Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Bugbear possible unknown virus unable to clean

Status
Not open for further replies.

jstevens

IS-IT--Management
Jul 31, 2001
144
US
I have a horrendous virus issue with a machine I'm working on. I will list the steps I have taken so far and information on what I have seen. I am really curious to see if anyone has seen this and knows what is going on for me.

Machine came in with an os error missing ntoskrnl.exe. Drive was pulled and put into another system and scanned with Symantec corp edition(SAV). Multiple bugbear / keylogger files were found and quarantined. System was deemed to be compromised and will be reloaded. All software was copied off to another machine. Original drive was fdisk'd and system restore from recovery partion was run (Hp Pavillion). OS is XP home. Data was transfered back. Profile data was put back in place, 3rd party apps re-installed and data replaced.

Norton retail 2004 was put on, updated. Symantec bugbear removal tool was run and reported clean. XP firewall enabled. Spybot put on, cleaned and immunized. Machine was returned to customer.

Just a few days later machine was returned with another failed OS error Cx00000015 Application error. This was a blue screen stop error. Pulled drive again, ran full scan, appeared clean SAV found nothing. Windows repair reinstall was run. I received a bunch of registration errors but re-install completed and machine booted to desktop ok and all services appeared to be starting. However machine was appearing to hang and not respond. Taskmgr reported a file dhzzyl.exe was running. Most likely a randomly generated viral process. Killed the app process tree, and it would restart again. Checked registry, found it was set to start in hklm\run. Removed and rebooted system. Process kept comming back. After about 30 minutes of diaging the machine further, the machine blue screened again with same application error.

Bleh, so I pulled the drive, downloaded AVG and ran a scan. It found 2 bugbear dll files in system32 folder and here is the weird part, AVG reported many hidden exe files. filename.jpg.exe The infected files would be cleaned but, after a rescan they were reported to be infected again. I just manually deleted the exe jpg files, possibly the introduction of the virus, deleted the bugbear dll files and the random exe file. Slapped the drive back in, and performed an XP repair reinstall again. Loaded up AVG locally and to my dismay, AVG kept reporting bugbear infection, the random dll files getting generated in the system32 folder. Running sysinternals process explorer, there did not appear to be any abnormal running applications.

If this was bugbear, I should be able to clean it up but I can't seem to. If it was a known virus the source file should have been detected and stopped. The virus must have been residing somewhere in the data that was transfered back to the machine originally because I was personally guaranteed that the machine was not placed back on any network including internet access. The restore partition was scanned with AVG and reported clean. I have no idea how it became reinfected again nor why I can't seem to fully get it cleaned up and stop the continious infection source. I doubt they clicked on these jpg.exe files.

So anyway, I am retransfering the data (programs, data, not windows folder) again and am going to have to reload because the OS is very buggy and having weird dll errors and crashing as well as the apparent continuing bugbear infection. I am assuming somewhere in the registry the virus is getting linked to run, either shell extension or vxd driver, somewhere. Why SAV and AVG cant find the source is beyond me. I have put AVG on the original machine I transfered data to (data having since being removed and now retransfering) and is clean, my workstation where I put the drive originally has AVG and is clean.

I am praying that after I reload, retransfer and update, this infection will be cleaned.

Jason
 
Your system may be re-infecting itself from WinXP System Restore. Make sure it is disabled.

bcastner has an excellent FAQ on this subject:
See FAQ608-4650


MCSE CCNA CCDA
 
Yes I would agree as infection was found in the system restore folder when I ran my scan initially. However, I have since, completely re-fdisked the drive and used recovery cd's to reload. Re-transfered data not including system information folder nor os folder. Loaded AVG, and bugbear dll's are still popping up.

Either the machine is getting reinfected over my network or somehow the virus source is getting transfered through the data store which I have scanned 1000 times and is reported to be cleaned and is getting launched how I dont know. If it was getting infected over my network, I would think other machines would have it too but I have not detected infections on any of my local machines.

Jason
 
How important is the data that has to be restored? Sounds like the only source it could be coming from - Kes:)
 
Ok here is the deal.

The virus bugbear was located somewhere in a 3rd party program folder. C:\helper After I reloaded the machine yet again, loaded up avg all was clean. I installed this program from cd and ran it, all was fine. I had backed up the entire program folder and transfered to another machine. That program folder was scanned with sav (high bloodhound) and avg (heuristics enabled) and reported clean. The entire program folder was then transfered back over writing the new install to replace program settings and data and when the program was run, bugbear launched. 3 dll's were created and 1 exe in system32 folder and registry run line updated, all with avg installed and im sure sav would not have prevented it as well.

The virus was somehow in this program's files and when transfering back and then running it, launched the virus. I removed the program, cleaned up bugb, reinstalled the app and just transfered the data folder and not its programs files and all is fine now. Bugbear must mask itself somehow I'm am really concerned how avg and sav didnt catch the dormant / embedded virus in these program files. Avg would display virus found, but not actually clean up the dll's and exe files in system32 folder. After avg reported it found bugbear, all 3 dlls and 1 exe were still there. Scary.

Jason
 
glad you got it sorted - perhaps if you had scanned with sysclean or stinger it may have got the files that AVG & SAV missed?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top