BRASTIA - how can I...
 

MegaSack DRAW - This year's winner is user - rgwb
We will be in touch

[Closed] BRASTIA - how can I kill it once and for all?

13 Posts
10 Users
0 Reactions
75 Views
Posts: 2
Free Member
Topic starter
 

I'm salvaging a pc from months of t'interweb usage with no proper AV/Spyware. The owner/muppet downloaded Antivirus Agent Pro which is a fake virus remover which forces users to coff up for fake updates.
It's almost there, but this bastard trojan keeps reappearing and stopping Kasp and SpybotS&D from opening. Reinstalls do nothing. PC Tools Spyware Doctor is the only thing that'll run but it's not picking up the cause of brastia.exe

help


 
Posted : 08/07/2009 8:10 am
Posts: 7337
Free Member
 

try Spybot.


 
Posted : 08/07/2009 8:15 am
Posts: 0
Free Member
 

Sounds like you have a DNS server Trojan dude


 
Posted : 08/07/2009 8:20 am
Posts: 5936
Full Member
 

Why not just do a full OS install ?


 
Posted : 08/07/2009 8:21 am
Posts: 0
Free Member
 

There are specific removal tools for that - google them
I'd do as lowey suggests though - make sure you format all discs & partitions


 
Posted : 08/07/2009 8:23 am
Posts: 41688
Free Member
 

2nd formatting and re-install, my HDD's on its last legs so gets that treatment anyway every few months.


 
Posted : 08/07/2009 8:27 am
Posts: 2
Free Member
Topic starter
 

a bit of success!!!

I noticed an uberdodgy looking file in the main Spybot folder. I deleted it but before I had returned from the recycle bin another dodgy had appeared. I renamed the main Spybot prog file, deleted the new dodgy and then was able to open Spybot, hoorah. It's checking and immunizing it's life away now. Same trick hasn't worked for Kasp. I'll keep you posted.


 
Posted : 08/07/2009 8:47 am
Posts: 2
Free Member
Topic starter
 

boogies found so far inc:

smitfraud
virantix
agentpz
mywebsearch

and bunch of other cack in the reg which has now been fixed

still hunting!


 
Posted : 08/07/2009 8:55 am
Posts: 356
Full Member
 

You could also try ComboFix, though depending on what you've got you're 'fake' AV could try and pretend that it's malware and not let you get to the site - If so, let me know and I'll host it somewhere for you to grab a copy of it.


 
Posted : 08/07/2009 9:19 am
Posts: 7925
Free Member
 

Take off and nuke the site from orbit - only way to be sure.

Or, a re-partition and format of all affected drives. Software is fine as a shield during operation, but you can't trust it for a deep clean IMO.


 
Posted : 08/07/2009 9:28 am
Posts: 41395
Free Member
 

Scienceofficer - Member
Take off and nuke the site from orbit - only way to be sure.

Ace quote - Aliens?


 
Posted : 08/07/2009 9:53 am
Posts: 10860
Full Member
 

[url=

yes[/url]


 
Posted : 08/07/2009 10:03 am
Posts: 2
Free Member
Topic starter
 

Just got to get rid of agent pz now. Hopefully Kasp will start working again after that.

Agreed though, I doubt it'll be completey clean again.


 
Posted : 08/07/2009 10:39 am
Posts: 2
Free Member
Topic starter
 

new update: SDfix has got Kasp working again. RegMechanic has closed some of the holes. There are still bugs but they're being dealt with. Annoyingly brastia still appears in the start.ini and will continue to do so until I can find the system files that have been buggered.


 
Posted : 09/07/2009 9:52 am