I think I have a rat, want windows 10 with clean install to kill it.

Status
Not open for further replies.

Nickexp

Reputable
Oct 22, 2014
50
0
4,530
A friend sent me a exe for something and it did work- but it also had a RAT coded into it he thinks since he was hacked a few months later. Basically- when windows 10 comes out, since the iso files won't be contaminated and the RAT won't be able to go over, since it was made before the windows 10 free stuff I want to install windows 10. And only windows 10. I want everything else GONE. Any idea of how to do that? Apparently the rat will transfer onto any USB device I plug in, and I don't want to factory reset to blank harddrives.

So- clean install, basically the same effect of wiping my harddrive clean. But with windows 10 ready to install. Thanks for any help, I don't want to have to change all of my passwords and shit. Or deal with getting my brother in law to get me the windows 10 iso files because I don't want to worry my parents or anyone about me getting a rat since I know what to do about it and an always do a clean install if all else fails.

And the RAT is crypted so anti virus won't do shit. Thanks for helping.
 
Solution
If you clean install prior to upgrading, you'll lose the ability to qualify for the free upgrade and future clean install capability. You will need to upgrade first, then download and clean install afterwards using the ISO.

IF YOU PLAN TO CLEAN INSTALL WINDOWS 10

YOU CANNOT CLEAN INSTALL INITIALLY OTHERWISE YOU PASS UP YOUR FREE UPGRADE

UPGRADE TO WINDOWS 10 VIA WINDOWS UPDATE OR BEGINNING THE WINDOWS 10 SETUP WITHIN THE WINDOWS 10 DESKTOP. THIS WILL REGISTER YOUR DEVICE AS A WINDOWS 10 DEVICE AND YOU MAY NOW CLEAN INSTALL WINDOWS 10 ON THE DEVICE.



From my extensive testing of the new Microsoft Product Testing introduced into Microsoft Windows 10 Build 10147 I can tell you the following:




•Direct clean installation from...
If you clean install prior to upgrading, you'll lose the ability to qualify for the free upgrade and future clean install capability. You will need to upgrade first, then download and clean install afterwards using the ISO.

IF YOU PLAN TO CLEAN INSTALL WINDOWS 10

YOU CANNOT CLEAN INSTALL INITIALLY OTHERWISE YOU PASS UP YOUR FREE UPGRADE

UPGRADE TO WINDOWS 10 VIA WINDOWS UPDATE OR BEGINNING THE WINDOWS 10 SETUP WITHIN THE WINDOWS 10 DESKTOP. THIS WILL REGISTER YOUR DEVICE AS A WINDOWS 10 DEVICE AND YOU MAY NOW CLEAN INSTALL WINDOWS 10 ON THE DEVICE.



From my extensive testing of the new Microsoft Product Testing introduced into Microsoft Windows 10 Build 10147 I can tell you the following:




•Direct clean installation from Windows 10 Installation Media, skipping product key twice or using the generic key leads to an unactivated product.
•Using the .iso to upgrade from the Windows Desktop will only allow activated versions of Windows to release the license agreement screen. This only allows Activated versions of Windows 7, Windows 8.1 or Windows 10 Insider 10130. After the install Windows 10 10147 is activated.
•Once the initial upgrade to Windows 10147 is complete the device is registered to Microsoft.
•Once a device is registered, you may clean install from the .iso by skipping product keys during Windows setup. Windows will activate automatically.
•The product activation is tied to the device. You can reinstall using a different Microsoft Account or Local Account and the device will activate.
•You may change minor hardware such as a SSD/HDD and clean install. I changed from a SSD to HDD for a quick test and Microsoft Product Activation was applied.
•It seems Windows Insiders with Build 10130 will be passed as eligible to reach Windows 10 RTM. Those who look to join the Windows 10 Insider program after the Windows 10130 .isos have been removed will not be able to install and activate Windows 10 Insider 10147 or later and hence will not be able to reach Windows 10 RTM.
 
Solution

Nickexp

Reputable
Oct 22, 2014
50
0
4,530
But then the virus will carry over. Any USB I plug in will get the RAT apparently. My friend who got it said don't risk it. My plan was to wipe all of my shit during the upgrade, killing the rat since it can't hide in iso for windows 10, as it won't recognise it. I'm not sure how to find the rats file. Or if it's in win32 or not. I don't even know how to check if I have it, all I know is if I do I'm and my friend is CERTAIN the file he sent me was what caused it on his system.
 

Astralv

Distinguished
First of all- why dont you deal with the virus by running Antivirus scans? There are free scanners for almost every antivirus in the market. Do you have Antivirus installed? Most likely you did not get infected. Do you experience any issues related to possible virus?

You upgrade to Windows 10 first, then you reinstall with ISO file clean. If you can not wait and want to do it now, you can reinstall your Windows 7/8 version clean, and then install Win 10 update. Make sure you install the drivers from the manufacturer of your PC or Motherboard.
 

Nickexp

Reputable
Oct 22, 2014
50
0
4,530


Do you know what a rat is? Remote Access Tool. Almost impossible to kill off and allows someone to control my PC. It's also crypted so antivirus is useless against it. This isn't one that the anti-virus companies make and distribute to get people to buy their software- this is a remote access tool, it will jump onto any USB I plug in (apparently) and will hide in my System 32 folder, and dig itself in deep enough to stay after a simple reset to factory default. RATs don't like leaving.
 

Nickexp

Reputable
Oct 22, 2014
50
0
4,530


Also- how do I upgrade to windows 10 now? You mean using the trail? Will that make me valid to upgrade later?
 
Just do a clean install with your recovery partition or installation disk, then upgrade later. If you don't have installation media, a product key or a recovery partition, then you're probably not using genuine software anyhow, in which case, I have no sympathy for you. If you are using genuine software, obtaining installation media for use with your current product key which you can extract from the system using Magic Jellybean keyfinder, should not be an issue and will allow you to wipe the system. It isn't rocket science and it also isn't as dire as you're trying to make it out to be. It's a simple process.

 

Astralv

Distinguished


I agree. Isn't the "Product ID" a key? The product ID is listed if you right click on "This PC" and go to Property.
 
No, it's not. The product key is hidden and must be either extracted using a utility, by way of a command line script, on the box the disk came in or on the prebuild PC desktop or laptop itself, stickered somewhere. The product id and product key are two different things.
 

Nickexp

Reputable
Oct 22, 2014
50
0
4,530


I didn't buy my copy. It is legit, but was given to me by my brother-in-law who works for Microsoft, so I have no CD. We installed using a USB after he downloaded the iso (yes- it was legit, he got it off of Microsoft site) and then entered his key (it has unlimited uses I believe because he works there, but they do monitor it). And I have no backups- I don't have a CD drive. My PC is expensive and so is my steam account, ect. So yes it's a big <mod edit> deal, they almost took my friends account with the same rat. I've been searching for signs of it because he's not sure if the file he gave me gave it to me or not. Either way- if anything happens I need to be able to clean install.
 

Nickexp

Reputable
Oct 22, 2014
50
0
4,530


xD I thought it would sound suspicious. But it's true. My friend gave me a software used for ratting (which I wanted to test on my laptop just for fun, not to actually hack, I could go to prison for hacking) and apparently he got a backdoor- so he thinks that caused it. But, I only ran the software once and never opened ports for it, unlike him. Plus nothing seems to be happening so I might be good. I still have the iso I think on the USB, and plan on if I need to do a windows 10 reset, getting the iso off of him. I wouldn't pirate an OS, that's how you get hacked.
 
Status
Not open for further replies.