bagle removal solution

Discussion in 'Malware Help (A Specialist Will Reply)' started by olithejunglist, Jan 6, 2010.

  1. olithejunglist

    olithejunglist Private E-2

    OS: XP 32

    I had all the problems associated with the srosa2 variant of this worm.

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sk9ou0s (Worm.Bagel)
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sk9ou0s (Worm.Bagel)
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sk9ou0s (Worm.Bagel)

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Trojan.Agent)

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1)
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1)

    Folders Infected:
    C:\Documents and Settings\oli\Application Data\m (Trojan.Agent)

    Files Infected:
    C:\Documents and Settings\oli\Application Data\drivers\srosa2.sys (Worm.Bagel)
    C:\Documents and Settings\oli\Application Data\m\data.oct (Trojan.Agent)
    C:\Documents and Settings\oli\Application Data\m\list.oct (Trojan.Agent)
    C:\Documents and Settings\oli\Application Data\m\srvlist.oct (Trojan.Agent)
    C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer)
    C:\WINDOWS\system32\wintems.exe (Trojan.Spammer)
    C:\Documents and Settings\oli\Application Data\m\flec006.exe (Trojan.Agent)

    To sort it out i disabled my system restore and recycle bin. then manually deleted the reg keys and contents of the C:\Documents and Settings\oli\Application Data\m folder. I could not delete the actual folder as it was 'not empty'. Using CMD i navigated to the folder and listed its contents which were 2 folders by the names of . and .. both completely undeletable. I also deleted srosa2.sys and thanks to forum help discovered a device in Non Plug & Play section of device manager called sk9Ou0s which i stopped and uninstalled.

    The real trick to this was that i was able to then reboot into a Vista 64 install on the same machine and run a fully up-to-date in depth full on avast system scan which picked up a load of the files that can't actually be seen in the relevant folders and deleted them. another virus that was found was a 'zipper' in my hiberfil.sys (not sure if this is related to the bagle worm).

    Another thing that i noticed was that when in vista i could not access the folder C:\Documents and Settings\oli\Application Data\ as the permissions would not allow me. I edited the security settings of this folder so i gained complete control as my vista profile and i could then manually delete the 'm' folder contained within. Doing this also allowed the AV software to discover tens of other bagle infected .exe's in that folder. When i rebooted back into XP i had to change the permissions of the application data folder back to my xp profile to gain access again.

    Admittedly this would only work on a dual boot system but to some sufferers of the bagle worm this may be a more useful solution than having to do a full reinstall.

    At the mo i am running every malware and av prog worth its salt to make sure the infection is properly gone. many a rescan and reboot to go.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Proper complete bagle removal instructions are here: Removing Bagle Infections

    Some comments for your continued education;) The folders represented by the , and the ,, are standard in every single folder. The single period represents the current folder that you are in. The double period means the next higher level folder up the chain. These had nothing to do with why you could not delete the m folder. You could not delete the m folder do to the infections rootkit like properties which were hiding files from your view. It does not matter whether you enable viewing of hidden files and folders. Files can still be hidden from your view while the infection is loaded when the OS is booted. That is why when you ran the Vista partition, you could now see the files that were previously hidden when you were booting the infected Win XP partition.

    Just to be safe, it would still be a good idea to run the above fix after booting back into Windows XP.
     
  3. olithejunglist

    olithejunglist Private E-2

    the thing about certain folders having invisible folders is new to me. what i thought was interesting was the folder permissions that were set. this must be a major security flaw with windows that a third party could infiltrate that level of the os. the bagle is a well developed virus; i just hope windows can keep up. on the other hand i may be switching to a linux os very soon. just glad i managed to sort it out in me own humble way.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rookits have been growing at an alarming rate since it is the best way to hide things from end users and from security programs. All OS's have design flaws, it is only the real popular OS that malware creators bother to do their dirty work on. Just like years ago they did not bother infecting FireFox because it was not that widespread. Now that FireFox is very popular, it actually has more securty issues than Internet Explorer and is a larger reason for posts in the malware forum than IE.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds