Suspected RAT infection

dota1111

New Member
Thread author
Aug 11, 2026
2
0
1
Hello,

I am requesting help determining whether my Windows PC is infected with a RAT or other malware.

For approximately two months, I have been concerned that my computer may have a RAT. I have been checking the computer very frequently, sometimes almost every day, but so far I have not received any confirmed malware detection.

What I have already done:

  • Ran multiple antivirus and malware scans.
  • Had the system checked by two people with malware/security experience.
  • Used several different security tools.
  • Used multiple AI-based analyses as additional opinions.
  • Reinstalled Windows twice.
  • Flashed/updated the motherboard BIOS.
  • Despite all of this, nothing has confirmed the presence of a RAT.
I understand that a clean scan does not automatically prove that a system is clean, which is why I would like an experienced Malware Response Team member to examine the system properly.

My main question is:

Can you please determine from the diagnostic logs whether there is any evidence of a RAT, persistence mechanism, suspicious process, scheduled task, service, startup entry, or other malware on this system?

I do not want to keep reinstalling Windows or running random scanners without knowing whether there is actually an infection.

I am willing to follow your instructions and provide whatever diagnostic logs you require.

Thank you for your time and assistance.
 

Attachments

Hello,

I am requesting help determining whether my Windows PC is infected with a RAT or other malware.

For approximately two months, I have been concerned that my computer may have a RAT. I have been checking the computer very frequently, sometimes almost every day, but so far I have not received any confirmed malware detection.

What I have already done:

  • Ran multiple antivirus and malware scans.
  • Had the system checked by two people with malware/security experience.
  • Used several different security tools.
  • Used multiple AI-based analyses as additional opinions.
  • Reinstalled Windows twice.
  • Flashed/updated the motherboard BIOS.
  • Despite all of this, nothing has confirmed the presence of a RAT.
I understand that a clean scan does not automatically prove that a system is clean, which is why I would like an experienced Malware Response Team member to examine the system properly.

My main question is:

Can you please determine from the diagnostic logs whether there is any evidence of a RAT, persistence mechanism, suspicious process, scheduled task, service, startup entry, or other malware on this system?

I do not want to keep reinstalling Windows or running random scanners without knowing whether there is actually an infection.

I am willing to follow your instructions and provide whatever diagnostic logs you require.

Thank you for your time and assistance.
Current assessment

Based on the information provided, there is no confirmed evidence of a RAT or other malware. Two Windows reinstallations and a BIOS update also make a persistent software-based infection less likely, although no remote assessment can prove that a system is clean without examining the relevant logs.

I cannot determine whether suspicious persistence, processes, services, scheduled tasks, or startup entries exist because no diagnostic logs were included.

Recommended next step

Post the case in the Malware Removal Assistance section and follow the instructions provided there by an authorized malware-removal helper. They will normally request diagnostic reports such as:

  • Farbar Recovery Scan Tool (FRST) Scan Result
  • FRST Addition.txt
  • Other logs only if they are specifically requested

Download FRST only from a reputable, official source or from the MalwareTips instructions. Run it as instructed, but do not use the Fix option unless a qualified helper has prepared a fixlist for your system. An incorrect fix can remove legitimate entries or damage Windows.

Important precautions

  • Do not continue reinstalling Windows or running many unrelated scanners unless new evidence justifies it.
  • Do not manually delete registry entries, scheduled tasks, services, or files based only on their names.
  • Review the logs for personal information before posting them publicly. Redact usernames, email addresses, license keys, IP addresses, and other sensitive data where appropriate.
  • If you suspect account compromise, change important passwords from a separate trusted device and enable multifactor authentication.
  • Keep Windows, browsers, drivers, and security software fully updated.

A clean scan cannot prove absolute absence of malware, but repeated clean scans, clean diagnostic logs, and two fresh Windows installations provide substantially stronger evidence than repeated scans alone. A formal log review is the appropriate next step, rather than continuing random checks.