Bamital infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Vin.F, Sep 1, 2010.

  1. Vin.F

    Vin.F Private E-2

    Hi,
    Two days ago I picked up a virus which AVG 9 detected as patched.fm or bamital.
    I decided to run a scan using hitman pro online and it detected winlogon and explorer.exe had been infected and the only way to fix it was reinstalling both files from the original xp disk which I was fortunate to have. After the removal I restarted the computer as instructed but again avg kept throwing up infection notices of explorer.exe and winlogon.exe. This time I ran MBam which detected 160 infections and i removed them and restarted, AVG still threw up infection notifications so I decided to run a scan with avg. As you could have probably guessed, AVG could not remove the files as they are whitelisted xp services. I analyzed with hijack this and sent the log for further analysis on hijackthis.de. Unfortunately there were no files in the log which users had flagged as potentially harmful and now I was back to square one.
    Frustrated, I decided to "upgrade" windows xp pro SP2 as I thought this might solve the problem. Unfortunately it did not. All it did was change the way users logged on and didn't boot straight into xp without prompting a password which was how I had previously configured it. To me it looked like I was on a network, which I thought was the result of the virus and a hacker now had control over my pc, (paranoid) so I decided to follow steps in removing netware for clients to change how users logged on. This had no effect and I was still recieving a notification that netware for clients had to be disabled even though it was.
    I was also unable to scan using AVG, I decided to uninstall/reinstall which went fine during uninstall but now when I went to install I got a cannot write to the registry type error ( can't remember exactly what it said).

    Then I decided to install a fresh copy of xp pro sp2 on a partition and see if I could attack the virus on the C drive from the new installation. Again avg could not install so I was kind of stuck. I decided to boot into safe mode which seemed to do the trick, avg installed fine and I ran a scan. Rebooted but still having trouble.

    I read somewhere that there was a fix for netware for client which I tried to install but I got an access denied message. I also got this message when trying to execute some other programs but again , I can't remember what exactly.
    Another issue I noted is that when I go to particular forums like geek police firefox crashes. I tried this on a couple of different sites, Google, major geeks, and most other sites seem to be working fine but as soon as I go to a particular info page on a forum about my issue firefox crashes.

    Anyway. Eventually I came here. I had no where else to turn and I was at my wits end. I read the READ and RUN thread and followed everything to the letter, So now I humbly ask for your help whoever you may be to rid my pc of this pest.

    Please find attatched all relavent logs. I also added an mbam error.txt file that I found when looking for the mbam log which seems to coincide with the scan. I don't know what's going on.

    :confused
     

    Attached Files:

  2. Vin.F

    Vin.F Private E-2

    Here are the remaining logs
    Thanks in advance!
     

    Attached Files:

    Last edited by a moderator: Sep 2, 2010
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Vin.F

    Vin.F Private E-2

    Thanks very much.
    Just to note I'm currently running a boot time scan with avast. If you need anything else please let me know. Thanks again.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below outdated Java, 6.21 is the current version and you already have that installed so leave that one alone.

    • Java(TM) 6 Update 7
    • Java(TM) 6 Update 16
    C:\AHCache.7z <--- delete this unless you know what it is.

    What do you know of these files in the C:\Windows\system32 directory??

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Fcopy::
    C:\WINDOWS\ERDNT\cache\winlogon.exe | C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\ERDNT\cache\explorer.exe | C:\WINDOWS\explorer.exe
    File::
    C:\Windows\lgfwup.ini
    c:\windows\system32\winlogon.vir
    c:\windows\explorer.vir
    Folder::
    c:\windows\NV9641776.TMP
    c:\windows\A7E07C2B2220441587E3784D5814BC93.TMP
    c:\windows\NV9641604.TMP
    DirLook::
    c:\documents and settings\vin\Application Data\563F0F826EC33837E949260799E2B7AE
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "TkBellExe"=-
    "36X Raid Configurer"=-
    "Gainward"=-
    "QuickTime Task"=-
    "Ai Nap"=-
    "NvCplDaemon"=-
    "PCSuiteTrayApplication"=-
    "ISUSPM"=-
    "nwiz"=-
    "NvMediaCenter"=-
    "LGODDFU"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run this:
    Using ESET's Online Scanner

    Run a full scan with your antivirus and tell me what it is flagging now if anything

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Attach the log from ESET as well.

    Let me know how things are running, please.
     
  6. Vin.F

    Vin.F Private E-2

     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then you can delete all the below files:

    But do not delete anything else!

    Attach logs when ready, I will be floating about somewhere... :)
     
  8. Vin.F

    Vin.F Private E-2

    Ok, Decided to stay awake. Armed with a redbull and the will to destroy, I vow not to sleep till this pest has been eradicated.

    One problem though, I cannot unstall the old version of Java as it's not showing up in the add and remove programs list.
    Shall I proceed with the rest of the removal process?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ... LOL I like your attitude, welcome to my world.

    Yep. :major
     
  10. Vin.F

    Vin.F Private E-2

    Ok, I just figured out a way round. Oddly enough Revo Uninstaller found both outdated Java installations so I removed them, Not sure if I should have removed registry Items and leftovers but I thought it made sense to do so. Slap me on the wrist If I'm wrong.
    Proceeding with attack plan.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, do proceed, but I have to take a pit stop (for sleep) 6am for me, and I am lacking in red bull supplies :-D See ya tomorrow
     
  12. Vin.F

    Vin.F Private E-2

    Quick update,
    Running combo fix was a real problem under my username (this is the ACC where I picked up the virus from in the first place), When restarting I kept getting windows messages saying basically that windows doesnt recognise filename "can't remember" (But it was definitely a CF file) do you want to browse for compatible programs or from the web. I browsed, located CF, clicked ok, CF began to run, Updated (Twice, as I have ran combo fix a dozen times at this stage, the other times I didn't even make it to the update stage as it kept crashing or cancelling) and then got a message saying CFscript.txt has been incorrectly spelled and that's where it's crashing at.
    I decided to login using Admin acc, Ran combo fix with CFscript, everything went well, I decided to turn off my firewall at this point just before the restart. Comp restarted, (don't think CF updated but not too sure) then completed the scan. I have a log from the Admin account so I thought that maybe it was the firewall that was causing my problems on my own acc.

    I decided to switch users, go through the whole process again on my own acc but kept failing in the same places. I'm not sure how consistent the log is going to be now or if switching the accs have upset the scanning process but for now I'm gonna skip the CF scan on my own acc, Run ESET, Run AVG, then Run MG tools on both accounts.

    Will report back soon. Redbull wearing off, coffee wearing off, feeling kind of tired! :zzz Just putting the kettle on now!!!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Dammit, that's the second time I have seen that problem since logging in half an hour ago! You need to get Combofix to run, in safe mode if not in normal mode, and see what gives, we need to replace the infected files!


    Two sugars and plenty of cow for me LOL
     
  14. Vin.F

    Vin.F Private E-2

    Well I hope you had a nice sleep. Im heading into my 28th hour now:tired
    Life looks different after 24 hours. Also please excuse any typos or ramblings that might find its way in to the text box. This is a side affect and is only temporary. If you get this little b***tard I'll owe you a beer/vodka/mountain dew or crab juice!

    So heres the story so far. ESET has been running for 6 hours and 43 minutes, I probably shouldn't have selected scan archived files but it's too late now. I'm pleased to say that during this scan it has detected bamital.dz trojan which I suspect was the cause of my heartache in the beginning,along with 50 other various nasty pieces of code.

    So back to Combo Fix, Will I still have to run it successfully under my username aswell as Admin? Also, will I need to rescan my pc with ESET again after?
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good. Let it keep going until it has finished. Then run it AGAIN afterwards immediately without rebooting. Run it a THIRD time, and attach logs from each run.

    On the account that is affected, your account. But let's finish off with ESET first, we are surely making progress.
     
  16. Vin.F

    Vin.F Private E-2

    No problem, whatever needs to be done to get this fixed. Will I scan again with the same preference settings or can I turn off archived files?:)


    I'm also running ESET on the affected account at the moment anyway, I only switched to Admin to run combo fix. Everything else outlined in your removal process have all been run on the affected account.

    Thanks again comrade.
    Coffee on the way, served in an udder!!!:yum
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yea, uncheck the option to scan archives.
     
  18. Vin.F

    Vin.F Private E-2

    Cool,
    Will post logs when they become available.
     
  19. Vin.F

    Vin.F Private E-2

    Ran Three scans with ESET, First turned up 53 infections, second and third ame up clean, but I'm not getting my hopes up just yet.
    I've attached the logs, Not sure whether I should run CF just yet or wait for your recommendation.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good afternoon!

    Yes, now run Combofix at this point, (not by using my script, just double click it to run it) and then do this afterwards:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    (At this point as fun as they were, I am going to delete a few of our silly comments and banter so we can see more clearly what has been done so far. :)
     
  21. Vin.F

    Vin.F Private E-2

    Good afternoon to you too.
    Understand the deletion of the posts, plus I realised that "Bumping Hurts"

    I just wanted to clarify, Do I need to first run CF normally and then with CFScript or do I need to run MGTools straight after the first run of CF.

    I've attached the log for CF's first run anyway.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You done good. Now let's have you do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  23. Vin.F

    Vin.F Private E-2

    Was having problems initially, had to click "Run As" > Admin to get it to scan.
    Not sure if that makes any difference.
     

    Attached Files:

  24. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall one of these two! You cannot run more than one anti virus!

    • avast! Free Antivirus
    • AVG Free 9.0

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Run this next!

    Running Kaspersky Online Scanner

    Now double click Combofix to run it again.

    Then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  25. Vin.F

    Vin.F Private E-2

    Registry Item added successfully, Continuing with the remaining steps.
     
    Last edited by a moderator: Sep 4, 2010
  26. Vin.F

    Vin.F Private E-2

    Ok, I'm running into a problem with kapersky online scanner

    Using chrome, was asked to install java plugin, clicked install but got a message saying that java was already installed on my computer, do I want to reinstall? I clicked no and opened up firefox, went through the whole install process but still didn't work. I double checked settings in both Chrome and FF and java options were activated for both. I'm a bit apprehensive using IE as my default browser had changed from chrome to IE and I was getting notifications from SuperAntiSpyware that the homepage change requests were detected which sounds like the work of spyware to me.
    Should I just run IE and see if I can get kapersky's online scanner to work through that or is there another alternative, What about another browser download?
     
    Last edited by a moderator: Sep 4, 2010
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yea, just use IE ;) I had issue myself with Firefox when I tried for some reason.
     
  28. Vin.F

    Vin.F Private E-2

    IE is also asking for java installations for kapersky online to work.
    Safe mode with networking?
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just skip the Kaspersky scan if you like, just continue on.
     
  30. Vin.F

    Vin.F Private E-2

    Ok, here's the logs
     

    Attached Files:

  31. Vin.F

    Vin.F Private E-2

    Just thought I'd post to let you know that my email account was accessed from a site called kolo.net

    I'm off all day today (Monday) so I can finally get rid of this pain in the ***. Hopefully.
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, I am back from a crazy busy weekend at work. Is AVG still detecting Bamnit? How is the machine behaving now? If you wish to run another scan with ESET you can, but do answer my questions. :)
     
  33. Vin.F

    Vin.F Private E-2

    Hey Kestrel, No worries. It was the weekend anyway so I wasn't expecting too much support anyways:-D

    Haven't run any additional scans, just wanted to see if you picked anything up in the logs. the pc seems to be the same it's a little sluggish for a quad core with 3gb of ram.
    Plus I haven't tried to change how users log on yet so I'm not too sure. I'm going to run a scan with avast, decided to get rid of avg as it didn't get great feedback in the "protecting yourself against malware" post plus I'll run an eset scan and see if anything comes up. I'll let you know how I get on anyway.
     
  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yep, avast scan and eset then. Go for it. Sluggishness is something we can look at afterwards, most importantly I need to see if the Bamnit infection has cleared.
     
  35. Vin.F

    Vin.F Private E-2

    Ok ran a quick scan with avast, no threats found. Also Eset has found no threats but when I started up the pc this morning SuperAntiSpyware pro had warned of home page changes.
    Not sure if this is still something to worry about.
     
  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    C:\Documents and Settings\vin\Desktop\4zz0l4nr.exe <--- What is this, something renamed by you?

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Tell me exactly what is inside of this directory?

    Use windows explorer to find and delete the below files:
    • c:\windows\system32\REN42.tmp
    • c:\windows\system32\REN41.tmp
    • c:\windows\system32\REN40.tmp
    • C:\Documents and Settings\vin\My Documents\avg9inst.log

    ...and the below folder:

    • c:\program files\AVG

    Now just for the hell of it, let's have virus total scan these files:

    • C:\WINDOWS\explorer.exe
    • C:\WINDOWS\system32\winlogon.exe
     
  37. Vin.F

    Vin.F Private E-2

    No I don't remember renaming anything like that, Scan it or delete it or both?


    Didn't set any proxies up by myself apart from open dns which, if I can remember correctly, isn't that address.

    Absolutely nothing from what I can see, (show hidden files is enabled)

    Completed the rest of the steps below, Virus total didn't detect anything suspicious in either explorer.exe or winlogon.exe.
    What's next? (this is looking positive :) )
     
  38. Vin.F

    Vin.F Private E-2

    Sorry, Just checked that file. It's GMER, Never ran it though, I think :)
     
  39. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So did you fix this line?

    Yes it very much *is*!
     
  40. Vin.F

    Vin.F Private E-2

    Yeah I fixed it but I think outlook express was dependant on it as I was getting connection errors. but That's easily fixable.

    Some other behaviour I've noted but never mentioned until now. I've got two OS's on my pc, Usually at startup I can select which O.S to boot but after I ran CF the first time, I need to bring up the boot options for safemode, start windows normally and then select the O.S. If I was to let it boot automatically it would boot into xp64.
    I still can't change the way users login from the UAC settings. Still, even after I have uninstalled netware for clients I get a notification saying that netware for clients needs to be disabled before I can proceed. Complete head scratcher if you ask me.
    Anyway, that's besides the point. What's the next step in the exorcism Major?
     
  41. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Next step will be final steps. :)

    Any remaining issues you have can be resolved in the software forum.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  42. Vin.F

    Vin.F Private E-2

    Sounds good, Thanks very much for all your help. Regarding "disabling System Restore and re-enabling it", Does it matter that I have already shut the pc down? Should I do another scan and then disable and re-enable?
     
    Last edited by a moderator: Sep 6, 2010
  43. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No, it doesn't matter. :)
     
  44. Vin.F

    Vin.F Private E-2

    Thanks very much for all your help again.
    I appreciate it. :clap
     
  45. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're most welcome ;) Safe surfing, and don't be greedy on that red bull LOL It's no good for ya!
     
  46. Vin.F

    Vin.F Private E-2

    Thanks, One can a day is all I have, Don't want to become addicted!:-D

    Can you point me in the right direction for fixing the last couple of issues I was having with boot-up and UAC settings please.

    Thanks a Million
     
  47. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds