braviax issue

Discussion in 'Malware Help (A Specialist Will Reply)' started by kildar, Mar 14, 2008.

  1. kildar

    kildar Private E-2

    malware removal

    hi geeks,i have downloaded some bad stuff.via free porn video.i have three new icons on desk top .error cleaner,privacy protector and spyware and malware protection.i am getting pop up warnings to many to write down.i have tried to download spy-bot.it will download but will not open up and run.please help me get my computer back from these pirates.thanks .i am no computer wiz either.kildar
     
  2. Lev

    Lev MajorGeek

  3. kildar

    kildar Private E-2

    i have run,smthrfraud program and was able to rid myself of error protector,privacy protector and the other one i think was spyware and malware protector.now have installed pc tools free version.have found braviax exec.in my windows file in C:/.followed instructions and cleaned and downloaded the three programs needed to fix the problem .the only one i can run is mgtools.spybot downloaded but will not run.the other one will not even download to computer.hope you can help me out.thanks .
     
  4. kildar

    kildar Private E-2

    Re: malware removal

    thanks for the reply.i have tried the read me first thing.i got all the way to dling the programs needed to begin the killing .did every thing to the letter.super antispyware,combo fix and spybot all downloaded the exec's but will not run.mg tools the only one i can run.ran smithfraud program and destroyed the three before mentioned error protector ect.downloaded pc tools ran scan and found adware mutant braviax exec..in c:/program files/windows..will not let me delete.i have the file qurantined .it seems to be the only problem left.if you could possiably come up with a solution for this .i will be glad to attach any logs you may want. thanks again for the reply you guys are really incrediable.kildar
     
  5. kildar

    kildar Private E-2

    hi geeks,i have id'ed some of the problem as c:/windows/braviax.exec,system 32/winivstr.exe.and system 32 braviax exe.thought i had problem in check,wrong again.rebooted and the problem is back.i am running in safemode now only.i have read your reply.and will enclose what logs i can get for you next post.thanks. kildar.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you follow the instructions exactly for running ComboFix! It must be on your Desktop, it must be renamed, and you must run it from the Start, Run box with the killall option as instructed.
     
  7. kildar

    kildar Private E-2

    Re: braviax issue solved

    :Dhi geeks,was able to run combofix and it enabled me to run the other software.superspyware caught 3 trojans,spybot ran clean,i have enclosed all the logs for your viewing .i think i may be ok.fingers crossed lol.wow thanks a ton.i learned alot from this.soon as i leave this site il have pc tools up and running again.you geeks are trully increditable.thanks kildar.
     

    Attached Files:

  8. kildar

    kildar Private E-2

    Re: braviax issue fixed

    hi major geeks,just wanted to thank you again for your help in getting my computer back from these pirates.i am running fine now.have pc tools in place.ran scan this morning .0 threats found!!:D.you guys are awesome thanks a ton.this is kildar and i am outta here.:major
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: braviax issue fixed

    That's nice but incorrect. You have some more to do. ;)

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O3 - Toolbar: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: etlrlws - {71EEB25C-DAB0-4675-8264-31391E46335B} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [braviax] braviax.exe
    O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - (no file)
    O22 - SharedTaskScheduler: calpastatin - {a0efe2fe-7249-4403-a00b-8be108617c75} - (no file)
    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
     
    File::
    C:\WINDOWS\system32\univrs32.dat
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. kildar

    kildar Private E-2

    hi again majorgeeks,i received Chaslang's reply and followed his instructions.i have enclosed the logs he was wanting ,hope they look better this time around.thanks again for your time and effort.my computer seems to be running better ,but really haven't had a chance to surf around any yet.i also had pc tools up and running and system restore turned on during this fix.not sure if that makes any difference?looking forward to your next reply.kildar.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But you did not get Symantec uninstalled properly before installing this. You need to run the below :

    Norton Removal Tool (SymNRT)

    If this does not remove everything, we may have to do it manually.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
     
  12. kildar

    kildar Private E-2

    thanks chaslang,enclosed log you requested.kildar
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to SAVRoam
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteSavRoam into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT and reboot whether it asks you to reboot or not.
    After reboot look at a new HijackThis log (from running analyse.exe) and make sure the below line is gone:
    O23 - Service: SAVRoam (SavRoam) - Unknown owner - (no file)

    If it is, then move onto the final steps below. If not, just come back and tell me it is not gone and tell me if you have problems running the above steps.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    2. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. kildar

    kildar Private E-2

    hi chaslang did as you requested.savroam service was stopped already. i disabled.i have enclosed last log.line023 savroam is deleted.i have deleted combofix as requested and now going to uninstall all other related tools .thanks a ton.for your time and help .kildar
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds