Remove Rattler. Description and removal instructions

 
Title: Rattler

Type: Remote Administration Tools
Severity scale:Rattler severity is 55  (55 / 100)
 
This tool is a plugin for Back orifice 2000 Remote Administration Tool. Its prime function is notifying the intruder each time when someone gets infected. It notifies the hacker via the e-mail. The author of this pest is a hacker called AdTropis. He created this tool using Visual C++ 6.0 (SP3) programming language. Many versions appeared in the internet from August 1999 to October 2003.

From the publisher:

"Rattler is a Back Orifice 2000 plugin that sends e-mail messages to a specified user when the IP address of the Back Orifice host machine changes. This can be extremely useful for users who have Back Orifice servers running on dial-up machines and/or machines configured for DHCP.

How It Works

Basically the operation of Rattler is very simple. It simply obtains a block of IP addresses that correspond to the machine on which it is running. If there have been any additions to this IP table Rattler sends an e-mail message containing the current IP table to a pre-defined recipient.

v1.10: Released 10/03/99 > Changed debugging messages a bit, added more debugging messages > WinSock is now initialized when the plugin is loaded > Fixed bug in GetIpList() > Fixed possible bug when calling gethostname() in SendMailMessage() > Added "Use Registry" option > Added multiple recipient capability > Added formatted subject line > Switched TCP/IP socket operations to non-blocking > Changed name of DLL to srv_rattler.dll for consistency

1.01: Released 08/29/99 > Fixed bug in WinSock init code > Fixed bug in getting mail host name > Fixed bug in getting TCP protocol information > Fixed bug in debugging options change

1.0: Released 08/23/99 > Initial release"


Rattler properties:
• Allows remote user connection
• Hides from the user
• Stays resident in background

Automatic Rattler removal:

remover for Rattler

Rattler manual removal:

Kill processes:
rmratreg.exe
Unregister DLLs:
44dad3cc.dll, rattler.dll, srv_rattler.dll, srv_rattler_3-03.dll, srv_ricq.dll, srv_ricq_3-02.dll

Delete files:
44dad3cc.dll, changelog.txt, rattler.cpp, rattler.def, rattler.dll, rattler.dsp, rattler.dsw, rattler.h, rattler.txt, readme.txt, resource.h, ricq.cpp, ricq.dsp, ricq.dsw, ricq.h, ricq.txt, rmratreg.c, rmratreg.exe, script1.rc, srv_rattler.dll, srv_rattler.dsp, srv_rattler_3-03.dll, srv_ricq.dll, srv_ricq.dsp, srv_ricq_3-02.dll

Other programs to remove Rattler:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 25/04/05
Information updated: 25/04/05

Additional resources related to Rattler:

Attention: If you know or you have a website or page about Rattler removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Rattler parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: