Problems with Braviax and running antispyware progs

Discussion in 'Malware Help (A Specialist Will Reply)' started by Tyraen, Sep 9, 2009.

  1. Tyraen

    Tyraen Private E-2

    Somehow i managed to get this nasty malware and I have been having a tough time removing it.

    After going through everything requested of me in the readme, i have found that only MGtools log will actually run/install. All of the other programs (including SAS, which is what i have used to remove other spyware in the past) would either not run, not install, or in the case of SAS, crash during the scanning process.

    Mg logs are attatched, this spyware is extremely annoying, some assistance would be appreciated.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    First download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    You don't need to attach a log from this running right now. We needed you to run this new version so that some steps in the below fix will work. We will create another new log later.

    Now run the C:\MGtools\SysBU.bat file by double clicking on it. It will run quickly and you may notice a quick command prompt window flash by.

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving many files here like you are doing.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 14
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Tyraen

    Tyraen Private E-2

    I did exactly as you advised, chaslang, and I am still infected with this annoying malware. Avenger either did not run properly or simply did not create the log file, because it is no where to be found (the log txt). I also attempted to run combofix.exe again after completed your list of tasks to do, and alas to no avail.
    I did your list of cleaning twice to ensure that it was done properly, as I made a few mistakes the first time. After i ran avenger for the second time, when i rebooted a message came up before loading windows to this effect:

    Invalid boot INI
    loading from c:\windows\

    before it loaded the OS. No idea what it means, but it was unique and thought was worth mentioning

    I have the MGtools log uploaded, but no avenger as mentioned.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Never do anything we don't ask you to do as stated in the READ & RUN ME. If you ran Avenger twice, the second run would delete a log from the first run if it ran.

    When you just double click on avenger.exe, does it open up the program?
     
  5. Tyraen

    Tyraen Private E-2

    Yes it does open the program up, and i copy/paste everything in the quote into the text field.

    When i ran it the first time, i checked for the avenger log before i did everything over again from the start, and I did not find it. I did an explorer search for the words "avenger" and it did not locate the log file either. There was a text file called.... i think fizjig.txt or something like that, and it had the same text i had input into avenger. This file was located in my root directory, but it was not called avenger.txt, so i assumed that this was not the log file.

    It did not appear the second time i ran through your instructions.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach the below two files to your next message:
    C:\Program Files\auth.txt
    C:\Program Files\ywji.txt


    Now try to delete the below files. Tell me what happens. Don't be surprised if you cannot delete some or all.
    C:\Documents and Settings\Tyr\Application Data\kucy.bat
    C:\Documents and Settings\Tyr\Application Data\qinakysat.bat
    C:\Documents and Settings\Tyr\Local Settings\Application Data\nulazohoj.scr
    C:\Documents and Settings\Tyr\Local Settings\Application Data\vedekeve.sys
    C:\Documents and Settings\All Users\Application Data\agyd.bat
    C:\Documents and Settings\All Users\Application Data\exuqyqa.bat
    C:\Documents and Settings\All Users\Application Data\zizaguda.com
    C:\Program Files\Common Files\fudeb.scr
    C:\Program Files\Common Files\orurehym.dl
    C:\WINDOWS\bexowahanu.exe
    C:\WINDOWS\cru629.dat
    C:\WINDOWS\eryj.reg
    C:\WINDOWS\exonuwa.scr
    C:\WINDOWS\install.dat
    C:\WINDOWS\is-1BBB9.exe
    C:\WINDOWS\is-1BBB9.lst
    C:\WINDOWS\is-1BBB9.msg
    C:\WINDOWS\kgt2k.INI
    C:\WINDOWS\rumufe.inf
    C:\WINDOWS\rylaq.bin
    C:\WINDOWS\Sysvxd.exe
    C:\WINDOWS\zeti.vbs

    Also try to delete the below folders:
    C:\Program Files\AntivirusPro_2010
    C:\WINDOWS\45235788142C44BE8A4DDDE9A84492E5.TMP
     
  7. Tyraen

    Tyraen Private E-2

    I'm assuming you wanted me to manually delete these by hand, so i went ahead and did that. I had no errors or blocks and deleted everything on your list.

    Requested .txt's are attached, and a million thank you's for such incredibly speedy replies.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Those files show that you have been working with some one else to remove this malware. Are you currently working on another forum?

    Okay! Even the below file deleted? Double check to make sure it did not come back.
    C:\WINDOWS\cru629.dat

    See how many of the below you can delete:
    C:\WINDOWS\system32\dllcache\beep.sys
    C:\WINDOWS\system32\braviax.exe
    C:\WINDOWS\system32\cru629.dat
    C:\WINDOWS\system32\imexupe.reg
    C:\WINDOWS\system32\minix32.exe
    C:\WINDOWS\system32\pzrgujec.txt
    C:\WINDOWS\system32\wingenocx.dll
    C:\WINDOWS\system32\wisdstr.exe
    C:\WINDOWS\system32\ybibygizav.vbs
    C:\WINDOWS\system32\ysuk.reg
    C:\WINDOWS\system32\_scui.cpl
    C:\WINDOWS\system32\chtqil.sys
    C:\WINDOWS\system32\glmyw.sys
    C:\WINDOWS\system32\gpwgflrg.sys
    C:\WINDOWS\system32\ryrucbj.sys


    Just stay online for as long as you can. This is a new type of infection and we are trying to learn all the ins and outs of it. So while you are online I can keep trying things. Normally you will have to wait for your thread to work its way thru our queues which are growing daily due to very complex malware (like yours) and the fact that so many people are getting this infection.
     
  9. Tyraen

    Tyraen Private E-2

    All additional files on said list have been successfully deleted and emptied from recycle bin.

    Cru629.dat did not return, i thoroughly scanned my windows folder to ensure it had not come back.

    I had run attempts via other sources of info to attempt and remove braviax.exe, since that was the noted program i noticed in task manager. These attempts involved sdfix, and some avenger work, nothing of which worked, at which point i made my post.

    Currently i am not doing anything other than what you have suggested, and have not since i made my original post.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now try the below steps! Make sure that you do not shutdown or reboot your PC until I say you can. ;)

    Look in Add/Remove Programs for Protection System See if it allows you to uninstall it.

    Also delete the below two files:
    C:\WINDOWS\Tasks\fjmbvsoa.job
    C:\WINDOWS\Tasks\rhciksys.job

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  11. Tyraen

    Tyraen Private E-2

    The protection system was successfully uninstalled, although it took several tries for it to fully go through. A text field requesting the reason for the uninstall appears, and i typed "does not function" the final attempt, which proved successful. I doubt that has any bearing on anything, but thought was worth mentioning.

    Received message that the entry to the registry was successful

    MG logs are here.

    *edit* Just deleted the two items in the tasks folder, after doing everything else. didnt notice it the first time
     

    Attached Files:

    Last edited: Sep 15, 2009
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's remove the old script logs.
    C:\Program Files\auth.txt
    C:\Program Files\ywji.txt

    And it seems you missed a few. Delete these now and then double check. They could be reviving themselves after a few minutes.
    C:\WINDOWS\system32\ybibygizav.vbs
    C:\WINDOWS\system32\drivers\chtqil.sys
    C:\WINDOWS\system32\drivers\glmyw.sys
    C:\WINDOWS\system32\drivers\gpwgflrg.sys
    C:\WINDOWS\system32\drivers\ryrucbj.sys

    Also see if the system allows you to delete the below two system files which are infected and will reinfect you at reboot.
    C:\WINDOWS\system32\dllcache\beep.sys
    C:\WINDOWS\system32\drivers\beep.sys


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    My next steps will be the real test! We will need get Avenger to work.
     
  13. Tyraen

    Tyraen Private E-2

    I deleted all files, none gave me any problems, and have been emptied from my bin

    i did NOT find beep.sys in my dllcache folder, i believe i had already removed this as requested by you from a previous post.

    A msg popped up at some point (i did not notice it right away) from windows saying that it did not recognize some of the files, and asked me to insert my windows XP CD. Since i dont have my CD, and my drives aren't working well anyway, i clicked cancel. It prompted me with an "are you sure" button, asking me if i wanted to keep these files that were not recognized (or something to that affect), and i said yes. After doing so i rechecked the files i had just deleted to make sure they stayed deleted, and i did not find them again. I will keep rechecking until i see another post from you. If i do find, should i continue to remove them?

    Here are my logs
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The msg from Windows is because the beep.sys file is now (hopefully missing). Once we get everything fixed, we will get a new valid copy installed.

    While I look at the new logs, do the below.

    If the below folder exists, delete it.
    C:\Program Files\GetModule

    Also delete the old version of ComboFix.exe from your Desktop.

    Now download the latest version of ComboFix but DO NOT RUN IT. Get it here: combofix.exe
     
  15. Tyraen

    Tyraen Private E-2

    All done as requested, beep.sys has not returned, awaiting further instructions

    Ill be honest this feels like i'm waging a battle of epic proportions.

    "its trying to revive itself! GO FOR THE HEART!"
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now just in case Avenger does not run exactly how we need, let's try to mess up the malware to hopefully block some of it from reloading. Create the below folders (yes folders not files) yourself. Name them exactly as shown with the .exe extension.

    C:\windows\braviax.exe
    C:\WINDOWS\system32\braviax.exe

    If you get the above dummy folders created, then continue on with the below. Do not continue if you have a problem creating these folders.

    If you have any protection software running right now, shut it down.

    Now we will try to run Avenger again. If it runs properly then when it reboots your PC and after reboot it will also try to run one program from MGtools and will also try to run ComboFix. So if you see ComboFix start to run, allow it to run.

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 15, 2009
  17. Tyraen

    Tyraen Private E-2

    Error! invalid syntax in command:
    "C:\MGtools\temp\XPSP3\eventlog.dll||C:\windows\system32\eventlog.dll"
    Skipping line. (file move mode)

    Will pend execution for confirmation on this issue.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that was a typo! I had two || in there. I fixed it in my last message. Copy and paste it in now from my edit.
     
  19. Tyraen

    Tyraen Private E-2

    Alright, did as you requested, and avenger did run this time (i think).

    Combofix did not run, and i dont know if SysBU.bat ran or not. On the plus side, braviax did NOT load up, seems that part of the problem has been (at least temp) neutralized. i still have iexplorer coming up, but at least it seems we are winning.

    Mg logs and avenger logs attached!
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Avenger ran but not properly due to the ||. It did not get the infected files replaced that we need to replace.

    I will post a new fix to run shortly.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  22. Tyraen

    Tyraen Private E-2

    Avenger ran, logs did not show anything different from last time.

    Here are requested files
    weird... says i have already attached this file in another thread.... guess it means the last time i posted the avenger log.

    That doesn't look good :(
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it did not run. At least not properly. Did you notice any error messages?

    • Delete the current Avenger.exe file from your Desktop.
    • Extract it from the ZIP file again to your Desktop.
    • Delete the current MGlogs.zip file.
    • Then reboot your PC into safe boot mode (assuming you can) and then try repeating the last fix.
    Attach the new logs. If this does not work, you will need to boot to the Recovery Console to replace the bad file. Do you have your Windows Boot CD?

    I will be signing off in a couple minutes. Have to get some sleep.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And another malware file has spawned.


    C:\WINDOWS\system32\drivers\keav.sys
     
    Last edited: Sep 15, 2009
  25. Tyraen

    Tyraen Private E-2

    I will try this, but its also late for me and i'm very tired. Thanks for all the help chaslang, i will post again once i've done as requested.

    Get some sleep, you friggin deserve it!
     
  26. Tyraen

    Tyraen Private E-2

    Alright, so I'm back and i did as you asked, booted into safe mode and tried to run avenger again after deleting the old .exe and .txt files and removing the old mslogs.zip file. Boot first into normal mode to re-read your instructions, then went to safe mode. Avenger did not run at all, no .txt files were made and i have no reason to believe it worked.

    I do not know how to run recovery console, and i do not have my windows boot CD, it is lost to the ages. And if i MUST go to that length in order to beat this virus, i may as well borrow a dvd drive and someone elses copy of XP and reformat my C drive. All of my important information is on a separate partition on my drive, and i lose little to nothing by reformatting this partition. I don't really want to go that far if i can help it, and i would like to keep going with this since it allows you guys to get more information to combat this new kind of malware, but if i have to I will.

    Mglogs attached.
     

    Attached Files:

  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well thanks for thinking of the information that trying to fix this helps us to collect. It does help. You seem to have a new version that has been blocking all attempts to run Avenger. Let's try one more thing.

    Download this program Inherit.exe from sUBs and save it to your Desktop where you should still have a copy of the avenger.exe program.
    • Now drag the avenger.exe file on top of the Inherit.exe file.
    • Then wait for it to say "OK"

    Now let's try again to use Avenger
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  28. Tyraen

    Tyraen Private E-2

    Sorry it took so long to get back, but i did as you said, the results were the same, avenger did not run at all.

    Here are MGlogs
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it's up to you what you would like to do. Since they only way to replace the file is when Windows is not running (which Avenger and ComboFix can normally do, but they do not run) then you are left with the below choices:
    1. Recovery Console - but you have no CD
    2. Slave the hard disk into another PC and manually copy the file to overwrite the infected one
    3. Make a CD like below which allows you to boot to a Windows like environment but Windows is not really running from your hard disk, thus you can make changes
    4. There are other Linux, Knoppix ...etc type boot CDs which can also be made and user
    5. Format and reinstall which may be faster and easier for you since you have everything backed up. No sense wasting anymore time.;)
     
  30. Tyraen

    Tyraen Private E-2

    alright ill reformat this week.Thanks for your help chaslang, let me know if there is anything elsei can do to help you guys out with this. Most people dont prepare like i do, and id hate to think of the crap they lose out if they get a bug like this one.

    Many thanks for the support
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds