Win32/Patched.FM (FL) detected

Discussion in 'Malware Help (A Specialist Will Reply)' started by alcretaz, Aug 30, 2010.

  1. alcretaz

    alcretaz Private E-2

    Hi,
    I appear to have contracted a nasty Win32/Patched.FM virus in my c:\windows\system32\winlogon.exe as well as a Win32/Patched.FL virus in my c:\windows\explorer.exe

    The virus does not seem to greatly affect my system, however when I try to run a deep system scan with VIPRE, it locates a "virus.win32.bamital.c" then crashes to a blue screen of death with the message "fatal system error, logon process terminated" and then resets. And when I install AVG Anti-virus, I'm bombarded with warnings about the above two viruses in the locations mentioned.

    I discovered the instructions at:
    http://forums.majorgeeks.com/showthread.php?t=221588
    And followed all of TimW's steps, however I am still infected.

    Any assistance would be greatly appreciated
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should NEVER follow instructions given for someone else!! Different machine, different fix!!

    I still need to see the C:\Mglogs.zip from running C:\MGTools.exe
     
  3. alcretaz

    alcretaz Private E-2

    Fair point, sorry. :)

    I could only upload the first 4, adding Mglogs.zip to this reply.
    Also, as per TimW's instructions (which I know I shouldn't have followed but I might as well add the results of so you can tell me if I've made everything worse) I've also uploaded the second Combofix log after using it with the code supplied in the 4th post in the thread quoted above:
    http://forums.majorgeeks.com/showthread.php?t=221588

    Thanks for all your help.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run Combofix again by double clicking it's icon on your desktop. Attach the resulting log ---> C:\combofix.txt
     
  5. alcretaz

    alcretaz Private E-2

    Ran Combofix again.
    Log attached

    Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run a scan with this: Norman Malware Cleaner

    Then after another reboot, see if you are still having problems. Also se if you can get a log from Norman to attach. Ignore any messages about items in the QooBox folder (from ComboFix) or in the MGtools folder being infected.
     
  7. alcretaz

    alcretaz Private E-2

    Ok, I ran the Norman Malware Cleaner. The log is attached.
    It advised me to reset so I hit yes. Nothing happened for 20 min.
    So I tried to reset via Start -> Shutdown. Again, nothing.

    I powered off the laptop and repowered it.
    Now it loads the Windows XP splash screen and goes to a blue screen of death with the following error:

    STOP: C000021a {Fatal System Error}

    The Windows Logon System Process terminated unexpectedly with a status of 0xc0000005 (0x00000000 0x00000000).
    The system has been shutdown.

    -----------------------------

    It should be noted that I'm fairly certain that this is the error I get when I ran the deep system scan with VIPRE.

    The error displays for roughly 2 seconds then the system resets. Currently it's stuck in this loop. I tried to access Windows through Safe Mode, same result except the error appeared for a millisecond before resetting.

    Thanks for your assistance
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Last edited: Aug 31, 2010
  9. alcretaz

    alcretaz Private E-2

    Hey Kestrel13!,

    The link you provided goes to a singular post, but doesn't have any instructions in it. I googled ESET'S Online Scanner, but it appears to be a browser based scanner, and at this stage I can no longer access Windows on my laptop at all.

    Am I missing something?
    Thanks. :)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. alcretaz

    alcretaz Private E-2

    I went through the corrupted registry recovery steps, still can't access Windows.
    I did all the part 1 steps through recovery console, then part 2 says to exit the console and login with the admin user via safe mode.
    Still crashes to the blue screen I mentioned previously, although the screen now flashes up for the briefest instant before resetting.

    I'm beginning to think ye old fashioned format and reinstall is the way to go. :(
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if the problem is due to the infected winlogon.exe file being deleted by Norman.

    Boot back into the Recovery Console and run the below steps. The below steps will assume that your CD drive is D so change this to the appropriate drive letter if yours is different.

    Once you are back to the C:\Windows> prompt of the Recovery Console, input the below brown bold font commands one at a time each followed by the enter key. Read the notes further down which comment on these commands.

    cd system32
    copy D:\i386\winlogon.ex_ winlogon.exe
    exit



    NOTES:
    • the first command should cause the prompt to change to C:\windows\system32>
    • the second command should copy the compressed winlogon.ex_ file ( yes the underscore is the correct file name ) from the i386 folder of your CD into the system32 folder and rename it to winlogon.exe, the file will automatically be uncompressed. Notice the space after the copy and after the ex_
    • the third command should reboot your PC. Remove the CD and see if Windows will boot.
    If Norman deleted winlogon.exe, it may have also take the incorrect action of deleting explorer.exe too and it will have to be replace. If Windows boots up this time but you have no Desktop then explorer.exe was deleted and similar steps to the above can be performed to restore it. However you don't need to run the cd system32 command since explorer.exe belongs in the C:\windows folder. Just skip to the second command and replace each case of winlogon with explorer
     
    Last edited: Aug 31, 2010
  13. alcretaz

    alcretaz Private E-2

    Ok.
    Following Chaslang's instructions gave me access back to Windows...
    I then ran ESET's online scanner and combofix again.
    Logs attached.

    I think we're making progress though... Combofix seemed to be relatively clean.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    LOgs didn't attach. Please re-try.
     
  15. alcretaz

    alcretaz Private E-2

    Sorry.
    Logs upload take 2...
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Almost done... now do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  17. alcretaz

    alcretaz Private E-2

    I got one error while I was running GetLogs.bat:

    "Please set registry key HKLM\Software\Microsoft\.NETFramework\InstallRoot to point to the .NET Framework install location"

    I hit ok and it continued...

    Logs attached.
    Thanks
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks good, so just to have one final sweep, run ComboFix again just by double clicking it, and then do this:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  19. alcretaz

    alcretaz Private E-2

    Logs attached.

    Thanks :)
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  21. alcretaz

    alcretaz Private E-2

    Fantastic. Thanks to everyone for all your help.

    The only issues I seem to be having with the system now is that a lot of my programs are either not associated correctly or not functioning, and for some reason the system is no longer registering the serial port... But I'm not sure whether this is residual effect from the virus or from the cleaning programs we've used.

    From the looks of it though the major problem of the virus is gone, so thank-you all VERY much. :)
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome!

    Tell me which programs?
     
  23. alcretaz

    alcretaz Private E-2

    The Bat keeps asking me for setup details when I boot up the computer, and no longer appears in the system tray like it used to.
    The .pdf and .xls files that are on my desktop are no longer associated with their programs.
    I use a program called VehCom for work which I think has been written in C++ or something... It now comes up with the error "Runtime error 429: ActiveX component can't create object"... Although I may need to talk to my boss about that one.
    Download Accelerator Plus tells me it cannot read it's configuration.
    When I hit Start -> Turn off computer, it takes a while (5-10 min) to bring up the options to suspend, shutdown or restart.

    That's all I can see at the moment...
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds to me like you ran the line that Kestrel13! gave in message # 10. If you did this and used a restore point from a time where any of these programs were not installed or from before various updates to those programs, you have lost all information about them in the registry. A possible solution would be to run System Restore and restore your system to a point in time just before you got infected or just before you came here. Otherwise all these programs you are having problems with may need to be reinstalled. However do note, if you already completed the Final Instructions given, then you will not have any restore points to use because you will have already delete them.

    Even if you become reinfected due to the reinstall, we can always reclean it.
     
  25. alcretaz

    alcretaz Private E-2

    I've already gotten rid of my restore points.
    I think we're gonna be looking at ye ol' fashioned re-installation of stuff. :)

    Any idea on the slow shut-down process? It seems intermittant too... which just makes it harder to t/shoot.

    Thanks :)
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    You will have to debug in the Software Forum. This is not likely a malware issue. Possibly problems with software you are using or Windows system corruption. You could see if it happens in safe boot mode. If not, then check what you load in normal boot mode vs safe mode.

    Also try running the below.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds