I was scanning an old internal HDD connected through a SATA/USB adapter for viruses using MSE. I was intending to revive it for use in another CPU by removing the viruses,repairing the drive.
MSE detected:
BrowserModifier:Win32/Zwangi (Removed)
SettingsModifier:Win32/PossibleHostFileHijack (Disinfected)
Virus:Win32/Bamital.L (Disinfected)
TrojanDropper:Win32/Manital.D (Removed)
Worm:Win32/Vobfus.F (Removed)
Worm:Win32/Autorun.UI!inf (Removed)
Worm:Win32/Conficker.C (Removed)
Tojan:Win32/Bamital!dat (Quarantined)
Tojan:Win32/Bamital.J (Quarantined)
in the old HDD.
However, MSE did not fully remove Tojan:Win32/Bamital!dat. MSE kept 'detecting 1 potential threat and suspended it'
When i tried to 'Take recommended actions' suggested by MSE by 'removing' or 'quarantine' it, it will encounter the following message,
'Security Essentials encountered the following error: Error code 0x800704ec. This program is blocked by group policy. For more information, contact your system administrator. '
The following situation repeats when i try to remove the Trojan. I tried the possible ways here but it did not work. http://answers.microsoft.com/en-us/protect/forum/protect_scanning/win32bamitaldat/df6acace-d6e3-4f4b-bdd5-0d5e209b197e
I have installed AVG 2012 free AV but it cannot remove it too. Malwarebytes Anti-Malware detected no Malware or any problems. ESET Smart Security 5 detected nothing too. In the end, I gave up and uninstalled these 3 programs. I have noticed that when AVG/Malwarebytes/ESET is scanning, it will pause at some % and MSE will 'detect' Bamital!dat. I think that MSE overrides all 3 programs and attempt to repair the problem itself. I have encountered some blue screen moments in the middle of scanning. I belive that the Viruses, Worms, Trojans listed above copied itself into my C: drive. I am at my wits end. MSE keeps 'detecting' the Bamital Trojan and pop up once in a while(like in every 15 mins or so).
Thank you,
Chang Rong
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Chan Family at 20:56:01 on 2011-12-08
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.65.1033.18.4061.2523 [GMT 8:00]
.
AV: ESET Smart Security 5.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: ESET Smart Security 5.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe
C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe
c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Nero\Update\NASvc.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://asia.wsj.com/home-page
uSearch Bar = Preserve
mDefault_Page_URL = hxxp://emachines.msn.com
mStart Page = hxxp://emachines.msn.com
mURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: AutorunsDisabled - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [Advanced SystemCare 5] "C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &D&ownload &with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - C:\Program Files (x86)\BitComet\BitComet.exe/AddAllLink.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll/206
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{3DB55346-043E-42A5-97B3-E47E2D5C4CAF} : NameServer = 165.21.83.88,165.21.100.88
TCP: Interfaces\{3DB55346-043E-42A5-97B3-E47E2D5C4CAF} : DhcpNameServer = 192.168.1.254
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
BHO-X64: AutorunsDisabled - No File
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: BitComet Helper: {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll
BHO-X64: BitComet ClickCapture - No File
BHO-X64: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
IE-X64: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files (x86)\BitComet\tools\BitCometBHO_1.5.4.11.dll/206
.
============= SERVICES / DRIVERS ===============
.
R0 epfwwfp;epfwwfp;C:\Windows\system32\DRIVERS\epfwwfp.sys --> C:\Windows\system32\DRIVERS\epfwwfp.sys [?]
R1 EpfwLWF;Epfw NDIS LightWeight Filter;C:\Windows\system32\DRIVERS\EpfwLWF.sys --> C:\Windows\system32\DRIVERS\EpfwLWF.sys [?]
R1 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys --> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-6-6 64952]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe [2011-11-25 490840]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 eamonm;eamonm;C:\Windows\system32\DRIVERS\eamonm.sys --> C:\Windows\system32\DRIVERS\eamonm.sys [?]
R2 ekrn;ESET Service;C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2011-9-22 974944]
R2 GREGService;GREGService;C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe [2010-1-8 23584]
R2 Live Updater Service;Live Updater Service;C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [2011-3-18 244624]
R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2010-5-5 503080]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-9-14 508264]
R3 MpNWMon;Microsoft Malware Protection Network Driver;C:\Windows\system32\DRIVERS\MpNWMon.sys --> C:\Windows\system32\DRIVERS\MpNWMon.sys [?]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys --> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-4-27 288272]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys --> C:\Windows\system32\DRIVERS\Sftfslh.sys [?]
R3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys --> C:\Windows\system32\DRIVERS\Sftplaylh.sys [?]
R3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys --> C:\Windows\system32\DRIVERS\Sftredirlh.sys [?]
R3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys --> C:\Windows\system32\DRIVERS\Sftvollh.sys [?]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-9-14 219496]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-13 206072]
S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
S3 s115bus;Sony Ericsson Device 115 driver (WDM);C:\Windows\system32\DRIVERS\s115bus.sys --> C:\Windows\system32\DRIVERS\s115bus.sys [?]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\Windows\system32\DRIVERS\s115mdfl.sys --> C:\Windows\system32\DRIVERS\s115mdfl.sys [?]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\Windows\system32\DRIVERS\s115mdm.sys --> C:\Windows\system32\DRIVERS\s115mdm.sys [?]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\Windows\system32\DRIVERS\s115mgmt.sys --> C:\Windows\system32\DRIVERS\s115mgmt.sys [?]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\Windows\system32\DRIVERS\s115obex.sys --> C:\Windows\system32\DRIVERS\s115obex.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys --> C:\Windows\system32\drivers\TsUsbGD.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S4 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service;C:\Program Files (x86)\BitComet\tools\BitCometService.exe -service --> C:\Program Files (x86)\BitComet\tools\BitCometService.exe -service [?]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-23 57184]
.
=============== Created Last 30 ================
.
2011-12-08 12:31:37 69000 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D3ACB6E4-6B8A-44B0-8DDB-FE3EA3A2166E}\offreg.dll
2011-12-08 12:07:06 388096 ----a-r- C:\Users\Chan Family\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-08 12:07:05 -------- d-----w- C:\Program Files (x86)\Trend Micro
2011-12-08 10:47:35 -------- d-----w- C:\Users\Chan Family\AppData\Roaming\ESET
2011-12-08 10:47:35 -------- d-----w- C:\Users\Chan Family\AppData\Local\ESET
2011-12-08 10:45:40 -------- d-----w- C:\Program Files\ESET
2011-12-08 09:18:01 -------- d-----w- C:\Users\Chan Family\AppData\Local\ElevatedDiagnostics
2011-12-08 08:18:50 -------- d-----w- C:\Program Files (x86)\Panda Security
2011-12-08 07:54:25 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-12-08 07:54:23 8822856 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4621E79A-AC37-45EB-8A65-BFF00E87A314}\mpengine.dll
2011-12-08 07:45:29 8822856 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D3ACB6E4-6B8A-44B0-8DDB-FE3EA3A2166E}\mpengine.dll
2011-12-08 05:58:08 -------- d-----w- C:\Users\Chan Family\AppData\Roaming\SUPERAntiSpyware.com
2011-12-08 05:58:08 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2011-12-08 05:28:32 -------- d-----w- C:\Users\Chan Family\AppData\Roaming\Malwarebytes
2011-12-08 05:28:21 -------- d-----w- C:\ProgramData\Malwarebytes
2011-12-08 05:28:17 25416 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-12-08 01:36:27 917840 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-12-08 01:36:26 917840 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9484C19C-0630-4418-B090-222754BF91F6}\gapaengine.dll
2011-12-07 12:23:41 502272 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{CA05B3D1-77EA-4451-902B-52DDC774B856}-winlogon.exe
2011-12-07 12:23:35 502272 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{A52F8168-6DE4-4198-B0E0-A881DE95FD8B}-winlogon.exe
2011-12-07 12:23:23 502272 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{9397BA68-F2BA-4989-A95E-3BBA4A303925}-winlogon.exe
2011-12-07 12:22:44 1032192 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{58E52985-EED7-437D-A619-80B96675C05E}-explorer.exe
2011-12-07 12:22:20 1032192 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{2D949B95-E9AD-4A81-8235-83CB2B520ABA}-explorer.exe
2011-12-07 12:22:14 1032192 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{68F45D14-D8E6-4DFD-9B2B-7FB25D41739C}-explorer.exe
2011-11-30 14:40:28 22872 ----a-w- C:\Windows\System32\RegistryDefragBootTime.exe
2011-11-25 09:01:41 74272 ----a-w- C:\Windows\System32\RtNicProp64.dll
2011-11-25 09:01:41 565352 ----a-w- C:\Windows\System32\drivers\Rt64win7.sys
2011-11-25 09:01:38 -------- d-----w- C:\Program Files (x86)\Realtek
2011-11-23 07:30:09 -------- dc----w- C:\Users\Chan Family\AppData\Local\MigWiz
2011-11-09 05:24:51 886784 ----a-w- C:\Program Files\Common Files\System\wab32.dll
2011-11-09 05:24:51 708608 ----a-w- C:\Program Files (x86)\Common Files\System\wab32.dll
2011-11-09 05:24:49 3144704 ----a-w- C:\Windows\System32\win32k.sys
2011-11-09 05:24:49 1923952 ----a-w- C:\Windows\System32\drivers\tcpip.sys
.
==================== Find3M ====================
.
2011-12-08 07:54:22 270720 ------w- C:\Windows\System32\MpSigStub.exe
2011-11-15 07:47:58 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-10-02 21:06:03 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
.
============= FINISH: 20:56:31.00 ===============
Attached File(s)
-
Attach.txt (89.14K)
Number of downloads: 1

Help
This topic is locked

Back to top












