<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: GMER - the Antirookit Software is Getting Internet Recognition</title>
	<atom:link href="http://www.siusic.com/wphchen/gmer-the-antirookit-software-is-getting-internet-recognition-158.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.siusic.com/wphchen/gmer-the-antirookit-software-is-getting-internet-recognition-158.html</link>
	<description>Random thoughts and news by Andrew Chen and friends</description>
	<pubDate>Fri, 30 Jul 2010 21:43:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5</generator>
		<item>
		<title>By: Bagle Virus = Disabled Antivirus</title>
		<link>http://www.siusic.com/wphchen/gmer-the-antirookit-software-is-getting-internet-recognition-158.html#comment-30010</link>
		<dc:creator>Bagle Virus = Disabled Antivirus</dc:creator>
		<pubDate>Sun, 29 Jun 2008 01:08:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.siusic.com/wphchen/gmer-the-antirookit-software-is-getting-internet-recognition-158.html#comment-30010</guid>
		<description>As I believe my computer to be on the road to recovery (fingers crossed) or recovered, I like to write a quick summary of the Bagle virus and how it manifested in my computer. I first noticed something was wrong when my sound went out after downloading cracked software from emule site that I could have gotten for free elsewhere. I couldn't play WMP, or sound from websites was missing. In fact sound all together was missing from my computer.

When I would press turtle beach santa cruz speaker icon on my desktop toolbar, I would get 'santa cruz not detected'. My volume wouldn't move. I spent several days unistalling and reinstalling latest sound drivers but still system would fail in their 'software configurations tests' on third and fourth part of test. Under Control Panel, Sound and Audio devices was basically greyed out, not recognizing or showing santa cruz {Just now I went and actually changed it back to Santa Cruz on all options and I know my system is free of the virus. Thanks Kaspersky!}.

By this time I was beginning think virus as the only thing I had been doing was downloading. I also could not access my Norton antivirus, either to remove it or access their folders. My System Restore was a wash, I couldn't go back at all and the few restore points that I had would fail on attempts. I could not access certain programs like spybot and hijackthis, resulting in a "this program is not a win32 exe program" or something like that. I also could not access certain 'login' pages such as my bank or yahoo. My internet was slow, certain pages wouldn't even come up. I was bringing up the task manager consistently to close programs or websites. The task manager would also say my computer was running at '100%' when I viewed Performance tab (now running at 0-7%).
I downloaded several antivirus programs; the first helpful was Malwarebytes, then Kaspersky online scanner, and finally something I know nothing about; Combofix (which might be an anti rootvirus).  I believe the bagle virus was able to bring other viruses into my computer as later AV scans brought up many. See above posts.

This win32 bagel worm virus is incidious. It disables your antivirus to a degree and access to important files/folders, often disabling any AV program that was designed to kill it. I was never able to locate my System Volume folder for some reason. It seems to take several major AV programs working together as I couldn't get Kaspersky to work until I used Malwarebytes several times but Kaspersky seemed to be much more thorough once it did work. It seems that Combofix and Kaspersky directions in the above posts have led to my computer's return to full functionality. Note; I have generally kept my System Restore off during all this scanning and cleaning. The rest of the information is in the above posts. I just ran another Kaspersky online scan and nothing came back (yeah!). I plan on running some other scans (not combofix--deleting this from my computer) from superantispy, kaspersky, and malwarebytes again in the next couple days. I also plan on running both Kaspersky AV programs and Windows firewall at all times. I'm walking into the light at the end of the tunnel. Thanks for replying guys. I would have eventually tried your way if this didn't work. A great computer back at work!  All the below came up on my av scans.


[Keywords; Bagle, hldrr.exe, srosa.sys, rootkit, wintems.exe, mdelk.exe, trojan.agent, worm.bagle, I-worm, win32]</description>
		<content:encoded><![CDATA[<p>As I believe my computer to be on the road to recovery (fingers crossed) or recovered, I like to write a quick summary of the Bagle virus and how it manifested in my computer. I first noticed something was wrong when my sound went out after downloading cracked software from emule site that I could have gotten for free elsewhere. I couldn&#8217;t play WMP, or sound from websites was missing. In fact sound all together was missing from my computer.</p>
<p>When I would press turtle beach santa cruz speaker icon on my desktop toolbar, I would get &#8217;santa cruz not detected&#8217;. My volume wouldn&#8217;t move. I spent several days unistalling and reinstalling latest sound drivers but still system would fail in their &#8217;software configurations tests&#8217; on third and fourth part of test. Under Control Panel, Sound and Audio devices was basically greyed out, not recognizing or showing santa cruz {Just now I went and actually changed it back to Santa Cruz on all options and I know my system is free of the virus. Thanks Kaspersky!}.</p>
<p>By this time I was beginning think virus as the only thing I had been doing was downloading. I also could not access my Norton antivirus, either to remove it or access their folders. My System Restore was a wash, I couldn&#8217;t go back at all and the few restore points that I had would fail on attempts. I could not access certain programs like spybot and hijackthis, resulting in a &#8220;this program is not a win32 exe program&#8221; or something like that. I also could not access certain &#8216;login&#8217; pages such as my bank or yahoo. My internet was slow, certain pages wouldn&#8217;t even come up. I was bringing up the task manager consistently to close programs or websites. The task manager would also say my computer was running at &#8216;100%&#8217; when I viewed Performance tab (now running at 0-7%).<br />
I downloaded several antivirus programs; the first helpful was Malwarebytes, then Kaspersky online scanner, and finally something I know nothing about; Combofix (which might be an anti rootvirus).  I believe the bagle virus was able to bring other viruses into my computer as later AV scans brought up many. See above posts.</p>
<p>This win32 bagel worm virus is incidious. It disables your antivirus to a degree and access to important files/folders, often disabling any AV program that was designed to kill it. I was never able to locate my System Volume folder for some reason. It seems to take several major AV programs working together as I couldn&#8217;t get Kaspersky to work until I used Malwarebytes several times but Kaspersky seemed to be much more thorough once it did work. It seems that Combofix and Kaspersky directions in the above posts have led to my computer&#8217;s return to full functionality. Note; I have generally kept my System Restore off during all this scanning and cleaning. The rest of the information is in the above posts. I just ran another Kaspersky online scan and nothing came back (yeah!). I plan on running some other scans (not combofix&#8211;deleting this from my computer) from superantispy, kaspersky, and malwarebytes again in the next couple days. I also plan on running both Kaspersky AV programs and Windows firewall at all times. I&#8217;m walking into the light at the end of the tunnel. Thanks for replying guys. I would have eventually tried your way if this didn&#8217;t work. A great computer back at work!  All the below came up on my av scans.</p>
<p>[Keywords; Bagle, hldrr.exe, srosa.sys, rootkit, wintems.exe, mdelk.exe, trojan.agent, worm.bagle, I-worm, win32]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
