Requesting help with ali.exe trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Angelus21, Oct 9, 2008.

  1. Angelus21

    Angelus21 Private E-2

    Hello there,

    Yesterday my brother wanted to check an email he had on my Windows based computer since he runs a Mac and sometimes can't view certain files. Well the email ended up being a trojan called ali.exe that has infected my computer and Norton was catching to quarentine.

    I came across this site in my searches to rid myself of this thing. I went through the RUN & READ ME FIRST thread up until the System Restore point.

    It would seem as if the problem has been eliminated as I don't have any of the programs popping up warnings that the file is running. I also checked in the file location that the .exe file is located in and it's no longer there. I however would like to be sure that my computer is rid of this trojan and as clean as possible.

    Attached are my logs from the software listed in the RUN & READ ME FIRST thread.

    I appreciate all help that is given as I know you guys are busy. Thanks a bunch.
     

    Attached Files:

  2. Angelus21

    Angelus21 Private E-2

    Attached to this post is the MGTools logs that you'll need as well.
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Welcome to MajorGeeks, Angelus21

    Please be patient as I am reviewing your logs.

    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Angelus21

    **PRINT OUT THESE INSTRUCTIONS NOW OR SAVE THIS SET OF INSTRUCTIONS BEFORE CONTINUING. Save your work and close all opened programs, exit all browser sessions!!**
    Please physically dis-connect from the internet, disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 1:
    Please download The Avenger by Swandog46 to your Desktop

    Step 2:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 4:
    Right click on the Avenger.zip folder and select "Extract All..."
    * Follow the prompts and extract the avenger folder to your desktop
    * Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
    Code:
    Files to delete:
    C:\WINDOWS\{00000~1.cdf
    C:\WINDOWS\{00000~1.bak
    C:\Documents and Settings\Ian McFadden\Local Settings\temp\cf10767.exe
    
    Folders to delete:
    C:\Program Files\Viewpoint
    C:\Documents and Settings\All Users\Application Data\Viewpoint 
    Now, open the avenger folder and start The Avenger program by clicking on its icon.
    • Right click on the window under Input script here:, and select Paste.
    • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
    • Click on Execute
    • Answer "Yes" twice when prompted.
    4.The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

    Step 5:
    Run Ccleaner, then re-boot into normal mode


    Step 6:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\avenger.txt

    Make sure you tell me how things are working now!
     
    Last edited by a moderator: Oct 11, 2008
  5. Angelus21

    Angelus21 Private E-2

    hello there and thanks for the quick reply. I would like to get a little clarification from your post so I don't end up FUBAR'ing anything.

    In Step 2 you say to go into my Add/Remove Programs section and remove the following. However you have not listed any programs. Was this a mistake or did it slip you mind in the madness that is read all of those logs. I know brain farts happen to me all the time.

    For Step 3 of running the HJT tool, you mention to "select the following lines" to fix, however again there's nothing listed to select. Did you perhaps forget to list these as well?

    Other than those two questions, it sounds like I'll be able to follow along pretty easily. I just wanted to be sure of what I'm doing is all.

    One last question I would like to ask, is will I need to enter Safe Mode at any point of this process?

    Thanks for the help and understanding as I greatly appreciate it.
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :eek:

    Gremlins!

    Hello, Angelus21... trying again!

    Please do this fix while in normal mode

    Step 2:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Then follow the rest of the steps, please.
     
    Last edited: Oct 11, 2008
  7. Angelus21

    Angelus21 Private E-2

    Hello again and thanks once again for the quick reply. I've followed the steps as you asked. The computer seems to be running much smoother now. Attached are the two scan logs that you've requested. Here's hoping everything checks out well.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're welcome, Angelus -

    Sofar... it looks good, the entries and files/folders were deleted. Going over your logs closely.

    dr.m
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello again, Angelus

    ^ 5 .... your logs are clean!


    Safe surfing! :cool
     
  10. Angelus21

    Angelus21 Private E-2

    Sounds great my good man. Thanks for taking the time to help me with my problem. I'll finish up the cleaning process in the Read Me thread and breathe a small sigh of relief. Again thanks for all the help.
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're very welcome, Angelus!

    dr.m :wave
    PS: Take a long tour of the site... lots of very good info & helpful members
     
    Last edited: Oct 12, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds