VBS: Malware-gen, Win32:Bravix-B [Drp] [RESOLVED]

I noticed that my background had been changed to an ad for windows warning message and a notice saying that I was infected with Win32\Adware.Virtumonde and Win32\PrivacyRemover.M64

There was also a pop-up for Antivirus XP 2008 license agreement, which I didn’t download or anything. So I scanned my computer with Avast!. The scan came up with several files which I moved to the chest, but some would not move and so I deleted them.

The files that show up when ever I rescan and won’t delete are:

c:\docume~1\admni~1\locals~1\temp\nsm4.tmp\euladlg.dll (Malware name: Win32:Adware-gen [Adw]) VPS version: 080919-0, 09/19/2008

It recommendes that I move the file to chest, but even after doing so it keeps reappering when ever I rescan.

c:\windows\system32\tdssl.dll (Maleware name: Win32;Bravix-B [Drp]) Maleware type: Dropper (VPS version:080919-0, 09/19/2008)

It recommendes that I move the file to chest but it will not let me, saying:

The Process cannot access the file because it is being used by another process
Cannot process ‘c:\windows\system32\tdssl.dll’ file

So then I delete the file, but it doesn’t go away and re-appears next time I scan.

Then a notice would pop up saying that:

Avast! has detected a virus in the operating memory. Since it is very dangerous to work with the computer while the virus is active, it is strongly recommended that you restart the computer and let avast! scan all your data in the boot phase, before the virus can be activated. Do you want to scedual the boot-time scan and restart the computer?

I click yes and it restarts my computer scanning. These things show up when it scans:

File C:\Documents and Settings\Administrator\Local Settings\Temp.tt1A.tmp.vbs is infected by VBS:Malware-gen

File C:\Documents and Settings\Administrator\Local Settings\Temp.tt1D.tmp.vbs is infected by VBS:Malware-gen

File C:\Documents and Settings\Administrator\Local Settings\Temp.tt1E.tmp.vbs is infected by VBS:Malware-gen

File C:\Documents and Settings\Administrator\Local Settings\Temp.tt20.tmp.vbs is infected by VBS:Malware-gen

File C:\Documents and Settings\Administrator\Local Settings\Temp.tt22.tmp.vbs is infected by VBS:Malware-gen

I send them all to the chest put they re-appear every time I rescan. I’ve deleted them all before too, and they re-appear anyway.

File C:\WINDOWS\SYSTEM32\tdssadw.dll is infected by Win32:Bravix-B [Drp]

File C:\WINDOWS\SYSTEM32\tdssl.dll is infected by Win32:Bravix-B [Drp]

File C:\WINDOWS\SYSTEM32\tdsslog.dll is infected by Win32:Bravix-B [Drp]

File C:\WINDOWS\SYSTEM32\tdssmain.dll is infected by Win32:Bravix-B [Drp]

File C:\WINDOWS\SYSTEM32\tdssserf.dll is infected by Win32:Bravix-B [Drp]

I send these ones to chest also and the same thing happens. They re-appear the next time I scan.

I have downloaded the newest version of CBO and this pops up:

Location of startup: FILE


Then it mentions that that was a trojan horse and that it has been shut down, but the file it comes from remains. I remove the file but it shows up again when I restart my computer.

That’s really all the information I can think of to give. My Avast! is the lastest version as is CBO. I’ve turned off my System Restore. My operating system is a Windows XP, I don’t know about the bit part. My only virus software is Avast! and now CBO.

I’m sorry if this was not clear enough. Normally I can fix these things on my own, but I guess that this is a real virus or something. I am sorry to bother you, but please help. I need my laptop back.

Welcome to the forums ,

I’ve just created a topic for such stuff

Try if that way helps you out :slight_smile:


Ah, thank you. This appears to be working so far. I’m on the last scan, so if that still shows stuff I’ll post my Hijack log.

Thank you very very much! I really appreciate your help. :slight_smile:

Okay so here's my Hijackthis log:

My background is now blue instead of blue with an ad. The other things have stopped popping up though.

Seems clear to me. Have you tried just changing the wallpaper ? (How to change a wallpaper?

Try Kaspersky’s online scanner and see if anything still pops-up. I think however that you’re totally safe now :slight_smile:


It won’t download all the way, it stops several seconds in and says that the license has expired.

The online scanner ? How’s that possible ?


For Antispyware/Malware Cleaning, Download, Install & Update with:

Malwarebytes’ Anti-Malware
SUPERAntispyware Free

If you’re looking for a good AV, I recommend either:

Avast! Home Edition
Avira AntiVir Personal

Go with Avast! for the features, But Avira for detection. :wink:

Only choose ONE Antivirus

Update your AV, Malwarebytes’ Anti-Malware and SUPERAntispyware. Reboot. On Reboot, Start pressing “F8” Until you reach the Safe Mode Configuration Screen. Click Safe Mode without Networking, And scan from there.

I personally use and like Avira AntiVir Personal. :wink:


Not for something or so but err


it’s explained in that topic Josh :slight_smile:


Ahh… Okay!


:slight_smile: I already did all that.

I’m sorry for being such a bother.

Well then your computer should be clean


Waa! Thank you so much! Really! :slight_smile:

Then I should close this one. :slight_smile:

Please PM any Online Mod if you want this thread re-opened.