Results 1 to 5 of 5

Thread: Infected with karna.dat - any help much appreciated

  1. #1
    nick s Guest

    Infected with karna.dat - any help much appreciated

    Hi guys,

    I was wondering if anyone could assist me with this most frustrating and
    nasty rootkit/virus that installed itself on my system through an active x
    photoshop tutorial !
    It restarted my PC and when it re-booted, I had a little white "X" on a
    circular red background in my system tray in the lower right of my screen,
    and this launched a little bubble saying "Your computer is infected! Windows
    has detected a spyware infection! It's recommended to use special
    antispyware tools to pervent (sic) data loss. Windows will now download and
    install the most up-to-date antispyware for you. Click here to protect your
    computer from spyware!" Notice that the message spelled "prevent"
    incorrectly...an obvious indicator that there was something malicious going
    on. Also, whenever I clicked the "close" icon for this message, it would
    simply pop right back up after a few seconds from the system tray.
    I have since found this to be a variant of the brastk.exe virus and have
    managed to remove this pop up from my desktop by finding instances of it in
    Windows , and Sys 32 and also the registry and deleting them.

    However, what ever came bundled with this virus is re-directing all of my
    Google searches using sites such as web-analytics, go-google.com among many
    others. Pages therefore won't load, and I've found that newly installed
    programs will not even run, making malwarebytes and other known fixers of
    such problems impossible.
    I finally managed to get Hijack This to work, by re-installing it on another
    drive. It created a log file that showed something called Karna.dat present.
    Installing other programs onto this drive, do not work though.

    This virus also disables my AVG anto virus from updating, aswell as Adaware.

    A reformat is absolutely my last option, and I'm sure there is a way of
    eradicating this from my system , I just don't have the knowledge do do it.
    I've already spent 2 days on this thing , so any help would be hugely
    appreciated.

    I've been getting some help from a friend who has helped me out in the past,
    but this is a time consuming thing , and I feel like I should throw this out
    to some other tech savvy folks and give this poor person a rest .

    Thanks

    Nick







  2. #2
    nick Guest

    Re: Infected with karna.dat - any help much appreciated

    I've spent the last 2 days on Google via another machine, hence me posting
    here as a last resort.
    Thanks for the links though. I seem to have erradicated most of the
    problems..for now


    "Emil Tiades" <emiltiades@marathon.org> wrote in message
    news:gfeurl$bas$1@aioe.org...
    >
    > On Wed, 12 Nov 2008 09:14:15 -0600, "nick s" <n@home.net> wrote:
    >
    >>Hi guys,
    >>
    >>I was wondering if anyone could assist me with this most frustrating and
    >>nasty rootkit/virus that installed itself on my system through an active x
    >>photoshop tutorial !

    >
    > less than 1 second with google
    > http://www.google.co.uk/search?hl=en...+removal&meta=
    >
    > 2 seconds with google
    > http://forums.majorgeeks.com/showthread.php?t=173220
    >




  3. #3
    siljaline Guest

    Re: Infected with karna.dat - any help much appreciated

    Download and run HijackThis;
    (http://www.trendsecure.com/portal/en...age=hijackthis)
    Read this Tutorial *before* first use;
    (http://www.bleepingcomputer.com/foru...howtutorial=42)
    Once done > run HijackThis > save a scan log and post it to /any/ of the
    following (expert) forums for analysis.
    *Note, //registration// *is* required prior to posting a log.

    - Not listed in any particular order -

    (http://forum.securitycadets.com/index.php?showforum=2)
    (http://forums.spywareinfo.com/index.php?&showforum=18)
    (http://www.spywarewarrior.com/viewforum.php?f=5)
    (http://www.bleepingcomputer.com/forums/forum22.html)
    (http://www.dslreports.com/forum/cleanup)
    (http://forum.malwareremoval.com/viewforum.php?f=11)
    (http://www.cybertechhelp.com/forums/...splay.php?f=25)
    (http://www.atribune.org/forums/index.php?showforum=9)
    (http://spywarehammer.com/simplemachi...php?board=10.0)
    (http://www.geekstogo.com/forum/Malwa..._Here-f37.html)
    (http://forums.spywareinfo.com/index.php?showforum=18)
    (http://www.techmonkeys.co.uk/forums/viewforum.php?f=8)
    (http://forum.networktechs.com/forumdisplay.php?f=130)
    (http://forums.maddoktor2.com/index.php?showforum=17)
    (http://forums.spywaretimes.com/index.php?showforum=2)
    (http://www.bluetack.co.uk/forums/ind...?showforum=172)
    (http://forums.techguy.org/f54-s.html)
    (http://forums.tomcoyote.org/index.php?showforum=27)
    (http://forums.subratam.org/index.php?showforum=7)
    (http://www.5starsupport.com/ipboard/...p?showforum=18)
    (http://www.malwarebytes.org/forums/i...hp?showforum=7)
    (http://www.wilderssecurity.com/forumdisplay.php?f=26)
    (http://makephpbb.com/phpbb/viewforum.php?f=2)
    (http://forums.techguy.org/54-security/)
    (http://forums.security-central.us/forumdisplay.php?f=13)
    (http://castlecops.com/forum67.html)
    (http://gladiator-antivirus.com/forum...?showforum=170)
    (http://www.lavasoftsupport.com/index.php?showforum=36)
    (http://forum.piriform.com/index.php?showforum=12)
    (http://aumha.net/viewforum.php?f=30)
    (http://www.castlecops.com/f67-Trend_...This_Logs.html)

    Post back the URL where you posted your log, *not* the entire log.

    Silj

    --
    "Arguing with anonymous strangers on the Internet is a sucker's game
    because they almost always turn out to be -- or to be indistinguishable from
    -- self-righteous sixteen-year-olds possessing infinite amounts of free time."
    - Neil Stephenson, _Cryptonomicon_



  4. #4
    nick Guest

    Re: Infected with karna.dat - any help much appreciated

    Thanks, I ended up solving this using Avenger and Malwarebytes.


    "siljaline" <spam@uce.gov> wrote in message news:gff2og$qub$1@aioe.org...
    Download and run HijackThis;
    (http://www.trendsecure.com/portal/en...age=hijackthis)
    Read this Tutorial *before* first use;
    (http://www.bleepingcomputer.com/foru...howtutorial=42)
    Once done > run HijackThis > save a scan log and post it to /any/ of the
    following (expert) forums for analysis.
    *Note, //registration// *is* required prior to posting a log.

    - Not listed in any particular order -

    (http://forum.securitycadets.com/index.php?showforum=2)
    (http://forums.spywareinfo.com/index.php?&showforum=18)
    (http://www.spywarewarrior.com/viewforum.php?f=5)
    (http://www.bleepingcomputer.com/forums/forum22.html)
    (http://www.dslreports.com/forum/cleanup)
    (http://forum.malwareremoval.com/viewforum.php?f=11)
    (http://www.cybertechhelp.com/forums/...splay.php?f=25)
    (http://www.atribune.org/forums/index.php?showforum=9)
    (http://spywarehammer.com/simplemachi...php?board=10.0)
    (http://www.geekstogo.com/forum/Malwa..._Here-f37.html)
    (http://forums.spywareinfo.com/index.php?showforum=18)
    (http://www.techmonkeys.co.uk/forums/viewforum.php?f=8)
    (http://forum.networktechs.com/forumdisplay.php?f=130)
    (http://forums.maddoktor2.com/index.php?showforum=17)
    (http://forums.spywaretimes.com/index.php?showforum=2)
    (http://www.bluetack.co.uk/forums/ind...?showforum=172)
    (http://forums.techguy.org/f54-s.html)
    (http://forums.tomcoyote.org/index.php?showforum=27)
    (http://forums.subratam.org/index.php?showforum=7)
    (http://www.5starsupport.com/ipboard/...p?showforum=18)
    (http://www.malwarebytes.org/forums/i...hp?showforum=7)
    (http://www.wilderssecurity.com/forumdisplay.php?f=26)
    (http://makephpbb.com/phpbb/viewforum.php?f=2)
    (http://forums.techguy.org/54-security/)
    (http://forums.security-central.us/forumdisplay.php?f=13)
    (http://castlecops.com/forum67.html)
    (http://gladiator-antivirus.com/forum...?showforum=170)
    (http://www.lavasoftsupport.com/index.php?showforum=36)
    (http://forum.piriform.com/index.php?showforum=12)
    (http://aumha.net/viewforum.php?f=30)
    (http://www.castlecops.com/f67-Trend_...This_Logs.html)

    Post back the URL where you posted your log, *not* the entire log.

    Silj

    --
    "Arguing with anonymous strangers on the Internet is a sucker's game
    because they almost always turn out to be -- or to be indistinguishable from
    -- self-righteous sixteen-year-olds possessing infinite amounts of free
    time."
    - Neil Stephenson, _Cryptonomicon_




  5. #5
    siljaline Guest

    Re: Infected with karna.dat - any help much appreciated

    nick wrote:
    > Thanks, I ended up solving this using Avenger and Malwarebytes.

    Good to hear - appreciate the post-back.

    Silj


    --
    "Arguing with anonymous strangers on the Internet is a sucker's game
    because they almost always turn out to be -- or to be indistinguishable from
    -- self-righteous sixteen-year-olds possessing infinite amounts of free time."
    - Neil Stephenson, _Cryptonomicon_


Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •