Bagle infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vamirez, Oct 23, 2008.

  1. Vamirez

    Vamirez Private E-2

    Hi,

    my Zonealarm stopped working with the message "...is not a valid Win32 application". I assumed this was bad news and I was right - I've got the Bagle Rootkit and apparently some other things... after a journey through different board to find help, I finally got here.

    I tried to follow the READ & RUN FIRST advice here on the board, with the following results:

    - CCleaner immediately closes

    - SuperAntiSpyWare completed its scan and removed some things, log attached

    - SpyBot installed, ran and also removed some stuff; then it asked me to restart the computer; I did that and subsequently it does not start anymore with the "...is not a valid Win32 application" message...

    - MalwareBytes Antimalware ran, removed some things and also asked for a restart; log attached

    - combofix doesn't run - "not a valid..."

    - MGTools ran through - log attached

    I'd be very happy if you could help me.

    Thx in advance,
    Vamirez
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  3. Vamirez

    Vamirez Private E-2

    Hi,

    thx for the answer - unfortunately I cannot run avenger.exe ("...is not a valid Win32...".
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to find and delete:
    C:\Dokumente und Einstellungen\SBOTT\Anwendungsdaten\m
    C:\WINXP\system32\drivers\rsgpxu.sys
    C:\WINXP\system32\dllcache\register.exe
    C:\WINXP\system32\dllcache\sysinfo.exe

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If you are successful, please get me a new MGLogs.zip by running the C:\MGtools\GetLogs.bat file.
     
  5. Vamirez

    Vamirez Private E-2

    Another problem turned up: I cannot see hidden files anymore and the option to make them visible has disappeared...

    Even so, I manually deleted 3 files from C:\Dokumente und Einstellungen\SBOTT\Anwendungsdaten\m; it doesn't let me delete the folder though, stating its not empty.

    I cannot find/see C:\WINXP\system32\drivers\rsgpxu.sys

    I deleted C:\WINXP\system32\dllcache\register.exe and C:\WINXP\system32\dllcache\sysinfo.exe

    Should I still execute fixME.reg?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes!! Then a new MGLogs.zip. :)
     
  7. Vamirez

    Vamirez Private E-2

    Allright, I executed fixME.reg and created a new MGlogs.zip.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I want you to run malwarebytes in safe mode...then again in normal mode. Also run it on each user account.

    Are you still unable to run Combo even in safe mode?
     
  9. Vamirez

    Vamirez Private E-2

    Argl, when I try to run safe mode, my machine simply reboots...

    Edit: I still cannot use Combofix.
     
    Last edited: Oct 24, 2008
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And MWB's...can you run it again on each user profile?
     
  11. Vamirez

    Vamirez Private E-2

    I ran MWB again on my user account, which is the admin account. The guest account is not activated. There was a third account, created by the .net framework, but I don't need that so I removed it.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And did it find anything?

    Please attach it to your next reply.
     
  13. Vamirez

    Vamirez Private E-2

    Sorry - yes, lots of the same stuff it found and removed before. Log attached.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good...now run it again...until it comes up with little to find....let me see the next results.
     
  15. Vamirez

    Vamirez Private E-2

    Next results attached.
     

    Attached Files:

  16. Vamirez

    Vamirez Private E-2

    And another run - only the rootkit is left! Log attached.
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Can you now run ComboFix?

    Do the registry patch that I gave you again.

    Attach Combo log if it runs....and run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file
     
  18. Vamirez

    Vamirez Private E-2

    Still cannot run Combofix.

    I ran fixME.reg again.

    New MGLogs.zip file is attached.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now please go to this link:http://live.sysinternals.com/

    • find the psexec.exe file listed in the list and click on it and download and save it to the C:\MGtools folder. Doing this properly is critical for other steps below to work properly.
    • Now download the attached FixBagle.exe file and make sure you save it to the C:\ folder so that you have a C:\FixBagle.exe file.
    • Now run the C:\FixBagle.exe file by double clicking on it.
    • Now run MBAM again, update it, run a scan. If it tells you it needs to reboot then IMMEDIATELY do the reboot before continuing with the below.
    • Now see if you can run SUPERAntiSpyware (SAS), update it, and run a scan. If it does not run, try renaming the executable file name as suggested in the READ & RUN ME to SAS.exe
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it
    • Now attach the below new logs
      • MBAM
      • SAS (if it ran)
      • C:\MGlogs.zip
     

    Attached Files:

  20. Vamirez

    Vamirez Private E-2

    Hi,

    okay - I did all that. Looks rather clean now :) Logs attached.
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's much better but we still have some registry entries from Bagle that did not get removed. Let's try to remove these as well as fix a few other minor things.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.


    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINXP\Temp


    • Now download the attached NEW VERSION of FixBagle.exe file and make sure you save it to the C:\ folder so that you have a C:\FixBagle.exe file. Yes you should be overwriting the old version.
    • Now run the C:\FixBagle.exe file by double clicking on it.
    • Now click Start, Run, and copy and paste the below bold print into the Run box and then click OK.
    c:\mgtools\psexec -s -i regedit

    • If the above works properly, you should see the Windows Registry Editor open up. If it does then continue. If it does not, then stop and make sure you entered the above properly.
    • In the Registry Editor click File, Import and then navigate to the C:\MGtools folder and double click on the FixBagle.reg file to import it into your registry. Make sure you double click on FixBagle.reg not FixBagle.bat. If it works properly you should get a success message about it being added to your regisrty.
    • If you get a success message continue on with the below, otherwise stop and explain to me any problems you had.
    Now run Ccleaner to clean temp files!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).




    Then attach the below log:
    • C:\MGlogs.zip
     

    Attached Files:

    Last edited: Oct 25, 2008
  22. Vamirez

    Vamirez Private E-2

    Okay - I was able to do all that. New MGLogs.zip is attached.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay there are still a couple of registry keys that just do not want to go away. TimW had you download Avenger back in message # 2 but you could not run it then. I suspect that you should be able to run Avenger now so let's try the below steps.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  24. Vamirez

    Vamirez Private E-2

    Yes, I was able to run the Avenger now.

    Even so, after the reboot I tried to open Combofix or Zonealarm and they are still "not valid Win32 applications".

    New logs attached.
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay this finally removed the last of the malware registry keys.


    I would not worry about ComboFix anymore since we are finished with it. The infection may have broken ZoneAlarm. I suggest that you uninstall it, reboot (do not skip) and then try reinstalling it. Does that help?
     
  26. Vamirez

    Vamirez Private E-2

    ZA looks really broken. Uninstall won't run with the message that its service is running, but in reality it isn't and cannot be started with an error message. In the administration tab of my system setting I also saw a hidden "desktop.ini" file - does that belong there?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if the below will work for you:

    http://forums.zonealarm.com/zonelabs/board/message?board.id=AllowAccess&message.id=103

    This is normal.
     
  28. Vamirez

    Vamirez Private E-2

    Hi,

    I wasn't able to delete all the ZA files, but cleaning the registry let me re-install and now its running again :)

    Soooo, that means everything is allright again now?
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  30. Vamirez

    Vamirez Private E-2

    Allright, I followed the final steps and am working through the "how to protect yourself from malware" page. Thank you very much for all the help!! :)
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds