This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Win32: Hilot

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I believe I got hit w/ Win32: Hilot.
Couldn't access Windows Defender so, I downloaded Avast 5.
The complete scan didn't come up w/anything so, I ran the Boot Scan & got this;
File C:\Users\Michael\AppData\Local\mspl32.dll is infected by Win32: Hilot
w/10 different options.

From what I've been reading it's rare but a bad one & realise it's going to take some time. :pullhair:

In the mean time, what can I do/ shouldn't do at this point?
I changed security levels to full/high.
I changed passwords from different computer, (on the same network).
I turn off the bad one now without doing any of the options as noted above & unplug from the network.

The bad one does run, the pop-up secruity warnings aren't that bad, "so&so file is infected",
(I find if I just leave the first warning up, the pop-ups stop), &
the Explorer redirects to "some page that won't open because it could harm the computer" doesn't come up too much.

Currently running a Gateway One w/ Vista 32 bit. w/service pack 1 I believe, (got it months ago).

Should I just go w/ the steps,
"Removal of Win32: rootkit & Win32: Hilot" by Angry Citizen or,
sit tight for now :popcorn:

Thanks
BTY, what files can I safely start to back up?, or more important,
what files/ locations should I stay away from ie,
can I safely start to back up My Music on CD's,
My Videos on DVD's,
My Pictures,
My Docs,
any known clean Program Files, etc.
or, can this thing multiply all over the place?

I'm just looking ahead to a possible nuke option &
where the badlands might be ie,
don't even think about trying to save anything in "such&such" place,
you're ok to save/back up these files/these places.

Thanks again,

Mike
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache

I can't open Java in the Control Panel, error msg is 'Application can't be executed. javaw.exe is infected. Do you want to open your antivirus software?'
I also downloaded Malwarebytes on a flash drive from my wife's computer, installed it on mine, but when I try to run it, it says mbam.exe is infected also :(

I also downloaded Malwarebytes on a flash drive from my wife's computer, installed it on mine, but when I try to run it, it says mbam.exe is infected also :(

Rename MBAM.exe to MBAM.com. Now try it

I also downloaded Malwarebytes on a flash drive from my wife's computer, installed it on mine, but when I try to run it, it says mbam.exe is infected also :(

Rename MBAM.exe to MBAM.com. Now try it


It says mbam.com.exe is infected… couldn't seem to change the file extension
Open Taskmanager (Ctrl/Alt/Del) and end the process for the file AV.EXE if listed. You will need to keep doing this so leave Taskmanager open until MBAM starts to scan.
Lets try this.

Download Combofix from any of the links below but rename it to ABCD.com before saving it to your desktop.

* IMPORTANT !!! Save ABCD.com to your Desktop

Link 1 <–Right Click and use Save As
Link 2<–Right Click and use Save As if using this link.



Then do this:

Go to [external image: Posted Image] -> Run -> copy/paste in the following single line command & click OK

"%userprofile%\desktop\ABCD.COM" /killall


[external image: Posted Image]
  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt

Lets try this.

Download Combofix from any of the links below but rename it to ABCD.com before saving it to your desktop.

* IMPORTANT !!! Save ABCD.com to your Desktop

Link 1 <–Right Click and use Save As
Link 2<–Right Click and use Save As if using this link.



Then do this:

Go to [external image: Posted Image] -> Run -> copy/paste in the following single line command & click OK

"%userprofile%\desktop\ABCD.COM" /killall


[external image: Posted Image]
  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt


Ok, I am the original poster's wife; he had to go out of town. This is my husbands computer running WIndows VIsta which I have rarely used, I don't see 'run' when you click start ;|… also, what is a HJT log and how do I get it?

His computer (the bad one) was on a wireless network with my computer which is not wireless. We use a Belkin Router which I disconnected because I am afraid of getting this trojan. I connected my good computer directly to my dsl modem because when I disabled the wireless connection on his bad computer (thinking I would prevent anything from accessing my good computer through the network) I got an error msg that I couldn't do it because it too was infected, although the connection says it is disabled, I am still getting intrusion alerts on his computer so I am thinking that somehow it was still connected somehow. Should I be afraid of reconnecting the Belkin and his network connection?
I don't use Vista. "win+R" brings up the RUN dialog box or the Windows Key Don't worry about the HijacKthis.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI