After Braviax Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by InvisionNole, Apr 7, 2008.

  1. InvisionNole

    InvisionNole Private E-2

    I though that I successfully got rid of the Braviax curse this weekend, after a couple of weeks of surfing and trying cures. The files themselves seem to be gone, but now my problem is fixing some of the damage it did...

    The first one that I cannot cure is that IE7 is redirecting to websites that contain other virii and malware. Whenever I first do a search and select an item, it goes someplace else and my Trend Micro Internet Security freaks out about things being downloaded that it is having to block. Additionally, the internet has slowed to a crawl on this computer.

    I would like to get this fixed and am not sure of the best way. I am attaching a copy of the HiJack This log for somebodies reference. Any help and suggestions would be greatly appreciated!

    Thank you.

    InvisionNole

    Log file attached and posted below.

    Log File:

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.
     

    Attached Files:

    Last edited by a moderator: Apr 7, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. Please only attach the logs we request. We do not need you to run or post logs from HijackThis on your own. They are automatically obtained by our procedures and it will be installed and run properly. Make sure that you disable Spybot's Teatimer as requested also uninstall the Viewpoint software as requested in step 1.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. InvisionNole

    InvisionNole Private E-2

    Thank you for the link. I ran these items last night and this morning but could not get the combofix.exe to work. I followed the directions down to the letter, and it seemed to work, but after about a minute it stopped. There is no log file, so before I post, I wanted to check to understand if this is needed.

    Basically I keyed in the command line and then hit RUN. A small window appeared that showed a bar and the harddrive was working. Then a blue command prompt box opened and closed and that was it.

    I waited for about 10 minutes and it didn't appear to be doing anything else. I checked for a log file, but none was present. I reran the program with the same results.

    I did move on to the next step and completed it and rebooted the system. Reran Trend Micro Internet Security before leaving for work and it found 3 items during the spyware search. Not sure what right now, as I left for work.

    I will post the logs that I have when I get home, but wanted to confirm if the combofix 'worked' or if I needed to do something else.

    Thank you,

    InvisionNole
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just skip ComboFix and complete all other steps and then attach the requested logs.
     
  5. InvisionNole

    InvisionNole Private E-2

    Chaslang -

    OK. I tried the Combofix one last time and still didn't appear to work, so here are the three log files.

    Overall the system is improved, and IE is not be rerouted to other webpages (at least as far as we can tell), but something must be working in the background because after any surfing 3-4 items will be found (spyware) and the occassioanl virus.

    Look forward to hearing back from you and thanks again for your time and trouble!

    InvisionNole
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Exactly what is being found and what is it finding it. If you are referring to cookies, they are not problems and you will always have cookies when you surf. It is normal.

    Now let's finish correcting a few more things.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    My Way Search Assistant <-- should have been uninstalled in step 0 of the READ ME
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 0 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. InvisionNole

    InvisionNole Private E-2

    Thank you for the help. Attached are the log files requested. Everything seemed to work in your instructions, so I will take it for a spin and then rerun Trend Micro when I am finished.

    To your question on what keeps being found - tracking cookies (I am used to these) and 'trogan viri'. I have also had a number of occurences of: dumphive.cfexe
    troj_rootkit.cy
    bkdr_small.cie
    troj_tibs.ru
    troj_wantvi.b

    I just checked my logs and I haven't had one since Tuesday morning, so maybe we (you) have gotten all of these for me and closed the door on how they were getting on my system.

    Thanks again for all of the support.

    InvisionNole
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not really helpful. I need to know where Trend Micro thinks it is finding these. dumphive.cdexe is not a problem. It is part of ComboFix. Don't bother running Trend Micro anymore until we complete final steps here on your malware removal. You may just be finding non-problems that are in backups from the cleaning procedures and things in System Restore. When you get finished with my final instructions (at the end of this message), all of this type of garbage will be removed.

    You started using MSconfig again. You must not use this to control startups like you are doing. Please read the info in step 1 of the READ ME again and click the link on Dealing with Startups.

    Your logs are clean!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you run Avenger, you can delete all files related to Avenger now.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. InvisionNole

    InvisionNole Private E-2

    Thank you for all of the help. It appears that all is now well and I have disabled and re-enabled restore points to keep everything working.

    You are right, I did use MSCONFIG again to stop two items from loading until we finished and will now try one of the other methods to remove these two items. I have not had any luck removing them any other way...

    Once again, thank you for all of your help and the additional link to the "How to Protect..." has some excellent tips and links. I may have to explore moving away from Trend Micro and I will definitely have my teenager read through this for her computer.

    Regards and Happy Computing,

    InvisionNole
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds