Sticky flec006.exe Win32.Bagl

Discussion in 'Malware Help (A Specialist Will Reply)' started by jncastellano, Jun 4, 2008.

  1. jncastellano

    jncastellano Private E-2

    Hi,

    I think i'm infected with a new version of win32.bagl with a flec006.exe file.
    I read other posts related with this kind of malware and...

    - Cannot kill processes related with svchost.exe and flec006.exe
    - Cannot boot in safe mode(also tryed with programs, registry codes, etc.)
    - Avenger and other tools from this page downloads as Win32 Ap not valid
    - hijackthis dies at 10 seconds ( malware protection¿??? )
    - Cannot run MGTools totally (abnormal end)

    I tryed to boot with a knoppix CD and delete files separatelly:

    flec006.exe in Document and Settings\usuario\Local ..\m
    c:\WINDOWS\system32\drivers\downld\

    I reboot but the malware is still in.

    Which files may i delete??

    Thanks for advice
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Since you have a Knoppix CD, boot from it and delete the below files if found. Some may not be found.

    C:\WINDOWS\system32\mdelk.exe
    C:\WINDOWS\system32\mdelk.pif
    C:\WINDOWS\system32\wintems.exe
    C:\WINDOWS\system32\drivers\hldrrr.exe
    C:\WINDOWS\system32\drivers\mdelk.exe
    C:\WINDOWS\system32\drivers\mdelk.pif
    C:\WINDOWS\system32\drivers\srosa.sys
    C:\WINDOWS\system32\drivers\down\a.bat
    C:\WINDOWS\system32\drivers\downld\a.bat
    C:\WINDOWS\system32\ban_list.txt

    And delete the below folders if found:
    C:\Documents and Settings\usuario\Datos de programa\m
    C:\WINDOWS\system32\drivers\down
    C:\WINDOWS\system32\drivers\downld

    Then reboot your PC and do the below.


    Copy the bold text below to notepad. Save it as fixBagle.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now try to run ALL steps in this READ & RUN ME FIRST. Malware Removal Guide and attach logs from the requested programs. If you cannot run ComboFix in normal boot mode, try safe boot mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds