braviax.exe take over

Discussion in 'Malware Help (A Specialist Will Reply)' started by FilthyFletch, Mar 13, 2008.

  1. FilthyFletch

    FilthyFletch Private E-2

    Well I got the braviax infection.I tried to et it out but after a few tries I can no longer even boot correctly. I can get to the desktop then I cant do anything else. The hour glass keeps turning and half the desktop icons dont load just show broken images.I tried to go to safe mode and I get to the desktop and then it disappears and its just a blank screen. I managed to run a few anti virus and spyware programs before this freeze out and removed a bunch of stuff that was loaded but now I cant do much of anything. When I go to shut down the error message about braviax.exe encountered a problem comes up then the same message saying explorer encountered the problem also .The only way to shut down is to hold the power button...Someone please help me..is there a auto remove I can put on a floppy or somthing to get it out or at least to get back into the system..Not sure if its related but on occassion when I try to reboot I get a short quick message before the windows splash page that looks to be inrussian or german but its up for only a few seconds then the windows splash comes up..Originally I got the red circlew ith the x and the winanamator trying to install...
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What exactly did you do and can you undo it. It will be rather impossible for us to help you if you cannot even boot into Windows in normal or safe mode to run anything. Can you bring up Task Manager and get things to run (like your browser to download files) from Task Manager? Also look in Task Manager to see if any processes are hogging the CPU and try to kill them. Even in safe mode with no Desktop, you still may be able to run Task Manager.

    Ideally we need to get you to be able to run the below or at least as much of it as possible.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. FilthyFletch

    FilthyFletch Private E-2

    Well i hadnt really done anything at all.When it first showed up I did a scan with antivir luke firewalker which found some additional isses like a wrom and a parasite b varient.I quarantined them and then it needed a restart. After that i was having issues booting up completely.At first I would get to the desktop but my icons that had to do with any type of adware removal,virus removal or firewall were all gone disappeared and then I could move my mouse but not click on anything. I did another restart and that was as far as i could get.I tried to go to safe mode but it started then flashed the desktop then the desktop would completely disappear.Basically this was hiding any means I had installed for virus or malware removal so I couldnt run them or access the net..So after messing with that I went and grabbed my windows disc and booted from the cd and did a repair and removed some things that I didnt need and I believe were the main culprit. I got rid of the braviax.exe , cru629.exe and the beep.sys files and then rebooted to safe mode and got in there and then did a search of my registry with regedit and cleaned up left over associated files..This seems to have fixed most of what was going on. I am back up and running now.My scans come up clean but I do have few issues lingering I have to fine tune.I have some browser issues now where loading stalls or freezes some occassionally and Im getting some occasional pop ups telling me to buy stuff..I probably need to root around some more or Im not real familar with like hijack but know if I run it someone who understands it can probably help me see if there is more still hiding..If this is what I should do Ill go ahead and do a posting of the hijack log and see if anyone sees anything. If there is more for me to do let me know and Ill give it a rip..Thanks
     
  4. FilthyFletch

    FilthyFletch Private E-2

    Also I dont know if it was all related but when I would restart I was getting a sentence in either rusian or german not sure which between my load screen and the windows splash screen.It was like 10 words but no idea what it said and it was up for like 8 seconds then the window logo splash came up..Thats now gone too after the repair I did
     
  5. FilthyFletch

    FilthyFletch Private E-2

    Heres a fresh log from Hijackthis

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     
    Last edited by a moderator: Mar 14, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions already given for running the READ & RUN ME. They do not ask for a HijackThis log to be posted. And all logs must be attachments to your message.
     
  7. FilthyFletch

    FilthyFletch Private E-2

    Ok guess the hijack log wasnt needed.I did all the other stuff in that read me first section guess Ill wait for whatever Im supposed to do now?????
     
  8. FilthyFletch

    FilthyFletch Private E-2

    Ok I had to undo the changes that the read me first said to do as my computer wouldnt load completely with normal startup checked .I had to get into safe mode and go back to selective startup and then hide the system folders.I can now eventually get to the desktop but now I get Microsoft Visual c++ runtime libary erro Program: C:\windows\explorer.exe....A buffer overrun has been detected which has corrupted the programs inetrnal state.The program cannot safely continue executuion and must be terminated...Never had this befoe..Now what do I do??
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Until you complete the instructions in the READ & RUN ME and attach ALL of the logs that were requested, we cannot help you. The logs are our visibility into what is going on with your system. Without the logs we are blind and can only guess and we will not guess as that will normally lead to major problems.
     
  10. FilthyFletch

    FilthyFletch Private E-2

    I have 2 questions then. I found a virus called win32.virus.parite that I cant quarantine or remove any links how to remove that.Also what logs in the read me first section it doesnt have nything about logs just say if I have logs they are to be attachments???Also whatever the logs are is there away to do it without using normal startup as my machine wont boot like that.Maybe to may things as there are like a hundred things that start up in that mode
     
  11. FilthyFletch

    FilthyFletch Private E-2

    Just went through the whole read me first thing again and no logs are asked for anywhere in it. I did all the scans,removals,cleaning downloaded the cc program ran it,I have hidden folders shown everything it says to do except have it starting in normal mode.What logs are you referring to as none have been requested by that section or you??
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not True!! I will quote from the Win XP Cleaning procedure for one example and since you never said what Windows version you have.
    If you really have Win32.Parite, you could be in for a total reinstall unless you have an antivirus program that will do a great job at finding and repairing the problems. This infection can affect every EXE and SCR file on your PC and also will possibly find its way to any shared drives on a network. The infection is know by a few names. Here is some info on it from Symantec:

    http://www.symantec.com/security_response/writeup.jsp?docid=2003-011708-2030-99&tabid=2
     
  13. FilthyFletch

    FilthyFletch Private E-2

    Well I guess the read me firs link you orignally gave me was a different link then your looking at as the stuff your quoting isnt on that page step 3 thats posted at the link you gave me is as follows
    3: Procedures based on your Windows Operating System
    If you have Windows 95, 98, or ME, continue here: Windows 98 and ME Cleaning Procedure
    If you have Windows 2000 or 2003 continue here: Win 2000 & 2003 Cleaning Procedure
    If you have Windows XP, continue here:Windows XP Cleaning Procedure
    If you have Vista, continue here: Vista Cleaning Procedure

    I got rid of the win32.paraite with a few cleaners,using the windows reapir opton removing the braviax.exe files,cru629.exe file and the beep.sys file then going to the safe mode panel running spyboy S&D and then adware then Bulldog antivirus program.I have no more infections but when I boot in normal mode my macjine is real slow and may even freeze but in safe mode runs fast as can be so I guess Ill have some searching and adjusting to go.I cleaned 689 infected files.If you have a direct link to the page you got yur quoted step 3 from Ill go there but thats not listed on the link you originally posted in this thread
     
  14. FilthyFletch

    FilthyFletch Private E-2

    Ok think I found where you got that info from its on another page linked to a word in a sentence.I didnt know the os names were links thought they were just different color to seperate the os types.WIll go into those and see what I find out to do..
     
  15. FilthyFletch

    FilthyFletch Private E-2

    Ok downloaded and followed the scans.I now have 3 logs.Superscanner found a ton of stuff the other scanners I used before didnt.Heres the logs..
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So then I assume this means you skipped all of the other blues underlined links in the procedure before this point too. You will need to go back and follow those steps. I can see from your logs that you have skipped some of them. One I can see is that you are still using MSconfig to control startups. So did you do each of the below as requested? If not, do them now:
    Based on seeing the below in your logs I can see the above were not done.
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    Java 2 Runtime Environment, SE v1.4.2_06
    Viewpoint Media Player
    You also ignore the below important notice at the beginning of the READ ME
    You have multiple antivirus programs installed. You must uninstall all but one right now.



    Note: Using blue underlined text to for hotlinks is standard operationg procedure on the internet. Also in many place in our procedure it did say "continue here:" and those words were followed by links which is the here.



    Why are your logs from safe boot mode? Are you having problems running in normal boot mode? We need to have logs from normal boot mode. After doing ALL of the above, from normal boot mode run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log
    • C:\MGlogs.zip
    If you cannot do the above in normal boot mode, then just tell me when you return and just get the new log from safe boot mode and we will continue.
     
  17. FilthyFletch

    FilthyFletch Private E-2

    Looks like I got everything cleaned up now.As everything is wrking great again and no new infectins have been found and I can now boot to normal windows desktop.I dont use any active virus programs but have Antivir installed and a trail copy of BullDog installed.There is also I hink the windows security stuff that xp installed other then those I dont have any others I knew of.DO I need to uninstall either antivir or bulldog even if they are not enabled?I did the other blue links.In the ad/remove malware from the add remove program section there was nothing to remove as far as malware.I wasnt able to boot my machine at all when normal startup was seleted not even to safe mode it would half bot then freeze and then 30 minutes later unfreeze but have no desktop icons so I had to do everything in selective startup mode.I tried to update the sun java but it keep telling me I have most current version for my os?? I do have 1 question though.After I ran the combo fix and it finished it never switched my clock back to a 12 hour setup.How do I get it out of the 24 hour mode and back to 12 hour mode as I see no option to switch back and forth just time zones and day light savings??I now can boot to normal mode so I guess I can run the programs again in this instead of safe mde and repost logs.I had to use safe mode to do the programs as I couldnt install ,boot up, or function anything in normal boot..If I stop msconfig selective boot it might not work I will see as it will load about 200 items on startup so Ill read about getting some of that stuff out but most says its microsoft system stuff which Im nervous about trying messing with but if it all loads my machine cant handle it..Also quick question while I go back and try again.After the combo fix when I boot I used to get and still do a screen when booting telling me my drives,bios version and ram gets scanned to see if it passes.Well I have 386 ram it used to scan and say 384 passed now it says 383 passes that seem like a worry??Ok Let me go try to boot in full startup mode and see if I can operate in that mode now.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see BitDefender and BullGuard. You may have already uninstall AntiVir but since you have been incorrectly using MSconfig, you have stuck registry entries for many many programs including Antivire. Note that both BitDefender and Bullguard are installed and they are both active. You need to uninstall one. If you do not then you will waste system resources slowing down your PC and you will make each program actually less effective rather than improving your security. They will fight against each other.

    Yes there was. That is where Viewpoint Media Player should have been removed.

    No you did not. You need to follow my instructions and uninstall all the old versions. Then use the link that I gave to you to get the current version and install it. Don't try to update via Sun Java just follow the instructions as given.

    That means it never finished running properly.

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.


    You have lots of malware trapped in MSconfig which needs to be removed. You should never have been using MSconfig this way to begin with as noted in the link given multiple times ( Dealing with Startup Processes ) I will take a look at your previous log and give you a partial fix (in another message ) to remove some of the things from MSconfig but you will have to put your system into normal startup mode and provide a log from this mode so we can finalize things. You must remain in normal startup mode and not use MSconfig like this anymore.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Ewido as it was discontinued long ago and was replaced by AVG Antispyware.


    Now copythe bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you note whether you receive a success message about adding the above to the registry. If you do not receive a success message then do not continue with the below because the above did not work. Just come back and tell me that the registry patch failed.

    Now put use MSconfig to put your PC into Normal Startup mode and then Reboot.

    After reboot, run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. FilthyFletch

    FilthyFletch Private E-2

    Ok went back through.I deleted anything that was java related and downloaded the newest version and it updated after install.I removed Bulldog and bitdefender.I went to remove ediwo but when I did it said uninstaller not found so I went and deleted whatever I could find related to it.I went to add/remove programs like you said viewpoint wasnt there so I manually looked for it and deleted it. I added the registry fix you had me add and got successful fix message.I ran cccleaners.I turned back to normal startup mode and rebooted.Took awhile for all to load and the computer is real slow now with everything running but runable.Got a few error messages when rebooted.Port magic is corrupt now,HAd a microsoft visual c++ error regarding veoh player and then got a erro messaage about veoh player and something about floating files??I got past those and ran the MGtools and am attaching the log zip now...
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Any programs that you still use and that are broken/given error messages may need to be reinstalled. If you don't use them, then uninstall them.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to ewido anti-spyware 4.0 guard
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    Do you still use the below software that is trying to load services? I would guess no to some of these and that these are just hanging around do to your having used MSconfig.
    Nero 7 is still installed but do you use the BackItUp program. If not, we can remove the service.

    You still have one old version of Sun Java installed. Uninstall Java(TM) SE Runtime Environment 6

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [DVDTray] "C:\Program Files\HP DVD\Umbrella\DVDTray.exe"
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: ComcastHSI - {00B73B80-3B49-11D9-82A6-0000E87A8BE3} - http://www.comcast.net/ (file missing) (HKCU)
    O9 - Extra button: Help - {00B73B81-3B49-11D9-82A6-0000E87A8BE3} - http://online.comcast.net/help/ (file missing) (HKCU)
    O9 - Extra button: Support - {00B73B82-3B49-11D9-82A6-0000E87A8BE3} - http://www.comcastsupport.com/ (file missing) (HKCU)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  22. FilthyFletch

    FilthyFletch Private E-2

    Ok followed your instructions. Yes the listed entries you asked about are left overs I dont use those anymore.Ok here are the 2 reports after processes were done.Everything seems to be ok I will try to find the corrupted programs online to restall and see if that stops the erro messages when starting.Still not running as fast as when msconfig is setup to selective but getting better.Just gotta find out how to turn off some of the other aol stuff so it doesnt auto load..Heres the logs..Also I wanted to ask how would I stop programs from starting up like I would with msconfig.exe selective setup as most dont have options to choose that so I have no idea as there are about 10 Id like o not load or start on startup.Thanks
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's fix them which will also improve startup and overall performance.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to NBService
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below Services (if you do not find them or get any errors, just continue):
      • Digidesign MME Refresh Service
      • Icecast Media Server
      • TuneUp WinStyler Theme Service
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste DigiRefresh into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below Services (if you do not find them or get any errors, just continue):
      • Icecast
      • TUWinStylerThemeSvc
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    That's because we are not finished recovering from the problems caused by using MSconfig like you did. Wait until we are finished.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Do you use AOL? If not uninstall it. If you use it, you still don't need all that junk to automatically run when you start your PC. Many can be removed permanently with HijackThis.


    That info was in the READ ME in step 1 and I gave you the same link in message # 16 and 18 right here in your thread. Here it is again: Dealing with Startup Processes


    You can use the tools in the above link to control things like the below which you may or may not need. Only you know what you use and don't use.

    O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1101014872\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.1c\AOL.EXE" -b
    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
    O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
     
  24. FilthyFletch

    FilthyFletch Private E-2

    Ok did those steps and gonna do a restart now.I downloaded the CPLStartup program.It only shows a few things as being able to tuen off so now I just have to get all the aol and things like auicktime and weba cam to not load up.Is there any more logs or steps to do now or should I be clean?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check out Autoruns.

    For items that you never want to startup, like Quicktime, you can just fix those startup O4 lines with HijackThis. If you never need AOL to startup, then fix those lines too or remove them with Autoruns.

    You logs were clean of malware in the last set. You can attach a new MGlogs.zip file now so I can see what your startup situation looks like.
     
  26. FilthyFletch

    FilthyFletch Private E-2

    Ok Ill try the other program.When you say Never startup you mean I can manulally open them from my programs list they just wont load automatically when the system boots up right?? Ok heres my log
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    You forgot to attach the new log.
     
  28. FilthyFletch

    FilthyFletch Private E-2

    Huh thought it attached Ill do it again...wait it keeps telling me I already attached this file to this thread and cant attach again??
     
  29. FilthyFletch

    FilthyFletch Private E-2

    Gonna try again.Also another question is it normal that after each startup if I run the CCleaner that it finds registry errors each time even though it says it fixes them each time??
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why, after all of the discussion that we have had, are you using MSconfig to control startups?????

    I doubt they are really errors, but tools like this always find things they believe are issues in the registry. Some of it is just due to normal activity from using your PC. You can discuss topics like this more in the Software Forum.
     
  31. FilthyFletch

    FilthyFletch Private E-2

    Using msconfig??? Im not I used those 2 programs you todme to get and have not typed msconfig in for days????
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but according to your runkeys.txt log, you are. The below shows it:
    Run MSconfig! If it does not show Normal Startup mode (and it cannot based on the above), then you are using MSconfig to control startups.
     
  33. FilthyFletch

    FilthyFletch Private E-2

    Well I went to the run box which had no msconfig in the history so I typed it and sure enough the selective setup was ticked.I put it back to normal and restarted and then ran autorun again and looked again and apparently running that autoruns makes it go into selective startup as it was at normal when I rebooted then I ran the autorun and checked and it was back in selective startup? Is that usual? I dont know the autorun program so maybe Im supposed t set something so it doesnt kick me into selective startup?? Ill do a new log verifiying normal startup first..
     

    Attached Files:

  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry again but no Autoruns does not put you in selective startup mode. Autoruns is totally independent of MSconfig. If you use Autoruns to disable startups, it makes its own registry keys. Here is an example of what it would look like for just one particular area
    This shows than Autoruns has disabled FreeRAM.exe and mnyexpr.exe from running at startup for the current user.

    You have something else locking or blocking you from putting your system into normal startup mode and keeping it there if it keeps reverting to Selective Startup.

    You current log shows you are in Normal Startup and that you have only one item disable with AutoRuns and that is the below:
     
  35. FilthyFletch

    FilthyFletch Private E-2

    Weird.I tried it a few times and everytime I run the autoruns it puts the machine into selective startup and everytime I put it in normal then retsrt its in nomal then I restart again to check its still in normal startup only if I use the autoruns.The 2 things you listed FreeRAM.exe and mnyexpr.exe I have no idea what those are I never selected those.I only chose to disable things like aol starups,antivirus startup and quicktime startup but it didnt turn any of those off as they are still running.Guess Ill try hijack this.When I scan to stop them from loading on startup do I just delete the entries for like quicktime and aoltopspeed or whatever else I dont want starting up? I wanna stop about 12 items from loading to get the speed back up on the system as it hangs some now with all these still starting and the 2 programs you gave me dont list most of the items in the startup and they dont turn them off as they all start again with restarts.Also appreciate your help I know your probably about tired of me.Thanks though I appreciate it
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly this is due to something else. I have tried this multiple times on my own PC and Autoruns has no effect whatsoever on normal vs selective startup.

    Those were just examples of what Autoruns could put into the registry. They were not examples from your PC.


    You just have HijackThis fix those O4 lines and that removes those startup keys from the registry which means they will not load anymore at startup since the registry entries are gone.

    Are you sure Autoruns is not showing them? Did you select the Everything tab which shows all startup? This will show everything considered a startup. Way more then you would ever know about.
     
    Last edited: Mar 21, 2008
  37. FilthyFletch

    FilthyFletch Private E-2

    Ok Im back with something related to what we did to clean up.I hadnt noticed as I hadnt used either my cdrw or my dvd burner til recently. Both are no longer showing up in my coputer or when I browse my drives. I see them in my hardware devices with exclamation marks on both. Both say driver is installed but a driver service has been disabled and another service may be providing this functionality. I tried to update drivers but cant find any drivers for either drive online at hp or googling the roms.Im not sure what I turned off or where to look.Any idea what might have happened or how to get my drives back so I can use them?? I tried to uninstall and reinstall and searched for new hardware it finds them but they get the yellow exclamation mark and same message every time
     
  38. FilthyFletch

    FilthyFletch Private E-2

    Ok I think I figured it out. For some reason when I deleted and turned off some of the nero stuff it was attached to my 2 drives. i turned all the nero stuff back on and updated it and my 2 roms showed back up and work.Said something about driver in the hig was missing in the low somthing but it corrected and they are back now..Thanks again for all the helps on the malware
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you run Avenger, you can delete all files related to Avenger now.
    6. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds