Austech



iTrader Today's Posts Donate My Posts Classifieds Site Rules FAQ's
Go Back   Austech > Technology > Security and Privacy
Register Members List Upgrade Account Search Today's Posts Mark Forums Read

Security and Privacy Spyware , Proxies , all security and privacy issues and software.

Reply
 
LinkBack (1) Thread Tools Search this Thread Display Modes
Old 13-11-08, 10:48 AM   1 links from elsewhere to this Post. Click to view. #1 (permalink)
Super Moderator
 
ssrattus's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
ssrattus will become famous soon enough
Default Antivirus 2009 even harder to remove now.

Have spent several hours trying to remove this completely and still some issues remain.

You get the "usual" white cross in a re circle in the task manager and the box saying install Antivirus 2009 etc.

It hides its processes so nothing is seen in taskmanager, it is using rootkit techniques.

System restore does not work. Stopping it cleans out the copies of the above files stored in the System Volume Information folder were the restore point files are kept.

Many antivirus/malware apps won't run, including Malware Antimalwarebytes.

HJTinstall doesn't run, Schmitfraud and vundofix only run when changing the file name.

IE and Firefox won't open most antivirus sites (urls resolve to the localhost address when you try to ping these sites) and for other sites you often end up at unexpected sites.

The cure:

Well haven't completely fixed it.

The files associated with it found to date and mentioned on the net are:

C:\WINDOWS\brastk.exe
C:\WINDOWS\karna.dat
C:\WINDOWS\DRIVERS\beep.sys
C:\WINDOWS\System32\karna.dat
C:\WINDOWS\SYSTEM32\brastk.exe
C:\WINDOWS\SYSTEM32\DLLCACHE\beep.sys
C:\WINDOWS\SYSTEM32\DLLCACHE\figaro.sys
C:\WINDOWS\SYSTEM32\DRIVERS\beep.sys

Also found a copy of svchost.exe in C:\WINDOWS\SYSTEM32\DRIVERS that should not be there.

Safemode deletions of the files mentioned above, removal of all mentions of the files in the registry eventually got rid of them. Running Schmitfraud using a different name may have helped. Avira antivirus does install OK and may have helped.

http://z-oleg.com/avz4.zip from Kaspersky may have helped too.

But eventually found when going back to the normal boot it stuck at the "windows is starting" point just before the username and password entry point. Booting to a XP disk and running Repair console and running chkdsk.exe /r fixed something and allowed a normal log in.

Have got rid of the self replicating brastk.exe etc and no white cross saying I need to install antivirus 2009.

BUT still IE and Firefox won't go to most antivirus sites still and many antivirus apps won't run or install. So it still isn't fixed.

Through Process Explorer I can see where svchost.exe with DCOMLauncher is the probable cause of the IE and Firefox problems, but the files themselves are OK and stopping this process causes a restart and stopping the DCOM service prevents a normal boot.

I am at my wits end now and a clean install may be the best answer.

BTW beep.sys is a normal system file that has been contaminated and can be copied back from another PC later. It is used because it is also run when in safe mode making getting rid of this malware all the more difficult.

Last edited by ssrattus : 13-11-08 at 12:39 PM.
ssrattus is online now   Reply With Quote
Old 13-11-08, 12:15 PM   #2 (permalink)
Senior Member
 

iTrader: (4)
Join Date: Jan 2008
Location: Gold Coast
Posts: 122
Spent time on board: 2 Weeks, 4 Days and 10:09:29
Mysterex is on a distinguished road
Default

Quote:
Originally Posted by ssrattus View Post

Have got rid of the self replicating brastk.exe etc and no white cross saying I need to install antivirus 2009.

BUT still IE and Firefox won't go to most antivirus sites still and many antivirus apps won't run or install. So it still isn't fixed.

Through Process Explorer I can see where svchost.exe with DCOMLauncher is the probable cause of the IE and Firefox problems, but the files themselves are OK and stopping this process causes a restart and stopping the DCOM service prevents a normal boot.

I am at my wits end now and a clean install may be the best answer..


did you try installing malware bytes again as that should fix the browser problems - otherwise try the portable thinstalled (sandboxed) version of malware bytes
Mysterex is offline   Reply With Quote
Old 13-11-08, 01:35 PM   #3 (permalink)
I'am Not a Bloody Joke
 
best4less's Avatar
 

iTrader: (10)
Join Date: Jan 2008
Location: Australia
Posts: 2,948
Spent time on board: 2 Months, 2 Weeks, 3 Days and 10:41:00
best4less is on a distinguished road
Default

ssrattus I got rid of one the other day i threw every program at it and then did a system restore then deleted all the system restore files and then threw everything at it again and registry cleaners LOL
and it still clean after 2 weeks, but you are right it has taken me about 4 hours LOL
__________________
Please wipe your feet before walking all over me
best4less is online now   Reply With Quote
Sponsored Links
Old 13-11-08, 02:42 PM   #4 (permalink)
Super Moderator
 
ssrattus's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
ssrattus will become famous soon enough
Default

Tried 4 versions of portable malwarebytes and they either don't run, if they run they don't update and don't find anything. Tried updating it on my good PC and then running it on the infected and it doesn't run.

Tried rootkit unhooker, doesn't run on the infected PC nor does the sopos anti rootkit.
ssrattus is online now   Reply With Quote
Old 13-11-08, 02:50 PM   #5 (permalink)
Super Moderator
 
ssrattus's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
ssrattus will become famous soon enough
Default

Given up, first time a virus/trojan has beaten me. Formatting as I write.
ssrattus is online now   Reply With Quote
Old 13-11-08, 03:12 PM   #6 (permalink)
Senior Member
 
Woodstock's Avatar
 

iTrader: (14)
Join Date: Jan 2008
Location: Mt Gambier
Posts: 791
Spent time on board: 3 Weeks, 2 Days and 4:44:04
Woodstock is on a distinguished road
Default

did ya have Malwarebytes running live (systray) ???
__________________
Trust thyself only, and another shall not betray thee.
Woodstock is online now   Reply With Quote
Sponsored Links
Old 13-11-08, 03:37 PM   #7 (permalink)
Super Moderator
 
ssrattus's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
ssrattus will become famous soon enough
Default

Quote:
Originally Posted by Woodstock View Post
did ya have Malwarebytes running live (systray) ???

Don't think so.

BTW, Posting with the newly installed Windows XP SP3 Vienna Concept right now, less than an hour from start of format (60GB) to up and running. Of course there are lots of other things to install yet.
ssrattus is online now   Reply With Quote
Old 13-11-08, 03:41 PM   #8 (permalink)
Premium Member
 

iTrader: (1)
Join Date: Jan 2008
Location: QLD
Posts: 98
Spent time on board: 1 Week, 3 Days and 12:19:06
SPLog is on a distinguished road
Default

A couple a programs I find useful for manually checking and removing unwanted programs - Process Explorer and AutoRuns.

Process Explorer
Process Explorer

AutoRuns for Windows
AutoRuns for Windows
SPLog is offline   Reply With Quote
Old 13-11-08, 03:56 PM   #9 (permalink)
Premium Member
 
rob916's Avatar
 

iTrader: (6)
Join Date: Apr 2008
Location: Victoria
Posts: 781
Spent time on board: 3 Weeks, 1 Day and 20:07:17
rob916 is on a distinguished road
Default

hijackthis is also good for checking for autoruns and processes.
__________________
There is ALWAYS a better way to do things.
rob916 is online now   Reply With Quote
Sponsored Links
Old 13-11-08, 04:08 PM   #10 (permalink)
Senior Member
 
Jaz808's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Location: Hell
Posts: 295
Spent time on board: 4 Days and 23:50:37
Jaz808 is on a distinguished road
Default

I used these tools

Malwarebytes
HiJackThis
SmitFraudFix
Dail-a-Fix
ATF Cleaner
FixPolicies

any finally got rid of it, also VirusLabs Response 2009 is the same
Jaz808 is online now   Reply With Quote
Old 13-11-08, 04:12 PM   #11 (permalink)
Super Moderator
 
ssrattus's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
ssrattus will become famous soon enough
Default

HJT would not install, even when re-named.

Parts of this malware is rootkit based meaning that the processes are hidden and the registry entries don't show in the registry. The files mentioned in the first post were not rootkit based.
ssrattus is online now   Reply With Quote
Old 15-11-08, 03:30 PM   #12 (permalink)
Senior Member
 

iTrader: (0)
Join Date: Jan 2008
Location: Cranebrook, NSW
Posts: 109
Spent time on board: 21:39:19
therufus is on a distinguished road
Default

We need to find the a$$hats that made this and perform sexual acts upon them using tractors.
therufus is offline   Reply With Quote
Sponsored Links
Old 15-11-08, 03:47 PM   #13 (permalink)
Premium Member
 
rob916's Avatar
 

iTrader: (6)
Join Date: Apr 2008
Location: Victoria
Posts: 781
Spent time on board: 3 Weeks, 1 Day and 20:07:17
rob916 is on a distinguished road
Default

I was thinking more along the lines of Tiger Tape and vasoline.
__________________
There is ALWAYS a better way to do things.
rob916 is online now   Reply With Quote
Old 16-11-08, 04:54 PM   #14 (permalink)
Premium Member
 

iTrader: (0)
Join Date: Jan 2008
Posts: 89
Spent time on board: 3 Days and 2:56:26
wileecotye is on a distinguished road
Default

format c: /s is the best cure
mac OSX and then Linux -no more problems
wileecotye is online now   Reply With Quote
Old 16-11-08, 05:21 PM   #15 (permalink)
Senior Member
 
mutanti's Avatar
 

iTrader: (1)
Join Date: Jan 2008
Posts: 143
Spent time on board: 2 Days and 5:31:05
mutanti is on a distinguished road
Default

When Im Doing Clients Computers I quite often remove there hard drive and scan it from my Office Service Computer which has the side panel off pretty much all the time for this purpose.
Does wonders for getting rid of Crap out of Clients computers....
I usually scan externall with MalwareBytes, AVG and it usually takes the worst out of the hard drive I then reinstall and scan again with Spybot S&D as well as AVG & Malwarebites again...
mutanti is offline   Reply With Quote
Sponsored Links
Old 16-11-08, 06:51 PM   #16 (permalink)
Super Moderator
 
ssrattus's Avatar
 

iTrader: (0)
Join Date: Jan 2008
Posts: 1,368
Spent time on board: 1 Month, 0 Weeks, 4 Days and 6:29:00
ssrattus will become famous soon enough
Default

Yep that would have been a probably been a viable solution mutanti. But with this particular PC a reformat and clean install wasn't to hard as the majority of the data is kept on the other partition.
ssrattus is online now   Reply With Quote
Old 07-12-08, 04:21 PM   #17 (permalink)
Senior Member
 

iTrader: (0)
Join Date: Jan 2008
Location: Cranebrook, NSW
Posts: 109
Spent time on board: 21:39:19
therufus is on a distinguished road
Default

I find MBAM problematic when scanning remotely. If I can install it on a problematic system, update it, then scan, it usually removes everything bad effectively. I have Avast + MBAM on our workshop machine to remotely scan hard drives and I've all but given up on MBAM for this purpose.
therufus is offline   Reply With Quote
Reply


LinkBacks (?)
LinkBack to this Thread: http://www.austech.info/security-privacy/13375-antivirus-2009-even-harder-remove-now.html
Posted By For Type Date
Austech - Powered by vBulletin This thread Refback 13-11-08 05:36 PM

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


server monitor
All times are GMT +10. The time now is 05:17 PM.


Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.

Ad Management by RedTyger