Can't get rid of Win32/Patched.FM and .FL

Discussion in 'Malware Help (A Specialist Will Reply)' started by swizard210, Aug 28, 2010.

  1. swizard210

    swizard210 Private E-2

    Hello all!

    I have somehow acquired, as per AVG 9, the virus Win32/Patched.FM/FL. It has infected both my explorer.exe and winlogon.exe files.

    I am running Windows XP Pro SP3.

    I looked at the following thread ( http://forums.majorgeeks.com/showthread.php?t=221588 ) in which the OP had the same problem, and followed all of Tim's instructions.

    Attached are my logs. I have two ComboFix logs (1 & 2) because I first tried it as per the READ & RUN ME directions, and then tried it as per Tim's instruction to make that CFscript.txt and drag it on the combofix.exe.

    However, after doing everything, when I turn my AVG9 back on, it still comes up with tons of the same threats (winlogon.exe and explorer.exe) again and again.

    I hope someone can please help me and resolve this issue soon.

    Have a great weekend!

    -Shiv
     

    Attached Files:

  2. swizard210

    swizard210 Private E-2

    Here are the rest of the log files.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. swizard210

    swizard210 Private E-2


    Thank you!
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      C:\WINDOWS\PWMBTHLP.EXE
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.


    Then do the same for the below file and also let me know the results:

    Code:
    C:\WINDOWS\system32\UCI32M57.dll

    Could you please get this: PWMBTHLP.EXE into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:



    log retrievable @ C:\collect.zip


    Your combofix log was incomplete, when you run the script I offer you please ensure that you do not touch the mouse or keyboard until the program has completely finished running. A mouseclick can cause it to stall!

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\qfe123.tmp
    C:\WINDOWS\qfe1E1.tmp
    C:\WINDOWS\qfe1E7.tmp
    C:\WINDOWS\qfe1F0.tmp
    C:\WINDOWS\qfe1F1.tmp
    C:\WINDOWS\qfeE3.tmp
    C:\WINDOWS\qfeF6.tmp
    
    FileLook::
    C:\WINDOWS\PWMBTHLP.EXE
    C:\WINDOWS\system32\UCI32M57.dll
    
    DirLook::
    C:\WINDOWS\system32\(null)
    C:\Documents and Settings\Shivam\Application Data\Update
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Also include the Jotti results and the collect.zip.
     
  6. swizard210

    swizard210 Private E-2

    Kestrel13!,

    All right, I did everything as per your directions, and I am attaching the requested logs.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    c:\documents and settings\Shivam\Application Data\Update <--- Delete this empty directory.

    Go to this link, download a fresh copy of combofix, let it over write the pervious version. (Do not run it yet)


    SystemLook

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      winlogon.exe
      explorer.exe
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt

    Now go to VirusTotal and upload the following files for analysis, report back to me the results.

    • C:\WINDOWS\system32\winlogon.exe
    • C:\WINDOWS\explorer.exe
    Run this:

    Using ESET's Online Scanner

    Attach the ESETScan.txt to your next reply.

    Run the new combofix.exe ensuring that it is indeed on your desktop.

    Now download and save this XPsp3bu.exe to your C:\ root folder. You must do this properly. Now run the XPsp2bu.exe program by double clicking on it. You may or may not notice a quick flash of a black window. This is normal. The program runs quickly and just extracts some files we need.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this, also let me know the Virus Total results and the log from ESET and SystemLook
     
  8. swizard210

    swizard210 Private E-2

    BIG PROBLEM! So I did the SystemLook, VirusTotal, and ESET. Then I ran ComboFix like you said, and after it finished, the log came up in notepad but I had no desktop or taskbar (start menu, etc.) I also got a Windows Error reporting window since Explorer.exe crashed. I restarted my computer, and now it won't even get past the screen where it says Windows XP with that orange/green like loading thing on the bottom. LIke those orange blocks that keep going in a marque fashion.

    After that screen it goes to a blue screen where it says winlogon.exe crashed or can't open or something.

    HENCE, I couldn't do the last 2 steps you requested (XPsp3bu.exe , and MGTools).

    I have a few important files on the computer I would really to be able to save still. Please reply back ASAP.

    Oh and I can't post the logs since they are on the computer as well.

    Thank you!!!
     
  9. swizard210

    swizard210 Private E-2

    Kestrel13!,

    Thank you so much for your continued support with my problem. It real meant a lot that you made it a priority and kept working at it.

    As I posted in my last reply, I ran into a big problem, etc. Unfortunately, I needed my computer fully functional for work, and so last night I took it to a friend's place who helped me retrieve my important data, after which, he just formated the HD, an installed a fresh copy of Windows.

    I HOPE that I don't run into a problem like this again, but if I do, I know I can count on you!

    I've noticed a significant number of people posting in this forum about this specific virus/malware/etc. (Win32/Patched.FM & .FL). Any idea what it is, or how it's suddenly impacting so many people?

    -Shiv
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahhh. Okay. No worries.

    It's a file infector, a form of Bamital. And there is going to be a wave of it coming in we expect. It likes to target legit windows files, infect them and make sure that finding a valid replacement is not easy.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds