win32.bagle.hi and win32.agent.bgy and...

Discussion in 'Malware Help (A Specialist Will Reply)' started by bouxh, Mar 18, 2008.

  1. bouxh

    bouxh Private E-2

    Hello, many thanks for the job you are doing.
    Two days ago I tried to install a NFS server from the net and I infected my windows Vista. Norton 360 partially dissapeared and was disabled. When I start windows 360...message "....not a valid win32 application". It is impossible to uninstall Norton 360 (program turning around without end), so impossible to reinstall Norton. I had other problems : with bitdefender (application failed to initiate) now it is running well, with Security center was turning off and impossible to turn on but now it accept to be turned on, with Iexplorer still need 2 minutes to have my home page on the screen...
    Spybot S&D found win32.bagle.hi and win32.agent.bgy, it suppressed the 2 malware but they are permanently comming back.
    I applied all your recommanded procedures and I need your help if possible.
    Attached the 3 log files
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O4 - HKLM\..\Run: [msr2c32] rundll32.exe msr2c32.dll,imos
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O15 - Trusted Zone: http://fr.advfn.com
    O15 - Trusted Zone: http://www.advfn.com
    O23 - Service: Microsoft® Forms DLL (msr2c32) - Unknown owner - rundll32.exe (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! If Spybot or Norton are still detecting anything, attach a log that shows exactly what and where.
     
  3. bouxh

    bouxh Private E-2

    Many thanks again to take my problem in charge.
    I ran the c:\mgtools\analyse.exe as requested....OK
    Running combofix.exe (renamed CF.exe) with the CFscript.txt the system crashed down at the beginning of the scanning process for viruses...
    I had the following message: "STOP: COOOO21a {fatal error system} The NT initial command process system process terminated unexpectedly with a status of 0xC0000001 (0x00000000 0x00000000)" (white letters on a blue screen)
    I restated windows, the file CFscript.txt dissapeared, access to internet was impossible (default gateway was set to nothing I reneter its IP address and now it is OK)
    Doing an mgtools\analyse again all the lines previously deleted by HJT dissapeared except the line 023 -Service Microsoft....DLL(msr2c32)...which are still there.
    A second attemt to run combofix gave me the same bad result....
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's try this a different way.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Microsoft® Forms DLL
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pastemsr2c32 into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Now re-run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O4 - HKLM\..\Run: [msr2c32] rundll32.exe msr2c32.dll,imos
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O15 - Trusted Zone: http://fr.advfn.com
    O15 - Trusted Zone: http://www.advfn.com
    O23 - Service: Microsoft® Forms DLL (msr2c32) - Unknown owner - rundll32.exe (file missing)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! If Spybot or Norton are still detecting anything, attach a log that shows exactly what and where.
     
  5. bouxh

    bouxh Private E-2

    Thanks again for your help.
    Stopping and disabling start up of Microsoft Forms DLL were OK
    I ran HJT, all the lines you asked to fix were already fixed previously, especially line 023 (all those lines do not appeare in the list).
    Running Avenger I had an error message (see the log file!).
    I deleted that "DLD.EXE" registry key with regedit ! don't know if this was fine ?
    I rebooted and ran Spybot and win32.agent.bgy and win32.bagle.hi are still detected.
    Other info : I was able to reinstall Norton 360 after an uninstallation with the Symantec removal tools. I did a complete scan and Norton 360 detect nothing.
    The main trouble I still have now : Each time I open an Iexplorer windows, I need to wait 2 minutes before to have the first page displayed....and after I can surf normally in that windows...
    Spybot log attached also
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you notice that one of the items mentioned by Spybot is the below folder which I have been giving you instructions to delete:

    C:\Windows\System32\drivers\down

    Avenger said it deleted it but apparently it did not work. See if you can delete this folder youself. Use safe boot mode if it will not delete in normal boot mode.

    Also do the below.

    Rename the below files so that instead of ending in .INI they end in .BAK
    Code:
     
    C:\Windows\System32\bscs.ini 
    C:\Windows\System32\BSPRINT.INI
    C:\Windows\System32\LOCALDEVICE.INI
    C:\Windows\System32\LOCALSERVICE.INI
    C:\Windows\System32\PerfStringBackup.INI
    C:\Windows\System32\REMOTEDEVICE.INI
    C:\Windows\System32\SHORTCUT.INI
    
    I'm not sure what these files are but I'm wondering if they are somehow related to your problems.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure you observe whether you receive a success message about adding the above to the registry. Be sure to tell me what happens.

    If you were able to delete the folder and the registry patch was added successfully, run Spybot again and attach a new log.

    Also attach a new MGlogs.zip file.
     
    Last edited: Mar 21, 2008
  7. bouxh

    bouxh Private E-2

    I will name C:\windows\system32\drivers\down the "down dir."
    Yes I deleted several times the down dir.
    Yes the fixME.reg deleted the HKEY_USERS.....\FirstRRRun entry in the registry.
    I checked this with regedit.
    I renamed the ini files with the bak extension...these ini files concerned my bluetooth usb stick, I don't think they are causing troubles ???
    BUT, the down dir. and the HKEY_USERS....\FirstRRRun entry are recreated each time I reboot the system or each times an Iexplorer windows is opened.
    That happens during the 2 minutes I wait to have the first page displayed in the Iexplorer windows, if I deleted several time the down dir, it is automatically recreated each time and I find all those down dir. in the recycle bin so the deletion performs well.
    Spybot : win32.agent.bgy and win32.bagle.hi still there !
    And Norton 360 is always protecting me !?&§"!!
    With all my gratitude.
     

    Attached Files:

  8. bouxh

    bouxh Private E-2

    Update: problem solved
    With the computer disconnected from the internet (because it appears that this virus is loaded back from the net during desinfection)
    I used a program named "Elibagla": http://www.zonavirus.com/datos/descargas/95/elibagla.asp
    It found mainly that: "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GOOGLETOOLBARNOTIFIER.EXE --> Eliminado Bagle.dldr" and this GOOGLETOOLBARNOTIFIER.EXE was deleted.
    I ran combofix, I deleted the restore point.. and apparently now everything is OK I hope for a long time. Spybot don't find anythig bad now.
    Many thanks again for your outstanding work, if you want more details about what I did please ask.
    My best regards
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Interesting! Glad to hear you found the root cause for it coming back. When you were deleting the C:\Windows\System32\drivers\down folder, did you happen to notice if any files showed up in the folder.

    Rename those files back to be .INI files now.

    If you are not having any other malware problems, it is time to do our final steps:
    1. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN
      • Now type cf /u in the runbox and click OK.
      • Note: The space between the cf and the /U, it must be there.
    2. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    3. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds