Rat virus

peeeerrlesss

New Member
Thread author
Aug 22, 2026
5
0
2
Hi, I suspect my PC may be infected with a RAT. Could someone please help me check for malware/persistence and determine if anything suspicious is present?
Thanks!
 
Hello ..! Welcome to MalwareTips..! :) My name is icotonev and I'm here to help you remove malware ..! Please follow the instructions in the following link:

 
...or a quick guide..:

Download Farbar Recovery Scan Tool and save it to your desktop. --> IMPORTANT

If your antivirus software detects the tool as malicious, it’s safe to allow FRST to run. It is a false-positive detection.
If English is not your primary language, right click on FRST.exe/FRST64.exe and rename to FRSTEnglish.exe/FRST64English.exe

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click on the FRST icon and select Run as administrator
  • Click Yes to the disclaimer
  • Click Scan and allow the program to run
  • The scanner will produced two logs on your Desktop: FRST.txt and Addition.txt.
  • Please copy and paste the contents of each report in separate reply windows
Next..: Please upload FRST.txt and Addition.txt to:
Log Upload - Fenris ... and the site will return a keyword for each of the logs. Please upload the logs under your current username -peeeerrlesss
... Reply back here with the keywords returned from the site after uploading FRST.txt and Addition.txt.

In your next reply, please include:
  • FRST.txt
  • Addition.txt
  • Keywords
 
Hello ..! There are no signs of malware on your system ..! Once again, I confirm that there are no active infections..!



Please stop creating multiple accounts and asking the same question over and over again...!



Farbar Recovery Scan Tool Fix
  • Close any open programs or windows because your computer may automatically reboot after FRST64 is run
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you

Code:
Start::
CreateRestorePoint:
CloseProcesses:

HKU\S-1-5-21-169602806-1406718758-3025781101-1001\...\Run: [MicrosoftEdgeAutoLaunch_5EFC0ECB77A7585FE9DCDD0B2E946A2B] => "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --win-session-start [5018440 2026-08-20] (Microsoft Corporation -> Microsoft Corporation)
DeleteValue: HKU\S-1-5-21-169602806-1406718758-3025781101-1001\Software\Microsoft\Windows\CurrentVersion\Run|MicrosoftEdgeAutoLaunch_5EFC0ECB77A7585FE9DCDD0B2E946A2B
Task: {F3E6E7ED-A196-4E44-8803-55FAB3AD4E29} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker => %systemroot%\system32\MusNotification.exe (No File)
S3 ACE-CORE101308; \??\C:\Program Files\AntiCheatExpert\ACE-CORE101308.sys (No File)
S3 ACE-CORE201308; \??\C:\Program Files\AntiCheatExpert\ACE-CORE201308.sys (No File)
S3 ACE-CORE301308; \??\C:\Program Files\AntiCheatExpert\ACE-CORE301308.sys (No File)
AlternateDataStreams: C:\WINDOWS\tracing:? [16]
C:\Users\Admin\AppData\Local\Microsoft\Windows\INetCache\IE\
C:\Users\Admin\AppData\Local\Roblox\UniversalApp\WebView2\EBWebView\Default\Cache\Cache_Data\

CMD: netsh winsock reset catalog
CMD: netsh int ip reset resetlog.txt
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns

RemoveProxy:
EmptyTemp:
End::

  • Click Fix
  • Note: The Emptytemp: command will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
In your next reply, please include:
  • Fixlog.txt
 
After running the Fix script, I was logged out of Twitch, ChatGPT, and other websites in my browser. This did not happen before running the Fix.
Could this have been caused by the Fix script, for example by CloseProcesses: or EmptyTemp:? Is there anything I should check or do next?
 

Attachments

There is no evidence of malicious or suspicious software on the computer. It is clean.
Let's do some control scans:

ESET Online Scan - ESET Online Scan - Eset Online Scanner will take some time, so be prepared.

ESET Online Scanner
  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply

In your next reply, please include:
  • eset.txt