Author Topic: win32:Bamital-BA[trj] and win32:adware[adw] infected my files  (Read 4049 times)

0 Members and 1 Guest are viewing this topic.

AmTheMan

  • Guest
Hi,
Avast lately detected those 2 viruses: win32:Bamital-BA[trj] and win32:adware-gen[adw], Bamital has infected my explorer.exe and avast keeps blocking the application and you know how important that application is, and adware has infected Winlogon.exe and that too is a one hell of an important application, i realize how dangerous Bamital and adware are, but everytime i boot up my computer i have to disable files agent to start "explorer.exe" and that action makes the way easier for both viruses to proceed.
I got another problem with this infection called "URL:Mal", so everytime i start chrome or any other navigator and on any site, avast keep popping up a warning message (of a infected site) hundreds of times.
:'(

PLEASE I REALLY NEED HELP!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: win32:Bamital-BA[trj] and win32:adware[adw] infected my files
« Reply #1 on: March 24, 2013, 09:19:43 PM »
follow this guide and attach the logs.....not copy and paste
http://forum.avast.com/index.php?topic=53253.0

AdwCleaner
Malwarebytes
OTL
aswMBR


when done the removal experts will be notified

OBS: and normal letter size will be just fine.  ;)



Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: win32:Bamital-BA[trj] and win32:adware[adw] infected my files
« Reply #2 on: March 24, 2013, 10:46:44 PM »
Hi before you run the main logs we will need to work outside of windows

Create an emergency repair USB drive:
Download Dr Web Live USB to your desktop
  • Connect a USB flash drive to the computer. Registering the plugging in event takes no more than 10 seconds.
  • Launch drwebliveusb.exe.
  • The program will detect available USB-devices automatically and prompt you to choose the one you’d like to use as an emergency repair drive. You can format the device if you like (a warning will be displayed before you proceed with formatting). In order to read the License agreement, follow a corresponding link found in the program window (the page containing the license agreement text will be loaded in your default browser).

  • To create a bootable USB flash drive, press the Create Dr.Web LiveUSB button.
  • Files will be copied automatically.
  • Once the copying process is completed, press the Exit button to close the application.
  • Reboot the infected computer with the USB in the drive
  • Ensure that the first boot device is USB - If you are not sure about that then see this page for instructions
  • As loading starts, a dialogue window will prompt you to choose between the standard and safe modes.


  • Use arrow keys to select  DrWeb-LiveCD (Default)
  • When the system is loaded, check the disks or folders you want to scan, and click on ?Start?.


  • The programme will now scan for and cure/delete any malware that it finds.  Allow it to do so 
  • Once completed reboot to normal windows
  • No log is produced so once in normal windows run a fresh OTL scan and let me know if the problems persist

AmTheMan

  • Guest
Re: win32:Bamital-BA[trj] and win32:adware[adw] infected my files
« Reply #3 on: April 06, 2013, 04:15:21 PM »
Sorry for my late reply, but I WANT TO THANK YOU A LOT, THANKS THANKS THANKS!!!!!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: win32:Bamital-BA[trj] and win32:adware[adw] infected my files
« Reply #4 on: April 06, 2013, 04:26:10 PM »
Sorry for my late reply, but I WANT TO THANK YOU A LOT, THANKS THANKS THANKS!!!!!
you are not done yet.....attach the log essexboy requested

AmTheMan

  • Guest
Re: win32:Bamital-BA[trj] and win32:adware[adw] infected my files
« Reply #5 on: April 08, 2013, 01:57:37 PM »
well i can tell you something and i mean no offense, Dr. web didn't help as he suppose to, when type cure on the 2 infected files the button get stuck and nothing happens... i am a PC expert and i had to find out the source of the virus i kept looking, i did the regedit thing and the safe mode thing, dr. web helped 20% and that is allow me to work on my computer without explorer.exe and winlogon.exe, the source was the usb i plugged it in before windows launchs... so avast couldn't stop it, i found the main location of the virus and made an execute on it, it was some place in application files. i got a slow internet so i guess logs application will take some time