Computing.Net > Forums > Security and Virus > Home Edition

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Home Edition

Reply to Message Icon

Name: WaRpEd
Date: May 24, 2008 at 10:47:11 Pacific
OS: Windows XP
CPU/Ram: ?
Product: Home Edition
Comment:

I am infected with a R.A.T. (Poison Ivy version 2.3.2)I have tried many online scanners, etc. I have tried deleting the registry key, however when you reboot, the registry key is re-created. I then tried changing the value of the stubpath to Disabled so it was not a correct file path, however when I rebooted, it created another stubpath. I can not get rid of this, and have been infected for about two weeks, could someone please help me? Does anyone have any other ideas of removing this RAT other than a re-format because I have lost my windows cd. Please post any answers or ideas you may have to help me fix this, thank you.



Sponsored Link
Ads by Google

Response Number 1
Name: Jennifer SUMN
Date: May 24, 2008 at 10:54:51 Pacific
Reply:

What Reg Key did you delete? Did you try a System Restore to a date prior to the software being installed?

Life's more painless for the brainless.


0

Response Number 2
Name: WaRpEd
Date: May 24, 2008 at 11:07:47 Pacific
Reply:

I know what registry key the RAT is using and I deleted it, but it just comes back, I have tried a system restore but everytime i try it says failed to restore to earlier date.


0

Response Number 3
Name: XpUser
Date: May 24, 2008 at 11:44:48 Pacific
Reply:

R.A.T. (Remote Administration Tool) by Poisonivy-rat.com appears to be a legitimate remote assistance tool. If it is, explain how you determined your machine is "infected" by R.A.T.

BTW Have you look at the website for info about deleting whatever registry entry you think is the culprit?

i_Xp/VistaUser


0

Response Number 4
Name: Jennifer SUMN
Date: May 24, 2008 at 13:50:41 Pacific
Reply:

I guess I should have said that. XPUser is right. This is a legitimate program. Why do you think it's "infected" your system? And, as XPU suggested, did you look at the ratforget.net site?

And, I repeat; which Reg Key/entry did you delete? Did you uninstall the software? Why did you install it in the first place? Or did someone else install it for RA?

The stubpath was probably created because the key still exists, or the software hasn't been unistalled.

Life's more painless for the brainless.


0

Response Number 5
Name: worldlibrary
Date: May 24, 2008 at 14:05:10 Pacific
Reply:

I have tried a system restore but everytime i try it says failed to restore to earlier date.

Did you try it in safe mode?


0

Related Posts

See More



Response Number 6
Name: Jennifer SUMN
Date: May 24, 2008 at 14:21:14 Pacific
Reply:

Text deleted..

Life's more painless for the brainless.


0

Response Number 7
Name: XpUser
Date: May 24, 2008 at 14:50:00 Pacific
Reply:

worldlibrary,

Forgive my intrusion but what does your comment have to do with this thread?

i_Xp/VistaUser


0

Response Number 8
Name: WaRpEd
Date: May 24, 2008 at 16:58:05 Pacific
Reply:

I haven't tried it in safe mode yet, i will try, and someone else sent me the "trojan". and yes i have looked at many sites such as ratforge.net, poisonivy-rat.com and many many others there are no ways of removing it manually that I can find. And as you can see, this can be used as a very malicious R.A.T. retrieving, all cached passwords, online banking info, paypal/ebay acounts, online game acounts as well as full control over the victims PC processes, installed aplications, etc. And there is nothing to un-install, you don't install anything. Just run a .exe file


0

Response Number 9
Name: btk1w1
Date: May 24, 2008 at 18:34:54 Pacific
Reply:

Have you navigated to c:/program files to have a look there for a R.A.T folder?... There might be an uninstaller in its folder.

If it is a legitimate program with no uninstaller, a third party utility such as Revo Uninstaller might be the ticket.

You could also run Hijackthis create a log, study the entries and have Hijackthis remove anything R.A.T related.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Home Edition

Windows XP Home Edition www.computing.net/answers/security/windows-xp-home-edition/26238.html

Fighting with Antivirus 2010 www.computing.net/answers/security/fighting-with-antivirus-2010/27428.html

SCANNOW command for XP Home? www.computing.net/answers/security/scannow-command-for-xp-home/18199.html