RogueKiller Startup Entries

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by wham, Dec 13, 2013.

  1. wham

    wham Private E-2

    Hello. I don't believe I have anything major going on other than some startup entries detected by RK that gave me pause. Thought I'd run it past you to make sure it's nothing more serious than it appears. Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is this file?

    • C:\Users\demigod\AppData\Local\70149b02515b3bb20dd492.47983420



    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [All Users][HJNAME] rundll32.exe : C:\Users\All Users\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe [x] -> FOUND
    • [Default][HJNAME] rundll32.exe : C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe [x] -> FOUND
    • [Default User][HJNAME] rundll32.exe : C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe [x] -> FOUND
    • [desktop.ini][HJNAME] rundll32.exe : C:\Users\desktop.ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe [x] -> FOUND
    • [Public][HJNAME] rundll32.exe : C:\Users\Public\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe [x] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.


    Now re run RogueKiller again, just a scan, and attach the log.

    Next > run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. wham

    wham Private E-2

    Thank you for your prompt response, Kestrel. I'm not sure what that file is. Can you tell me what report you found it in? Is it ok if I don't run Windows Repair? The last time I ran it on an XP system it never quite ran the same way again. Hiccups and massive slowdowns ensued, especially during file transfers. I don't want to risk the same thing happening on this machine.

    Noticed the registry entries doubled on this latest RK report. Is that odd?
     

    Attached Files:

  4. wham

    wham Private E-2

    Just wanted to add that upon reboot, I ran RK again and the same five startup entries showed up again.

    EDIT: If firewall was the only reason why you wanted me to run Windows Repair, then I don't think it's necessary to do so, as it has been functioning properly the whole time.
     
    Last edited: Dec 13, 2013
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your choice wham... :) I'm just going off what the logs told me:

    So if you are using the Windows Firewall, What are you currently using for antivirus?


    No.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.

    Code:
    :Files
    C:\Users\All Users\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe
    C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe 
    C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe 
    C:\Users\desktop.ini\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe 
    C:\Users\Public\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32.exe 
    C:\Users\demigod\AppData\Local\70149b02515b3bb20dd492.47983420
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.


    Now re run RogueKiller again, and attach log.
     
  6. wham

    wham Private E-2

    Sorry for the misunderstanding but what I meant by "functioning properly" was that I didn't have a problem re-enabling it. It was turned off voluntarily. I should've mentioned that right off the bat. My apologies.

    The Startup entries are still there. Also, I've included a screenshot of rundll32.exe running in Task Manager. This is only the second time it's been visible in Task Manager and the first time that it appeared after a reboot.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you right click it and open file location, where does it reside?
     
  8. wham

    wham Private E-2

    Seems that it consistently shows on reboot if I try to move it with OTM. It resides in C:\Windows\System32. I've attached another screenshot if you'd like to see for yourself. Doesn't show itself in msconfig on the Startup tab either. I'll leave it running a little longer and see if it goes away on its own instead of killing it manually.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you please get this: rundll32.exe into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    log retrievable @ C:\collect.zip
     
  10. wham

    wham Private E-2

    Here you go.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's fine. I'm starting to believe what RogueKiller is showing, all those rundll32.exe files, are not actually there. I'll follow up with another post in a moment.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's fine. I'm starting to believe what RogueKiller is showing, all those rundll32.exe files, are not actually there. I'll follow up with another post in a moment. I think that's what entries appended with an [x] means.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download SystemLook

    Double-click SystemLook.exe to run it.
    Copy the content of the following codebox into the main textfield:
    Code:
    :filefind
    rundll32.exe
    Click the Look button to start the scan.
    When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  14. wham

    wham Private E-2

    That was my initial thought too.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Whatever is causing those entries to show in the RK log is not malware I'm certain of it now. You can see for yourself from the results of the systemlook log that the places RK says the rundll32.exe exists is not true. :) We have nothing to be concerned about.
     
  16. wham

    wham Private E-2

    Was doing some sleuthing and I think the culprit is Windows 7 Gif Viewer. I installed it some months ago as an alternative to Windows Photo Viewer because it doesn't play animated gifs like Windows Picture and Fax Viewer did on XP. Problem is, it doesn't have an install location and it's nowhere to be found in Programs and Features.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Correct. I found out something to confirm this too, from another thread on another forum. Can you try using Revo Uninstaller to find it and remove it?
     
  18. wham

    wham Private E-2

    Gif Viewer is not among the populated list of installed programs. I failed to mention that the .exe and accompanying .dll are still in the root folder. Attached a screenshot of root folder. Deep-six them with SHIFT+Delete or go into Hunter Mode via Revo and purge them that way?
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below files from the root folder and those may go away.

    C:\rundll32.exe
    C:\shimgvw.dll


    These showed in the newfiles.txt log from MGtools
     
    Last edited: Dec 16, 2013
  20. wham

    wham Private E-2

    Yea, they went away. So I presume the 12 registry entries are not a cause for concern?
     

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those other entries are just fine. Ready for final steps? :)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  22. wham

    wham Private E-2

    Done and done. Thank you Kestrel and chaslang. I always appreciate your efforts very much. :)
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    From both of us, you are most welcome. :) safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds