Send to a Friend

RZ71's avatar

Suggestions on removing a RAT or KL?

Asked by RZ71 (61points) August 15th, 2016

For those who may be unfamiliar with the acronyms, I am referring to a remote administrative tool and a key logger.
The RAT giving the person on the other end full control of the victim’s computer and the key logger only recording keystrokes and taking screenshots of information that is displayed on your screen at certain intervals.

I used a neat little RAT/KL scanner and apparently it has found a process called “SkypeHost” (not signed) under

C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe

Now, let’s be realistic, this appears to be pretty darn suspicious even if it does seem to be a legit Microsoft application (which I know it is not). I mean, you HAVE to make it look legit and like it belongs if you’re going to try and “hack” or keylog or RAT someone. I am convinced this is an obvious RAT or KL. Now, the problem is trying to remove it.
The apparent “RAT”(er) has denied me access to remove the file(s) in the folder or the folder itself. Now we definitely have a problem. Is there any alternative that doesn’t require resetting the entire laptop to factory settings or wiping the drives, or the laptop. I’m not sure, maybe those ARE the only alternatives, but I hope there are other options. Thank you all for responding.

Using Fluther

or

Using Email

Separate multiple emails with commas.
We’ll only use these emails for this message.