chaslang please read!

Discussion in 'Malware Help (A Specialist Will Reply)' started by LimeLyfe, Aug 15, 2009.

  1. LimeLyfe

    LimeLyfe Private E-2

    Hello chas, i am one more person who needs to work on controling my friends surfing habits. First i would like to thank you for the intensive tutorial on fixing malware. i read and followed as much of the readme as possible. Here is my situation:

    I contracted the Braviax.exe virus while downloading an update for flash player.

    I Currently have McAfee and SpyHunter 3 and have ran both to eliminate the virus.

    i was unable to download or run SpyBot search and destroy or SuperAntiSpyware

    i deleted all viewpoint and java and programs from list to delte on add/remove programs list

    i successfully ran CCleaner, SmitFraudFix, avenger, and Mglog.

    Most of the virus has been deleted. There is no longer a pop up asking me to download and pay for fake virus removal software. Braviax.exe and Braviax.dat are both gone when searched for.

    MY ONLY REMAINING PROBLEM: Many Virus/Spyware removal programs are being blocked still. I am unable to update or install them. Certain pages searched for on Mozilla or IE are being redirected by something. I will attach any logs i have. thank you. Please Help if you can chaslang, And thank you for all the info you provided.
     

    Attached Files:

  2. LimeLyfe

    LimeLyfe Private E-2

    Anyone read this? any idea's or clues?
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well I'm not Chaslang as you can see, but you are next in my work queue so I shall be taking on your thread :)

    Why did you run avenger and what exactly did you do with it, could you let me know?

    Were you able to download/run Malware Bytes Anti-Malware? What errors did you get when trying to download SAS?

    Were you able to run Combofix? If not in normal mode, you could try running it in safemode, or even by renaming it to abc.com for example and then trying to run it. Looking at your logs it appears you did indeed run it, may I have the log from it please?

    Let me know and in the mean time I shall review the logs that you have already provided. I will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    Thanks :)
    Kes13!
     
    Last edited: Aug 18, 2009
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. MGTools is running from the wrong location, I would like for you to move it onto your root drive which is C:\

    2. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    3. Now we need to use Avenger since you cannot install Combofix and already have avenger installed:


    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    4. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    • C:\WINDOWS\Temp
    • C:\Documents and Settings\Benji\Local Settings\TEMP

    5. Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.


    6. Now see if you can get SAS > MBAM and Combofix to run

    7. Run the new MGTools.exe and attach the ---> C:\mglogs.zip that it generates into your next reply as well as the log from avenger.

    8. if successful attach logs from those into your next response here.

    9. Please ensure you let me know how your machine is behaving now :)

    To summarise I would like to see logs from:
    • SUPERantispyware
    • Malware Bytes
    • Combofix
    • avenger
    • MGTools
     
  5. LimeLyfe

    LimeLyfe Private E-2

    everything seems to be running well, SAS works and no pop ups anymore. If i experience any more problems i'll send a more detailed response, just wanted to say thanks!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, if you wish to continue on with my last instructions please do so, if not then you can follow the final steps: :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds