Braviax in the cobofix log and in msconfig startup

Discussion in 'Malware Help (A Specialist Will Reply)' started by pastorgeek, Mar 13, 2008.

  1. pastorgeek

    pastorgeek Private E-2

    Hi
    I ran all the steps, how does it look? I also still have a delself.bat on the desktop.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are in pretty good shape but we have a little to do.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    You need to copy this file C:\I386\BEEP.SYS to the below two folders to replace the infected ones that were deleted
    C:\WINDOWS\SYSTEM32\DLLCACHE
    C:\WINDOWS\SYSTEM32\DRIVERS
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe

    After clicking Fix, exit HJT. And then reboot your PC before doing the below.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. pastorgeek

    pastorgeek Private E-2

    Re: Braviax in the combofix log and in msconfig startup

    Thanks! I am very grateful for your help.

    I haven't replaced the beep.sys files, my cd is the one that came with my laptop (xp home) and I was using it at work and the network admin loaded xp pro. I can get the disk, but it's a hassle - suggestions?

    I forgot to reboot before ccleaner, rebooted ran again.

    I still have delself.bat on the desktop.

    Thanks again!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Braviax in the combofix log and in msconfig startup

    Read my message again. You don't need your disk.

    Just delete it.

    Based on your logs, you did not perform the fix I gave you with HijackThis (analyse.exe) in my last message. Please run those steps again and make sure you click Fix checked after selecting the lines and after making sure all browsers are closed.
     
  5. pastorgeek

    pastorgeek Private E-2

    Re: Braviax in the combofix log and in msconfig startup

    I'm sorry, I did the fix but didn't get the log right. I hope this is!
    :eek: I read the message but I only understand this stuff a little. Thanks for the help!
     

    Attached Files:

  6. pastorgeek

    pastorgeek Private E-2

    Re: Braviax in the combofix log and in msconfig startup

    Does this log tell you if I did the beep.sys thing right? - should have done it before I sent last log, sorry.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Braviax in the combofix log and in msconfig startup

    You're welcome.

    Yes you did it right! ;)

    You forgot to delete the below:
    C:\Documents and Settings\Kelly B. Griffith\Desktop\delself.bat

    After deleting the above file your logs will be clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    2. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    3. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    4. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    5. After doing the above, you should work thru the below link:
     
  8. pastorgeek

    pastorgeek Private E-2

    Re: Braviax in the combofix log and in msconfig startup

    Thank you very much!

    Combofix.exe is on the desktop, and I copied and pasted *combofix /u* into run - says it can't find it.

    Is it necessary to delete these tools? would they be useful if I ever have to contact you again?
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Braviax in the combofix log and in msconfig startup

    Then just delete the below yourself:
    C:\Documents and Settings\Kelly B. Griffith\Desktop\ComboFix.exe
    C:\ComboFix.txt
    C:\QooBox <-- this is a folder

    The tools are updated very frequently and you must always make sure you are using current versions. Thus, you should always be redownloading the tools to make sure you are current. The READ & RUN ME changes too, so you must always make sure you are following instructions from the current online copy before posting here.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds