TrojanDropper HTML meta ao - or not.... Hard to be sure. USB controllers not working.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aeolus, Jul 21, 2012.

  1. aeolus

    aeolus Private E-2

    Hello, hope you can help...

    Problems assumed to be caused by malware or Trojan but not easy to be sure.

    Op-sys – Win XP SP3 fully patched and up to date; also running Kaspersky Internet Security 2011.

    SELF – grey-hair with good general knowledge of windows and hardware, but fortunately, only rare experience of successfully fighting malware, once before, with help from Major Geeks, I think.

    SO WHAT’s WRONG? PRESENT EFFECTS ON MACHINE:

    *USBs........​

    * Sound card..... and​

    * system restore..... ​

    ....... are all inactivated (although not “disabled”, just non-working); ​

    Kaspersky reports having found “Trojan Dropper HTML meta ao” May be an unconnected finding.​


    DETAILS

    1. USB ports don’t work. More precisely, the whole USB control subsystem is down; shown by (a) In Device Manager, the whole ‘family’ of USB controllers & ports have ! marks. (b) Dev Manager properties reports driver is “Missing or corrupted (Code 39)” but attempts to reinstall or update fail. Root hubs are absent from Device manager [would be expected to be there, I think]. (c) Trying to work-around this, I installed a [never-previously-installed] “daughter” USB card (with its own controller and ports) in a PCI slot but the newly installed USB controller immediately exactly mirrored the fault that affecting the on-board controllers/ports. This seems to exclude flaky hardware on the board as the new hardware fell victim to the same problem.

    2. Sound card. This is inactive – in Device Manager and control panel it appears no sound card is loaded or installed – although other software/services do appear to be installed e.g. sound and video codecs. RE-install is ineffective.

    3. System Restore not working (although it doesn’t report it’s switched off). SR can show restore points and can create further ones, but attempting to use a restore point goes through the entire procedure but results in (something like) “restore not successful and no changes have been made”.

    4. Kaspersky reports that on 12th July it detected " Trojan-Dropper.HTML.meta.ao. " This file is not now found although it's not clear if KIS removed it, or some other process caused it to disappear.

    CHRONOLOGY OF EVENTS

    Was installing new Kaspersky IS because old licence had just expired four days previously. As part of upgrade replaced KIS 2009 with new install of KIS 2011. Consequently for a few minutes, no AV software was installed while the switchover happened. Nothing appeared to go wrong.
    The next morning, USB ports were completely inactivated. A full scan by KIS2011 showed the Trojan named above.

    Later within the next two days, I realised both sound hardware, and system restore, were not working.

    ACTION TAKEN – LOGS

    Have followed Forum instructions and used CCleaner, then downloaded and installed RogueKiller, Anti Malware, HitMan Pro; and MG Tools. Have only permitted cleaning or removal by MBAM which found 1 threat and removed it. Have scrupulously avoided self-fix attempts with these.

    Logs ready for posting.

    Hope you can help determine whether there is in fact any malware affecting my USB ports, sound card, and System Restore.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: TrojanDropper HTML meta ao - or not.... Hard to be sure. USB controllers not work

    Welcome to Major Geeks!

    You do not appear to be having malware problems. That item Kaspersky mentioned may not really have been a real case of malware. Without seeing a log showing exactly what was found and where I cannot fully say. But typically things with names like this are not really big problems.

    I would suggest uninstalling Kaspersky and rebooting and see if anything changes. Then if still having a problem, see if System Restore will work without Kaspersky installed.

    Other than that, I suggest posting in the Hardware Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds