Hey Chaslang

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheOldThug, Oct 21, 2008.

  1. TheOldThug

    TheOldThug First Sergeant

    Well unfortunately it looks like my daughter has picked up some spyware again. Been a long time. I havent done the do me first yet but I will and post logs. Just a few questions. I am pretty sure it is a file called brastk.exe. Tried changing it's name and it renamed itself back. I have also tried to run spybot and AVG 7.5 and neither will open. Also tried to run defrag and it wouldnt start. I am down to 15% open disk, that culd have something to do with defrag. Will try to get this started this weekend. Just wondered if u had any comments b4 I start.

    I do use Firefox, spywareblaster, AVG 7.5, Spybot. I even tried to go to safe mode to run spybot and AVG but they wouldnt open there either.
     
  2. TheOldThug

    TheOldThug First Sergeant

    After looking at the readme I see that I am supposed to unplug from the internet while doing some of the procedure, this is a laptop. How do u suggest I do that?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hi OldThug,
    Wired laptops are no diferent than wired desktops. You can just unplug them; however I'm guessing what you really meant was that it is a wireless connection. You can either disable the wireless interface or shut off your wireless router while doing the steps. You could take another approach for now and just run all steps while connected and see what happens. In many cases, having the PC connected may not matter.
     
  4. TheOldThug

    TheOldThug First Sergeant

    Thx yes, it is wireless. I should have been more specific.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay make sure you attach all 4 logs when you finish the cleaning procedure. Brastk.exe is Trojan/Backdoor and is considered dangerous.
     
  6. TheOldThug

    TheOldThug First Sergeant

    I got thru most of the steps. I at first could not run super anti spyware, spybot, or avg. After running malwarebytes it cleaned up the brastk.exe problems and I was able to run those. I can now also run defrag, all I did was analyze.... did not run it. I did analyze just to see if it would work after getting rid of the problem. I also did Java just before running MGtools. I Have not run combofix, I was confused on the recovery console and was afraid it would always boot up to a choice once it was installed.(I do have a XP disk) This is my daughters laptop and and didnt want to add any steps for her booting up. Hopefully we can just skip the combofix. I found no other problems when running SAS or spybot. I see that SAS boots up at start up now. Is that necessary and is it a good thing. When MGtools was running I saw alot of "could not find this file" or something like that. I have not toggled off system restore yet. Also I just realized I did not scan D: drive with SAS, it is a RECOVERY drive that comes with gateway Laptop and I have never used it. I dont think any of the other programs would let me choose that.

    BTW I have windows XP. I thought I would never be back here after having Firefox, spyware blaster, spybot, and avg on my computer. I havent updated in about a month so maybe that was the problem.

    I am not sure why I cant find the logs for SAS or malwarebytes. I have there folders open and do not see either of them. I did a search on all files and folders for SASlog.txt and it does not find it. I have extensions open and show all files as originaly instructed. I will look some more and see if I can find them.

    Tho there seems to be no problems now I am posting so u can take alook anyway

    Thx again for your help.
     

    Attached Files:

  7. TheOldThug

    TheOldThug First Sergeant

    Have checked again and cant find SAS log or malwarebytes. I looked in their respective folders. Am I doing spmething wrong, I know I ran both of them and they showed me their results. Malware I think was a log type file that opened and i just closed it but am not sure. SAS found nothing.
     
  8. TheOldThug

    TheOldThug First Sergeant

    Also just ran Avg 7.5 with updated virus defs and it said it found 1 Virus32/Themida. Looks like it deleted it, didnt ask me what to do. Results just said 0 moved to vault, 0 cleaned, and 1 deleted.
     
  9. TheOldThug

    TheOldThug First Sergeant

    Also BTW I never disconnected from the internet since u said prolly OK to do it connected.
     
  10. TheOldThug

    TheOldThug First Sergeant

    I read thru the instructions again and see that I can look at the MBAM log off a tab, so I copied it and put in a text file. Here it is.
     

    Attached Files:

  11. TheOldThug

    TheOldThug First Sergeant

    I am so sorry to do this in such a piece meal fashion, once again after reading your instructions I have found the log thru their interface. There was 2 of them, dont know why only ran it once, have included both on one text file.
     

    Attached Files:

    • SAS.txt
      File size:
      928 bytes
      Views:
      4
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I stongly suggest that you run it now. The infections you had could leave other things around the it may find. You don't have to install the Recovery Console since you have a CD. Installing it is just a safety net. Also even when it is installed, the bootup will just breeze right past it in a couple seconds if no keys are pressed.

    I would like to see the ComboFix log before giving you the rest of the fix.


    SpywareBlaster and Spybot do not provide any active realtime antispyware protection. You do not have any realtime spyware protection installed.
     
  13. TheOldThug

    TheOldThug First Sergeant

    OK I ran it. Here is the file. Did not install recovery console. I did everything in normal setup but it is a pain. When it boots up there is something that starts called oemreset. It opens the device manager box and then continues to test different devices such as showing a little video. I believe it is testing sound or video things. Was this way from the time I got it. Must also be testing sound devices. I was afrad if combofix rebooted it would screw it up since you are supposed to close all boxes and not run any programs. The device manager box opened but it didnt run the videos till after combo was done. I noticed combofix deleted D:/autorun.inf. The D drive is strictly a recovery drive on gateway computers. Hope that didnt screw it up.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just junk from you don't need. It is the below startup process that loads this:
    O4 - Global Startup: Oemreset.lnk = C:\WINDOWS\OPTIONS\OemReset.exe

    PC Vendors always put lots of junk on their PCs that most users do not need nor do they want it. The below is more of this kind of junk:

    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe


    No this should not be a problem for a Recovery drive. Not sure why that file would even be there. You could look at the quarantined file with notepad to see what is in it. You should find it in a folder like below:

    C:\QooBox\Quarantine\D

    I'm working thru the logs now.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Also it looks like you may have two installs of Spybot:
    Spybot - Search & Destroy 1.5.2.20
    Spybot - Search & Destroy

    Both appear to be the old version. You should uninstall these and install the current version given in the READ & RUN ME.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (file missing)
    O20 - AppInit_DLLs: karna.dat

    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now delete the below file.
    C:\WINDOWS\system32\TDSSosvd.dat

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  16. TheOldThug

    TheOldThug First Sergeant

    Had a C folder with nothing in it but no D folder
     
  17. TheOldThug

    TheOldThug First Sergeant

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    O20 - AppInit_DLLs: karna.dat


    Did everything but the following:
    Windows messanger: Do I choose the uninstall option?

    There was no karna.dat line


    The infection seems to be gone.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  19. TheOldThug

    TheOldThug First Sergeant

    Thank you once again for all your help Chaslang. You guys are the GREATEST. I will finish with your recommendations. Just a few last questions.

    To remove combofix I can just copy and paste into the RUN box the line exactly as you have it, quotes and all? (Just double checking the instructions... sorry)
    "%userprofile%\Desktop\combofix" /u

    While installing the new spybot it asked me if I wanted to back up the registry and I said yes. Does that create any malware problems for the future if I needed to use it?

    I am kind of surprised combo fix doesn't allow me to put that D:/autorun.inf file back. It deleted it instead of quarantining it. As I mentioned there was no C:\QooBox\Quarantine\D. What happens if it deleted a file it shouldn't?

    Can I turn off SAS to open when windows starts? Since there is no realtime protection with the free version I see no reason for it to be on the task bar or show its banner everytime windows starts.

    Could both of these lines be fixed with HJT and not hurt anything?
    O4 - Global Startup: Oemreset.lnk = C:\WINDOWS\OPTIONS\OemReset.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No!

    I'm surprised too. I don't really think that file should be required on for a recovery partition but I cannot say that for sure.

    The banner option can be disabled in Preferences, General & Startup. The icon in the tray uses very little resources. The full progam is not actually running. The main reason for allowing it to load is that some malware will prevent you from starting up the program, but if this tray item is already loaded, the malware may not be able to stop it. It's up to you, it is meant to be a feature. If you don't get many infections then disable it from loading at startup.

    Yes. Personally if it were me, BigFix would have been uninstalled right out of the box along with many other things that were put on the PC by the manufacturer. ;)
     
  21. TheOldThug

    TheOldThug First Sergeant

    Chas I just thought of one more thing. My daughter has a flash type drive, one of those little things you put in a USB slot. I know she has put some files on it since she got the infection. She usually just copies photos and her college papers on it. Is there anything I should do about that. Sorry that I forgot to put this in my last post since you have already answered it and youwould have been done with me.
     
  22. TheOldThug

    TheOldThug First Sergeant

    Am having a strange problem after fix. When the flash drive(little memory stick) or a cd rom is put in drive no box comes up showing what is on them. For example stick a blank CD into copy onto but the window doesnt come up asking what I want t o do.
     
  23. TheOldThug

    TheOldThug First Sergeant

    I wonder if that had anything to do with that autorun.inf file.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the below patch.

    Copy the bold text below to notepad. Save it as FixAP.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now you must reboot to see if this will work.


    Another possible thing to try is the below from MS. You would have to make sure your USB device is plugged in first.

    http://www.microsoft.com/downloads/details.aspx?familyid=c680a7b6-e8fa-45c4-a171-1b389cfacdad&displaylang=en
     
    Last edited: Oct 29, 2008
  25. TheOldThug

    TheOldThug First Sergeant

    Ran your patch, it took it, the CDrom drive and the flash drive are now working. How in the hell do you know all this stuff.... it always amazes me. Thanks again and once again I hope it is a long, long time before I have to come back here.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Good job Jerry!;)

    I'm an engineer, we are information collectors. :-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds