Remove Win32:beagle-aww Please

Discussion in 'Malware Help (A Specialist Will Reply)' started by patryduf, Oct 16, 2008.

  1. patryduf

    patryduf Private E-2

    I am desperate to get rid of this virus. I do not have Wifi anymore and the tools to remove this virus, as posted in other threads, are not running for more than 3 seconds. I managed to start in safe mode just after running the tools several times and run those tools again in safe mode, but as soon as I come back in windows the virus installs itself back and I'm at square one again.

    I run XP SP3, on a VAIO laptop, Avast. I tried Combofix, Elibagla, gmer and DrWeb CureIt.

    I NEED that computer back. HELP!

    Thanks
    Patryduf

    Logs:
     

    Attached Files:

    Last edited by a moderator: Oct 16, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the other three requested logs:

    Superantispyware
    MalwareBytes
    MGLogs.zip
     
  3. patryduf

    patryduf Private E-2

    Here they are.
    Looks like I still can't get my wifi back...

    I left the laptop as it was after all the scans. Did not reboot, did nothing.

    Thanks for your help,

    Patryduf
     

    Attached Files:

  4. patryduf

    patryduf Private E-2

    Use this Combofix file as it is more recent.
    I did not read the instructions for the previous one.
    Sorry.
     

    Attached Files:

  5. patryduf

    patryduf Private E-2

    Can someone tell me if I should reinstall networking services... just to get my connexion back? Could it ruin the whole work in progress?

    Thanks
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not certain yet what is causing your wifi issues...it maybe malware or it could be hardware...did you look in the device manager to see if anything was amiss?

    Could you tell me what this is:
    Code:
    C:\Documents and Settings\Yvon\Desktop\
    ELIBAGLA.BEA%D8B%D8%D8H.EXE
    
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  7. patryduf

    patryduf Private E-2

    C:\Documents and Settings\Yvon\Desktop\
    ELIBAGLA.BEA%D8B%D8%D8H.EXE

    This is a malware scanner I downloaded after someone in another forum or research on the net (don't remember) told it worked for him.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok......please run the rest and attach the logs. :)
     
  9. patryduf

    patryduf Private E-2

    I had a few error messages that I will post in a couple of minutes...
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ooops...must be nap time.....

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:
    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  11. patryduf

    patryduf Private E-2

    Log files with error...

    Now executing the "good" actions
    :)
     

    Attached Files:

  12. patryduf

    patryduf Private E-2

    Here are the files.

    Thanks again for your time, Tim

    Yvon
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try again:

    Now we need to use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Drivers::
    srosa
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA\0000]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combo.
     
  14. patryduf

    patryduf Private E-2

    Everything is there with "this device is working properly" status.
    I uninstalled all devices and reinstalled. No change.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This srosa driver may be the cause...but if not ( since I am assuming that your internet hardwire connection is working), it could just be that your wireless nic card died. :(

    Those can be purchased for @ $50...(USB wireless....)

    Get me the logs and lets see if we managed to kill it yet.
     
  16. patryduf

    patryduf Private E-2

    Ok... Rebooting..
     
  17. patryduf

    patryduf Private E-2

    Those USB keys are nice tools!

    Give me good new... :major
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet...combo killed it.

    Now the question is does the wifi still not work? If it does not...I would suggest posting in either hardware or software....( though if the computer is a little old you may just need to replace the wifi card or purchase a USB Wireless device).

    Let's clean up from the scans how:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you do get a success message, then:
     
  19. patryduf

    patryduf Private E-2

    fixMe.reg has been successfully entered into the registry.

    YESSS!

    It really makes my day... Thank you so much, Tim!

    For the Wifi, I'll try to find something...

    :wave
     
  20. patryduf

    patryduf Private E-2

    Tim!

    For the wifi, i saw that the service WZCSVC was not started due to the NDIS dependencie was not started itself. Went to the net for a research and found that:

    skoman

    Junior Member with 21 posts. Join Date: Feb 2007
    Experience: Computer Illiterate

    16-Jun-2008, 04:55 AM #3
    I fixed the problem.I see that Wi-FI has been demaged on everybody that has been infected with win32 bagle worm.So here is my solution to the problem
    I found that the service still exist in the registry but its not visible in the service.msc console.
    So here is what I did:
    Go to Start>run>regedit
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndisuio
    I changed the start value to 2(automatic).It was 4(disabled)
    After reboot my WIFI was working again.


    AND IT WORKED!!!
    Can you see the tears in my eyes?

    Thanks again so much for your time and perseverence with my case.
    I wish I never need your assistance again... but if I do, I will certainly ask and recommend the "MAJOR GEEKS" for help.

    Have a nice weekend!
    Yvon
    (The guy with a (sort of) brand new laptop)
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Glad to here you got it running.... and good info. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds