Has Buritos been removed?

Discussion in 'Malware Help (A Specialist Will Reply)' started by GuruDave, Sep 11, 2008.

  1. GuruDave

    GuruDave Private E-2

    Yes, I opened the stupid UPS email (since I just mailed a package).

    Yes, I got the stupid Braviax and it's cousins, Buritos and Karina.

    Yes, I fell for the Windows prompt and ordered the fake Spyware protection.

    And yes, I figured out what really happened!

    SO --

    This is all I have done and it appears that the malware is gone --

    I purchased and downloaded Spyhunter

    I ran it several times,... It said that the malware had been removed. But, of course, it came back everytime I rebooted.

    Since Buritos kept coming back, I downloaded the Combo Fix. I renamed it and ran it a couple of times with mixed results (never seemed to finish).

    Then, on my own, I decided to do system restore to the day before and Voila! There appears to be no more Braviax,... No more Buritos, and no more malicious tray icons. The other thing that kept happening before was that picture viewing was disabled in Explorer -- and this is fixed too.

    So AM I DONE? If system restore was so helpful in getting rid of the malware, why don't more people suggest it?

    Please advise... I want to be sure I'm fixed.

    Thanks in advance.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Some forms of malware disable system restore.... among other things. You are fortunate that you were able to run it.

    Now for the bad news ......sometimes we find that a restore point is also infected from a previous file.....so to be certain, you should do these things:

    Download and run MalwareBytes
    Download and run MGTools.exe

    Both of these will be found in the READ & RUN ME FIRST. Malware Removal Guide

    Be sure to attach the logs when you are ready. :)
     
  3. GuruDave

    GuruDave Private E-2

    OK... I am currently running Malwarebytes... still scanning.

    But I noticed that I cannot do the updates. It is asking about a firewall. But I only used an old Norton firewall (as far as I know) which appears to be disabled.

    Is there a way to see if I have another firewall running? I know windows firewall indicates that it is not turned on and McAfee is not active.

    Is it possible that the malware disabled the old (outdated) Norton Internet Security that I had?

    Thanks.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will only be able to answer that when you attach the two logs. :)
     
  5. GuruDave

    GuruDave Private E-2

    Log from Malwarebytes

    <Removed inline log.>
     

    Attached Files:

    Last edited by a moderator: Sep 11, 2008
  6. GuruDave

    GuruDave Private E-2

    <Removed inline log>
     

    Attached Files:

    Last edited by a moderator: Sep 11, 2008
  7. GuruDave

    GuruDave Private E-2

    OK.... I have tried to post/attach both logs.

    They sound promising.

    Please let me know what you think.

    Thanks again! :wave
     

    Attached Files:

  8. GuruDave

    GuruDave Private E-2

    Sorry... Here's the other one.

    I still can not do an update on MalwareBytes.

    Any guess as to what could be blocking the access?

    Thanks.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No idea why you cannot update...If you have a problem automatically installing the update due to no internet connection or other reason, you can manually download and install the update from here: Malwarebytes' Anti-Malware Database

    Is your Norton antivirus suite up to date? Or has the license expired?

    Your logs are clean....let's clean up:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then it is time to do our final steps:
     
  10. GuruDave

    GuruDave Private E-2

    The reason for the inability to access the internet was because of my old Norton software. It has been out of date for a while, but was my only existing firewall. Somewhere in the infection it was compromised OR somewhere in the cure, it was disabled. But it held onto some level of control. When I ran a Symantics file to eliminate all traces of Norton, the problem stopped and malwarebytes (and McAfee) were suddenly able to access the Internet. I guess that means problem solved.

    As for cleaning up per your instructions, the reg edit went in just fine. But I'm not sure if I need to do any of the second half of your instructions. I did use Combo Fix, but that appears to have vanished with my System Restore. Do you think there is anything else I need to do?

    You have been a great help. Thanks so much for your time and interest.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should probably run Norton Removal Tool and read the How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds