Two days ago braviax.exe ended up on a computer that had Kaspersky 7.0 installed and being updated daily. The Kaspersky update ran an 12:33 noon according to file time stamps. At either 1:07 or 2:43 pm braviax.exe got installed and then something called winreanimator.exe got installed.
Hijackthis does not start when an attempt to open it is made.
Kaspersky will not start (does not show in the bottom right hand any longer - had to look at files in the directory to identify ver 7...125 )
Downloaded SDFix.exe on another computer and copied it to the infected one - but in both safe mode and regular mode it will not open.
All files that are named winrean*.* have been removed off of the drive.
All files time stamped 1pm thru 2:50 pm on the 23rd have been removed off of the drive.
All files braviax.exe(file size 16896) and winivstr.exe(file size 308712) have been removed (in safe mode) but they keep coming back at next reboot SO I did a copy con to write a junk text string to the file names making the files less than 1k in size and then made the files read only.
Now when the computer boots the HK in Run again shows the braviax.exe to run and the desktop shows a dos screen that has just finished running autoexec.nt ( I checked it and it shows a line I enetered that says Set StaNum-1) with a C: prompt followed by a flashing cursor, as though a program had started.
How does the braviax.exe get rmoved when programs can't be installed?
Start Free Trial