rid of this nasty nasty bit of malware?

    Thanks

    Jim
     
  2. Pilli

    Pilli Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    6,217
    Location:
    Hampshire UK
    Hi Jim, Try removing it in Safe Mode.
     
  3. Gavin - DiamondCS

    Gavin - DiamondCS Former DCS Moderator

    Joined:
    Feb 10, 2002
    Posts:
    2,080
    Location:
    Perth, Western Australia
    Send a copy to submit@diamondcs.com.au if the filescanner doesn't detect it, must be new. Then delete all detected files (possibly in Safe Mode) when we update tomorrow

    Manual removal right now, you may be able to manually find them all, probably random names 2 different filesizes probably one 220kb the other 430kb, all will be exactly the same size in bytes and one or more will be autostarted from the registry :)
     
  4. Jim C

    Jim C Guest

    Cheers Guys.

    I will try to capture one of them and send it across and also try to remove in safe mode - & thanks for the swift reply

    Jim
     
  5. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Submit all your finds, don't hold back by no means, Gavin is very grateful as ever, with the largest database on internet in TDS already and who knows how many more surprises to be added for us in near future :cool:
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.