Computing.Net > Forums > Security and Virus > win32:bravesentry-b[adw] virus ? or

win32:bravesentry-b[adw] virus ? or

Reply to Message Icon

Original Message
Name: jimmyzowens
Date: February 19, 2008 at 19:48:43 Pacific
Subject: win32:bravesentry-b[adw] virus ? or
OS: windows xp
CPU/Ram: intel celeron m
Model/Manufacturer: gateway
Comment:

getting some malware keeps loading everytime i turn computer on , avast picks it up but keeps coming back , also loads computer up with lots of files. i saw you help another guy here and ive downloaded hijack this and have my file savec on my desktop



Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: February 19, 2008 at 20:03:28 Pacific
Reply: (edit)

Go to the this link:

Disable Realtime Protection

Follow their directions to disable any realtime protection that you have as it will interfere with the fix by reinstalling the corrupt files.

Please download and install the latest version of HijackThis v2.0.2:


Download the "HijackThis" Installer from this link:
Hijack This


1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.

Please download ComboFix to the desktop from one of the following links:

Link1

Link 2

Link 3

Double-click combofix.exe
Follow the prompts.
(Don't click on the window while the program is running, it may cause your system to hang.)
Please post the log it produces.


Report Offensive Follow Up For Removal

Response Number 2
Name: Kaithlyn
Date: February 20, 2008 at 06:06:00 Pacific
Reply: (edit)

have you tried to removal bravesentry manually? here's manual brave sentry removal. good luck.

tc;


Report Offensive Follow Up For Removal

Response Number 3
Name: jimmyzowens
Date: February 21, 2008 at 21:49:42 Pacific
Reply: (edit)

when i drag the logs into the comments screen it just shows them full screen it wont let me put them there to send and submit????????????


Report Offensive Follow Up For Removal

Response Number 4
Name: jabuck
Date: February 22, 2008 at 10:26:07 Pacific
Reply: (edit)

Highlight the log with your cursor> press "ctrl c" without quotes (copy)( click the top left corner of the comments screen then press "ctrl v" without quotes (paste). See if that will get the logs posted.



Report Offensive Follow Up For Removal

Response Number 5
Name: jimmyzowens
Date: February 22, 2008 at 17:25:22 Pacific
Reply: (edit)

yea copy and paste wont work tried dragin the hi jack this log in there to and same thing ???????? i dont know lol


Report Offensive Follow Up For Removal


Response Number 6
Name: jabuck
Date: February 22, 2008 at 19:43:45 Pacific
Reply: (edit)

It may be the keyboard has a hot key setup on it.

Press "shift alt" then "ctrl alt" then see if it will copy/paste.


Report Offensive Follow Up For Removal

Response Number 7
Name: jimmyzowens
Date: February 23, 2008 at 08:56:00 Pacific
Reply: (edit)

ComboFix 08-02-22 - Owner 2008-02-21 16:21:04.2 - NTFSx86

Running from: C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\YR0TW330\ComboFix[1].exe

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.

((((((((((((((((((((((((( Files Created from 2008-01-22 to 2008-02-22 )))))))))))))))))))))))))))))))
.

2008-02-18 20:27 . 2008-02-18 20:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-18 20:27 . 2008-02-18 20:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-18 19:44 . 2008-02-18 19:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-18 19:17 . 2008-02-18 19:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-18 19:17 . 2008-02-18 19:17 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-31 21:14 . 2008-01-31 21:14 <DIR> d-------- C:\Program Files\LimeWire
2008-01-31 19:13 . 2008-01-31 21:03 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-01-30 20:01 . 2005-08-27 02:38 1,435,272 --a------ C:\WINDOWS\system32\Flash.ocx
2008-01-30 20:01 . 2003-11-19 14:59 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2008-01-30 20:01 . 2004-05-11 10:56 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2008-01-30 20:01 . 2004-02-05 21:53 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX
2008-01-30 20:01 . 2004-01-09 11:54 188,416 --a------ C:\WINDOWS\system32\actsplash.ocx
2008-01-30 20:01 . 2004-03-09 00:00 131,856 --a------ C:\WINDOWS\system32\MSADODC.ocx
2008-01-30 20:01 . 2001-03-28 23:02 89,088 --a------ C:\WINDOWS\system32\ProgressBar4.ocx
2008-01-30 20:01 . 1999-01-26 19:36 11,012 --a------ C:\WINDOWS\system32\threadapi.tlb
2008-01-27 18:03 . 2008-01-27 18:03 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Eyeblaster
2008-01-27 18:02 . 2008-01-27 18:02 <DIR> d-------- C:\My Games
2008-01-27 18:02 . 2008-01-27 18:02 <DIR> d-------- C:\My Download Files
2008-01-27 18:01 . 2008-01-27 18:01 774,144 --a------ C:\Program Files\RngInterstitial.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-21 19:25 --------- d-----w C:\Documents and Settings\Owner\Application Data\MSN6
2008-02-20 03:35 --------- d-----w C:\Program Files\Trend Micro
2008-02-18 00:39 --------- d-----w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-02-18 00:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-01 03:58 --------- d-----w C:\Program Files\DigiTech
2008-02-01 02:13 --------- d-----w C:\Documents and Settings\Owner\Application Data\Audacity
2008-02-01 02:12 --------- d-----w C:\Program Files\REAPER
2008-02-01 02:11 --------- d-----w C:\Documents and Settings\Owner\Application Data\REAPER
2008-01-28 02:07 --------- d-----w C:\Program Files\Real
2008-01-28 02:07 --------- d-----w C:\Program Files\Common Files\Real
2008-01-20 19:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Sports Stats 2.0
2008-01-20 19:39 --------- d-----w C:\Program Files\NCH Swift Sound
2008-01-20 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-01-14 17:27 --------- d-----w C:\Program Files\BrowsingAdvisor
2008-01-14 00:22 --------- d-----w C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
2008-01-13 05:37 --------- d-----w C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-01-12 03:53 --------- d-----w C:\Program Files\PlayMP3z
2008-01-03 04:04 --------- d-----w C:\Program Files\Microsoft Games
2008-01-03 03:18 --------- d-----w C:\Program Files\MSN Games
2007-12-31 21:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-31 00:31 --------- d-----w C:\Program Files\GameSpy Arcade
2007-12-31 00:02 --------- d-----w C:\Program Files\EA GAMES
2007-12-30 22:33 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-12-28 05:37 --------- d-----w C:\Program Files\Common Files\EasyInfo
2007-12-14 19:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-12-04 04:36 368,640 ----a-w C:\WINDOWS\system32\ReWire.dll
2006-09-17 22:35 80 --sh--r C:\WINDOWS\system32\D4988260E1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 11:00 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 06:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 06:47 688218]
"SMSERIAL"="sm56hlpr.exe" [2006-01-11 09:22 544768 C:\WINDOWS\sm56hlpr.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-26 17:20 413696 C:\WINDOWS\stsystra.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 02:01 32768]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 11:17 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 11:17 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 11:13 77824]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 11:30 139264]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-11-11 20:40 1236992]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-18 16:19 98304]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 17:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2006-06-18 16:14:20 2168360]
Windows Desktop Search.lnk - C:\Program Files\MSN Toolbar Suite\DS\[u]0[/u]2.05.0001.1119\en-us\bin\WindowsSearch.exe [2005-09-20 17:10:04 238080]


.
Contents of the 'Scheduled Tasks' folder
"2008-02-21 04:35:53 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-21 16:23:22
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-21 16:24:16
ComboFix-quarantined-files.txt 2008-02-22 00:24:07
.
2008-02-21 23:37:34 --- E O F ---


Report Offensive Follow Up For Removal

Response Number 8
Name: jabuck
Date: February 23, 2008 at 10:10:02 Pacific
Reply: (edit)

Please go to Virus Total and upload the following file for analysis:

D4988260E1.dll

Post the results in your reply.


Report Offensive Follow Up For Removal

Response Number 9
Name: jimmyzowens
Date: February 23, 2008 at 13:11:02 Pacific
Reply: (edit)

not sure how to locate this file i went to virus total and tried copy and paste from your post , and it uploaded for about 15 min and nothing. then i chose the browse option and searched for the file but could not find it. not sure what im doin wrong ?


Report Offensive Follow Up For Removal

Response Number 10
Name: jabuck
Date: February 23, 2008 at 14:49:57 Pacific
Reply: (edit)

Use the browse button at the site to find the file, once you find the file double click it and it should appear in the empty space to the left of the browse button> click "send file".


Report Offensive Follow Up For Removal

Response Number 11
Name: jimmyzowens
Date: February 23, 2008 at 17:39:50 Pacific
Reply: (edit)

i browse and type in the file name as you have written it and it says file not found


Report Offensive Follow Up For Removal

Response Number 12
Name: jabuck
Date: February 23, 2008 at 19:08:34 Pacific
Reply: (edit)

Set up the computer to view hidden files:
To show hidden files do the following:
Click Start > My Computer
On the Tools menu, click Folder Options.
Click the View tab.
Uncheck Hide file extensions for known file types.
Uncheck Hide protected operating system files.
Under the Hidden files folder, locate and check Show hidden files and folders.
If you see a warning message, click Yes.
Click Apply > OK.

You cannot copy/paste it or type it in. It has to be the file itself before they can tell if it infected.

Go to the VirusTotal site again.

Click the browse button> a "choose file box will open> in the "look in" window at the top of the box click the drop down arrow just to the right of the "look in" window> double click "local disk(c:)"> double click "windows"> double click "system32"> double click D4988260E1.dll.

Now the file should be in the "Upload a file" window just to the left of the Browse button.

Now click the send file button and await the results.


Report Offensive Follow Up For Removal

Response Number 13
Name: jimmyzowens
Date: February 24, 2008 at 09:40:46 Pacific
Reply: (edit)

ok first off i apologize for my lack of computer knowledge , secondly i appreciate you and this site greatly. is there anywere to make a donation , thirdly i followed your instructions to the tee and all the files are in alpabetical order on the system32 page and there is no file ther by that name??????????????


Report Offensive Follow Up For Removal

Response Number 14
Name: jabuck
Date: February 24, 2008 at 16:15:16 Pacific
Reply: (edit)

Computing.net does not accept donations at this time but your off is truly appreciated.

Open Notepad and copy/paste everything between the X"s into it and make sure "File::" is at the very top of the page.
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
File::
C:\WINDOWS\system32\D4988260E1.dll

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Go to File on the top bar and choose" Save As", Change the "Save As Type" to All Files, Name it CFScript.txt then save it to your desktop.
Then drag/drop the CFScript.txt onto ComboFix.exe (the red X on your desktop) if combofix does not auto start click "run".

Post a new Combofix log.


Report Offensive Follow Up For Removal

Response Number 15
Name: jimmyzowens
Date: February 24, 2008 at 19:38:24 Pacific
Reply: (edit)

ComboFix 08-02-25.2 - Owner 2008-02-24 19:28:30.3 - NTFSx86

Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]

FILE ::
C:\WINDOWS\system32\D4988260E1.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\D4988260E1.dll

.
((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.

2008-02-24 10:14 . 2008-02-24 10:14 <DIR> d-------- C:\Program Files\Defraggler
2008-02-23 10:23 . 2008-02-23 10:36 <DIR> d-------- C:\Program Files\Creatrix
2008-02-18 20:27 . 2008-02-18 20:27 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-18 20:27 . 2008-02-18 20:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-18 19:44 . 2008-02-18 19:44 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-18 19:17 . 2008-02-22 17:48 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-18 19:17 . 2008-02-18 19:17 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-31 21:14 . 2008-01-31 21:14 <DIR> d-------- C:\Program Files\LimeWire
2008-01-31 19:13 . 2008-01-31 21:03 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-01-30 20:01 . 2005-08-27 02:38 1,435,272 --a------ C:\WINDOWS\system32\Flash.ocx
2008-01-30 20:01 . 2003-11-19 14:59 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2008-01-30 20:01 . 2004-05-11 10:56 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2008-01-30 20:01 . 2004-02-05 21:53 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX
2008-01-30 20:01 . 2004-01-09 11:54 188,416 --a------ C:\WINDOWS\system32\actsplash.ocx
2008-01-30 20:01 . 2004-03-09 00:00 131,856 --a------ C:\WINDOWS\system32\MSADODC.ocx
2008-01-30 20:01 . 2001-03-28 23:02 89,088 --a------ C:\WINDOWS\system32\ProgressBar4.ocx
2008-01-30 20:01 . 1999-01-26 19:36 11,012 --a------ C:\WINDOWS\system32\threadapi.tlb
2008-01-27 18:03 . 2008-01-27 18:03 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Eyeblaster
2008-01-27 18:02 . 2008-01-27 18:02 <DIR> d-------- C:\My Games
2008-01-27 18:02 . 2008-01-27 18:02 <DIR> d-------- C:\My Download Files
2008-01-27 18:01 . 2008-01-27 18:01 774,144 --a------ C:\Program Files\RngInterstitial.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 23:31 --------- d-----w C:\Documents and Settings\Owner\Application Data\Audacity
2008-02-24 23:30 --------- d-----w C:\Documents and Settings\Owner\Application Data\MSN6
2008-02-24 08:11 --------- d-----w C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-02-24 03:11 --------- d-----w C:\Program Files\REAPER
2008-02-20 03:35 --------- d-----w C:\Program Files\Trend Micro
2008-02-18 00:39 --------- d-----w C:\Documents and Settings\Owner\Application Data\ZoomBrowser EX
2008-02-18 00:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-02-01 03:58 --------- d-----w C:\Program Files\DigiTech
2008-02-01 02:11 --------- d-----w C:\Documents and Settings\Owner\Application Data\REAPER
2008-01-28 02:07 --------- d-----w C:\Program Files\Real
2008-01-28 02:07 --------- d-----w C:\Program Files\Common Files\Real
2008-01-20 19:40 --------- d-----w C:\Documents and Settings\Owner\Application Data\Sports Stats 2.0
2008-01-20 19:39 --------- d-----w C:\Program Files\NCH Swift Sound
2008-01-20 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-01-14 17:27 --------- d-----w C:\Program Files\BrowsingAdvisor
2008-01-14 00:22 --------- d-----w C:\Documents and Settings\Owner\Application Data\NCH Swift Sound
2008-01-12 03:53 --------- d-----w C:\Program Files\PlayMP3z
2008-01-03 04:04 --------- d-----w C:\Program Files\Microsoft Games
2008-01-03 03:18 --------- d-----w C:\Program Files\MSN Games
2007-12-31 21:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-31 00:31 --------- d-----w C:\Program Files\GameSpy Arcade
2007-12-31 00:02 --------- d-----w C:\Program Files\EA GAMES
2007-12-30 22:33 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-12-28 05:37 --------- d-----w C:\Program Files\Common Files\EasyInfo
2007-12-14 19:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-12-04 04:36 368,640 ----a-w C:\WINDOWS\system32\ReWire.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 11:00 15360]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 06:47 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 06:47 688218]
"SMSERIAL"="sm56hlpr.exe" [2006-01-11 09:22 544768 C:\WINDOWS\sm56hlpr.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2005-12-26 17:20 413696 C:\WINDOWS\stsystra.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 02:01 32768]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" [ ]
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 11:17 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 11:17 118784]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 11:13 77824]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 11:30 139264]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2005-11-11 20:40 1236992]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-18 16:19 98304]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" []
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 17:17 443968]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe [2006-06-18 16:14:20 2168360]
Windows Desktop Search.lnk - C:\Program Files\MSN Toolbar Suite\DS\[u]0[/u]2.05.0001.1119\en-us\bin\WindowsSearch.exe [2005-09-20 17:10:04 238080]


.
Contents of the 'Scheduled Tasks' folder
"2008-02-24 10:17:02 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 19:30:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-24 19:31:27
ComboFix-quarantined-files.txt 2008-02-25 03:31:09
ComboFix2.txt 2008-02-22 00:24:17
.
2008-02-21 23:37:34 --- E O F ---


Report Offensive Follow Up For Removal

Response Number 16
Name: jabuck
Date: February 24, 2008 at 20:09:13 Pacific
Reply: (edit)

How is the computer operating?


Report Offensive Follow Up For Removal

Response Number 17
Name: jimmyzowens
Date: February 25, 2008 at 18:04:45 Pacific
Reply: (edit)

normal as far as i know , i shut it off the yesterday and turned it back on and havent seen any probs , do u think that i will have any problems , i dont know how to read those forms you had me post , so i hope everything looks ok ?.
and if its all fixed . thx its nice to see you kind of people out there. help us wanna bees . lol


Report Offensive Follow Up For Removal

Response Number 18
Name: jabuck
Date: February 25, 2008 at 19:08:35 Pacific
Reply: (edit)

The computer looks ok. I would suggest that you uninstall LimeWire and find a safer p2p program or you may soon be reinfected.

Glad we could help.


Report Offensive Follow Up For Removal

Response Number 19
Name: jimmyzowens
Date: February 26, 2008 at 18:29:30 Pacific
Reply: (edit)

any suggestions on another p2p type like limewire?????????. oh and ill keep checkin in in you guys decide to take donations.


Report Offensive Follow Up For Removal

Response Number 20
Name: jabuck
Date: February 26, 2008 at 19:07:23 Pacific
Reply: (edit)

Looks as though LimeWire is now considered clean.

Link to Safe and unsafe p2p listings:

http://p2p.malwareremoval.com/


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: win32:bravesentry-b[adw] virus ? or

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




Have you ever used OpenOffice?

Yes, as my main suite.
Yes, occationally.
Yes, but only once.
No, never.


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge