Page 1 of 2 12 LastLast
Results 1 to 20 of 25

Thread: Antivirus 2009 even harder to remove now.

  1. #1
    Senior Member
    ssrattus's Avatar
    Join Date
    Jan 2008
    Posts
    4,160
    Thanks
    515
    Thanked 821 Times in 490 Posts
    Rep Power
    455
    Reputation
    5922

    Default Antivirus 2009 even harder to remove now.

    Have spent several hours trying to remove this completely and still some issues remain.

    You get the "usual" white cross in a re circle in the task manager and the box saying install Antivirus 2009 etc.

    It hides its processes so nothing is seen in taskmanager, it is using rootkit techniques.

    System restore does not work. Stopping it cleans out the copies of the above files stored in the System Volume Information folder were the restore point files are kept.

    Many antivirus/malware apps won't run, including Malware Antimalwarebytes.

    HJTinstall doesn't run, Schmitfraud and vundofix only run when changing the file name.

    IE and Firefox won't open most antivirus sites (urls resolve to the localhost address when you try to ping these sites) and for other sites you often end up at unexpected sites.

    The cure:

    Well haven't completely fixed it.

    The files associated with it found to date and mentioned on the net are:

    C:\WINDOWS\brastk.exe
    C:\WINDOWS\karna.dat
    C:\WINDOWS\DRIVERS\beep.sys
    C:\WINDOWS\System32\karna.dat
    C:\WINDOWS\SYSTEM32\brastk.exe
    C:\WINDOWS\SYSTEM32\DLLCACHE\beep.sys
    C:\WINDOWS\SYSTEM32\DLLCACHE\figaro.sys
    C:\WINDOWS\SYSTEM32\DRIVERS\beep.sys

    Also found a copy of svchost.exe in C:\WINDOWS\SYSTEM32\DRIVERS that should not be there.

    Safemode deletions of the files mentioned above, removal of all mentions of the files in the registry eventually got rid of them. Running Schmitfraud using a different name may have helped. Avira antivirus does install OK and may have helped.

    from Kaspersky may have helped too.

    But eventually found when going back to the normal boot it stuck at the "windows is starting" point just before the username and password entry point. Booting to a XP disk and running Repair console and running chkdsk.exe /r fixed something and allowed a normal log in.

    Have got rid of the self replicating brastk.exe etc and no white cross saying I need to install antivirus 2009.

    BUT still IE and Firefox won't go to most antivirus sites still and many antivirus apps won't run or install. So it still isn't fixed.

    Through Process Explorer I can see where svchost.exe with DCOMLauncher is the probable cause of the IE and Firefox problems, but the files themselves are OK and stopping this process causes a restart and stopping the DCOM service prevents a normal boot.

    I am at my wits end now and a clean install may be the best answer.

    BTW beep.sys is a normal system file that has been contaminated and can be copied back from another PC later. It is used because it is also run when in safe mode making getting rid of this malware all the more difficult.
    Last edited by ssrattus; 13-11-08 at 01:39 PM.



Look Here ->
  • #2
    Senior Member
    Join Date
    Jan 2008
    Location
    Port Lincoln
    Posts
    657
    Thanks
    145
    Thanked 362 Times in 179 Posts
    Rep Power
    264
    Reputation
    2205

    Default

    Quote Originally Posted by ssrattus View Post

    Have got rid of the self replicating brastk.exe etc and no white cross saying I need to install antivirus 2009.

    BUT still IE and Firefox won't go to most antivirus sites still and many antivirus apps won't run or install. So it still isn't fixed.

    Through Process Explorer I can see where svchost.exe with DCOMLauncher is the probable cause of the IE and Firefox problems, but the files themselves are OK and stopping this process causes a restart and stopping the DCOM service prevents a normal boot.

    I am at my wits end now and a clean install may be the best answer..

    did you try installing malware bytes again as that should fix the browser problems - otherwise try the portable thinstalled (sandboxed) version of malware bytes

  • #3
    Senior Member
    best4less's Avatar
    Join Date
    Jan 2008
    Location
    Australia
    Posts
    7,684
    Thanks
    3,487
    Thanked 2,207 Times in 1,132 Posts
    Rep Power
    758
    Reputation
    15165

    Default

    ssrattus I got rid of one the other day i threw every program at it and then did a system restore then deleted all the system restore files and then threw everything at it again and registry cleaners LOL
    and it still clean after 2 weeks, but you are right it has taken me about 4 hours LOL
    When you do things right, people won't be sure that you have done anything at all

  • #4
    Senior Member
    ssrattus's Avatar
    Join Date
    Jan 2008
    Posts
    4,160
    Thanks
    515
    Thanked 821 Times in 490 Posts
    Rep Power
    455
    Reputation
    5922

    Default

    Tried 4 versions of portable malwarebytes and they either don't run, if they run they don't update and don't find anything. Tried updating it on my good PC and then running it on the infected and it doesn't run.

    Tried rootkit unhooker, doesn't run on the infected PC nor does the sopos anti rootkit.

  • #5
    Senior Member
    ssrattus's Avatar
    Join Date
    Jan 2008
    Posts
    4,160
    Thanks
    515
    Thanked 821 Times in 490 Posts
    Rep Power
    455
    Reputation
    5922

    Default

    Given up, first time a virus/trojan has beaten me. Formatting as I write.

  • #6
    Senior Member Woodstock's Avatar
    Join Date
    Jan 2008
    Location
    Mt Gambier
    Age
    51
    Posts
    1,728
    Thanks
    74
    Thanked 82 Times in 57 Posts
    Rep Power
    262
    Reputation
    336

    Default

    did ya have Malwarebytes running live (systray) ???
    Trust thyself only, and another shall not betray thee.

    http://s18.postimage.org/h9xu3rrhx/fb_sevapers.jpg

  • #7
    Senior Member
    ssrattus's Avatar
    Join Date
    Jan 2008
    Posts
    4,160
    Thanks
    515
    Thanked 821 Times in 490 Posts
    Rep Power
    455
    Reputation
    5922

    Default

    Quote Originally Posted by Woodstock View Post
    did ya have Malwarebytes running live (systray) ???
    Don't think so.

    BTW, Posting with the newly installed Windows XP SP3 Vienna Concept right now, less than an hour from start of format (60GB) to up and running. Of course there are lots of other things to install yet.

  • #8
    Junior Member
    Join Date
    Jan 2008
    Location
    SE QLD
    Posts
    247
    Thanks
    28
    Thanked 67 Times in 35 Posts
    Rep Power
    213
    Reputation
    301

    Default

    A couple a programs I find useful for manually checking and removing unwanted programs - Process Explorer and AutoRuns.

    Process Explorer


    AutoRuns for Windows

  • #9
    Premium Member rob916's Avatar
    Join Date
    Apr 2008
    Location
    Bargara, Queensland.
    Age
    52
    Posts
    1,573
    Thanks
    49
    Thanked 75 Times in 36 Posts
    Rep Power
    251
    Reputation
    248

    Default

    hijackthis is also good for checking for autoruns and processes.
    What happens if I press alt + F4?

  • #10
    Senior Member Jaz808's Avatar
    Join Date
    Jan 2008
    Location
    Hell
    Posts
    1,048
    Thanks
    30
    Thanked 146 Times in 99 Posts
    Rep Power
    247
    Reputation
    742

    Default

    I used these tools

    Malwarebytes
    HiJackThis
    SmitFraudFix
    Dail-a-Fix
    ATF Cleaner
    FixPolicies

    any finally got rid of it, also VirusLabs Response 2009 is the same

  • #11
    Senior Member
    ssrattus's Avatar
    Join Date
    Jan 2008
    Posts
    4,160
    Thanks
    515
    Thanked 821 Times in 490 Posts
    Rep Power
    455
    Reputation
    5922

    Default

    HJT would not install, even when re-named.

    Parts of this malware is rootkit based meaning that the processes are hidden and the registry entries don't show in the registry. The files mentioned in the first post were not rootkit based.

  • #12
    Junior Member
    Join Date
    Jan 2008
    Location
    Cranebrook, NSW
    Posts
    143
    Thanks
    8
    Thanked 6 Times in 6 Posts
    Rep Power
    205
    Reputation
    130

    Default

    We need to find the a$$hats that made this and perform sexual acts upon them using tractors.

  • #13
    Premium Member rob916's Avatar
    Join Date
    Apr 2008
    Location
    Bargara, Queensland.
    Age
    52
    Posts
    1,573
    Thanks
    49
    Thanked 75 Times in 36 Posts
    Rep Power
    251
    Reputation
    248

    Default

    I was thinking more along the lines of Tiger Tape and vasoline.
    What happens if I press alt + F4?

  • #14
    Member
    Join Date
    Jan 2008
    Posts
    335
    Thanks
    0
    Thanked 20 Times in 12 Posts
    Rep Power
    213
    Reputation
    161

    Default

    format c: /s is the best cure
    mac OSX and then Linux -no more problems

  • #15
    Senior Member mutanti's Avatar
    Join Date
    Jan 2008
    Age
    52
    Posts
    577
    Thanks
    134
    Thanked 120 Times in 69 Posts
    Rep Power
    248
    Reputation
    1542

    Default

    When Im Doing Clients Computers I quite often remove there hard drive and scan it from my Office Service Computer which has the side panel off pretty much all the time for this purpose.
    Does wonders for getting rid of Crap out of Clients computers....
    I usually scan externall with MalwareBytes, AVG and it usually takes the worst out of the hard drive I then reinstall and scan again with Spybot S&D as well as AVG & Malwarebites again...

  • #16
    Senior Member
    ssrattus's Avatar
    Join Date
    Jan 2008
    Posts
    4,160
    Thanks
    515
    Thanked 821 Times in 490 Posts
    Rep Power
    455
    Reputation
    5922

    Default

    Yep that would have been a probably been a viable solution mutanti. But with this particular PC a reformat and clean install wasn't to hard as the majority of the data is kept on the other partition.

  • #17
    Junior Member
    Join Date
    Jan 2008
    Location
    Cranebrook, NSW
    Posts
    143
    Thanks
    8
    Thanked 6 Times in 6 Posts
    Rep Power
    205
    Reputation
    130

    Default

    I find MBAM problematic when scanning remotely. If I can install it on a problematic system, update it, then scan, it usually removes everything bad effectively. I have Avast + MBAM on our workshop machine to remotely scan hard drives and I've all but given up on MBAM for this purpose.

  • #18
    Junior Member oscillator_1's Avatar
    Join Date
    Jan 2008
    Posts
    244
    Thanks
    113
    Thanked 24 Times in 14 Posts
    Rep Power
    210
    Reputation
    157

    Default

    Quote Originally Posted by ssrattus View Post
    Given up, first time a virus/trojan has beaten me. Formatting as I write.
    Hi M8,

    I had the same problem as you.

    Format and re-install was the only solution for me, as none of the spyware or malware programs would run.

    But scanning the infected HDD from another computer is a good idea.

    If I ever run into this problem again will try extrernat scan.

    Cheers

  • #19
    Senior Member Woodstock's Avatar
    Join Date
    Jan 2008
    Location
    Mt Gambier
    Age
    51
    Posts
    1,728
    Thanks
    74
    Thanked 82 Times in 57 Posts
    Rep Power
    262
    Reputation
    336

    Default

    had it m8's pc other week .. was real prick ... disable avg and malwarebytes ... even typing those 2 words in firefox using google ..it just close firefox ... even in safe mode .. format and reinstall was only answer ..
    Trust thyself only, and another shall not betray thee.

    http://s18.postimage.org/h9xu3rrhx/fb_sevapers.jpg

  • #20
    Junior Member
    Join Date
    Feb 2008
    Age
    45
    Posts
    154
    Thanks
    0
    Thanked 1 Time in 1 Post
    Rep Power
    203
    Reputation
    17

    Default

    I hate spending time removing viruses. At the first sign of infection I blow my install away with a clean image in 2 minutes. It takes longer than 2 minutes to complete the task but most of my stuff at home is server based (IMAP email server, file server, firewall, even a lot of apps) so I can recover and keep working in about 10 minutes to an hour for almost everything else. I use drive snapshot for imaging.

  • Page 1 of 2 12 LastLast

    Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •