brastk.exe ate my parrents machine.

Discussion in 'Malware Help (A Specialist Will Reply)' started by IdiotZ42, Nov 20, 2008.

  1. IdiotZ42

    IdiotZ42 Private E-2

    First off let me start by saying I ran through all the steps that I was able to complete in the READ & RUN ME FIRST sticky, and will attach all available logs.

    My sob story:

    My dad calls me up and says, "the computer isn't working again." (Not much new here) So I go over and give it a look. there is this stupid red circle X icon down in the running tasks bar that keeps popping up with some obviously bogus "you're infected; download a better antivirus" message.

    I can't seem to find where this message's task is in task manager, but I have comodo fire wall, antivirus, and boclean actively running in paranoid mode on his machine. (Yes he must have said it was ok to run the malware) So I pull up comodo's fire wall and find a few interesting things in the log.

    My friend google tells me that brastk.exe (the most active program in the log) is a bad guy, and comodo says that av.dat created a couple registry keys to run brastk.exe on start up. I can't find av.dat on the hard drive, but I am able to delete the brastk.exe in the windows dir. There is another in the system32 dir that windows won't let me delete so I boot into cmd prompt only and kill it too. however when I restart both are back from the dead, and comodo says av.dat played with the registry again.

    So I kind of half *** my way stepping through brastk.exe and come up with karna.dat, which also happens to be both in the win dir and the system32 dir. (The following websites found in brastk.exe might be victoms; but my guess would be more like perpetrators, and I do really want to kick them in the nuts: do-step-scan.com, do-monster-progress.com, domonster-progress.com, do-power-scan.com, dopower-scan.com, do-monsterscan.com, do-stepscan.com, doscan-progress.com, do-fixed-progress.com, domanaged-scan.com, domake-progress.com)

    I kill all brastk and karna and it still grows back. So I kill them again, and replace with empty files. yay they no longer grow back. I use the windows system info to find beep.sys which lives in system32\dirvers, and system32\dllcache. google is indifferent about this one, it may or may not be a system file, but when I look into the file it does have karna and brastk in it.

    this prompts me to go and update comodo av, yes i know i should have done that before this point. This doesn't work, comodo av cannot connect. This is odd, I go and ping antivirus.comodo.com, and it pings 127.0.0.1 just fine. ARGGGG. arp says there are no entries found. there are no important entries in the system32\drivers\etc\hosts or lmhosts.sam files on the machine. nbtstat -c says there are no names in chache. route print says nada useful. ipconfig /displaydns ah ha so this is where it lives, but ipconfig /flushdns doesn't get rid of it. so i browse the comodo website for a manual update, but was not able to find one in my limited attn span.

    Ok installed AV/Fire wall fails me and won't update, google doesn't yet know all about this issue, and i must use another machine to even browse antivirus.comodo.com. it's time to give those major geeks guys a buzz. (Kudos to you all for not redirecting the ip addr in the browser bar. for example: http://74.86.201.210/showthread.php?t=35407 works just fine when http://91.199.212.171/ does not because it redirects to http://antivirus.comodo.com/)

    Major Geeks Steps
    I skimmed all this stuff first to down load at work onto a non infected/working machine, and saved all the files to a thumb drive.

    CClean ran great. no issues, no whining, no problems.

    SAS install did absolutely nothing when i double clicked it. so i renamed per instructions, and it installed. the update did not work because of the same 127.0.0.1 issue. although i was able to manually dnload the update, and this ran after i renamed it to sasd.exe. after install the SAS exe will not run, and if you rename it then it crashes before it will not run. However if you open up the SAS directory and find a RUNSAS.EXE, this I believe creates a copy of the SAS executable with a random file name (such a good idea). I ran the random SAS executable and was able to complete the SAS instructions as directed. Its log file is attached.

    SpyBotSD installed after i renamed it, and updated after i found the manual update file. This one however will not run no matter howmany times you click it. And it still wouldn't run after it was renamed.

    mb wouldn't install even after i renamed the install. see attached MBerror.jpg

    after i downloaded the restore thingy from microsoft in order to drag onto combofix nothing happened when i dragged it on. it also wouldn't run when clicked/renamed.

    MGtools.exe almost didn't run. I had to go into the MGtools dir and start the GetLogs.bat file manually. it's log is also attached.

    Summary:
    so this is where i am. two log files and a error picture attached.
    most important exes won't run, most important dns are redirected to 127.0.0.1, comodo av is KIA, comodo fire wall with defence+ is alive and well, and comodo BOclean appears to be doing the same nothing that it always was doing.

    Thank you for the help,
    IdiotZ42
     

    Attached Files:

  2. IdiotZ42

    IdiotZ42 Private E-2

    Some other things i forgot to mention.

    av.dat is still MIA

    the little red-x-circle icon down in the taskbar flashed that bogus message constantly while you're trying to do anything, and i found this same message embedded verbatim into brastk.exe

    I also found no extension text files with weird filenames growing in the windows dir. they appeared to be some sort of terse status file, i will attach one the next time i'm over at my parents house.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Where were you trying to run it from? Did you have the EXE file saved to the problem PC and did you have it somewhere that was not a Temp folder?

    Did you try running ComboFix.exe by just double clicking on it and did you try running it in safe boot mode?


    Uninstall the below old versions of software:
    J2SE Development Kit 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 4
    Java 2 Runtime Environment, SE v1.4.2_03

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
    O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\PPCToolbar.dll (file missing)
    O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - c:\program files\peoplepc\toolbar\PPCToolbar.dll (file missing)
    O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
    O4 - HKCU\..\Run: [A00F2C4CA03.exe] C:\DOCUME~1\DALEKA~1\LOCALS~1\Temp\_A00F2C4CA03.exe
    O4 - HKUS\S-1-5-21-177086865-21320931-3691902931-1007\..\Run: [A00F2C4CA03.exe] C:\DOCUME~1\DALEKA~1\LOCALS~1\Temp\_A00F2C4CA03.exe (User '?')
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O20 - AppInit_DLLs: karna.dat
    O23 - Service: Security Center wscsvcWmiApSrv (wscsvcWmiApSrv) - Unknown owner - C:\WINDOWS\system32\ADSMSEXTn.exe (file missing)

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Dale Kaiser\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. IdiotZ42

    IdiotZ42 Private E-2

    I saved the file to the desktop, and tried to run it from there.

    I beleive I did try running ComboFix.exe by double clicking it after the drag-n-drop didn't work. I started with the READ & RUN ME FIRST thread, so I did not see the "try it in safe mode" suggestion until I had finished with that thread. It said not to go back and try steps over again, so I didn't.

    I had no problems doing this step. However I would like to at some future point reinstall the v1.4 and v1.5 JDKs. In order to be able to develop for Win95&98. If you have any suggestions on how to keep this separate from the active machines IE/internet I'd be glad to hear them.

    When I ran HJT the following was not in the check list:
    O4 - HKUS\S-1-5-21-177086865-21320931-3691902931-1007\..\Run: [A00F2C4CA03.exe] C:\DOCUME~1\DALEKA~1\LOCALS~1\Temp\_A00F2C4CA03.exe (User '?')

    This ran fine, and gave me a success message.

    After the PC shutdown it hung at the restart (black screen with blinking carrot) for a few long seconds. Then it came up into the normal XP login screen. When I typed the first character of the password into the prompt the PC immediately rebooted itself. After this it did not hang again when it was booting up. This time when it got to the login screen it allowed me to type in the password and login. When it finished loading the profile it had avenger.txt open in notepad, and an error message displayed (see attached avengerErr.jpg)

    No other issues in the above steps, all ran as expected, and the requested logs are attached.

    The internet 'filter' for lack of a better term is still active. E.G. it still redirects antivirus.comodo.com, forums.majorgeeks.com, and I'm sure many others to localhost.

    The comodo antivirus is still KIA. I will probably have to reinstall this anyways; comodo has had a major update that combines both the antivirus and firewall, which was released sometime after the machine concocted the brastk influenza.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Install them on another PC that you don't surf with if that is an option. Otherwise you will have to live with the fact that they are security risks.

    Since your logs are clean, this does not appear to be a resident malware issue. I suggest that you uninstall Comodo AntiVirus Beta 2.0 and COMODO Firewall Pro and then reboot and see where things stand. If no change, also run the below.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
     
  6. IdiotZ42

    IdiotZ42 Private E-2

    This did not help, but after I completed these steps I tried spybot s&d to see if the programs were still being blocked from loading.

    this ran and found stuff to remove. (see attached log) After this I am now able to browse to forums.majorgeeks.com

    Should i go back at this point and try some of the other steps that were not working before? Or install the latest version of Comodo?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay looking better! ;) I would first suggest trying to run a couple scans we were not able to run before. Download, install, update and run Malwarebytes and attach a log. Also see if you can get ComboFix to run now and attach a log.

    Then you can reinstall Comodo.
     
  8. IdiotZ42

    IdiotZ42 Private E-2

    both Malwarebytes and ComboFix install fine, and the update i downloaded for malwarebytes ran. but neither of the programs will load normally nor in safe mode when i click on them.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try this!

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
    • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    • Then search forTDSSserv.sys
    • Let me know if you find this or not.
    • If you do find it, right click on it, and select “Disable”. Do not try to uninstall it.
    • Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.
     
  10. IdiotZ42

    IdiotZ42 Private E-2

    TDSSserv.sys did exist, and after I disabled it I was able to run both MalwareBytes and ComboFix (see attached logs).
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Excellent. Now get me a new and hopefully final MGlogs.zip and if it is clean, we will move on to final steps...... That is assuming everything is running OK now.
     
  12. IdiotZ42

    IdiotZ42 Private E-2

    attached is the MGlogs.zip, and as far as I can tell everything seems to be running correctly. I can get to the antivirus websites, and so far all of the programs i've tried running worked.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean. Now you need to get this PC properly protected which is included in the below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. IdiotZ42

    IdiotZ42 Private E-2

    Thank you for all the help. I ran through the above, and it looks like I'm good to go.

    Also I was wondering, in the above info it mentioned creating a restricted user account to surf the internet with. If I create a new account called surf, and set the run as on the firefox short cut to the surf account. what restrictions should i put on the surf account?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No special restrictions should be required since you are logging into a Restricted user account it should already be restricted. You may have to decide at some point what policies you may need to create to allow things that are not allowed on a restricted account. Like installing software and updates....etc However you need to boot up and log into the restricted user account to get the full benefits of it. If you are going to boot up in an admin account, you are defeating the whole purpose of having the restricted account.
     
    Last edited: Dec 12, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds