Infected with Bagle and possibly others

Discussion in 'Malware Help (A Specialist Will Reply)' started by ctknhall, Jan 24, 2010.

  1. ctknhall

    ctknhall Private E-2

    Please help me clean out this malware (and any others). The infection occured about a week ago when I think one of my kids ran an exe they should not have, now I have to try to clean it up. I have tried various online scans and even the Kaspersky rescue disc and nothing is able to clean it. I am not able to go into Safe Mode either. One curious thing is my system does not seem to be slowed down.

    I have gone through the Run and read me first removal guide with little success. I even tried running the FindyKill.exe found in another post and it would not run, no error message.

    I followed the XP cleaning instructions and here is what happened to explain why I only have 2 logs attached:

    I ran ccleaner succesfully.

    SAS would not run, kept getting sas.exe is not a valid win32 application, from looking on the sas website I found a msdos com file which made sas run. So I performed a scan, it found about 29 items in both the registry and files, I went through the process to remove them and rebooted. When my system came back up and I opened sas again there was no log file so I ran the scan again, this time it found 3 instances and I captured the attached log file before the reboot.

    Mbam would get as far as asking for the language then stop, even renaming the .exe did not help.

    I could not even copy combofix from my thumb drive to the desktop, it would hang as soon as I clicked on the file to move it over. I was able to boot into linux puppy and copy the file to the desktop. When I rebooted back into windows and tried to execute it I got the same not a valid win32 app message as before.

    Rootrepeal also did not work, I ran it and a small window appeared saying initializing and stayed that way for more than 30 minutes, brought up task manager and it said it was not responding, checked the process and it was using over 90% of the cpu, I left it for a few more minutes and nothing happened so I killed it.

    MGtools worked and the log is attached.

    If you need any other information then please let me know.

    Thank you in advance for your time.

    -Chris
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment Standard Edition v1.3.1_03"
    Java(TM) 6 Update 5

    Do you know what this is:
    C:\Program Files\Common Files\bg17_800.zip?? If not leave it in my fix below. If so, take it out.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. ctknhall

    ctknhall Private E-2

    Thank you TimW, I will perform these procedures when I get home from work tonight and then reply with how it goes.

    I am a little confused about the Spybot TeaTimer though, I uninstalled Spybot months ago as it was not working properly (error messages when it was scheduled to run). If I open either windows task manager or process explorer I never see the TeaTimer process running. Did the uninstall leave some remnant active? When I look at add/remove programs Spybot is not there. Not sure how I can follow the directions if I cannot open Spybot. :confused

    I will uninstall the java update and check out that .zip file.

    My AV and other anti-spyware will not open as it is anyway. LOL

    Thanks so much, I will return later!
     
  4. ctknhall

    ctknhall Private E-2

    Tim, I cannot execute avenger, I get the not a valid win32 application error.

    I have uninstalled the java update and I do not know what that zip file is so I want it gone. Also, I double checked and I do not see Spybot in all programs.

    I will try to manually remove those files if needed, but I will wait for your reply.

    Oh yeah, you also requested the combofix logs, did you mean the avenger logs? (If I can get it to work)

    Thanks!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the below:

    Removing Bagle Infections
     
  6. ctknhall

    ctknhall Private E-2

    Downloaded FindyKill to my desktop and it will not run when I double click it. No error message. I tried to execute it again with task manager open and it see it appear as a process for about 1 second then it disappears.

    Is there an alternate way to launch the app? I did not see any in the topic.

    Thanks again!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try using a different user account to run it. Also try renaming the FindyKill.exe file to FK.exe
     
  8. ctknhall

    ctknhall Private E-2

    I renamed it to FK and it did not work so I logged in as a different user and placed it exe on the desktop and was able to install it as directed. I double clicked on the new icon and it ran, I saw the 1st screen then entered e and then choose #1 research, then clicked OK on the following screen.

    I did not notice the desktop icons or start menu disappear and I never saw any of the next screens. I did not click on anything, I checked after 10 minutes and still nothing. I checked after an hour and still nothing. I wanted to open task manager to see if it was running but since the instructions said not to open anything I resisted that temptation. At that time I had to leave for work so I left it in the possibly running state.

    Should I have seen the command type windows before this point?
    What should I do now? (when I get back home)

    Thanks!
     
  9. ctknhall

    ctknhall Private E-2

    I was finally able to get FindyKill to run, I had to execute it as soon as possible after a reboot. Here is the log.

    Thanks!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that's the first log. Did you run the second part to do the cleanup? You need to do that.
     
  11. ctknhall

    ctknhall Private E-2

    OK, I was able to complete the Bagle removal instructions, attached is the post scan log.

    So far things look good, after the deletion I noticed windows update was showing ready to download updates, possibly a good sign?

    I looked through the logs and saw quite a few corrupted files, what should I do with those?

    Should I perform any of the steps below listed by Tim? I noticed that some of the files he had set to delete are still in the system.

    Should I uninstall Avast and reinstall it? I was also thinking about going with Avira and the Comodo Firewall, thoughts? I will also be performing the other recommendations in the how to protect yourself thread.

    I have rebooted and things seem fine now, I am able to open things I was not able to before, like Windows firewall (which I will soon disable and replace).

    Thank you all again for your help.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Avast, SUPERAntiSpyware, Spybot Search & Destroy. Then reboot your PC. After reboot continue with the below.

    • Now download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.
    Now download and install Avast! Home Edition If you don't want to reinstall Avast then download and install AntiVir Personal Edition

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  13. ctknhall

    ctknhall Private E-2

    Thanks chaslang, I uninstalled Avast but SAS and Spybot are not in add/remove programs. I looked in Program files\superantispyware for an obvious uninstall command but did not see one.

    Not sure if I should go ahead with the reboot and the rest of the directions or if I need to do something else to remove sas. Also, as I posted earlier I uninstalled spybot several months ago so it is also not in add/remove or program files.

    Please advise.

    I have already downloaded the new sas and Avira so I am ready to go on that front.

    Thanks!
     
  14. ctknhall

    ctknhall Private E-2

    Update:

    I looked on the sas website and found an uninstall exe so I uninstalled sas with it then rebooted.

    I installed the new version of sas and will post the log when the scan is complete. No problems with the install, so that is good news!

    Since spybot has been uninstalled I did not worry about it.

    I will make another post with the requested logs.

    Thanks!
     
  15. ctknhall

    ctknhall Private E-2

    SAS found no infections, log is attached. :cool

    Avira successfully installed.

    Ran Ccleaner

    Attaching a copy of the mglogs.

    Please let me know if you see anything else.

    Thanks!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    Java 2 Runtime Environment Standard Edition v1.3.1_03
    Java(TM) 6 Update 15

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)
    O2 - BHO: (no name) - {B0C2804D-438F-411B-BF2D-6A07AC4C3923} - (no file)
    O15 - Trusted Zone: *.animemusicvideos.org
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment
    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  17. ctknhall

    ctknhall Private E-2

    Thanks chaslang, I am at the point of dragging the CFscript.txt file located on my desktop to the combofix icon on the desktop. When I drag the txt file onto combofix nothing happens.

    Am I missing something?

    Thanks!
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have not gotten the CFScript.txt to run with ComboFix, then do the below instead.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. ctknhall

    ctknhall Private E-2

    Thanks chaslang, Avenger worked. Here are the logs.

    I completed all the requested steps.

    Please let me know what to do next.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  21. ctknhall

    ctknhall Private E-2

    Thanks so much chaslang I have done the cleanup and I am now in the process of installing the recommended apps in the how to protect yourself thread.

    I will also be making restricted accounts for the other family members so maybe it will help in the future.

    :celebrate
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds