Bagle Crumbs in my PC

Discussion in 'Malware Help (A Specialist Will Reply)' started by DRAG0N, Feb 3, 2008.

  1. DRAG0N

    DRAG0N Private E-2

    Hi Guys,

    My computer has been suffering from a bagle infestation for the past week.

    Due to a lapse of sanity with a P2P file I lost all the antivirus, anti spyware, firewall etc programs on the computer (due to the virus), it wouldn't stay on the internet and Windows activation came up and said I had 3 days to activate. Any initial attempts to reinstall antivirus were unsucessful. All antivirus related programs became "not valid win32 applications" ect and apparently my admin user lost the right to start services.

    With the use of some antivirus programs that would run from cd I was able to take back partial control and get an online scan at trend micro. After that one I could install NOD32 and hopefully complete the roundup.

    Viruses found during various scans included:

    Trojan.Bagle-48
    Worm.Bagle.JT
    Win32.Bagle.LY
    Win32.Bagle.MF
    Win32.Bagle.LF
    Win32.Bagle.MJ

    I also found & deleted using advice on forums hldrrr.exe and srosa.sys.

    However, even though scans are now reporting clean the system is not running quite right. Notably:

    1) Internet explorer when it will connect to the Internet won't stay online and I have to reboot to get back online.

    2) The hard drive seems to run hard for brief periods without any apparent cause.

    I have run through your excellent Malware removal guide and read the related posts but am still troubled.

    I would be grateful if an expert could look at my logs and advise of any further work that is required.

    Many Thanks in advance for your efforts.
     

    Attached Files:

  2. DRAG0N

    DRAG0N Private E-2

    Please find last log attached to this one.

    Once again thanks in advance.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I see you have Norton SystemWorks/Utilities installed. As far as I know this contains an antivirus program and more. If this is true, you currently have two antivirus programs installed and per the first instructions in the READ ME, you should have uninstalled Norton before uninstalling NOD32. You need to uninstall one of these now.



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: TBSB02678 Class - {BDCA7AC9-C27B-4D30-A808-9B9081279C03} - C:\PROGRA~1\QUICKN~1\YOUTUB~1.DLL (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O20 - Winlogon Notify: 5E - C:\WINDOWS\system32\5E.tmp (file missing)
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Panther/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg
    O24 - Desktop Component 1: (no name) - file:///C:/DOCUME~1/Panther/LOCALS~1/Temp/msohtml1/03/clip_image002.jpg

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  4. DRAG0N

    DRAG0N Private E-2

    Hi Chaslang,

    Thanks for the prompt reply.

    In order requested:

    1. Norton Systemworks 2004 did not have the antivirus component installed I only had it on my system for the utilities. It has been uninstalled anyway as it only responded with the "not a valid win32 application" message when I tried to open it. I used Add/Remove programs and the Norton removal tool to make sure. I did have an aborted earlier attempt to install Norton AV 2007 on the HDD but the bagle virus killed it. I have deleted all the leftover files.

    2. Ran C:\MGtools\analyse.exe and it removed the lines requested.

    3. Ran Avenger as instructed. It had a few issues (see log attached)

    4. Ran Ccleaner as requested.

    5. Ran the C:\MGtools\GetLogs.bat and attached.

    As for the computers current state. We are making progress but I must say it still has one main issue and "she don't feel quite right".

    Notably,

    a) Still having issues with the internet - I can open Internet Explorer and visit a few sites sucessfully and after that it just reports that it cannot display the webpage and will not connect to any other sites without a reboot. Additionally, in this state, programs like NOD32 and AVG Anti-Spyware seem to have an issue connecting for a manual update BUT Mailwasher and Outlook seem to connect happily. ???

    b) Opening & closing programs in general takes longer and is glitchy (doesn't run smoothly like I am used to) - Could this be NOD32? I haven't used this product before.

    c) Hard drive is still having little infrequent bursts of activity which seem to be unrelated to anything.

    Once again I would like to thank you for your assistance with this problem.

    Drag0n
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the logs we have looked at thus far, your clean.

    This does not sound like something malware would do. Have you tried another browser like FireFox? Also if you boot in safe mode does it behave the same?

    This however does sound like something that a Bagle infection would do. Thus perhaps something else is hiding on your PC, or the previous installations of NOD32 and AVG AS that were performed while infected could be not totally functional. I will give you a couple things further down to run.


    Not sure but a Bagle infection typical would only impact antimalware type programs not other programs. You could uninstall NOD32, AVG Antispyware and then ZoneAlarm one at a time and then reboot each time after installing one program to see what effect it has.


    Additional steps to try:


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
      [*]It will create a folder named HostsXpert in whatever folder you extract it to.
      [*]Run HostsXpert.exe by double clicking on it.
      [*]click the Make Writeable? button.
      [*]click Restore Microsoft's Hosts File and then click OK.
      [*]Click the X to exit the program
    Now run this procedurehttp://esupport.trendmicro.com/support/viewxml.do?ContentID=en-125991 and then attach the sysclean.log file here.

    Now run this procedure Running GMER to detect rootkits and attach the requested log.

    Also run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.
     
  6. DRAG0N

    DRAG0N Private E-2

    Hi Chaslang,

    I have created and merged fixME.reg, restored my Hosts file and run Sysclean and GMER as directed. Please find attached the logs (inc MGlogs.zip) as requested.

    I also must report that I think that I may have stumbled on the the issue with internet while I was testing Internet Explorer in safe mode. Found I had no internet access at all after booting safe mode with networking. The only network adapter that showed up was the wireless adapter and it has been non-functional since the virus. (I'm not sure what its issue is but the WZC service refuses to be started). Anyway, I disabled it in device manager since I normally use a wired connection to my router and after reboot found my connection had stabilized.

    The system is still running "glitchy" and I think your advice on uninstall / reinstall of the security programs is good, but unless you find something in the latest logs then I guess this ceases to be a Malware issue.

    Do you think I might get any value from running "system file checker " or performing a repair install of XP to freshen up the OS??

    I would like also to thank you again for all your efforts on my behalf.

    DRAG0N
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    All your logs are still clean.

    You can give sfc a run to see if it helps. It will not hurt. Other than that try what I said remove one application at a time and rebooting just to see if any of them are causing you a problem. Based on all your logs, any remaining problems do not appear to be malware.
     
  8. DRAG0N

    DRAG0N Private E-2

    Hi Chaslang,

    I'd just like to report that my system is now running sweet as ever, many thanks to you.

    SFC had a fairly busy run and I also discovered that file fragmentation was at 87% (Not totally sure why because I defrag religiously).

    A few defrags later and the system seems back to its old self again.

    Thank you for all your efforts, you are a true champion in my books.

    DRAG0N
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. I'm happy to hear things are back to normal.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds