Not what you were looking for? Ask our experts!
Reply
Contributor
mel032901
Posts: 51
Registered: ‎06-29-2012
Accepted Solution

Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

Norton is not able to remove these threats and I have been constantly notified that my computer is under attack.  I've run Malware Bytes and Spybot Search and Destroy.  Neither worked.  I also ran Norton Power Eraser and received a message that said the processes of explorer.exe, svchost.exe and winlogon.exe are Bad.  I think that this is where the Trojan's have attached themselves.

 

I was unable to run Norton for a few days and downloaded AVG.  Total Crap.  It allowed these to infect my computer after years of Norton keeping it clean.  I have upgraded Norton today and am running Norton Internet Security 2012.

 

My son used IE last night instead of Firefox to browse the internet (FB, Youtube and Pandora).  I believe this is when it happened and I've spent all day trying to get this off of my computer.

 

AND this "Adobe Flash Player Installer" keeps trying to load over and over but I think it's associated with the whole Trojan outbreak on my computer.

 

PLEASE!!!! Any help will be appreciated!!!

dickevans
Posts: 12,330
Registered: ‎04-08-2008

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2


mel032901 wrote:

Norton is not able to remove these threats and I have been constantly notified that my computer is under attack.  I've run Malware Bytes and Spybot Search and Destroy.  Neither worked.  I also ran Norton Power Eraser and received a message that said the processes of explorer.exe, svchost.exe and winlogon.exe are Bad.  I think that this is where the Trojan's have attached themselves.

 

I was unable to run Norton for a few days and downloaded AVG.  Total Crap.  It allowed these to infect my computer after years of Norton keeping it clean.  I have upgraded Norton today and am running Norton Internet Security 2012.

 

My son used IE last night instead of Firefox to browse the internet (FB, Youtube and Pandora).  I believe this is when it happened and I've spent all day trying to get this off of my computer.

 

AND this "Adobe Flash Player Installer" keeps trying to load over and over but I think it's associated with the whole Trojan outbreak on my computer.

 

PLEASE!!!! Any help will be appreciated!!!


Welcome,

I cannot help you. We do have an expert who specializes in this type of problem. A couple of cautions. First, do not attempt to run and more 'fixers'. At best they do nothing, at worst they may make it impossible to clean up. Second, when Quads starts helping please follow his instructions exactly. He is a volunteer. He may be in a different time zone so be patient and wait for his instructions.

Stay well and surf safe

Dick
Win7x64 SP1 current NIS V21
Contributor
mel032901
Posts: 51
Registered: ‎06-29-2012

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

Thanks!  Will do.

Bot Obliterator
Quads
Posts: 16,529
Registered: ‎07-21-2008

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

ANY other user other than the thread starter is not to use any instructions, scripts or proceedures,  The work though in cleaning a system is individual and only for that system due to a number of factors.

 


 

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability. Do as the instructions ask nothing extra or run things twice
  • If I ask a Question just answer it, don't run anything unless it states.
  • Major steps used:

1. Find

2. Break

3. Destroy

4. Cleanup  (including system as a whole)

 

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.

 

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forum, (sometimes :smileylol:)

  • Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.

 

 You have made a bigger hole for yourself,  Norton AVG, Spybot S&D............................  Uninstall Spybot and AVG,  then use AVG's Removal tool.

 

What is your operating system  and include whether 32 bit or 64 bit??

 

Quads

Contributor
mel032901
Posts: 51
Registered: ‎06-29-2012

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

Thank you for your help.  I realize that loading AVG was a bad idea.  I still had Norton on my computer but just could not update it at the time.

 

I'm running Windows XP 32 bit.  I've removed Spybot and AVG (earlier) but whatever is going on with this computer, I'm unable to get to the AVG removal tool.  I'm being redirected like crazy on my browser (Firefox).

dickevans
Posts: 12,330
Registered: ‎04-08-2008

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

hxxp://www.avg.com/us-en/utilities

change the 'xx' to 'tt'

Dick
Win7x64 SP1 current NIS V21
Contributor
mel032901
Posts: 51
Registered: ‎06-29-2012

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

Awesome.  Thank you!  Downloading now.

Contributor
mel032901
Posts: 51
Registered: ‎06-29-2012

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

AVG removal tool has finished running.

Bot Obliterator
Quads
Posts: 16,529
Registered: ‎07-21-2008

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

What is detected as Trojan.Gen.2  and Trojan.Gen etc.

 

Quads

Contributor
mel032901
Posts: 51
Registered: ‎06-29-2012

Re: Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

Trojan.Gen
c:\windows\installer\{5fff96ff-f4b8-7d87-ec73-42df1fdf4954}\u\00000008.@

there are about 3 pages on my Quarantine/Blocked list of different instances of this using different ending variables:
00000004.@
000000cb.@
etc.

 

It is a long list and I didn't seen any .Gen2 at this time but I did see them earlier.

 

And a constant barrage of the System Infected: Bamital Trojan Activity 3 from differing Attacker URLs all stemming from my computer trying to access the internet (as Norton is detecting, thank goodness)