{"id":465,"date":"2008-11-18T11:37:08","date_gmt":"2008-11-18T19:37:08","guid":{"rendered":"http:\/\/www.gamerabaenre.com\/?p=465"},"modified":"2008-11-18T11:37:08","modified_gmt":"2008-11-18T19:37:08","slug":"viruses-are-fun","status":"publish","type":"post","link":"https:\/\/gamerabaenre.com\/?p=465","title":{"rendered":"Viruses are fun&#8230;"},"content":{"rendered":"<p>Last night, I went to grab the day&#8217;s O&#038;A show off the mininova torrent site.  It&#8217;s not there, so I run off to the other site that usually has all the shock jock shows (O&#038;A, Ron &#038; Fez, etc) and I&#8217;m not sure if I picked up the bug here, or somewhere else; but the bloody computer sneezed&#8230;. *sigh* Time to start up the usual clean up and hack tools.  Attempt to run <a href=\"http:\/\/en.wikipedia.org\/wiki\/Hijackthis\">hijackthis<\/a> or <a href=\"http:\/\/en.wikipedia.org\/wiki\/Malwarebytes\">MalwareBytes <\/a>; and got nothing&#8230;. this is gonna be a fun night.<\/p>\n<p><!--more--><\/p>\n<p>In my task tray, there is a nice new icon, a red dot with an X.  Any attempt to click on the bloody thing brings up an &#8220;XP antivirus pro 2009&#8221; program.  This is a fake anti virus program.  It hits the browsers, as searches through google, while they pull up legit links and addresses. clicking on them only redirects to some odd search pages &#8211; so nothing useful.  It would also reboot.  So my computer for all intents and purposes is dead in the water. <\/p>\n<p>It is interesting that hijackthis and malwarebytes are not running.  I pot up the task manager and watch the processes tab, and then click on hijackthis and malware again.  Malwarebytes just runs, and is in limbo; while hijackthis is no where to be found.  Acrord32info pops up however, since there are no adobe acrobat programs running, it looks like hijackthis is being restricted and run as acrord32info; how cute.  I shut down and restart in safe mode.<\/p>\n<p>Attempts to run the cleaner programs again result in nothing.  I take a look in my \/windows\/system32 for new files created that day, and lo and behold, I find braskt.exe, karna.dat and a few other unsavory things.  Deleted.  A search for the two files on the machine are done and I remove all instances.  Reboot, and the virus is back again.  Next up, I rename the hijackthis executable and run it, it runs.  Awesome, the bug actually has a redirect to restrict a list of programs from being run.  With hijackthis up, I find the karna.dat problem and delete it, there isn&#8217;t the braskt executable so this is odd.  Malwarebytes still refuses to run.  I grab <a href=\"http:\/\/en.wikipedia.org\/wiki\/Ccleaner\">ccleaner <\/a> and try ti install it.  Nothing.  I rename the setup file and it runs.  Executing ccleaner, I find the braskt executable, but not the karna.dat.  Damn, the little bug is pretty bloody savvy; I&#8217;m impressed.<\/p>\n<p>It is a good thing I have a second computer as all my research and software downloads were done using the second computer.  The desktop was just dead in the water.  So in safe mode it stayed.  After running ccleaner and hijackthis, the computer was restarted, and the red dot with the X was still there.  Running hijackthis and ccleaner; braskt and karna returned.  Oh goodie, there&#8217;s a rootkit too.  And now it&#8217;s back to the drawing board.<\/p>\n<p>Time to bring out the relief&#8230; <a href=\"http:\/\/www.bleepingcomputer.com\/forums\/topic131299.html\">SDfix<\/a> was called up from the bullpen.  Downloaded from my useable machine and then put onto the desktop, the program was run.  Following the instructions from the above link, and once rebooted, the lovely red dot and X are now gone from the task tray.  hijackthis and ccleaner are run, and nothing unusual or suspect is turned up.  Malwarebytes is executable now, and set to scan.  <\/p>\n<p>All said and done, the little nasty buggers were removed and the computer is back to normal.  It was a bit of a pain in the ass as the damn bugs are getting pretty impressive with a higher intellect.  The battle between good and evil wages on; and balance is once again restored to the force.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last night, I went to grab the day&#8217;s O&#038;A show off the mininova torrent site. It&#8217;s not there, so I run off to the other site that usually has all the shock jock shows (O&#038;A, Ron &#038; Fez, etc) and I&#8217;m not sure if I picked up the bug here, or somewhere else; but the [&hellip;]<\/p>\n","protected":false},"author":222,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"ocean_post_layout":"","ocean_both_sidebars_style":"","ocean_both_sidebars_content_width":0,"ocean_both_sidebars_sidebars_width":0,"ocean_sidebar":"","ocean_second_sidebar":"","ocean_disable_margins":"enable","ocean_add_body_class":"","ocean_shortcode_before_top_bar":"","ocean_shortcode_after_top_bar":"","ocean_shortcode_before_header":"","ocean_shortcode_after_header":"","ocean_has_shortcode":"","ocean_shortcode_after_title":"","ocean_shortcode_before_footer_widgets":"","ocean_shortcode_after_footer_widgets":"","ocean_shortcode_before_footer_bottom":"","ocean_shortcode_after_footer_bottom":"","ocean_display_top_bar":"default","ocean_display_header":"default","ocean_header_style":"","ocean_center_header_left_menu":"","ocean_custom_header_template":"","ocean_custom_logo":0,"ocean_custom_retina_logo":0,"ocean_custom_logo_max_width":0,"ocean_custom_logo_tablet_max_width":0,"ocean_custom_logo_mobile_max_width":0,"ocean_custom_logo_max_height":0,"ocean_custom_logo_tablet_max_height":0,"ocean_custom_logo_mobile_max_height":0,"ocean_header_custom_menu":"","ocean_menu_typo_font_family":"","ocean_menu_typo_font_subset":"","ocean_menu_typo_font_size":0,"ocean_menu_typo_font_size_tablet":0,"ocean_menu_typo_font_size_mobile":0,"ocean_menu_typo_font_size_unit":"px","ocean_menu_typo_font_weight":"","ocean_menu_typo_font_weight_tablet":"","ocean_menu_typo_font_weight_mobile":"","ocean_menu_typo_transform":"","ocean_menu_typo_transform_tablet":"","ocean_menu_typo_transform_mobile":"","ocean_menu_typo_line_height":0,"ocean_menu_typo_line_height_tablet":0,"ocean_menu_typo_line_height_mobile":0,"ocean_menu_typo_line_height_unit":"","ocean_menu_typo_spacing":0,"ocean_menu_typo_spacing_tablet":0,"ocean_menu_typo_spacing_mobile":0,"ocean_menu_typo_spacing_unit":"","ocean_menu_link_color":"","ocean_menu_link_color_hover":"","ocean_menu_link_color_active":"","ocean_menu_link_background":"","ocean_menu_link_hover_background":"","ocean_menu_link_active_background":"","ocean_menu_social_links_bg":"","ocean_menu_social_hover_links_bg":"","ocean_menu_social_links_color":"","ocean_menu_social_hover_links_color":"","ocean_disable_title":"default","ocean_disable_heading":"default","ocean_post_title":"","ocean_post_subheading":"","ocean_post_title_style":"","ocean_post_title_background_color":"","ocean_post_title_background":0,"ocean_post_title_bg_image_position":"","ocean_post_title_bg_image_attachment":"","ocean_post_title_bg_image_repeat":"","ocean_post_title_bg_image_size":"","ocean_post_title_height":0,"ocean_post_title_bg_overlay":0.5,"ocean_post_title_bg_overlay_color":"","ocean_disable_breadcrumbs":"default","ocean_breadcrumbs_color":"","ocean_breadcrumbs_separator_color":"","ocean_breadcrumbs_links_color":"","ocean_breadcrumbs_links_hover_color":"","ocean_display_footer_widgets":"default","ocean_display_footer_bottom":"default","ocean_custom_footer_template":"","jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"ocean_post_oembed":"","ocean_post_self_hosted_media":"","ocean_post_video_embed":"","ocean_link_format":"","ocean_link_format_target":"self","ocean_quote_format":"","ocean_quote_format_link":"post","ocean_gallery_link_images":"on","ocean_gallery_id":[],"footnotes":""},"categories":[149],"tags":[346,350,351,347,352,349,348],"class_list":["post-465","post","type-post","status-publish","format-standard","hentry","category-mindless-ramblings","tag-braskt","tag-ccleaner","tag-hijackthis","tag-karna","tag-malwarebytes","tag-sdfix","tag-virus-removal","entry","owp-thumbs-layout-horizontal","owp-btn-normal","owp-tabs-layout-horizontal","has-no-thumbnails","has-product-nav"],"aioseo_notices":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p7qf6-7v","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=\/wp\/v2\/posts\/465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=\/wp\/v2\/users\/222"}],"replies":[{"embeddable":true,"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=465"}],"version-history":[{"count":0,"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=\/wp\/v2\/posts\/465\/revisions"}],"wp:attachment":[{"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gamerabaenre.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}