![]() |
| |||||||
| Security and Privacy Spyware , Proxies , all security and privacy issues and software. |
![]() |
| | LinkBack (1) | Thread Tools | Search this Thread | Display Modes |
| |
#1 (permalink)
|
| Super Moderator iTrader: (0) Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
![]() | Have spent several hours trying to remove this completely and still some issues remain. You get the "usual" white cross in a re circle in the task manager and the box saying install Antivirus 2009 etc. It hides its processes so nothing is seen in taskmanager, it is using rootkit techniques. System restore does not work. Stopping it cleans out the copies of the above files stored in the System Volume Information folder were the restore point files are kept. Many antivirus/malware apps won't run, including Malware Antimalwarebytes. HJTinstall doesn't run, Schmitfraud and vundofix only run when changing the file name. IE and Firefox won't open most antivirus sites (urls resolve to the localhost address when you try to ping these sites) and for other sites you often end up at unexpected sites. The cure: Well haven't completely fixed it. The files associated with it found to date and mentioned on the net are: C:\WINDOWS\brastk.exe C:\WINDOWS\karna.dat C:\WINDOWS\DRIVERS\beep.sys C:\WINDOWS\System32\karna.dat C:\WINDOWS\SYSTEM32\brastk.exe C:\WINDOWS\SYSTEM32\DLLCACHE\beep.sys C:\WINDOWS\SYSTEM32\DLLCACHE\figaro.sys C:\WINDOWS\SYSTEM32\DRIVERS\beep.sys Also found a copy of svchost.exe in C:\WINDOWS\SYSTEM32\DRIVERS that should not be there. Safemode deletions of the files mentioned above, removal of all mentions of the files in the registry eventually got rid of them. Running Schmitfraud using a different name may have helped. Avira antivirus does install OK and may have helped. http://z-oleg.com/avz4.zip from Kaspersky may have helped too. But eventually found when going back to the normal boot it stuck at the "windows is starting" point just before the username and password entry point. Booting to a XP disk and running Repair console and running chkdsk.exe /r fixed something and allowed a normal log in. Have got rid of the self replicating brastk.exe etc and no white cross saying I need to install antivirus 2009. BUT still IE and Firefox won't go to most antivirus sites still and many antivirus apps won't run or install. So it still isn't fixed. Through Process Explorer I can see where svchost.exe with DCOMLauncher is the probable cause of the IE and Firefox problems, but the files themselves are OK and stopping this process causes a restart and stopping the DCOM service prevents a normal boot. I am at my wits end now and a clean install may be the best answer. BTW beep.sys is a normal system file that has been contaminated and can be copied back from another PC later. It is used because it is also run when in safe mode making getting rid of this malware all the more difficult. Last edited by ssrattus : 13-11-08 at 12:39 PM. |
| | |
| | #2 (permalink) | |
| Senior Member iTrader: (4) Join Date: Jan 2008 Location: Gold Coast
Posts: 122
Spent time on board: 2 Weeks, 4 Days and 10:09:29
![]() | Quote:
did you try installing malware bytes again as that should fix the browser problems - otherwise try the portable thinstalled (sandboxed) version of malware bytes | |
| | |
| | #3 (permalink) |
| I'am Not a Bloody Joke iTrader: (10) Join Date: Jan 2008 Location: Australia
Posts: 2,948
Spent time on board: 2 Months, 2 Weeks, 3 Days and 10:41:00
![]() | ssrattus I got rid of one the other day i threw every program at it and then did a system restore then deleted all the system restore files and then threw everything at it again and registry cleaners LOL and it still clean after 2 weeks, but you are right it has taken me about 4 hours LOL
__________________ Please wipe your feet before walking all over me |
| | |
| Sponsored Links | |
| | |
| | #4 (permalink) |
| Super Moderator iTrader: (0) Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
![]() | Tried 4 versions of portable malwarebytes and they either don't run, if they run they don't update and don't find anything. Tried updating it on my good PC and then running it on the infected and it doesn't run. Tried rootkit unhooker, doesn't run on the infected PC nor does the sopos anti rootkit. |
| | |
| | #6 (permalink) |
| Senior Member iTrader: (14) Join Date: Jan 2008 Location: Mt Gambier
Posts: 791
Spent time on board: 3 Weeks, 2 Days and 4:44:04
![]() | did ya have Malwarebytes running live (systray) ???
__________________ Trust thyself only, and another shall not betray thee. |
| | |
| Sponsored Links | |
| | #7 (permalink) |
| Super Moderator iTrader: (0) Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
![]() | Don't think so. BTW, Posting with the newly installed Windows XP SP3 Vienna Concept right now, less than an hour from start of format (60GB) to up and running. Of course there are lots of other things to install yet. |
| | |
| | #8 (permalink) |
| Premium Member iTrader: (1) Join Date: Jan 2008 Location: QLD
Posts: 98
Spent time on board: 1 Week, 3 Days and 12:19:06
![]() | A couple a programs I find useful for manually checking and removing unwanted programs - Process Explorer and AutoRuns. Process Explorer Process Explorer AutoRuns for Windows AutoRuns for Windows |
| | |
| | #9 (permalink) |
| Premium Member iTrader: (6) Join Date: Apr 2008 Location: Victoria
Posts: 781
Spent time on board: 3 Weeks, 1 Day and 20:07:17
![]() | hijackthis is also good for checking for autoruns and processes.
__________________ There is ALWAYS a better way to do things. |
| | |
| Sponsored Links | |
| | |
| | #11 (permalink) |
| Super Moderator iTrader: (0) Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
![]() | HJT would not install, even when re-named. Parts of this malware is rootkit based meaning that the processes are hidden and the registry entries don't show in the registry. The files mentioned in the first post were not rootkit based. |
| | |
| | #15 (permalink) |
| Senior Member | When Im Doing Clients Computers I quite often remove there hard drive and scan it from my Office Service Computer which has the side panel off pretty much all the time for this purpose. Does wonders for getting rid of Crap out of Clients computers.... I usually scan externall with MalwareBytes, AVG and it usually takes the worst out of the hard drive I then reinstall and scan again with Spybot S&D as well as AVG & Malwarebites again... |
| | |
| Sponsored Links | |
| | |
| | #16 (permalink) |
| Super Moderator iTrader: (0) Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
![]() | Yep that would have been a probably been a viable solution mutanti. But with this particular PC a reformat and clean install wasn't to hard as the majority of the data is kept on the other partition. |
| | |
| | #17 (permalink) |
| Senior Member | I find MBAM problematic when scanning remotely. If I can install it on a problematic system, update it, then scan, it usually removes everything bad effectively. I have Avast + MBAM on our workshop machine to remotely scan hard drives and I've all but given up on MBAM for this purpose. |
| | |
![]() |
LinkBacks (?)
LinkBack to this Thread: http://www.austech.info/security-privacy/13375-antivirus-2009-even-harder-remove-now.html | ||||
| Posted By | For | Type | Date | |
| Austech - Powered by vBulletin | This thread | Refback | 13-11-08 05:36 PM | |
| Thread Tools | Search this Thread |
| Display Modes | |
| |