Norton Internet Security / Norton AntiVirus
Register  ·  Sign In  ·  Help
Jump to Page:   1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 · 9 · »  |  Next Page
Trojan - Major problems : brastk.exe
Options    Options  
kavanb6930
Visitor
Posts: 6
Registered: 10-19-2008


kavanb6930

Message 1 of 121

Viewed 42,810 times


This nasty little bugger hijacks your machine and stops you from accessing Norton, Mcafee or any spyware scanning websites. It even stops norton from starting up.

 

I can't believe there's no mention of it yet on this forum!or even in Symantecs security alerts!!!!

 

I got it by aclicking 'allow this instance'  for access to my pc. I thought it was the site 'Savefile' where I was getting a U2 video from asking so in a moment of weakness I said 'allow this instance' 2-3 times.  

 

It started by rebooting my pc, then on restart of windows, puts a red X in your active icons with a message saying your computer has been infected! no kidding!!!!!!!

 

It puts a few files on your pc :  brastk.exe and karna.dat in both c:\Windows and c:\windows\system32 and svchost.exe in c:\windows\system32\drivers. 

 

I killed it by rebooting in Safe mode and ran  a process I downloaded called Brastkremover.exe that I got from here

 

 After that, i removed all entries for brastk.exe and karna.dat that were still left in the registry and the files that were still left in windows\system32. (My boot drive is a D:\ so maybe the tool didn't fully remove it.).

 

I then rebooted and it's appeared mostly gone (No RED 'X') but I still could not go to symantec's website but  at least norton started up. I ran a quickscan and it found 'Backdoor.Tidserv'. After that I could get to the website.

 

I hope this helps someone else.

 

 

 

 

 

 

 

 

 

 

Kudos!
10-19-2008 10:40 AM

All Users' Tags:

 
Re: Trojan - Major problems : brastk.exe
Options    Options  
Floating_Red
Super Bot Obliterator
Posts: 4261
Registered: 05-30-2008



Message 2 of 121

Viewed 41,569 times


01. What Norton Product and Version are you using, e.g. N.I.S. 2009?

02. Removal instructions for Backdoor.Tidserv: http://www.symantec.com/security_response/writeup.jsp?docid=2008-091809-0911-99&tabid=3.

03. If there is any indication of another Threat on your computer, please Post the exact Threat Name.

04. Run a Full System Scan in Safe Mode, with Updated Virus Definitions.

05. If none of the Steps have worked, please click on this Web Link: http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html.  Download, install, Update, and Run a Full Scan in Safe Mode.

06. Let us know the Results of the Scans.


 

Tuesday, November 17, 2009: The ThreatCon was Changed to Level 1: Normal | Sunday, November 01, 2009: There has been a huge increase in the Global Threat Activity, which appears to be Targetting the S.M.B.v.2 Remote-Code Exectuation Vulnerability.  Keep Anti-Virus Products up-to-date and install all available Patches. | Microsoft have Released their November Patches.
Kudos!
10-19-2008 12:35 PM
 
Re: Trojan - Major problems : brastk.exe
Options    Options  
Tech0utsider
Regular Contributor
Posts: 1451
Registered: 07-29-2008


Tech0utsider

Message 3 of 121

Viewed 41,512 times


Download Norton Antibot:

 

http://www.pcworld.com/downloads/file_download/fid,67195-order,4-page,1-c,antivirussecurity/download.html

 

It should flag the process as malicious and quarientine it. 


 

=\
Kudos!
10-19-2008 03:26 PM
 
Re: Trojan - Major problems : brastk.exe
Options    Options  
Tech0utsider
Regular Contributor
Posts: 1451
Registered: 07-29-2008


Tech0utsider

Message 4 of 121

Viewed 41,457 times



kavanb6930 wrote:

This nasty little bugger hijacks your machine and stops you from accessing Norton, Mcafee or any spyware scanning websites. It even stops norton from starting up.

 

I can't believe there's no mention of it yet on this forum!or even in Symantecs security alerts!!!!

 

I got it by aclicking 'allow this instance'  for access to my pc. I thought it was the site 'Savefile' where I was getting a U2 video from asking so in a moment of weakness I said 'allow this instance' 2-3 times.  

 

It started by rebooting my pc, then on restart of windows, puts a red X in your active icons with a message saying your computer has been infected! no kidding!!!!!!!

 

It puts a few files on your pc :  brastk.exe and karna.dat in both c:\Windows and c:\windows\system32 and svchost.exe in c:\windows\system32\drivers. 

 

I killed it by rebooting in Safe mode and ran  a process I downloaded called Brastkremover.exe that I got from here

 

 After that, i removed all entries for brastk.exe and karna.dat that were still left in the registry and the files that were still left in windows\system32. (My boot drive is a D:\ so maybe the tool didn't fully remove it.).

 

I then rebooted and it's appeared mostly gone (No RED 'X') but I still could not go to symantec's website but  at least norton started up. I ran a quickscan and it found 'Backdoor.Tidserv'. After that I could get to the website.

 

I hope this helps someone else.

 


Upload those leftover files to Virustotal.com and tell us the results and general consensus of the AV engines. 

 

Also, what version of Norton are you using? 


 

=\
Kudos!
10-19-2008 03:28 PM
 
Re: Trojan - Major problems : brastk.exe
Options    Options  
jAW
Super Contributor
Posts: 107
Registered: 05-19-2008


jAW

Message 5 of 121

Viewed 41,455 times


Hi,

 

Good that you managed to solve the problem and that you share your experience. The brastk is a variant of Trojan.Virantix.C.

 

 

jAW

Kudos!
10-19-2008 03:31 PM
 
Re: Trojan - Major problems : brastk.exe
Options    Options  
johna Super Spam Squasher
Super Spam Squasher
Posts: 900
Registered: 07-01-2008


johna

Message 6 of 121

Viewed 41,365 times


Hi kavanb6930

 

SONAR should have picked that up if you were using NIS09, which version are you running?

 

Thanks

Kudos!
10-19-2008 08:55 PM
 
Re: Trojan - Major problems : brastk.exe
Options    Options  
kavanb6930
Visitor
Posts: 6
Registered: 10-19-2008


kavanb6930

Message 7 of 121

Viewed 41,211 times


Hi . sorry for the delay .

 

I'm using NIS 2008. I hadnt as yet updated to NIS2009 but I have been keeping uptodate with liveupdates.

 

 I'm still getting the svchost trying to conenct to the itnernet but i put a block always on it now.

 

So i still have remnants.

 

 

 

Kudos!
10-20-2008 04:21 AM
 
Re: Trojan - Major problems : brastk.exe
Options    Options  
Dieselman743
Regular Contributor
Posts: 1909
Registered: 09-11-2008


Dieselman743

Message 8 of 121

Viewed 41,208 times


Do not block svchost. Its part of Windows and needs to be allowed. Sometimes malware can hide has an svchost but aslong as your system is clean then allow it. I have it allowed on my machines but outgoing only.
 

Real Time Protection = NIS 2009 + NAT
Behavior Analysis = Threatfire
On Demand = MBAM
Kudos!
10-20-2008 04:24 AM
 
Re: Trojan - Major problems : brastk.exe   [ Edited ]
Options    Options  
johna Super Spam Squasher
Super Spam Squasher
Posts: 900
Registered: 07-01-2008


johna

Message 9 of 121

Viewed 41,198 times


Hi kavanb6930

 

I advise you to update to NIS09 (for free) through the Norton Update Centre, and let us know if you are still experiencing any problems.

 

Thanks

Message Edited by johna on 10-20-2008 09:39 PM
Kudos!
10-20-2008 04:30 AM
 
Re: Trojan - Major problems : brastk.exe   [ Edited ]
Options    Options  
kavanb6930
Visitor
Posts: 6
Registered: 10-19-2008


kavanb6930

Message 10 of 121

Viewed 41,170 times


Ive uploaded the file to virustotal but they already had it. i reanalysed anyway and click below for the results.

 

http://www.virustotal.com/analisis/2385f3ce72187c12d6769c965016ba85

 

Symantec says this is thew 'very low' risk fakeavalert.

 

I don't consider a malware that hijacks all my web queries and blocks every virus scan and spyware website a 'very low' risk!!!!!! Symantec needs to get in gear!!!

 

I just did a chat with them and got some useless guy trying to sell me services to 'clean my pc' with 30 days followup support. I told him 3 times i did not need it andf he still tried to sell it to me. Talk about annoying!!!!!

 

 

 

[edit: removed unnecessary word .]


Message Edited by Allen_K on 10-20-2008 04:50 PM
Kudos!
10-20-2008 05:00 AM
 
Jump to Page:   1 · 2 · 3 · 4 · 5 · 6 · 7 · 8 · 9 · »  |  Next Page