Can't get ATMLI.dll to go away!

Discussion in 'Malware Help (A Specialist Will Reply)' started by VaporTrail2515, Mar 8, 2009.

  1. VaporTrail2515

    VaporTrail2515 Private E-2

    Hi! I'm new to this, so please let me know what you guys need and how to post it correctly so I don't waste your time!!!
    I'm working on a PC that has a trojan horse. I've run SAS, Spybot, and MBAM. MBAM is the only scan that comes up with "infections".
    I've also run a norton scan and it comes up with 1 infection. That's where I got the ATMLI.dll file name. Norton keeps attempting to quarantine the file to no avail. And when MBAM "removes" the file, it still comes back. So, I guess you could say that atmli.dll isn't the cause but some sort of result of this trojan. My problem is I can't find the cause to get rid of it!!!
    I realize that you will need logs, but I thought it better for you to tell me what logs you'd like rather then me posting a bunch that could potentially be useless. So, let me know what you'd like.
    Thanks!
    Kevin
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome

    I would like to see logs from both MBAM and SAS. The logs from SAS and MBAM can be found in the below folders. You have to substitute your real user account name where you see UserName

    I would also like to see the ComboFix log ---> C:\combofix.txt
    And the logs from running MGTools.exe ---> C:\MGlogs.zip

    Thanks
    Kes
     
  3. VaporTrail2515

    VaporTrail2515 Private E-2

    Hi Kes! Thanks for taking on the bug. I appreciate it! Here are the logs from MBAM and SAS. I have not yet used Combofix or MGTools, however, I'll read the associated posts regarding how to use them and post them either later on tonight, or tomorrow.
    Thanks again!!!
    Kevin
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're very welcome :) I'll be here in the morning by the time you've attached the remaining logs.

    kes
     
  5. VaporTrail2515

    VaporTrail2515 Private E-2

    Kes,

    Just pulled the combofix log and the MGTools log. Here they are. I'll be checking in tomorrow night around 9, so please leave any instructions and I'll do my best to oblige.

    Kevin
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there

    1) The versions of SUPERantispyware and MalwareBytes that you have installed currently are outdated.

    Please uninstall both, download the newest versions of each from the link given in the R&R, update them, run scans and attach the logs they generate.

    2) Please go to Add and Remove Programs and uninstall the following software as requested in step 1 of the R&R

    • Viewpoint Media Player (Remove Only)

    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {C42B7D00-166E-4D1E-9FA6-3390EDE86B51} - C:\WINDOWS\system32\atmli.dll
    O4 - HKCU\..\Run: [CS Update] copy /Y "C:\WINDOWS\system32\msxml71.dll.upd" "C:\WINDOWS\system32\msxml71.dll"

    After clicking Fix exit HJT

    4) Now we need to use ComboFix

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    
    KILLALL::
    
    File::
    C:\WINDOWS\system32\msxml71.dll
    C:\WINDOWS\system32\atmli.dll
    
    DirLook::
    c:\documents and settings\HP_Administrator\Application Data\alot
    
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C42B7D00-166E-4D1E-9FA6-3390EDE86B51}]
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    5) Could you please get this ryqwwdmm.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    6) Now run Ccleaner!

    7) Now go to this link Using MGTools and download the new version of MGtools.exe using the black bold print link in the first sentence. Overwrite your previous MGtools.exe file with this one.

    8) Run the new MGTools.exe and attach the logs it generates --> (C:\MGlogs.zip)

    9) Attach the logs from running ComboFix and the new logs from MBAM and SAS also.

    10) Let me know how things are running now

    Thanks
    Kestrel13!
     
  7. VaporTrail2515

    VaporTrail2515 Private E-2

    Kes,

    Running instructions on infected PC. Reloaded and re-ran the MBAM and SAS programs. I'm attaching the logs here. I'll post again in a bit regarding the outcome of instructions as well as the requested logs.

    Kevin
     

    Attached Files:

  8. VaporTrail2515

    VaporTrail2515 Private E-2

    Kes,

    Completed instructions. Here are the logs from Combofix and MGTools. I'm also attaching the collect.zip file (not sure if that's included with the MGTools.zip collection or not? Better safe then sorry!).
    Oh! Step 10!!!
    So far, post-scans, PC status is the same. Atmli.dll still lives in system32 and the pc can't access the internet. :(

    Kevin
     

    Attached Files:

  9. VaporTrail2515

    VaporTrail2515 Private E-2

    Sorry, for some reason the MGlogs.zip file didn't seem to make the attachments on the previous post. Posting here. Sorry!!!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    ...Stubborn little file... I was going to have you boot into safe mode to try and get rid of it manually, but let's do this instead to save messing about:

    1) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {C42B7D00-166E-4D1E-9FA6-3390EDE86B51} - C:\WINDOWS\system32\atmli.dll

    After clicking Fix exit HJT


    2) Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will
    popup for you to view when you login after reboot.

    2) Now on another subject tell me if you knowingly installed the below toolbar. it is considered adware or a PUP (potentially unwanted program)

    • ALOT Toolbar


    3) Run Ccleaner!

    4) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Thanks
    Kestrel13!
     
  11. VaporTrail2515

    VaporTrail2515 Private E-2

    Kes,

    Yes, this is a stubborn one. Not that it's a huge matter, but one of the first things I did was boot into safe mode and attempt to delete this file (which obviously didn't work!!! LOL!). It just won't die!!! Grrrr....

    Here are the logs.

    What's next?

    Kevin

    PS - I uninstalled that ALOT toolbar prior to running all instructions. Don't know how it got in. But it's gone.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Stubborn aint the word LOL Let me speak to either Chaslang or TimW regarding this. I'll get back to you ASAP!

    Kes
     
  13. VaporTrail2515

    VaporTrail2515 Private E-2

    Well, I hope they have good news!!!

    Let me know... thanks for all your help on this one too, Kes!!!

    Kevin
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ok, I have finished consulting with the masters :)

    1) Authentium AntiVirus SDK - 2 ---> will be clashing with Nortons! You must only be running one AV on your machine:

    2) Navigate to the trouble DLL:

    • C:\WINDOWS\system32\atmli.dll
    Right click the dll and check properties for permissions... let me know.

    3) You still have Windows Messenger running-

    If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    4) Are all your browser's add-ons / plugins removed?


    We need to use Avenger again. I left brackets in my script by mistake last time.
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    5) Run Ccleaner!

    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    7) Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.


    Thanks
    Kestrel13!
     
  15. VaporTrail2515

    VaporTrail2515 Private E-2

    Kes...

    Glad to see we've got some options still available to us!!! :D

    I just got home and it's late, so I'll proceed with instructions provided tomorrow.

    Thanks again!
    Kevin
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem, there is more to do, however first let's tackle the below, remnants from that ALOT Toolbar:

    Use Windows Explorer to find and delete the below bold directory:

    • c:\documents and settings\HP_Administrator\Application Data\alot
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi again!

    Now we need to use ComboFix to remove a malware file.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
     
    KILLALL::
     
    File::
    c:\windows\system32\drivers\ryqwwdmm.sys
     
     
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe


      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from ComboFix.


    And then let me know how your machine is behaving. Hopefully we've nuked it all now!
     
    Last edited by a moderator: Mar 15, 2009
  18. VaporTrail2515

    VaporTrail2515 Private E-2

    Good Evening Kes!

    Well it seems like I missed alot yesterday! I'm starting with your post regarding Authentium AV SDK and working to the most current post. I found Authentium in a Verizon PC Security Checkup package. I'm currently uninstalling it.

    I'm going to have to boot into Safe Mode to get the permissions for atmli.dll. When I go into permissions for it, all I get are the general and summary tabs. I'll reboot into safe mode and post results.

    In the mean time I'm going to disable Windows Messenger and proceed as instructed in the post.

    Kevin
     
  19. VaporTrail2515

    VaporTrail2515 Private E-2

    Kes,

    Update #1.
    Ran Avenger successfully (however, I don't think it removed our issue)
    Also got new MGlogs. Both are attached.

    Regarding Add-ons. All add-ons for IE6 are disabled. I double checked this.

    Successfully removed Authentium AntiVirus SDK.

    Checking now on permissions. Proceeding as instructed. Will post again shortly.

    Kevin
     

    Attached Files:

  20. VaporTrail2515

    VaporTrail2515 Private E-2

    Kes,

    Update #2.
    Booted into Safe Mode. Got all permissions for atmli.dll file. I've attached screenshots of permissions for all users (they're all the same), and the advanced permissions screen (just to see if there were any inherited permissions, but there weren't).

    Also, went to delete alot folder in App Data. It wasn't there?

    Moving forward...

    Kevin
     

    Attached Files:

  21. VaporTrail2515

    VaporTrail2515 Private E-2

    Update #3. (last one for tonight!)

    All programs ran successfully.

    Logs for Combofix and MGTools are attached.

    Here's where I'm at. ATMLI.dll is still in System32. BUT!!!
    On a hunch... I wanted to see if I could access the internet. I can't. But, it's not because my internet is blocked. I pinged the google website (from a working computer) and got the IP. When I typed the IP it came up. However, from there I was unable to get a google result up when I typed in majorgeeks. So, I'm not sure if it's a hijack, or simply a DNS problem at this point? I'll leave that for you to figure out!
    When I attempted to ping www.google.com from a cmd prompt on the infected PC, the firewall prompted me that PING was attempting to access the internet (which I allowed) but then the response was, "Ping request could not find host www.google.com. Please check the name and try again."

    So, I still have no internet (for all intents and purposes) and the file still exists. :( This thing is like the plague!!! It just won't go away!

    Look forward to hearing from you tomorrow!!!
    Kevin
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's try the below.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Now click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window
    Now run Ccleaner!

    Now run Malwarebytes ( and close all browser windows before running the scan ) and fix anything that MBAM finds and IMMEDIATELY AFTER fixing make sure that you reboot. DO NOT RUN ANYTHING ELSE. You must reboot immediately

    Now after reboot run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • the new log from Malwarebytes
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  23. VaporTrail2515

    VaporTrail2515 Private E-2

    Chaslang,

    Thank you for your joining the fight against my problem!
    Ran Combofix. I've attached the log to this post.
    I also successfully added that registry file. I grabbed a screenshot of the success message too, if you need it for further information.
    Flushed the DNS tables via command prompt successfully. (that was a cool little trick too! I may steal that for future use, if you don't mind!)
    Ran MBAM as instructed rebooting IMMEDATELY after scan completion. From what I could see there were no infections found. I've attached that log as well.
    Reran GetLogs and attached that log too.

    Here's a status report on the machine. ATMLI.dll is gone. However, I still can't browse the internet. I attempted once again to ping google via command prompt and got the same message "Ping request could not find host www.google.com. Please check the name and try again." However, when I entered the IP into IE and attempted to search majorgeeks I had a slight glimmer of hope. Autocomplete prompted me as to whether I wanted to turn it on or not. I didn't and was then resolved to the "Page cannot be displayed" screen which has haunted me throughout this endeavor.
    I do feel that we're making progress, though!!!

    I was thinking that perhaps I need to reset IE to it's default settings, but I'm not going to make a move until advised.

    So, I guess let me know what the next move is!
    Kevin
     

    Attached Files:

  24. VaporTrail2515

    VaporTrail2515 Private E-2

    Chaslang,

    Still can't browse the internet. ATMLI is gone. What's next?

    Kevin
     
  25. VaporTrail2515

    VaporTrail2515 Private E-2

    Nevermind! I figured out what the problem was... NORTON! (you're shocked, I know... LOL!) Apparently the Norton firewall was blocking all sorts of stuff (including DNS) which is why nothing worked! I have reset the firewall and removed all the extra entries. It's back in "learning mode" and doing well so far! I'm actually writing this post via the used to be infected PC. All is well in the world again...

    I'd like to thank you Chaslang and you too Kestrel13 for all your help with my problem. I never would have been able to get this stupid ATMLI file off if it weren't for your help! :)
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. We are happy to hear you got it fixed.

    Since your last logs were clean and if you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds