Win32:Beagle-AAW can't get rid of it :(

Discussion in 'Malware Help (A Specialist Will Reply)' started by Princesca, May 14, 2009.

  1. Princesca

    Princesca Private E-2

    Hi guys,

    I downloaded from emule a file called wav to text (or text to wav) but all I got was a Virus :( (it's my faul, i shouldn't have opened a 2mb file :cry) after scanning with an Avast bootable disk (BART), I saw that there were few infected files with Win32:Beagle. I tried to follow your instructions that I read in other posts, but I cannot run Combofix in Windows and I've tried all the other software I've read in your posts, but they don't seem to work...I still cannot run Windows in safe mode and cannot run all security software.
    But why the Avast bootable disk didn't solve the problem? I've read it was the best antivirus from bootable cd :confused

    Thank you for your kind help,

    Francesca
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Use the additional tips/notes in the below to help you move further along. Pay close attention that we say not to stop!!!

    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Princesca

    Princesca Private E-2

    Hi,

    I couldn't run the the safe mode of Windows. Malawarebytes didn't find anything and did not produce a log or at least I didn't find it. This time I could install again Spybot (the one already installed didn't work) which found two malware and fixed them, but I can't see a log for those, it was written win32Bom ..someting like that but it was not Beagle, that's for sure.
    Ah, ComboFix said there was Antivir running, but I uninstalled it, so again, I didn't know what to do. I proceded anyway and these are the logs I managed to get...I hope I followed correctly the procedure you stated.
    Thank you,

    Francesca
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    You weren't supposed to run in safe mode so that does not matter.

    It always creates a log and so does SUPERAntiSpyware. Please attach the logs which you can find as shown below. Since you ran MBAM more than once, please attach both logs from it.
    Code:
    "C:\Documents and Settings\FRANCESCA\Datiapplicazioni\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    17 May 2009         465  "SUPERAntiSpyware Scan Log - 05-17-2009 - 13-08-05.log"
     
     
    "C:\Documents and Settings\FRANCESCA\Dati applicazioni\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    13 May 2009        1050  "mbam-log-2009-05-13 (20-14-37).txt"
    17 May 2009         983  "mbam-log-2009-05-17 (16-09-18).txt"
    
    Your logs do not show signs of an active Bagle/Beagle infection. I see signs that you once had the infection and that pieces were removed by ComboFix in a previous scan. Do you have some scan telling you that you are still infected? If so, what scanner and attach a log from it?


    You do need to uninstall all of the below out dated versions of software:
    a-squared Free 2.0
    Ad-Aware SE Personal
    Java(TM) 6 Update 12
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Spybot - Search & Destroy 1.5.2.20

    Then you should reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    I also strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing. Perhaps some of these bagle tools you are downloading are even being detected as problems.
     
    Last edited: May 20, 2009
  5. Princesca

    Princesca Private E-2

    Hi,

    thank you for telling me where to find the logs, which I have enclosed.

    If I scan now the PC with a BART disk (Avast Bootable disk) it doesn find anything, but I still have the same problems, for example, I cannot reboot in safe mode, it loops. Or if I try to open Skype it says:
    "Exception EAccessViolation in module Skype.exe at 00528AF6.
    Access violation at address 00928AF6 in module 'Skype.exe'. Write of address 0000006E"
    or if I try to open Avast it says:"ashAvast.exe is not a valid Win32 application".

    What do you think?
    Thank you,

    Francesca
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. Princesca

    Princesca Private E-2

    Here you are :)

    Francesca
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay FindyKill remove some more issue, but did you notice that it sees that some of your applications have been corrupted. You need to uninstall all of the below and reboot:

    A-squared
    Avast4
    FireFox
    Mozilla Thunderbird
    PartitionMagic 8.0
    Skype

    After reboot reinstall all but A-squared



    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Then attach the new C:\MGlogs.zip file

    Make sure you tell me how things are working now!
     
    Last edited: May 23, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds