win32.Bagle.SVL - Need help

Discussion in 'Malware Help (A Specialist Will Reply)' started by pelasgos, Jul 7, 2008.

  1. pelasgos

    pelasgos Private E-2

    Hi there,
    i have read the forum about the removal procedures and the instructions ABRI gave to a similar case, and i guess it is different for each user.
    So i need some experts help to get rid of the nasty virus.
    I include 2 attachements, you might find helpful to give me further instructions.

    Symptoms:
    -No access on system or hidden files.
    (Only after i run MGtools i was able to see hidden or system files)
    -Not able to boot in safe mode.
    -Not able to install any antivirus
    (i had the ESET nod32 running fully up to date, when this happend)
    ATF-Cleaner - NOT running
    ComboFix.exe - NOT running
    avenger - NOT running

    Please advise :(
     

    Attached Files:

  2. pelasgos

    pelasgos Private E-2

    Also i run Bitdefender on line scanner.
    Hi reports that he finds and deletes win32.bagle.svl (not 100% sure about the extension),
    but nothing improves on my computer.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't already, please disable the Guest account in User accounts.

    Please use add/remove programs to uninstall:
    Safety Alerter 2006 --> if it fails to install, look for this uninstall string :
    C:\DOCUME~1\jahewi\LOCALS~1\Temp\tmp1C.tmp /del

    Delete this:
    D:\Documents and Settings\Panagiotis\Application Data\m

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now see if you can run the other scans and then also run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
    Last edited: Jul 7, 2008
  4. pelasgos

    pelasgos Private E-2

    Hi TimW,
    thanks for helping me.

    - 1.- I never had or have "Safety Alerter 2006" installed on my pc.
    - 2.- I only see hidden files, after i run MGtools.exe
    So in order to delete the following file:
    ***D:\Documents and Settings\Panagiotis\Application Data\m***
    i first run MGtools.exe and then I was able to send it to the Recycle Bin.
    I wasn't able to empty the Recycle bin. I tried to restore the file in order to rename it "skata" and then to delete it again. But after that i couldn't sent it to the Recycle bin again.
    - 3.- All other steps were executed as advised.
    - 4.- No scans were possible what so ever (all programms were rejected)
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    D:\Documents and Settings\Panagiotis\Application Data\m\flec006.exe
    
    
    Folder::
    D:\Documents and Settings\Panagiotis\Application Data\m
    D:\Documents and Settings\Panagiotis\Application Data\skata
    D:\Documents and Settings\Panagiotis\Desktop\BAGLE
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now clean out:
    D:\Documents and Settings\Panagiotis\Local Settings\Temp\


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.
     
  6. pelasgos

    pelasgos Private E-2

    Just to make things clear:
    -Combofix will not run-
    No matter how i try it,
    through doubleclicking it
    or mousedraging the .txt file over it,
    or via the Start and Run procedure exactly as described.

    Anywhay i attache a fresh MGlogs.zip
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It was a shot...often, even though you can't seem to run it, it will still work when dragging a file over it.

    This is still showing.....can you manually delete it:
    D:\Documents and Settings\Panagiotis\Application Data\m\flec006.exe

    Is this a work computer?
     
  8. pelasgos

    pelasgos Private E-2

    Cannot locate "D:\......Application Data\m\flec006.exe",
    i only see an "m" and an "skata" file, with no contents and i cannot delete them, even through the command line.

    Previously deleted "m" files are still in my Recycler.

    Yes this is a working computer, it has accountant programms and sql server installed on it from the company i work in.:cry

    Yesterday i run a on line scan with bitdefender. I sent you the report
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip ...now download the latest version ....once you have it installed run the fixBagle.bat file. Then attach the new log.
     
  10. pelasgos

    pelasgos Private E-2

    Here is the log, after running the latest fixBagle.bat
     

    Attached Files:

  11. pelasgos

    pelasgos Private E-2

    I tried "Malwarebytes" scan.
    This time he found and deleted many infected files
    and also the recycler bin that i couldn't empty.
    Here are the latest logs
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run MWB before or after getting the new MGLogs?

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  13. pelasgos

    pelasgos Private E-2

    Hi Tim,

    i have done everything you say, except the avenger.
    While trying to run it, i get messages like this:
    "Warning: %systemroot% (D:\WINDOWS) is not the same as %windir% (%SystemRoot%)"
    or
    "Fatal error: %systemdrive%(D:)is not a prefix of %windir% (%SystemRoot%).
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks like you didn't allow the D:\MGtools\GetLogs.bat file to run completely.

    You still have this showing, so lets try again:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  15. pelasgos

    pelasgos Private E-2

    Hi Tim,
    I merged the new text in the registry.
    So i send you a fresh log file
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The little buggers don't want to go bye bye......

    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Let's see if that kills it.
     
  17. pelasgos

    pelasgos Private E-2

    While trying to run avenger.exe, i get messages like this:
    "Warning: %systemroot% (D:\WINDOWS) is not the same as %windir% (%SystemRoot%)"
    or
    "Fatal error: %systemdrive%(Dis not a prefix of %windir% (%SystemRoot%).
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Create a restore point ....not go to start / run / and type regedit ...expand :
    HKEY_LOCAL_MACHINE .....expand:
    SYSTEM ...expand:
    Current control set ...expand:
    enum ....expand:
    root ..scroll to LEGACY_SROSA ...click it to highlight ..go to edit ...and delete it.

    Do the same for the other two.

    Let me know if that is successful.
     
  19. pelasgos

    pelasgos Private E-2

    Cannot delete neither key.
    It says:
    "Cannot delete LEGACY_SROSA. Error while deleting key"
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    ComboFix is not on your desktop ...did you remove it?
     
  21. pelasgos

    pelasgos Private E-2

    Yes i removed it some days ago
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download it to the desktop, rename it, and doulbe click it.

    combofix.exe
     
  23. pelasgos

    pelasgos Private E-2

    Done.
    I think ...LEGACY_SROSA... is now gone.
    I send you the latest logs to check out.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good....let's do a little house cleaning from the scans:

    First download and install:
    Java Runtime 6

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now tell me if you are having any other malware issues before we do the final instructions.
     
  25. pelasgos

    pelasgos Private E-2

    Ok, ready for the final instructions
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:

    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\combo-fix" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.

    12. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  27. pelasgos

    pelasgos Private E-2

    Many thanks Tim,
    i appreciate your help, you are doing a great job.

    May lifeforce be with you
    Pelasgos
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome, safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds