Cannot remove Bamital Trojan and Trojan.Gen & .Gen2

Norton is not able to remove these threats and I have been constantly notified that my computer is under attack.  I've run Malware Bytes and Spybot Search and Destroy.  Neither worked.  I also ran Norton Power Eraser and received a message that said the processes of explorer.exe, svchost.exe and winlogon.exe are Bad.  I think that this is where the Trojan's have attached themselves.

 

I was unable to run Norton for a few days and downloaded AVG.  Total Crap.  It allowed these to infect my computer after years of Norton keeping it clean.  I have upgraded Norton today and am running Norton Internet Security 2012.

 

My son used IE last night instead of Firefox to browse the internet (FB, Youtube and Pandora).  I believe this is when it happened and I've spent all day trying to get this off of my computer.

 

AND this "Adobe Flash Player Installer" keeps trying to load over and over but I think it's associated with the whole Trojan outbreak on my computer.

 

PLEASE!!!! Any help will be appreciated!!!


mel032901 wrote:

Norton is not able to remove these threats and I have been constantly notified that my computer is under attack.  I've run Malware Bytes and Spybot Search and Destroy.  Neither worked.  I also ran Norton Power Eraser and received a message that said the processes of explorer.exe, svchost.exe and winlogon.exe are Bad.  I think that this is where the Trojan's have attached themselves.

 

I was unable to run Norton for a few days and downloaded AVG.  Total Crap.  It allowed these to infect my computer after years of Norton keeping it clean.  I have upgraded Norton today and am running Norton Internet Security 2012.

 

My son used IE last night instead of Firefox to browse the internet (FB, Youtube and Pandora).  I believe this is when it happened and I've spent all day trying to get this off of my computer.

 

AND this "Adobe Flash Player Installer" keeps trying to load over and over but I think it's associated with the whole Trojan outbreak on my computer.

 

PLEASE!!!! Any help will be appreciated!!!


Welcome,

I cannot help you. We do have an expert who specializes in this type of problem. A couple of cautions. First, do not attempt to run and more 'fixers'. At best they do nothing, at worst they may make it impossible to clean up. Second, when Quads starts helping please follow his instructions exactly. He is a volunteer. He may be in a different time zone so be patient and wait for his instructions.

Stay well and surf safe

Thanks!  Will do.

ANY other user other than the thread starter is not to use any instructions, scripts or proceedures,  The work though in cleaning a system is individual and only for that system due to a number of factors.

 


 

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability. Do as the instructions ask nothing extra or run things twice
  • If I ask a Question just answer it, don't run anything unless it states.
  • Major steps used:

1. Find

2. Break

3. Destroy

4. Cleanup  (including system as a whole)

 

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.

 

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forum, (sometimes :smileylol:)

  • Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.

 

 You have made a bigger hole for yourself,  Norton AVG, Spybot S&D............................  Uninstall Spybot and AVG,  then use AVG's Removal tool.

 

What is your operating system  and include whether 32 bit or 64 bit??

 

Quads

Thank you for your help.  I realize that loading AVG was a bad idea.  I still had Norton on my computer but just could not update it at the time.

 

I'm running Windows XP 32 bit.  I've removed Spybot and AVG (earlier) but whatever is going on with this computer, I'm unable to get to the AVG removal tool.  I'm being redirected like crazy on my browser (Firefox).

hxxp://www.avg.com/us-en/utilities

change the 'xx' to 'tt'

Awesome.  Thank you!  Downloading now.

AVG removal tool has finished running.

What is detected as Trojan.Gen.2  and Trojan.Gen etc.

 

Quads

Trojan.Gen
c:\windows\installer\{5fff96ff-f4b8-7d87-ec73-42df1fdf4954}\u\00000008.@

there are about 3 pages on my Quarantine/Blocked list of different instances of this using different ending variables:
00000004.@
000000cb.@
etc.

 

It is a long list and I didn't seen any .Gen2 at this time but I did see them earlier.

 

And a constant barrage of the System Infected: Bamital Trojan Activity 3 from differing Attacker URLs all stemming from my computer trying to access the internet (as Norton is detecting, thank goodness)

Are you using Norton 2011, 2012 +??

 

I have to seperate what is zeroaccess and what it being reported as Bamital.

 

Quads

I downloaded the free version of Norton Internet Security 2012 for the 30 day trial.  I am unable to renew my subscription until next month.  Things are a bit tight financially right now.  Hence, why I was stupid and downloaded AVG.

Also, it might help to know that everytime the "Adobe Installer" tries to load, Norton tells me the threat has been blocked.  That's the Trojan.Gen threat.

I will be out for a couple of hours, but.

 

Open notepad,  then open Norton and go into each detection listed and the details,  click the "copy to Clipboard"

 

you can then paste into Notepad the details,  one under yje next,   may end up long.

 

Then save the .txt document.

 

Then you can attach all the threat details .tx to a  post.

 

Quads

Ok...will do.  No problem on timing.  I'll just log off and get back on in the a.m. (I'll post the .txt file tonight).

 

Thanks for your help.  Very much appreciated.

Here is the .txt file.  There are just a ton of the System Infected: Bamital Trojan Activity 3.  It's constant.  I copied a lot of them into the .txt file...hoping it's enough to give you the info you need.

 

I also "halved" the text file and at the bottom put the Trojan.Gen and .Gen2 info. 

 

Again, thank you.  I will be on again in the a.m. (Central time).  Have a great night.

Seein as Malware is auto loading as well I have an idea but XP makes this longer and harder.

 

Can you burn CD's??   And do you have a Flash Drive??

 

Quads

Good morning.  Yes, I can burn CDs and I also have a Flash Drive.

I will split this step

 

a)  Please download http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/   You need to download the 32bit version.


Transfer it on to the Flash Drive ready.

 

b)  Download  hxxp://oldtimer.geekstogo.com/OTLPENet.exe    to your desktop  (change the xx to tt)

 

Ensure that you have a blank CD in the drive

Double click OTLPENet.exe and this will then open imgburn to burn the file to CD for you ready.

 

Quads

Ok.  I've done both.  I apologize for the delay...I'm running Saturday errands in between being online.