Beagle(Bagle)/Mitglieder/Netsky infection in Outlook pst files

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by rivered, Sep 28, 2005.

Thread Status:
Not open for further replies.
  1. rivered

    rivered Private E-2

    I added system info after the original post which made it look like someone already answered my original post. Figured I'd repost. If you guys were already working on this, my apologies...

    Wanted to start off by thanking the guys/gals at majorgeeks. I have been cleaning my personal computers and those at my office so successfully its become almost a hobby to me. I use the "READ ME FIRST - Basic Spyware..." by Major Attitude and it has fixed every issue I've ever encountered up until now.

    I restarted the infected computer in safe mode and ran the Bitdefender and RavAntivirus scans(System Restore has been disabled - WinXP). Bitdefender didn't find anything, but RAVAntivirus found 212 infected files and 6 separate viruses. All infected files were in my c:\documents and settings\...\Microsoft\Outlook\outlook.pst, outlook2.pst, archive.pst, outlook4.pst files.

    RAV did NOT remove these viruses. This is not uncommon and on occasion I have had to manually remove the culprit files after an RAV scan. Since this is a .pst file which contains about a year and a half worth of emails (1.6 gigs) I didn't want to delete the file. I recall receiving these emails months ago (I believe there was about 20 of them over time). On each occasion they were deleted, but for some reason, on 2005-09-25 at 16:52:19(info obtained from my T1 provider who is threatening to disconnect me if this is not resolved), they all became active.

    I have downloaded Avast! and that program finds 5 of the six viruses. It lists the information a little differently than RAV which enabled me to import the pst file into a new outlook profile in an attempt to find and permantly delete the infected email. I was able to find the email but not delete all of them. I have tried to remove the attachment without success and tried to delete the entire email without success as well. Each time I run Avast! I try to delete, delete at startup, move or repair and all operations fail either with "Error occurred during file deleting :Error 0x80040119" or "Error occurred during file deleting: The system can not find the file specified" or "Error occurred during moving to chest: There are no more files" or "Error occurred during repair: There are no more files".

    I do not have Norton's. I have been working on this for 2 days now and can not do anything else until this is resolved. Any help would be greatly appreciated.

    Below are the names of the viruses that were found.

    1. Iframe_Exploit* - This shouldn't be possible because I'm running Explorer 6.0.2900.2180.xpsp_sp2_gdr.050301-1519. I'm told this only affects 5.0 or earlier. This is the one that does not appear to be found by Avast!

    2. Win32/Bagle:AI

    3.JS/Dword.dr*

    4. Trojan Proxy: Win32/Mitglieder.CL

    5.Trojan Proxy: Win32\Mitglieder.CN - Why have one version when you can have two

    6. Netsky.k@mm

    Again, there does not appear to be any other infections on my computer outside the pst files. RAVAntivirus and Avast! are not able to clean them for some reason. Any help would be appreaciated

    System Info is:

    Microsoft Windows XP Professional
    Service Pack 2
    IE 6.0.2900.2180
    Pentium 4A, 2666 mhz (5*533)
    381 MB ddr sdram
    82 gb ic35l090avv207-0 hard drive
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post duplicate threads! This one is closed.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds