Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Help with strange virus please!
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Help with strange virus please!  
Forum Quick Jump
 
New Topic Post reply to : Help with strange virus please! Printable version of : Help with strange virus please!
[ << Previous Thread | Next Thread >> ]

ii-ii-iii
New Member


Date Joined Oct 2008
Total Posts : 7
 
   Posted 10-11-2008 12:39 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
Hey everyone.

Have this malicious program for a few days I just can't get rid of it no matter what.

What it does:

Nothing harmful it seems other than; making a small windows like bubble in the icon field bottom right corner, where it says that I should protect my computer from spyware etc. by clicking this bubble I would gain that protection. Of course I haven't clicked it. Also it has a phoney red windows (Warning your computer isnt safe without antivirus) cross copy as an icon. The objective of the virus seems to be to fool the user into clicking that bubble...Other than this I haven't noticed anything strange.

This is what I've done so far:

Kaspersky 8, quarantined one of the files. But all the files are recreated everytime my computer boots. Also terminated actions attempted by the virus.

Removed the files manually in fail-safe mode. Recreated next boot...

Removed the regfiles in RUN (run-->regedit), so that they won't be started when comp boots. Reg keys also recreated.

Had to rename Kaspersky and Hijackthis in order to run them, program seemed to block these by their name.

File names which I suspect are involved are:

wini10731.exe (C:\WINDOWS\system32)

brastk.exe (C:\WINDOWS and C:\WINDOWS\system32)

msauc.exe (C:\WINDOWS (not recreated by some reason))

karna.dat (C:\WINDOWS and C:\WINDOWS\system32)

And the autostart regfiles for brastk.exe (recreated) and msauc.exe (not recreated).

I think I got this via firefox googling for images..

Hijackthis log inclued

File Attachment :
hijackthis1.log   19KB (application/octet-stream)
This file has been downloaded 84 time(s).
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 10-11-2008 6:54 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
Hello smile


Go to add/remove programs in controlpanel, and remove:

LogitechDesktopMessenger

 
Reboot normally ->
 
and save it on the desktop. Then double click on it (Fix_download.exe).
You may have to allow the program to download files from the web! 

The program download the necessary cleaning programs. Once the program 
is downloaded, there will be a folder on your desktop named 
Fix.   – if the instructions not automatically opens, so 
double-click "FIX_manual.htm" in Fix folder. 

Please follow the instructions and copy the logs here,
in this Topic:
 
Note : Fix_download.exe is detected by some antivirus programs  as a "RiskTool" /infection; it is not a virus. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

 

 If necessary, temporarily disable your anti-virus, real-time protection before downloading
 



Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

ii-ii-iii
New Member


Date Joined Oct 2008
Total Posts : 7
 
   Posted 10-12-2008 12:19 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
Thanks a lot! I'll try that asap.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 10-12-2008 7:00 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
Ok. Please don´t attach the files - Thank You


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

ii-ii-iii
New Member


Date Joined Oct 2008
Total Posts : 7
 
   Posted 10-12-2008 1:42 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
Forgot about that. How stupid of me blush

I ran the fix kit, malwarebytes removed 14 items. In all my eagerness I forgot to save the logfile. It said that the deletes were successful, though I still suspect something is wrong. As I cannot run hjt by it's real name. Had it renamed "1.exe" to run it..
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 10-12-2008 2:20 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
Ok, please post combofix log and a log from hijackthis (1.exe) ;-)


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

ii-ii-iii
New Member


Date Joined Oct 2008
Total Posts : 7
 
   Posted 10-12-2008 6:28 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
Thanks once again!

I'll post the logs as soon as I can. Though as I wrote before, I didn't save the log from malwarebytes..forgot : sad Ran a scan once again but this time it was clean. Although I can see through hjt that it isn't.
Back to Top
 

ii-ii-iii
New Member


Date Joined Oct 2008
Total Posts : 7
 
   Posted 10-13-2008 1:52 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
I just booted my comp and noticed that I can now run hjt under it's rightful name. Everything seems to be in order. Thanks very much!
Back to Top
 

ii-ii-iii
New Member


Date Joined Oct 2008
Total Posts : 7
 
   Posted 10-13-2008 1:54 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
I just booted my comp and noticed that I can now run hjt under it's rightful name. Everything seems to be in order. Thanks very much!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 10-13-2008 4:32 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
That´good news smile
 
 
If you want Me to check, please post the other log fiels


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

ii-ii-iii
New Member


Date Joined Oct 2008
Total Posts : 7
 
   Posted 10-13-2008 6:30 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
I've checked them and everything seems ok. But I'll give you a tell if I discover something. Thanks for the offer! blush
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13812
 
   Posted 10-14-2008 8:19 (GMT +1)    Quote: Help with strange virus please!Alert an admin about: Help with strange virus please!
Please do


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 
New Topic Post reply to : Help with strange virus please! Printable version of : Help with strange virus please!
 
Forum Information
Currently it is Wednesday, December 03, 2008 7:00 AM (GMT +1)
There are a total of 64.512 posts in 15.910 threads.
In the last 3 days there were 19 new threads and 77 reply posts. View Active Threads
Who's Online
This forum has 27326 registered members. Please welcome our newest member, DooN.
40 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Help with a (win32 trojan gen other) (0)03-12-2008 02:25:45 (finz)
Ok...I'm infected, now what? (24)03-12-2008 02:11:28 (Zalen)
Antivirus disabled/URL Redirect Malware.Wont let me install MALEWAREBYTES (3)03-12-2008 02:08:19 (cgamm)
Trojan Horse Generic 12.KAO (5)03-12-2008 02:01:58 (Taryn)
No Safe Mode, explorer.exe crashes, no internet (0)03-12-2008 00:49:20 (roygbp)