Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Found braviax virus on our company pc
Search Topic:
Uniqs:
2413
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Securty Device(s) may of effected User Profile startup »
« A Flash game:Fight against malwares with security protection  
AuthorAll Replies


on my pc today

@comcast.net

Found braviax virus on our company pc

Hi anyone know anything about this nasty (Braviax.exe) found it in the startup.
Made one of our pc just constantly turn on an off. but i finally got into the pc and first i got a message your pc is infected,funny how norton did not stop it.
Way to go norton!!!.
Anyway how do i remove this from our pc at work.it causes serious problem at times.
Our tech service is not to good and very laxed seems like i have to keep on this guy all the time. but any help to this issue would be welcomed.


EGeezer
Summer is passing
Premium
join:2002-08-04
Country!
Just the thing for you


a href

@bellsouth.net
reply to on my pc today
»www.cmilner.com/crapware.php


onmy pc today

@comcast.net
reply to on my pc today
thank you very much jents this has helped. and i made a copy of the instuctions to our it guy .maybe he will learn from this.


on my pc today

@comcast.net

reply to on my pc today
Re: Found braviax virus on our company pc

well i must say the info here i got from you guys was on the money. a matched perfectly to the problem.
But it's a nasty one and we have elected to remove the pc from our server to risky to keep it online and to costly to repair if it get into our other pc's so it's been trashed.
We thought better to just get a new pc instead of having to pay for consulting and work which can end up cost big bucks in labor time.
So at this time i thank you all here at dslreports for your care in this matter.

daveinpoway

join:2006-07-03
Poway, CA

Do I understand correctly that you went out and bought a new PC instead of wiping the hard drive clean and re-installing Windows on your old computer? Seems like an extreme way to go to me!

Obviously, you need better security programs and/or procedures. If you don't do this, your new PC will soon get infected, just like the old one did.


Psicop
More human than human
Premium
join:2005-12-21

reply to on my pc today
quote:
We thought better to just get a new pc instead of having to pay for consulting and work which can end up cost big bucks in labor time.
Hey! If I infect mine would you buy me a Mac AirBook? I desperately need one and can't afford it.

Send me a PM for my personal details.

Thank you very much.



Btw, to avoid further infections in the future tell your IT guide to do some homework:

»csrc.nist.gov/itsec/


Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

reply to on my pc today
said by on my pc today :

Hi anyone know anything about this nasty (Braviax.exe) found it in the startup.
Made one of our pc just constantly turn on an off. but i finally got into the pc and first i got a message your pc is infected,funny how norton did not stop it.
Way to go norton!!!.

Norton isn't an Anti-Spyware or Anti-Malware program. It is an Anti-Virus program. You should have an additional type of protection running if you are going to have any PC directly connected to the Internet. Was your Norton not updated or a older version?

»Ugh - Ultimate Defender infection

Regards,

Doctor Olds
--
What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?

zteardrop

join:2005-12-20
Brooklyn, NY

said by Doctor Olds See Profile :

said by on my pc today :

Hi anyone know anything about this nasty (Braviax.exe) found it in the startup.
Made one of our pc just constantly turn on an off. but i finally got into the pc and first i got a message your pc is infected,funny how norton did not stop it.
Way to go norton!!!.

Norton isn't an Anti-Spyware or Anti-Malware program. It is an Anti-Virus program.
Absolutely incorrect. Its all of the above.


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

reply to on my pc today
said by on my pc today :

well i must say the info here i got from you guys was on the money. a matched perfectly to the problem.
But it's a nasty one and we have elected to remove the pc from our server to risky to keep it online and to costly to repair if it get into our other pc's so it's been trashed.
We thought better to just get a new pc instead of having to pay for consulting and work which can end up cost big bucks in labor time.
So at this time i thank you all here at dslreports for your care in this matter.
Great idea..I suggest you go out and buy a backup for all the rest of the PC's and change them out daily so everything does not turn into a botnet via your server and end up shutting you down.

»www.bleepingcomputer.com/forums/···205.html
--
Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/


Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

reply to zteardrop
said by zteardrop See Profile :

said by Doctor Olds See Profile :

said by on my pc today :

Hi anyone know anything about this nasty (Braviax.exe) found it in the startup.
Made one of our pc just constantly turn on an off. but i finally got into the pc and first i got a message your pc is infected,funny how Norton did not stop it.
Way to go Norton!!!.

Norton isn't an Anti-Spyware or Anti-Malware program. It is an Anti-Virus program.
Absolutely incorrect. Its all of the above.
That must explain why the original poster above is currently using it YET still got infected with a known Malware threat that is 3 months old and has been written up by other Malware Removal/Detection Programs that do detect the Braviax infection above. Just because a program claims it does a list of detection types doesn't always mean it actually is able to do so.

Norton AV is a very good AV, but it isn't a magic bullet for all other Malware. There are many other true Anti-Spyware, Anti-Malware, Anti-Root-kit and Anti-Trojan detection/removal programs out there that walk all over Norton AV since those other types of Malware are not it's specialty.

»www.cmilner.com/crapware.php
quote:
In the case of this braviax\cru629 infection, it took me hours of research and tinkering to finally get rid of it.

This malware was detected by Windows Defender as Win32/Renos. The malware promptly terminated Windows Defender's process and would not let it restart. Some Defender! Symantec detected it as PERFCOO and claimed to remove it, which it did not.
--
What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?


Vistaluvr

@rr.com
reply to on my pc today
I saw a PC with AVG free on it, let this braviax.exe through.


Dave at Stanford

@Stanford.EDU

reply to on my pc today
I got this last night on my laptop at home over a WiFi
connection.

Here is how I removed it:

1. Stop the barviax process (hit control-alt-delete and press the processes tab)

2. Run msconfig and clear the check boxes for barviax.exe
and vrjb.exe from running on startup

3. Delete bravix.exe and vrjb.exe

4. Run regedit and delete all references to bravix and cru629

5. Reboot

This worked for me

Dave


Telly Boot
Premium
join:2002-05-15
Vancouver, BC
·TELUS

reply to Name Game
(Hopefully without encouraging a slugfest), if this is looming as a major annoyance, would it be useful to have a thread listing which programs are effective at removing Braviax ?
CounterSpy? »research.sunbelt-software.com/th···d=203602
Is there an agreed name for it? Braviax, cru629 or Trojan-Downloader.Hertu (?) Doesn't show up in Norton under any of those.
--
Dawn,n,The time when men of reason go to bed. (Ambrose Bierce.)


Raz

@tele.dk

reply to zteardrop
said by zteardrop See Profile :

said by Doctor Olds See Profile :

Norton isn't an Anti-Spyware or Anti-Malware program. It is an Anti-Virus program.
Absolutely incorrect. Its all of the above.
Yeah, that's what they claim. Unfortunately it looks like it does not a good job.


Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

reply to Telly Boot
said by Telly Boot See Profile :

would it be useful to have a thread listing which programs are effective at removing Braviax ?
CounterSpy? »research.sunbelt-software.com/th···d=203602
Is there an agreed name for it? Braviax, cru629 or Trojan-Downloader.Hertu (?) Doesn't show up in Norton under any of those.
Prevx has this to say.

»www.prevx.com/filenames/95425137···EXE.html
quote:
The filename BRAVIAX.EXE was first seen on Jan 31 2008 in The EUROPEAN UNION. It has also been seen in the following geographical regions of the Prevx community:

* ARGENTINA on Mar 7 2008
* SPAIN on Feb 26 2008
* The UNITED STATES on Feb 26 2008

The filename BRAVIAX.EXE refers to many versions of an executable program.
The most common file size is 18,432 bytes. But the following file sizes have also been seen:

* 11,264 bytes
* 16,384 bytes
* 16,896 bytes

The filename is associated with the malware group SystemDefender:Spyware-a.
These files have no vendor, product or version information specified in the file header.

BRAVIAX.EXE has been seen to perform the following behavior(s):

* The Process is packed and/or encrypted using a software packing process
* Changes the Internet Explorer Search Page
* Disables the Notification Baloon for the Windows Security Center
* Disabling the Windows Built in Firewall enabling rogue processes to access the internet without user knowledge or permission
* This Process Creates Other Processes On Disk
* This Process Deletes Other Processes From Disk
* Can communicate with other computer systems using HTTP protocols
* Executes a Process
* Registers a Dynamic Link Library File
* Creates a new Background Service on the machine
* Looks at the contents of the autoexec.bat file
* Reads email address and phone book details
* Opens pop up browser windows
* Includes file creation code which could be used to test for interception by security products
* Creation and Registration of a Browser Helper Object in Internet Explorer
* Modifies Windows Initialization And System Settings Used On Start up
* Changes the Internet Explorer Home Page Settings

BRAVIAX.EXE has been the subject of the following behavior(s):

* Added as a Registry auto start to load Program on Boot up
* Created as a process on disk
* Executed as a Process
* Registered as a Dynamic Link Library File
* Has code inserted into its Virtual Memory space by other programs
* Terminated as a Process

BRAVIAX.EXE can also use the following file names:

* 023342-3496F479.EXE
* 76187864.EXE
* 04836836.SVD
* 012877-24401E90.EXE
* 27044453.SVD
* 57134588.DAT
* A0193409.EXE
* A0193418.EXE
* A0193419.EXE
* BEHAVIAX.EXE
* 56846728.EXE
* BRAVIAX.EX_
* 63594485.EXE
* 16782586.SVD
* 37741952.EXE
* 37483906.SVD

--
What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?

DemonChicken

join:2006-10-15
Boon, MI
·Alltel Axess

AVAST! > Norton, if you spend some more time on computer forums on here or other sites, you will learn that norton is the ass of all virus protection software.



Glad to help.


Oleg
Bellsouth Fastaccess
Premium
join:2003-12-08
Birmingham, AL
reply to on my pc today
Norton is a joke
-
Forums » Up and Running » Security » SecuritySecurty Device(s) may of effected User Profile startup »
« A Flash game:Fight against malwares with security protection  


Saturday, 30-Aug 01:17:02 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [330] Comcast 250GB Cap Goes Live October 1
· [223] FBI To Allow Warrantless Investigations
· [154] Industry Reacts To Comcast Cap Plans
· [130] AT&T Thanks Democrats For Telecom Immunity
· [123] Time Warner Cable Cripples TiVO, Gets FCC Fine
· [120] Why Run FTTH When You Can Pretend You Do?
· [67] Telus CAPS 'Unlimited' EVDO Data Plans
· [65] Game Publishers Follow The RIAA's Lead
· [61] Friday Open Thread
· [60] Qwest Defends Not Running FTTH
Most people now reading
· Comcast has new Acceptable Use Policy besides the 250GB cap [Comcast HSI]
· Steele vs Paypal - Hoax or Not - You Make the Call [Security]
· Home UPS powered by car battery [Electronics]
· [iPhone] Did I Buy A Fake iPhone? [All things Macintosh]
· Criss Angel revealed. [56k lookout! (broadband heavy)]
· Humidity Problem in Office Building [Home Repair & Improvement]