PDA

View Full Version : Bagle Infection and wintems process



squart
2008-02-28, 19:04
Hi everybody,
my computer (Windows XP SP2) got recently infected by a virus that has blocked my antivirus and related programs (Spyware Doctor,Spybot SD, Zonealarm, can no longer be launched). Unfortunately even Hijackthis does not run. I was able to get a log from Rootkit Revealer.
It all started when I inadvertently opened an exe file receive from a source which I trusted, but it was not that good….
Now I know from kaspersky online scan facility (http://www.kaspersky.com/scanforvirus) that unfortunately that file contained the Trojan-Downloader.Win32.Bagle.jf.
Symptoms, besides the inability to launch the main antivirus programs, are the following:
- Internet navigation does stall after a few web address changes.
- Online scans for virus (e.g. those from pandascan, f-secure, symantec, and McAffee) do not start the job (things stall on that page for a minute or so and nothing else happens).
- starting windows in safe mode is prevented (it would bring me back on the booting options saying that an error occurred and the only way to get through is to start windows normally.
I also see in the task manager processes that a wintems.exe process (known as a related threat) is active and can not be terminated. Another problem is that something prevents me to start windows in safe mode (only the normal start will get through).
Could anyone give me some help on how to do to clean up the infection ?

I will appreciate your cooperation and I thank you in advance for support and directions

Andrea Squartini

Shaba
2008-03-01, 12:35
Hi squart

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
Link 3 (http://subs.geekstogo.com/ComboFix.exe)

http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_FF.gif


http://i266.photobucket.com/albums/ii277/sUBs_/combofix/CF_download_rename.gif
--------------------------------------------------------------------

Double click on Combo-Fix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall

Shaba
2008-03-06, 12:09
Due to the lack of feedback this Topic is closed.

If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.