bagle strikes again - please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Marcelinho, Apr 12, 2008.

  1. Marcelinho

    Marcelinho Private E-2

    Hello to all (sorry for my bad english.) im new here. I m from portugal.

    Big problem, only XoftspySE detects, nothing else works (antispyware - Antivirus).

    Please need some help of you guys.

    Thanks

    tell me what you need to now
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks! Marcelinho, and no worries on your english as its fine, your best bet is to follow the below guide in which we direct everyone to follow first, from the logs gained and attached in your next post in this thread our malware experts will be able to find and name the malware thats attacking you and from that post some manual removal instructions for you to follow.

    If you do find any of the steps hard to follow due to language, please do let us know and we will try our best to assist you to run those steps.



    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Marcelinho

    Marcelinho Private E-2

    Thanks, im doing the that,
    thanks again
     
  4. Marcelinho

    Marcelinho Private E-2

    Can´t make the ccleaner to work, i used tuneup utilities 2007, find bagle IX worm with panda antivirus scan drive: windows\system32\drivers\srosa.sys he as desinfect the file and sais to reebot, on reeboot a file name crack open a window that sais file to crack . i Closed that. With Xoftspy Se i found Bangle IX in registry and e erase it. Still dont work. reboot again and the the same file opens again the windom. where can i find MGtools.
    Thanks
     
  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi


    What errors happen when you use CCleaner, please describe why it would not work?

    As for MGTools the download location and instructions for running are in the specific read me for your version of Windows here Read & Run Me click the link that is for your Windows version then follow the instructions 1 by 1.


    Its best to follow the guide as we have a better understanding of what these applications do and what they have cleaned, so once finished your at a point in which is a known one in terms of whats been checked for and removed, deviating and using other applications will add to the lenght of time taken to help you remove this malware, which is our primary goal and one our malware experts are very good at.
     
  6. Marcelinho

    Marcelinho Private E-2

    Halo, thanks. I installed SAS, and do what you said there, but when it discovers, c:\windows\system32\srosa.sys my monitor turns Blue.
    Can´t erase Forder Temp of pandasecurity.
    Panda says is W32/bagle.rp.worm, try to eliminate but don´t works, xoftspy says is Bagle.IX worm,try to eliminate still dont work. In the next reboot hes here again.

    what to do next?
    Thanks,

    Hell to the guys who do this ...
     
  7. Marcelinho

    Marcelinho Private E-2

    About Ccleaner, simply doesen´t work (nothing happens).
     
  8. Marcelinho

    Marcelinho Private E-2

    hello again,
    can´t enter spybots - Message error "c:\programs\spybot - search and destroy\spybotSD.exe is not a win32 valid aplication"

    this is getting better, im thinking in formating...

    thanks
     
  9. Marcelinho

    Marcelinho Private E-2

    run malware bites, found 2 and clean, need reeboot, now run ccleaner seems ok.
     
  10. Marcelinho

    Marcelinho Private E-2

    ccleaner remove many entrances... combofix don´t starter, same error, not a valid....win32 plication
     
  11. Marcelinho

    Marcelinho Private E-2

    Combofix starter same as mgtools. I send zip file. Computer running faster again, dont start Pandasecurity 2008, and other items, going to do other scan
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where are you running ComboFix from? The cf.exe file is supposed to be on your Desktop and it is not there. Also you must follow the instructions in the READ ME for running it properly.

    You need to get the other logs that are requested attached. Like the logs from SUPERAntispyware and Malwarebytes Anti-Malware.
     
  13. Marcelinho

    Marcelinho Private E-2

    I will give you the logs, but now im on work, later at home. I thing evering now is working. No malware found. everythings works. dont now if i will install again panda security. i pay monthly this antivirus, it seams very heavy to the system but that have all protection.
    What is your expert opinion?

    Thanks,
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Personally I don't like any internet security suites. Just like you have noticed, everyone who installs them winds up complaining that their PC is slow and they often come to this forum looking for malware to be the cause when it is the security suite that is the problem.
     
  15. Marcelinho

    Marcelinho Private E-2

    OK, heres the log files,
    See if is anything wrong, please.
    Thanks,
     

    Attached Files:

  16. Marcelinho

    Marcelinho Private E-2

    i have install avira antivirus and comodo firewall, superantispyware. what is your opinion about that.
    thanks.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's fine but you need a realtime antispyware blocking tool. The free version of SUPERAntiSpyware is an on demand scanner and does not provide protection. If you purchase it, you will get protection and a great tool. Otherwise you need to install a realtime spyware blocker as seen here: How to Protect yourself from malware! I also recommend that you use Spybot (without Teatimer) and use the Immunize feature. Also install and use SpywareBlaster.


    Looks like the scanners took care of the worst of your problems. We have just a little to do.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} -

    After clicking Fix, exit HJT.

    Now delete the below file. Let me know if you have a problem doing this.
    C:\WINDOWS\system32\drivers\wnmsav.dat

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds