brastk.exe & delself.bat karna.dat

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sssteve72, Oct 30, 2008.

  1. sssteve72

    sssteve72 Private E-2

    I tried to do the read and run me first malware removal guide (I downloaded the programs) but I stopped after trying both SAS and Spybot. Both programs installed but when I double click them nothing loads. I can't run the programs. Actually I already had Spybot installed but it wouldnt load the first time so I uninstalled it and then downloaded a new one and installed it but it still won't run.

    This is how my problem started. I was looking for a video converter. I clicked on a link and a web page opened. when it came up I heard IE clicks like I was clicking on links but I wasn't then I got an error about WAB.exe couldn't finish loading or something. Then my computer just restarted. Now I have the little Red button with the white X in my systray and it keeps popping up messages to say I am infected (no kidding). I never clicked it because it just looks like spyware to me.

    I see delsef.bat on my desktop, brastk.exe in my C:windows directory and karna.dat in a couple of places. I deleted delsef.bat and brastk.exe. Of course brastk.exe just reappears with each restart of my computer.

    I'm not sure where to go from here since I can't even run thru the "run me first".

    Anyone with any ideas?
     
  2. sssteve72

    sssteve72 Private E-2

    Ok I went ahead and tried MBAM and it worked and seems to have removed the red circle with the white X.
     
  3. sssteve72

    sssteve72 Private E-2

    I've run Combo Fix and MG Tools and the logs are attached.

    Things seem to be normal.

    If anyone can tell me if it looks good it would be most appreciated.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are you running this PC without protection installed?

    Did you install Covenant Eyes keylogging software yourself??? Why?

    Do you have any idea what the below two drivers are from?
    Look for the files and get Properties info on them by right clicking on them and selecting Properties, Version. Let me know what you find. I bet the 2nd file cannot be found.

    Also delete the below file I assume you made while trying to remove the infection?
    C:\WINDOWS\system32\deletebrastak.exe



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.


    Your logs are basically clean but I want to find out about those two drivers.
     
  5. sssteve72

    sssteve72 Private E-2

    1) What can I say, I procrastinate. I need to get virus protection reinstalled. I've been without it for... well a stupid amount of time.
    2) Yes I installed it and it is fine. It is a internet monitoring software I use. (aka kids)..
    3) I have no idea on those two drivers. I did a file search and couldn't find either of them. I tried looking at the path and couldn't find the file. I did a registry search and I find the seriall.sys in a couple of places. One path for example is HKEY_Local_Machine\SYSTEM\ControlSet003\Services\seriall Then it is listed under the Imagepath Key. bDMusicb.sys shows up at this location in the registry HKEY_USERS-1-5-21-1123561945-343818398-68200-3330-1003\Software\Microsoft\earch Assistant\ACMru\5604 The Key Name is 000 the data line is bDMusicb.sys. But again I have no idea what it is related to and I can't find that actual file on the computer. I'm guessing if the files aren't on the computer it is fairly safe to delete the registry entries. Any opinions?

    4) You are correct I changed the filename to deletebrastak.exe, it has now been deleted.

    I'll run the HJT or analyse.exe.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then let's remove them.


    We will use ComboFix to remove those drivers.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Then attach the new c:\combofix.txt log
     
  7. sssteve72

    sssteve72 Private E-2

    The log is attached.

    Can I delete any registry key that contains the seriall.sys or the bDMusicb.sys values?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    When you ran ComboFix, part of cleaning up the drivers should have removed the registry keys. You can see references to the LEGACY keys in the ComboFix log. Are you implying there are additional keys? Be very careful doing manual deletions in the registry. Also note the some keys cannot simply be deleted while Windows is running.
     
  9. sssteve72

    sssteve72 Private E-2


    It appears to have deleted them when I ran combofix this time around. I just did a search thru the registry and it doesn't find any reference to those two drivers now.

    I just downloaded a new 2009 PC-cillin. Now that we seem to have this fixed I will install it.

    Thanks again for your help. :cool:cool:cool
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds