Followed all READ AND RUN ME FIRST steps-still bothered after Trojan infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by StoneHenge, Jan 15, 2011.

  1. StoneHenge

    StoneHenge Private E-2

    Greetings:

    Last week McAfee detected and removed:
    \LocalSettings\ApplicationData\cormst.dll

    that led to the detection of Trojan:win32/Hiloti.gen!D

    I followed all steps in the READ AND RUN ME FIRST page.

    When I log on that user account I am still getting the pop-up:

    Error loading C:\Documents and Settings\User\Local Settings\Application Data\ovifohav.dll

    I can still perform all actions through the administrator account.

    I appreciate all suggestions/assistance/help you can give.

    Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. StoneHenge

    StoneHenge Private E-2

    Thanks Kestrel.

    I am attaching four of the five requested logs. The fifth will follow in the next reply.

    Kindest regards
     

    Attached Files:

  4. StoneHenge

    StoneHenge Private E-2

    Here is the fifth log that you requested.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I take it you ran scans on this affected account?

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Please disable Spybot's TeaTimer.

    How to disable Spybot's TeaTimer

    Uninstall the below outdated versions of Java.
    • J2SE Runtime Environment 5.0 Update 6
    • Java(TM) 6 Update 12
    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Optional to fix to free up resources


    After clicking Fix exit HJT.


    If you do not know what these are then please delete them.
    • c:\program files\276k9w4c.exe
    • c:\program files\ng5a4nta.exe
    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    I strongly advise you to cleanup your Desktop. Remove eveything but links to run programs. Do not download and save programs here and defintely do not use it for long term storage. You need to keep ComboFix.exe here for now as we need it, but we will be removing it when we are finished with your cleanup. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  6. StoneHenge

    StoneHenge Private E-2

    Kestrel:

    I will follow all of those steps. Also, I checked SpyBot startup, and it has the apparent location of the infected item listed in the startup list; so I unchecked it, and the problem 'seems' to have ceased because the dll is no longer running at startup. I still have issues with access to some folders, but for now, here is what SpyBot indicates as the malicious .dll

    HK_CU:Run (User S-1-5-21-3752200638-408136642-4136389770-1010)

    Tzojolelole

    Rundll32.exe “C:\Documents and Settings\Col\Local Settings\Application Data\ovifohav.dll”,Startup

    Thanks, again. And now I'll follow your next steps.

    Cheers
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm i did not see in the logs what spybot is referencing. As I had previously asked, are you indeed running scans on the account that is affected? If not, you need to. But follow my previous instructions first.
     
  8. StoneHenge

    StoneHenge Private E-2

    Kestrel

    I followed all of your instructions.

    Here are the MGtools logs you requested.

    Nowhere in the logs did I find reference to what SpyBot found in the startup list.

    I'm not sure how to go about deleting a .dll that only shows up in a startup list, but doesn't have an identifiable .exe

    Also, I deleted:

    276k9w4c.exe and hg5a4nta.exe

    both of those were outdated DrWebCureIt applications I ran prior to contacting you.

    Kestrel, is there any way to delete the .dll and its application by accessing this key?:

    HK_CU:Run (User S-1-5-21-3752200638-408136642-4136389770-1010)

    I just checked SpyBot, and the oddly-named Tzojolelole is still present in the startup list.

    I appreciate your help Kestrel. I'll wait for your next set of instructions.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If the "Col" account is where the trouble is happening (which clearly it is by your screenshot and the file path you gave, then you need to be running all the scans from scratch on THAT account. :)
     
  10. StoneHenge

    StoneHenge Private E-2

    AHA!! Never thought of that Kestrel!

    I'll start working on it tonite and repost all the logs for you when I'm done!

    thanks again!
     
  11. StoneHenge

    StoneHenge Private E-2

    Kestrel, how are ya?

    I re-scanned everything through the other account as you asked me to do.

    Still same issue...which leads me to ask a few other questions before I get a reply from you.

    1) You will find my logs attached in two messages after I post now.

    2) Is there a way for SpyBot to tell me what .exe is linked to the .dll that I can still diasble on startup through S&D?

    3) Do you know the name of another 'TaskManager' management program I can run to identify which .exe is running to cause this error?

    I am attaching a shot of Windows TaskManager to show that it is THE TOP rundll32.exe that always causes the problems, and closes when I 'X' the error dialog box.

    4) A windows search for the 'infected' key returns a list of folders associated with: User S-1-5-21-3752200638-408136642-4136389770-1010 ; all of the folders associated with that User ID are Microsoft files. Can it be that the virus removed by McAfee affected the Microsoft files?

    I am posting a snap (screenshot) of the User ID, and a second one of the Microsoft folders associated with that user.

    5) Can I use (Win XP Pro > Start > Control Panel > Administrative Tools > Event Viewer > System) Event Viewer to access the Processor Affinity box to uncheck all CPUs associated with this process to stop it from running?
    Would this affect the performance of my HD which up to now has run VERY WELL, and been virus free for over two years? (I am attaching a .jpg of the ttwo presently 'checked' CPU boxes on which this error message 'seems' permitted to run).

    6) When I ran the scans through the affected account, I found that I can only run binaries (EXEs) by accessing them as an administrator, whereas prior to this infection I was able to run programs without administrator access.

    7) I guess my burning question in all this is: how can I identify which .exe is powering the .dll error report, and can I find out this information via a Windows, SpyBot, MBAM, or Panda source? If not, is there any other option that YOU know of that would help me to identify which executable is running to generate this .dll error message.

    Again, K-Rock, these are just questions, and if there is a better solution or more troubleshooting you can think of I will try everything you give me (AND... I'll do it in the correct order so as not to irritate you :major). If you have another rootkit analyzer, or program definitions configurator I'll follow your lead.

    Gratefully, StoneHenge

    p.s. logs are to follow
     

    Attached Files:

  12. StoneHenge

    StoneHenge Private E-2

    Kestrel:

    Logs - set 1.
     

    Attached Files:

  13. StoneHenge

    StoneHenge Private E-2

    Kestrel:

    Logs - set 2.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The logs you just attached are still from the user account named "bo" . You need to provide logs from the "col" user account if you wish to fix the problems occurring on it. You don't need to identify any processes or DLLs. Once you attach the proper logs, we should be able to tell you what to do to remove the problem. All you need to do is run MGtools affter logging into the col account and you should have logged out of the other user account first. You may need to change col to an admin account to run MGtools properly.
     
  15. StoneHenge

    StoneHenge Private E-2

    For sure! I logged in as 'col' but had to run the scans as 'administrator' 'BO' because the programs would otherwise not run.

    I will give 'col' admin access and re-run the logs tonite.

    Thanks chaslang!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but that makes everything run as "bo" ;) which is what I see in the logs. Just make a temporary change to col's permissions and then log into that account and run MGtools. You only need to run MGtools for now and attach the new log.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It looks like you ran the scans on the "bo" account again!



    • Admin
    • Administrator
    • bo
    • col <--- You need to be using this account and running scans on this account! :)
    • gin
    • Guest
    • HelpAssistant (Disabled)
    • SUPPORT_388945a0 (Disabled)
    • tu
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahh, thanks Chas. Didn't see your post until just.
     
  19. StoneHenge

    StoneHenge Private E-2

    Kestrel: so far I have NOT been running in SafeMode, is that okay? I didn't see anything in the Read and Run Me First Post about safemode; I will begin re-scanning in a few minutes...just in case you get this message. Otherwise I'll proceed in Normal Mode.

    Thanks
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Normal mode. Yes please! :)
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just MGtools is all you need to do to start. This will only take 5 to 10 minutes max.
     
  22. StoneHenge

    StoneHenge Private E-2

    :waveIt may take me all nite, but I'll get it for you!!!:wave:
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOOO! See my last few messages!!! Only MGtools and it will be a few minutes
     
  24. StoneHenge

    StoneHenge Private E-2

    Chaslang: You're right, it really was only 10 or so minutes...

    Attached you will find the MGlogs you requested.

    Thank you very much for your help.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Then delete this file if it exists, but I suspect it may not.

    C:\Documents and Settings\col\Local Settings\Application Data\ovifohav.dll

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running now?
     
  26. StoneHenge

    StoneHenge Private E-2

    Kestrel: Attached you will find the MGlogs for my Dell that is now running perfectly and amazingly fast!!!:p

    Special thanks to you and Chaslang for your excellent work and attention to detail.

    I'm wondering what turned you on to the RegEdit4 fix? ...and how was I off track to think it was an infection? What could have caused the change to my registry? the infection? or the removal of it? What made you think it only affected the "col" account and not others? Is there an AV that could have prevented this issue?

    What direction do I go now? SysRestore toggle? Hiberfil?

    How does a person like me 'give back' to MajorGeeks as a thank you for all the attention and help you've given?

    Also, do I have to get another virus in order to make 50 posts so I can PM you?:-D...No, really?!?!?

    I'm seriously not worthy, but thank you VERY much (*I believe it is fully fixed*)

    ...but I still waiting for your reply to know what to do next.


     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall these outdated versions of java

    • Java(TM) 6 Update 5
    • Java(TM) 6 Update 7
    But keep 6.23 as it is current.

    You're welcome.

    We use alot of reg patches, maybe to kill off a reg key or a value, or if available we will use combofix or avenger to do the same job.

    It was obviously there at some point, however perhaps some software like spybot was used to prevent it from running or perhaps someone had used MSCONFIG to control the bad start up. It was trapped anyway, and now it has gone.
    What change?

    Because from the screenshot you gave and the file path you provided revealed it was in the Col account! :)
    Ooooh good question. But the answer is going to be vague. Fact is, the best antivirus out there is the person at the keyboard.
    I will list final steps for you to follow soon.
    At the end of each of my posts is a couple links. We do not accept donations but lots of cool geekwear to look at!

    No need for PM's. We would rather it be out in the open in the forum if it is regarding anything technical. That way everyone benefits. The restriction on not being able to send PM's until after 50 posts has been made is a bit of a precaution.
    Yes! So do I, I am not seeing anything else to deal with.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  28. StoneHenge

    StoneHenge Private E-2

    Kestrel13!

    1) Thank you very much for your help. I didn't make the 50 post mark, and I hope I won't ever need to post here again with problems. You know, I joined MajorGeeks last summer, but I didn't require any help; I just found this site when looking for TweakFiles (*an old school site from wayyyyy back*). Reading others' posts in the malware forum this week has opened-up my own 'troubleshooting' brain about what fixes could be applied. AND - the restriction from posting my ideas really makes me want to check in everyday to find out how the problems get resolved without interfering with you professionals. I'll keep reading along to find out how other posts get their fixes.

    2) I'm not sure if there is a forum here to ask about software, but if you have a minute to share your thoughts on Hostsman and Sandboxie - it'd be well received.

    3) When MBAM released their full, paid version I was studying at the university and didn't have the ca$h to buy it. Well, I bought it tonight, so I can sleep a little better knowing it will be active about malware, even when I'm not! But, you're right, the best AV protection is the person at the keyboard.

    4) Kestrel, is it better to disable startup programs through msconfig, or through SpyBot, or another program?

    5) Is there a tutorial here on MG to learn more about registries and how they work?

    Thanks Kestrel
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ah!! Way before my time then! :)
    There is indeed a Software Forum you can post in and ask questions relating to what you mentioned.

    Never through MSCONFIG. Anything other than normal mode is primarily only used for troubleshooting and diagnostic purposes. If you wish to control start up's I would suggest you use something such as Start Up CPL
    Try taking a look at the below links.

    Windows registry information for advanced users
    How to add, modify, or delete registry subkeys and values by using a registration entries
    Windows Registry
    Registry Hives

    Most welcome.
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I also refer you to step 4 of the READ & RUN ME again. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds