Hello boys and girls, hope I come close to doing this right.
I have a lot to say and ask.
WindowsXPHome SP2.
Scenario.
Clicked on a image, doing a search, I thought I recognized the site and would
be safe, NOT.
Avast! popped up saying Alert was “HIGH” it was a “Figaro.sys” file
(I read one post here on this).
saying,
Sign of “Win32:Agent-QNI[trj]” Has been found in “C:\WINDOWS\system\dllcache\figaro.sys” file.
I accidentally “told avast to delete it”, (was going to move it to the chest,
but the click time lagged on my computer or something).
Right after I did that, my system rebooted.
as it booted and got to the desktop (I have Msconfig set to show every time)
I noticed in MSCONFIG 2 new entries both named the same,
“brastk”, “C:\WINDOWS\system32\brastk.exe”.
I unchecked them both hit ok etc, and then Windows Defender pops up.
“TrojanDownloader:Win32/Renos” Aler level HIGH, I told it to remove it.
Then I think it started a scan automatically, and found,
The same Trojan as above but this time since defender was scanning I was
able to see the file and directory it was referring to, which was the above,
“C:\WINDOWS\system32\brastk.exe”.
I told it to remove it.
Then I had to do some manual scanning, I did 2 or 3 Quick scans, each time
finding something a little different.
Then it found a
“TrojanDownloader:Win32/FakeRean.gen!C” Alert level HIGH.
Referring to the file and directory,
“C:WINDOWS\system32\wini101982.exe”.
I told it to remove it.
Then it found my home page has been changed,
from google to google, BUT I never ever had google as my home page,
So I told it not to allow it, I opened up Intner options and deleted the info
for the home page closed and did another quick scan and it found it again.
So I did it again then it was okay, I set it back to my page I use.
I have not used this computer or shut it down yet.
I did a FULL scan with the Heuristic search archives and all that with Defender
it appears okay.
Then I did a FULL thorough, Scan archives, heuristic etc scan with Avast.
Which took about 12 hours for 30 GB. of files on a 60GB Hard drive.
AND I think I want this to be another post, because it found some files
I downloaded, and I think they are FP’s, plus I have a question about
Avasts scanning fo downloads, and manually scanning local drives.
So anyway AVAST! only found these 4 files that I had in my Documents,
That I think are FP’S. Other than the original FIGARO.SYS it found.
I did quarantine the 4 files i think are FP’s, for the moment until I do other
scans and research etc.
So I searched using the basic start menu search function,
which I have set to search all files and folders hidden and system etc etc,
for the 3 files I have noted.
Figaro.sys (Not found in system)
brastk.exe (Not found in system)
wini101982.exe (Not found in system)
I opened back up MSCONFIG and I still see 1 Entry of,
“brastk”, “C:\WINDOWS\system32\brastk.exe”.
There were 2, I want to remove this from the MSCONFIG, HOW ?
I also did a search of the registry for “brastk”,
and The first one it found is located in the
CURRENT_USER\Software\microsoft\Windows\ShellNoRoam\MUICache,
and it is the, C:\WINDOWS\system32\brastk.exe,
And I think I want to delete this entry yes ?
SO FAR this is where I am.
Any help Would be GREATLY appreciated.
I was thinking about doing a system restore (I have never done this)
But I want to if it will delete any files I have downloaded or made since the last
Creation of a restore point ?
or only programs installed since then ?
which I don’t have any programs I have installed since then so…
I don’t even know if this is a necessary step.
Oh as a side note (maybe)
When I was searching for the files I also went to the system32 folder manually
and looked didn’t find anything BUT, I noticed something I have not noticed
before which are a bunch of 64.5 Kb, NLS files, apparently all created at the same time about a year ago and start with the letter
“c_” and some number. So I say these are nothing. just funny I didn’t notice
those before, I try to pay attention But I am broke quite often
7 children
Okay Sorry, back to, So what do i do next ?