Please help me get rid of Braviax!

Discussion in 'Malware Help (A Specialist Will Reply)' started by zozoquark, Mar 30, 2008.

  1. zozoquark

    zozoquark Private E-2

    I believe I have followed all the correct steps to this point. I have attached the MGlogs.zip and have avenger.exe on my desktop. Please help. Thank You!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't supply us with a Malwarebytes or SAS log. However:

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    Java 2 Runtime Environment, SE v1.4.2_08

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  3. zozoquark

    zozoquark Private E-2

    TimW,

    Thanks for the reply. I appreciate your help!
    I had a problem with your first task. I get an error when trying to remove both older versions of Java. The error is..."Error applying transforms. Verifiy that the specified transform paths are valid." Reg issue? I was able to install Java 6 and then remove it with Add/Remove programs. Should I plow ahead with the other tasks or wait and try to fix this problem first?

    Thank you,
    Jeff
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    By all means ...plow ahead! :)
     
  5. zozoquark

    zozoquark Private E-2

    TimW,

    Thank you again for all your help! I think you have banished Braviax from my computer. I have to hand it to you guys.... you are good at what you do, and thank god you are around for the rest of us dopes. I have attached the log files you requested. Should I be worried by the fact I cannot remove the older versions of Java? Please let me know.

    Thanks again,

    Jeff
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We are getting there.....let's do this:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Did you set these internet policies:
    If not, please add them to the below HJT fix.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP\
    C:\Documents and Settings\Default\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  7. zozoquark

    zozoquark Private E-2

    TimW,

    After running HJT, I copied the text for REGEDIT4 into notepad (saved as instructed). I double clicked on it only to have it open a "open with" dialog. After a right click I had a merge option and choose it, after which another "open with" dialog appeared. Is it "merged" or not. How can I check that I have done what you have instructed me to do?

    Jeff
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your PC lost the Windows File Association for .REG files. Let's fix it.

    Now Copy the bold text below to notepad. Save it as RegFix.reg to your desktop. Be sure the
    "Save as" type is set to "all files". Then Click Start, Run, and enter regedit and click OK.
    This will open the Registry Editor.

    In the Registry Editor click File and Import. Navigate to the RegFix.reg patch you saved on your
    Desktop and double click on it. Click OK at the prompt to add to the registry. Do you get a success
    message for this?
    Then retry the fixME.reg patch and continue on with the rest of the instructions.
     
  9. zozoquark

    zozoquark Private E-2

    :)TimW,

    I think I have completed everything as instructed. The log files are attached. My computer seems to be running fine and virus free! Please advise after your review.... Again, I cannot thank you and this website enough for all your help! You guys are great!

    I had an episode with a "Registry Fix" software application that apparently, I have not fully recovered from. This coupled with a sneeky virus led me to you.

    I would have never arrived at this recovery point without you. Thanks again!
    Please let me know if we need to do anything else to make things right.

    Jeff
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look good....let's do two things:

    Run thisDisable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    And:
    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type combofix /u in the runbox and click OK.
    * Note: The space between the X and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds