win32 bamital.ek and comp restart at logon

Discussion in 'Malware Help (A Specialist Will Reply)' started by ploizzo, Oct 30, 2010.

  1. ploizzo

    ploizzo Private E-2

    Hello,

    I week ago I started getting and svchost.dll error on my windows xp comp. It started shutting down my hp image monitor program and would pop up a few times here and there. I updated my Zonealarm AV program and ran it and fixed a couple of trojans. Then I started getting a stop error 0x0000007b (0xf78ba524, 0xc0000034, 0x00000000, 0x00000000). I rebooted and got a BSOD same stop error and I booted into safe mode. Then I started getting redirects in Internet Explorer and I tried to go to the windows update page and get a cannot load page error.

    I followed the procedure in the sticky and ran the Microsoft Malicious Software REmoval tool and cleaned the problems it found. Then ran ATF cleaner and MBAM. Rebooted, ran ESET and it found win32 Bamital.el & Bamital EK. I fixed those and it said that Bamital ek could not be cleaned. I restarted and now everytime I get to Windows logon the computer restarts itself. I tried booting into safe mode with networking and the same thing happened. I have the logs from each scan but I cannot get to them since I can no longer login.

    Any help is much appreciated. Please let me know what I should do.

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should have followed our cleaning procedure and immediately attached the logs as requested. We do not ask you to run Malicious Software Removeal Tool, ATF Cleaner, nor Eset in our cleaning procedure. What has now happened is that you have had files required for Windows to work deleted.

    Have you tried booting to last known good configuration? If that does not work, you will need to boot your Windows XP boot CD and restore and files that were deleted. Did you write down what the other tools removed? If not then start by trying to restore winlogon.exe and explorer.exe from the Recovery Console. ( see what was done in message # 9 in this link:Following instructions - still having trouble )
     
  3. ploizzo

    ploizzo Private E-2

    Thanks for the help. I was on a different site that used those tools and no one got back to me. Sorry.

    I did try last known good configuration and that restarts as well at the login screen. I will go ahead and restore winlogon and explorer from the recovery consile and post back. Thanks again.
     
  4. ploizzo

    ploizzo Private E-2

    ok, i ran recovery console tried to copy winlogon.ex_ from the CD to the system32 folder and it says "access is denied". I am assuming this is something from the virus? It asked for the administrator pass and I logged in. I would assume i should have full access to everything.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you boot from the CD or did you boot Windows and then access the CD.
     
  6. ploizzo

    ploizzo Private E-2

    oops, i was using the wrong drive letter when trying to copy the files.

    ok, so I copied the winlogon and explorer files and I can log in.

    Where do we go from here?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:


    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  8. ploizzo

    ploizzo Private E-2

    OK, I followed the instructions. First issue, I got through the Super anti spyware scan and it found two threats and I hit ok and it quarantined and removed them. I restarted normally and got through the logon screen and then I had no desktop. I hit ctrl+alt+del, restart, and it froze so I manually restarted. Booted into Safe Mode and ran Malware Bytes and it came up with no threats. I restarted into Safe mode and saved the log. I tried running combofix per the instructions and I got to the accept the disclaimer window, hit yes and nothing happened after that. I restarted, tried it again, and the same thing... got to the accept the disclaimer window hit yes and nothing.

    I started the Rootrepeal program and similarly, nothing happened. Rebooted tried again and nothing happened.

    Then I ran mgtools successfully and the log is attached.

    SO, I have the SAS log, Mbam log, & mgtools log.

    THanks
     

    Attached Files:

  9. ploizzo

    ploizzo Private E-2

    Chaslang, any updates?
     
  10. ploizzo

    ploizzo Private E-2

    Anyupdates ?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let me refer you to the below link again which was in my first messag:

    Don't Bump! It Only Hurts You!!!

    Can you get an MGtools log from Normal Boot mode now or is it still impossible to boot normally?

    You need to uninstall the below which Grisoft stopped supporting many years ago.

    AVG Anti-Spyware 7.5


    Do you have your Windows XP boot CD? You may have to boot to the Recovery Console to replace infected copies of some Windows system files. Like explorer.exe and winlogon.exe
     
    Last edited: Nov 5, 2010
  12. ploizzo

    ploizzo Private E-2

    Chaslang, sorry for the delay in getting back to you and for the bump. I was traveling the past few days and could not be in front of the infected computer.

    I booted up in normal mode, and was able to run MGtools and the log file is attached. I uninstalled AVG, and yes I do have my Windows setup disc.

    THanks for all the help!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


    Boot into the Recovery Console ( see how to do this in option 2 here: http://support.microsoft.com/kb/314058 ) and run the below steps. The below steps will assume that your CD drive is D so change this to the appropriate drive letter if yours is different.

    Once you are in the C:\Windows> prompt of the Recovery Console, input the below brown bold font commands one at a time each followed by the enter key. Read the notes further down which comment on these commands.

    copy D:\i386\explorer.ex_ explorer.exe
    cd system32
    copy D:\i386\winlogon.ex_ winlogon.exe
    exit



    NOTES:
    • the first command try to copy a compressed copy of Windows explorer.exe from your CD back to the Windows folder. Yes the underscore ( .ex_ ) is correct.
    • the second command should cause the prompt to change to C:\windows\system32>
    • the third command should copy the compressed winlogon.ex_ file ( yes the underscore is the correct file name ) from the i386 folder of your CD into the system32 folder and rename it to winlogon.exe, the file will automatically be uncompressed. Notice the space after the copy and after the ex_
    • the fourth command should reboot your PC. Remove the CD and see if Windows boots normally
    Now shutdown all protection software and run a scan with ComboFix and attach the new log. Download current copy of combofix.exe first.
     
  14. ploizzo

    ploizzo Private E-2

    OK, I booted into recovery console, copied the files, booted normally, shutdown zonealarm firewall, and ran combofix.exe.

    I got to the disclaimer popup and agreed to it and then nothing happened.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said you shutdown the firewall. Your logs indicate you have ZoneAlarm Security Suite installed. Did you shutdown all of ZoneAlarm's protection. Did ComboFix post any warnings about Zonealarm running? Do you have the current version of ComboFix ( please download it again from the READ & RUN ME link ).

    If it will not run in normal boot mode, see if you can run it in safe boot mode.
     
  16. ploizzo

    ploizzo Private E-2

    OK, sorry again it took this long to get back to you.

    I did shutdown zonealarm and I believe all of its processes were shutdown as well before I ran Combofix. Combofix did not post any warning about Zonealarm it didnt do anything after I accepted the disclaimer.

    So, I restarted the computer to boot into safemode to try again and now i get a BSOD stop error: 0x0000007E (0xC0000005, 0x86F38562, 0xF78EA7EC, 0xF78EA4E8). I have tried booting normally, with last know good config, & safe mood; and each time it loads with the windows xp logo until right before you would normally get the logon screen and then it goes to the BSOD.

    I tried copying the winlogon.exe & explorer.exe from the windows setup disc and that didnt help either.

    Not sure what to do now.

    Thanks & I will be around this infected beast for the next 5 or 6 days.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What did you do in trying to copy both those files, exactly?
     
  18. ploizzo

    ploizzo Private E-2

    From the recovery console, I copied winlogon.ex_ from the i386 directory on the windows xp setup disc to winlogon.exe in the windows/system32 folder & explorer.ex_ from i386 to explorer.exe in the windows folder.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  20. ploizzo

    ploizzo Private E-2

    ok, I did what it said in part one of "recovering from a corrupt registry" (backed up the reg files, deleted the files, and copied the repair files in) and then I restarted in safemode and got the same blue screen message as before.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can try doing a scan with a bootable disc:
    Kaspersky Rescue Disc

    If that doesn't help I am going to suggest you post in the software forum to try to get your system to boot. :(
     
  22. ploizzo

    ploizzo Private E-2

    I will try scanning and post back. thx
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this a desktop computer or a laptop? IF a desktop, you may need to slave it in another computer and save your important files and data. Then do a clean install. The BSOD error could be either software or hardware issues. You would not know until you did a reinstall.
     
  24. ploizzo

    ploizzo Private E-2

    Yeah, it is a desktop and I just bought a hard drive enclosure to pull the files i need off it... just in case the it does come down to a reinstall.
     
  25. ploizzo

    ploizzo Private E-2

    Question on Kaspersky Rescue Disk, I started it up and got to the end user license. It says press a to accept, r to reboot, & p to shut down. I am pressing a but it doesnt do anything. I am using a wireless keyboard, do you think I need a wired keyboard to do this?
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds