Win32.Bagle.hi Trojan, perhaps more

Discussion in 'Malware Help (A Specialist Will Reply)' started by joans34, Apr 9, 2009.

  1. joans34

    joans34 Private E-2

    Afternoon :)
    I was infected with this virus after I foolishly opened an infected .zip file I downloaded. After I opened such program my computer immediately restarted once it was back up my McAfee firewall and BitDefender wouldn't start, the Security Center in Windows Vista was turned off as well as the firewall and Automatic updates.
    I can't run several programs, I get an error says <Application directory>.exe is not a valid Win32 application. I've tried downloading new scanner tools but in normal mode it won't let me install them or simply would just restart the system again. I got to make some scans in Safe Mode I attach my logs on MGlogs and ComboFix. I hope you can most kindly help me.

    Thanks in advance

    Joan.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Did you notice any error messages while running MGtools? Your logs are incomplete. Also did you accept the license agreement for HijackThis as requested.

    Having you been using the Guest user account on this PC? I see a lot of files and folders for it. This account is a security risk and should always be disabled.

    Also what user ID are you logging in with. What I see does not match the user account names on the PC.

    Uninstall the below software:
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Development Kit 6 Update 7
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. joans34

    joans34 Private E-2

    Hi again, thanks for your help.
    I have just one quick question before doing this. I'm a software engineer student in college and I think I need the java packages for my programming class projects (we use java), do I have to uninstall them? I use Eclipse as my IDE, will the uninstalling interfere with anything?
     
  4. joans34

    joans34 Private E-2

    I ran TrojanHunter and Spybot before coming here. It seems is all working well partially, TrojanHunter revelaed some trojans that were taking care of as well as spybot, spybot kept revealing the same trojan over and over after I ran it again. After that I came here. I have the windows security up and running again as well as the firewall. I can't uninstall some utilities I had to such as bitdefender 2009. I can't reinstall my Windows Live Messenger still due to a fatal error, Doesnt say much about the error however. I can't run the Windows Wireless system for some reason, so my laptop isn't getting wireless internet. BEfore I ran trojanhunter, combofix and MGtools and removed all that stuff the computer was extremely slow and the mouse lagged repeatedly, this is gone; is actually faster! :D
    So that's it so far, Thanks again. :)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your last log from MGtools is very incomplete. You must make sure you are following the instructions for running it with Vista. See this link Using MGtools also make sure you download the current version and then run the MGtools.exe file. Make sure UAC has been disabled and you have rebooted. Also make sure you accept the TrendMicro HijackThis license agreement by clicking the Accept button twice.

    Attach the new MGlogs.zip file.
     
  6. joans34

    joans34 Private E-2

    As you requested here are the logs again, I tried to follow every single step, hopefully this time the logs will be complete
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do you have so many antivirus/security suite programs installed? Didn't you read the early instructions in the READ & RUN ME?

    You need to decide which program from the below list you wish to use and then you must immediately uninstall the others.

    AVG Free 8.5
    BitDefender Free Edition v10
    BitDefender Total Security 2009
    McAfee SecurityCenter
    Norton Security Scan

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\temp
    C:\Users\Joan\AppData\Local\Temp

    Now run Ccleaner to clean out only temp files and nothing else!

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    The Bagle infection appears to be fixed now; however the infection may have been the cause of the problems with your wireless inferface. Try the below to see if it helps:

    Fixing Wireless Zero Config Service
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds