Some kind of Bagle, I can't get rid of

Discussion in 'Malware Help (A Specialist Will Reply)' started by madcan, May 16, 2008.

  1. madcan

    madcan Private E-2

    Hi everyone,

    Seems like I have a Bagle problem and I can't get rid of it for 1 whole week of working day and night. I am working on a Windows installed on a Mac Pro, and since something is obviously wrong I can't boot on Safe Mode. And thanks to Bagle, I can't install any antivirus softwares. I can't even run some programs like Avenger as well, telling me they are not valid Win32 applications.

    I got a log by mgtools, I hope you can help me:
     

    Attached Files:

    • HJT.txt
      File size:
      17.7 KB
      Views:
      2
    Last edited by a moderator: May 16, 2008
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We need all the logs from doing the Read and Run First....you have the MGLogs.zip as the HJT log was from running the MGTools.exe.

    Can you run Combofix?

    You need to find and delete:
    C:\Documents and Settings\PG03\Application Data\m\flec006.exe
     
  3. madcan

    madcan Private E-2

    Okay here are the other logs.

    I also can run Combofix but I am not sure it finishes it's job because explorer.exe gets shutdown and doesn't come back though Combofix window doesn't show any more activity. And I can't install antivirus after Combofix either.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You had AVG8 installed at one point...did you uninstall it?
    You also have/had panda running at startup ...again, did you uninstall it?

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  5. madcan

    madcan Private E-2

    Hello again,

    Thanks for the info. AVG doesn't appear in Add/Remove Programs. I had Panda Active Scan due to an online scan I think and uninstalled it now. I also deleted the R0 line with analyse.exe now.

    But when I click on avenger.exe it says: "c:\documents and settings\PG03\Desktop\avenger.exe is not a valid Win32 application"
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    File::
    C:\WINDOWS\vmumin.dat
    
    Folder::
    C:\Documents and Settings\PG03\Application Data\M
    C:\WINDOWS\system32\drivers\downld
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Tell me if you have errors with that....and if not, attach the combo log.
     
  7. madcan

    madcan Private E-2

    Thanks again. I've done what you've told me but since I am doing them to my work computer via Logmein, once Combofix started logmein disconnected. I will see the result when I go to the office on monday morning and then will send the log here.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know.....:)
     
  9. madcan

    madcan Private E-2

    Hello again,

    Sorry I couldn't write before, I was out of office for one week. Now I am back, I am sending you ComboFix.txt.

    Thank you once more.
     

    Attached Files:

  10. madcan

    madcan Private E-2

    Okay, ignore the last log I sent. In case that may be wrong since I didn't use the computer since the last scan I redone it. Here is the new log.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  12. madcan

    madcan Private E-2

    Hello again,

    Thank you. I did what you told me and here is the zip file.

    Cheers.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This computer is getting re-infected. I see the guest account is not disabled, there is no java and what are you using for anti-virus?

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  14. madcan

    madcan Private E-2

    Hello,

    Thank you again. I was using superantispyware but that was the only thing i could because i was not able to install any antivirus softwares. Avenger.exe was one of the not working programs as well but it worked this time so I guess something is going right? :)

    Here are the new logs. I didn't try installing any antivirus softwares yet again. Should I? And guest account looks disabled now.

    Cheers.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After doing the below, please download and install and anti-virus program from Top Freeware Picks.

    Your guest account is still showing as active.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  16. madcan

    madcan Private E-2

    Hello,

    Thank you very much. At last I did what you told me and Avast is installed now. Here are the logs after doing what you told me. Now I will also make a boot scan.

    But guest account looks disabled under control panel. I got logmein installed, do you think it's the reason?

    Thank you once more. You've really saved me from too much trouble.
     

    Attached Files:

  17. madcan

    madcan Private E-2

    Hi again,

    Well to add one more thing, I still can't install avg or symantec antivirus because they can't start a service after installation. I got avast installed for now. Do you think this is a malware related issue as well?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay...we are a bit swamped.....please find and delete:
    C:\WINDOWS\xxxvideo.hta

    Now tell me what service can not be started?

    Has Avast found anything....I will double check your logs in the AM.
     
  19. madcan

    madcan Private E-2

    Hello,

    Thank you, I deleted that file. Avast also found some viruses and deleted them. In second scan it didn't find anything else. To be sure I tried to install AVG and then Symantec Antivirus but they both gave an error about not being able to start a service.
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You probably can't do that with Avast installed......still a few things to address:

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime 6

    Now one last time run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  21. madcan

    madcan Private E-2

    Hello,

    Okay here are the logs after this. Again, I uninstalled avast and tried to install symantec antivirus and it gave me this error: "Error 1920. Service Symantec Antivirus failed to start. Verify that you have sufficient privileges to start system services."

    Then I tried installing AVG and it gave me this: "Local machine: installation failed
    Installation:
    Error: Action failed for file avgmfx86.sys: starting service....
    Error 0x80070002"

    And my user account is selected as Computer administrator.
     

    Attached Files:

  22. madcan

    madcan Private E-2

    Well I cleaned registry with searching "avg" and looks like something was left behind after an installation because I installed it now. Symantec problem must be something similar. So then can we say I am clean? :)
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    These are still showing:
    C:\Program Files\Alwil Software\Avast4
    C:\PROGRA~1\AVG\AVG8

    You need to uninstall one of them...and we have seen a lot of issues with AVG8!

    What are these:
    C:\Program Files\2d3
    C:\Program Files\eyeon
    C:\Program Files\Vidomi

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\PG03\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and lets hope you are clean. :)
     
  24. madcan

    madcan Private E-2

    Hello,

    Yes AVG8 made my computer go berserk after I installed it and restarted my computer. I uninstalled oth AVG and Avast and using Antivir now.

    2d3, eyeon and vidomi directories are for some professional visual softwares we use at work so they are not harmful.

    And here are the logs after the last actions.Everything's working normal right now, or it seems like that :)
     

    Attached Files:

  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good....but still want this to go bye bye:

    Run C:\MGtools\analyse.exe by double clicking on it(Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Reboot and check that it is gone.
     
  26. madcan

    madcan Private E-2

    Hello,

    Thank you very very much. I did that as well and now windows\config directory is empty with that line in mgtools gone. So looks like everything is okay, right?

    Cheers.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet.....If you are not having any other malware problems, it is time to do our final steps:

    1 If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\cf" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    2 *If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    3 *If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    6. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    7. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  28. madcan

    madcan Private E-2

    Hello again,

    Thank you very much, I did what you told me. ComboFix couldn't be uninstalled automatically so I did it manually. So now everything's fine and I can't thank you enough. So thank you again :)

    Cheers.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome..safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds