Cimag trojan infection?

#1 Chrispythegull


Posted 01 December 2010 - 04:11 PM

Hi there,

I am currently using Firefox as my main browser on a relatively new machine with Windows 7. About a week ago I noticed that I was suddenly being redirected from any yahoo search result I was trying to click on. My browser would unexpectedly open a new tab and send me to a free walmart giftcard page with an annoying popup in the middle which asked me if I wanted a free giftcard...

In searching around the internet in the past few days I have installed and uninstalled many different free antiviruses, and sure enough several of the programs identified a recent VAIO Download (This is the type of computer I have) as being a malicious download. Incidentally there is a very small window which always pops up from VAIO when I start up the machine which shows a little status bar as if it were downloading. The window is very small and is only big enough to show a very small bar, which doesn't seem to change in terms of progress. When I had attempted to scan my computer with the various software, It also repeteadly senses an infection from a "Cimag.trojan" which it is unable to either 'clean' or 'delete'. The program redirects me in Firefox in safemode as well.

Most troubling, I have received several bluescreen crashes that I had never experienced before, sometimes immediatey on startup. When the syste is able to load properly, I get a notice saying that C:users\Chrispythegull\Appdata\local\kmcstat.dl is not able to load, as "The specified module can not be found". The initial problem that began ALL of this was when I came back to my computer from being AFK only to find that I could no longer click on any programs and my left clicke on my trackerpad was working improperly!

I have no idea what to do! I would very much appreciate any assistance.

#2 boopme


Posted 01 December 2010 - 11:24 PM

Hello and welcome.. the Cimag is a Trojan.Downloader. It is a Trojan that runs in the background, falsely alerting the user that the computer is infected with spyware. This trojan will then advise the user to download an affiliated rogue Anti-Spyware product. Other acivities that this Trojan will carry out include downloading and installing other malicious files.

I think we can get it with these steps and resolve the other issues.
Next run MBAM (MalwareBytes):

Please download Malwarebytes Anti-Malware and save it to your desktop.
Download Link 1
Download Link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

Troubleshoot Malwarebytes' Anti-Malware

Please perform a scan with Eset Online Antiivirus Scanner.
This scan requires Internet Explorer to work. Vista/Windows 7 users need to run Internet Explorer as Administrator.
To do this, right-click on the IE icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run As Administrator from the context menu.
  • Click the green Posted Image button.
  • Read the End User License Agreement and check the box:
  • Check Posted Image.
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Check Remove found threats and Scan potentially unwanted applications. (If given the option, choose "Quarantine" instead of delete.)
  • Click the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer.
  • If offered the option to get information or buy software at any point, just close the window.
  • The scan will take a while so be patient and do NOT use the computer while the scan is running. Keep all other programs and windows closed.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop as ESETScan.txt.
  • Push the Posted Image button, then Finish.
  • Copy and paste the contents of ESETScan.txt in your next reply.
Note: A log.txt file will also be created and automatically saved in the C:\Program Files\EsetOnlineScanner\ folder.
If you did not save the ESETScan log, click Posted Image > Run..., then type or copy and paste everything in the code box below into the Open dialogue box:

C:\Program Files\ESET\EsetOnlineScanner\log.txt
  • Click Ok and the scan results will open in Notepad.
  • Copy and paste the contents of log.txt in your next reply.
-- Some online scanners will detect existing anti-virus software and refuse to cooperate. You may have to disable the real-time protection components of your existing anti-virus and try running the scan again. If you do this, remember to turn them back on after you are finished.

NOTE: In some instances if no malware is found there will be no log produced.


I get a notice saying that C:users\Chrispythegull\Appdata\local\kmcstat.dl is not able to load,

Its not unusual to receive such an error after using specialized fix tools.

A "Cannot find...", "Could not run...", "Error loading... or "specific module could not be found" message is usually related to malware that was set to run at startup but has been deleted. Windows is trying to load this file but cannot locate it since the file was mostly likely removed during an anti-virus or anti-malware scan. However, an associated orphaned registry entry remains and is telling Windows to load the file when you boot up. Since the file no longer exists, Windows will display an error message. You need to remove this registry entry so Windows stops searching for the file when it loads.

To resolve this, download Autoruns, search for the related entry and then delete it.

Create a new folder on your hard drive called AutoRuns (C:\AutoRuns) and extract (unzip) the file there. (click here if you're not sure how to do this.)
Open the folder and double-click on autoruns.exe to launch it.
Please be patient as it scans and populates the entries.
When done scanning, it will say Ready at the bottom.
Scroll through the list and look for a startup entry related to the file(s) in the error message. {{ kmcstat.dl}}
Right-click on the entry and choose delete.
Reboot your computer and see if the startup error returns.
#3 Chrispythegull

Posted 02 December 2010 - 09:06 PM

Hi there and thank you so much for your response. I've just run malwarebytes and it found six items, all of which were deleted or quarantined successfully. I will be restarting my system now. And will be right back. Meanwhile, here are the results of the log.

