Removing the Braviax Spyware
Carl M. Milner, Jr.
Cm2 Consulting
http://www.cmilner.com/
Removal of braviax\cru629 malware
Download and install a reputable spyware detection and removal program such as Spyware Doctor which is available free as part of the Google Pack. Spyware Doctor did not detect or remove the braviax/cru629 infection, but is useful in detecting and removing the crap that it downloads.
Disconnect your computer from the Internet. If the crapware can't find the Internet, it can't download any more crap.
Restart your computer from the installation CD in Restore Console mode. With my PC, I had to hit F12 during the boot process and tell it to boot from the CD ROM. When the "Welcome to Windows Installation" window came up, I pressed R to enter the Restore Console.
Navigate to the Windows directory. (If you are at the C:\> prompt you would type cd windows and hit enter. If you need to back up to get to the C:\> prompt, type cd .. and hit enter until you get there.) Once you are at the C:\WINDOWS> prompt type del braviax.exe and hit enter. When your computer returns to the prompt, type del cru629.dat and hit enter.
Navigate to the System32 directory by typing cd system32 and hitting enter. Once you are at the C:\>WINDOWS\SYSTEM32> prompt type del braviax.exe and hit enter. Then type del cru629.dat and hit enter.
Navigate to the C:\WINDOWS\SYSTEM32\DLLCACHE> directory. Type del beep.sys at the prompt and hit enter.
Navigate to the C:\WINDOWS\SYSTEM32\DRIVERS> directory. Type del beep.sys at the prompt and hit enter.
Type exit and hit enter to exit the Restore Console and reboot the computer. You will want to reboot in safe mode. To do this on my PC one must begin madly pressing F8 until a boot menu comes up. Once you have booted to safe mode, open regedit (Click on the "Run" option on the Start menu, type regedit into the text box and hit enter). Once the Registry Editor is open, select My Computer. Then click on the Edit menu item and select Find. In the find dialog box type in braviax (you may omit the .exe part so it will find all references to the nastyware.) When the search finds a value or key containing the word braviax, delete it. Keep searching until all instances have been found and deleted. Repeat this process for cru629. When all instances have been found and deleted, close the Registry editor. Your computer should now be clean of this crap. You may run Spyware Doctor, your anti-virus, and Windows Defender (which should now be runnable). Spyware detectors may find crap that braviax downloaded.
The key to keeping the crapware from reinstalling itself seems to be the removal of beep.sys which normally is a legitimate Windows program. It does not seem to be critical to the operation of the computer. Your machine may not now beep upon start up. If you miss the beep, you could find an uninfected computer with the same operating system as yours and replace the file with a copy from it. That may or may not work. Personally, I'll live without the bleeping beep.