Malwarebytes' Anti-Malware 1.50

Database version: 5235

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

12/2/2010 6:03:26 PM
mbam-log-2010-12-02 (18-03-26).txt

Scan type: Quick scan
Objects scanned: 176581
Time elapsed: 3 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\Users\chrispythegull\AppData\Local\ulovasam.dll (Trojan.Agent.U) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RkHit (Rogue.SpywareCease) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mfalokaxuwe (Trojan.Agent.U) -> Value: Mfalokaxuwe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Mtumiciqu (Trojan.Agent.U) -> Value: Mtumiciqu -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\program files (x86)\instant spyware remover (Rogue.InstantSpywareRemover) -> Quarantined and deleted successfully.

Files Infected:
c:\Users\chrispythegull\AppData\Local\ulovasam.dll (Trojan.Agent.U) -> Quarantined and deleted successfully.

#4 Chrispythegull

Posted 02 December 2010 - 09:13 PM

A follow up: I noticed on logging into windows I got another immediate pop up from "Rundll" saying "There was a problem starting C:\\users\Chrispythegull\appdata\local\ulovasam.dll. I still noticed significant slowness and when I brought back up Firefox and searched Yahoo, I was redirected to a bogus spam site when I clicked a link. My tracker pad issues with left click still persist as well.

#5 boopme


Posted 02 December 2010 - 09:28 PM

Hello, we need to run another tool to get the rootkit.
Also this is another orphan to be dealt with by Autoruns.

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
Be sure to download TDSSKiller.exe (v2.4.0.0) from Kaspersky's website and not TDSSKiller.zip which appears to be an older version of the tool.
  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller. will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

Clear your Temp files.
Please download TFC by Old Timer and save it to your desktop.
alternate download link

Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista, right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

Rerun MBAM (MalwareBytes) like this:

Open MBAM in normal mode and click Update tab, select Check for Updates,when done
click Scanner tab,select Quick scan and scan (normal mode).
After scan click Remove Selected, Post new scan log and Reboot into normal mode.

Please ask any needed questions,post logs and Let us know how the PC is running now.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 Chrispythegull

Posted 02 December 2010 - 10:18 PM

Here is the text from the ESET online scan:

C:\Users\Chrispythegull\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\11d5729c-3a01dce9 multiple threats deleted - quarantined
C:\Users\Chrispythegull\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3\185da1c3-4f9b826b multiple threats deleted - quarantined

#7 Chrispythegull

Posted 02 December 2010 - 10:43 PM

Even though I was not able to find the startup services in Autorun, when I was forced to reboot after rootkiller found the rootkit and deleted it, I got no further messages about applications being unable to start! Additionally, when I brought up Firefox, I no longer had a strange google homepage that I never set as my default and I was no longer redirected when I clicked on yahoo search results!!

Here are the results from the Rootkiller scan:

#8 boopme


    To Insanity and Beyond

  • Global Moderator
  • 72,740 posts
  • Gender:Male
  • Location:NJ USA
  • Local time:02:04 PM

Posted 02 December 2010 - 10:48 PM

OK, this look s like we got it. I think we just needed that reboot to un muddle things.

I think you are good to go. :thumbup2:
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 Chrispythegull

Posted 02 December 2010 - 10:52 PM

Finally, here are the results of the final Malwarebytes Anti-malware scan: Before I post it, can I ask where I might have downloaded these issues that created such problems for me? Also, what programs do you recommend I purchase or download for free to ensure that this type of thing NEVER happens again? I want to sincerely thank you for your help and assistance with this! You're a lifesaver!

Malwarebytes' Anti-Malware 1.50

Database version: 5235

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

12/2/2010 7:50:44 PM
mbam-log-2010-12-02 (19-50-44).txt

Scan type: Quick scan
Objects scanned: 173211
Time elapsed: 2 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#10 boopme


Posted 02 December 2010 - 11:22 PM

Hello, it is truly hard to say exactly where /how you got yours. Maybe an Email attachment,online download clicking an Ad link on a page. But reading the following info should help you to understand it and prevent it.

Tips to protect yourself against malware and reduce the potential for re-infection:Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Keeping Autorun enabled on USB and other removable drives has become a significant security risk due to the increasing number of malware variants that can infect them and transfer the infection to your computer. To learn more about this risk, please read:

Make sure that the Windows Firewall is enabled.

Make sure that all important/critical updates, including service packs for the operating system and programs are installed from Microsoft Update (Windows Update).

Make sure Internet Explorer is at version 8 and updated with all patches.

In Internet Explorer 8, use the SmartScreen Filter.

Make sure that IE Internet Security settings are at least set to medium-high (default).

Enable the pop-up blocker in IE.

On Vista and Windows 7 make sure that User Account Control (UAC) ON and not running with elevated privileges.

Make sure that Windows Automatic Updates are set to at least notify, but the preferred setting is to download and install automatically. If you update manually, be sure to update as soon as possible after being notified of available updates.

Make sure that installed applications, especially Adobe Acrobat, Adobe Flash, and Java are at their latest versions. Many vendors are regularly updating and patching for security holes.

Never click through links from unknown sources and use caution even if they are from a "trusted" source.

Never open unsolicited email attachments.

Practice safe web browsing.

You are very welcome!!
Oh do you use a Flashdrive??
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

