Help! Can't remove W32.Allim worm virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by RichLiv, May 25, 2007.

  1. RichLiv

    RichLiv Private E-2

    PC randomly tries to send numerous random emails (real or fake) that Symantec Anti-Virus is stopping saying has a virus so they appear not to send. Have run SAV many times. Claims have W32.Allim worm that comes through AIM. Each start up Quick-Scan w/ SAV says W32.Allim; Terminate Process Required. Count 7. File name: aolsvc.exe or aolupd.exe are listed. I click the remove risks now. Always says it cleaned, but Count says only 2 or 4. I have also followed SAV's full on line steps for removal. When I get to the Regedit part, I find no files to remove at all in the registry with the file names infected.

    So, the last 1-1/2 days, I ran all the Major Geeks: READ & RUN ME FIRST: Malware Removal Instructions. This has not removed the problem and I have not tried the Alternate Removal programs yet. Three logs are attached, then I will do another post with additional logs.

    I also saw numerous Major Geeks prior threads for W32.Allim, but they are not current and the solutions are different each time. I would like to see recommended current solutions.

    Thanks so much in advance for your help
     

    Attached Files:

    Last edited: May 25, 2007
  2. RichLiv

    RichLiv Private E-2

    Here are the additional log/tex files for my post just sent:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Do you user AOL's software to connect to the internet or do you just use AIM?

    Start by uninstall CounterSpy and AVG AntiSpyware since you already have Windows Defender and SuperAntiSpyware running. Too many antispyware blocking tools can be just as bad as too many antivirus programs.

    First uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 9


    Now let's remove some malware services.
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to AOL Update Manager
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above to Stop and Disable the below two Services (if you do not find them or get any errors, just continue):
      • AOL Client Service
      • Print Spooler Service
    • Click OK until you get back to Windows.
    • Next, run HJT, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/paste AOL-Hosts into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now repeat the above to delete the below two Services (if you do not find them or get any errors, just continue):
      • LOAD-AOL_Serv
      • auhtuquwenlu
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.
    Continue by downloading a tools we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\Help\aolupd.exe
    C:\WINDOWS\System32\Catroot\aolsvc.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O4 - HKLM\..\Run: [c] C:\WINDOWS\system32\c.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [xrikbgoa] C:\WINDOWS\system32\xrikbgoa.exe
    O4 - HKLM\..\Run: [dncvopnv] C:\WINDOWS\system32\dncvopnv.exe

    After clicking Fix, exit HJT.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\c.exe
    C:\WINDOWS\system32\xrikbgoa.exe
    C:\WINDOWS\system32\dncvopnv.exe
    C:\WINDOWS\Help\aolupd.exe
    C:\WINDOWS\system32\tklohjl.exe
    C:\WINDOWS\System32\Catroot\aolsvc.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.
    Now after reboot, please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Also please run this procedure: Getting Uninstall Programs List From The Registry and attach the requested log!

    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  4. RichLiv

    RichLiv Private E-2

    Thank you "CHASLANG" & "TIM W" for your plans of attack. It seems to have worked based upon preliminary use after completing you. Per your closing directions, I have attached the GetRunKey, ShowNew and HJT logs.

    A few comments and responses to your questions and instructions:
    I use Firefox for internet connection, but my wife still is most comfortable using AOL. I did find we had 3 different AOL versions installed though and uninstalled all of them. So right now, we are running without any AOL browsers on the system.

    CounterSpy and AVG AntiSpyware were installed when I did the Major Geeks READ ME & REMOVE FIRST instructions. I can't not find how to uninstall CounterSpy. There is not uninstall program and it does not show up in my Control Panel>Install/Uninstall Programs sections. So it is still resident and starting up automatically at Re-Boot. Need suggestions on its uninstall.

    I took a break when done with the services.msg section. At that time, I ran Spybot and it said I had the Trojan;Print Spool in files DC8.exe, and three[1].exe. This was new stuff, but perhaps always there and revealed by the other prior removals.

    When running HJT, did not find auhtuquwenlu on the list. Also did not find, the c.exe, realsched.exe and dncvopnv.exe files. Must have have already been removed.

    When running Pocket Killbox, entering the file list by Copy/Paste did not work. I had to enter each one with a semi-colon ";" separator between them to get it to work.

    I did received the PendingFileRenameOperations message, and did a manual reboot.

    At the end of the process, I saw the GetRunKey and ShowNew logs were still the original ones, so I presumed I needed to re-run these programs to get new logs even though you did not instruct me to do so.

    Will do the Uninstall List from Registry and attach in next submission.

    Thanks again for all your help.
     

    Attached Files:

  5. RichLiv

    RichLiv Private E-2

    I have attached the log from GetUnKeys. I had difficulty trying to get the XPProFix to unzip and run. Not sure what is going on here. Let's see where we stand.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to attach the new HJT log. Please attach one.

    Are you sure it is not in Add/Remove programs? Look for Sunbelt CounterSpy! I see it listed in both your newfiles.txt and getunkey.txt logs which means it should be there. Check again! If you cannot find it, reinstall it and then reboot. After reboot, then look for it in Add/Remove programs and uninstall it.

    You should always follow the directions we give to you in the order given and do not do anything else except what we request.

    That will not work and nothing was removed by Killbox as seen in the newfiles.txt log.

    The directions said:
    which means you must get new logs! ;)
     
  7. RichLiv

    RichLiv Private E-2

    II guess I never learned the alphabet past the letter "R", but I looked to "S" anyway and found the word Sunbelt followed by Counterspy and fully removed itl.

    Whenever I try to attach the HighJackThis log, on the upload says already attached to this thread. I checked the log that I have. The .log is dated 5/24 which seems to be the original log, not a new one from having run the program again. Don't know why no knew one. Suggestions? Can't find another log to send you with Search.

    Since you said I did not run Killbox properly, out of futility trying to copy/paste file names that did not work ...
    Do you want me to re-run either HJT or Killbox or both.

    Just curious, unrelated question -- I have microsoft .net frameworks in my uninstall list for 1.1 and 2.0. Can 1.1 be deleted or is it supplemental.?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have to save a new log or you don't get one! One of the options when you start HJT is Do a system scan and save a logfile That is what you should be doing in order to get a new log.

    I don't need you to run Killbox again. Based on your ShowNew log it seems that HJT removed the files anyway. But I do need to see a new HJT log.

    I'm not sure whether both are required or not. You would be better off asking this question in the Software Forum. Personally I would think only the 2.0 version should be required, but then it would seem a little strange for Microsoft to not have uninstalled 1.1 before updating to 2.0.
     
  9. RichLiv

    RichLiv Private E-2

    Thanks for Round 3! I just did a HJT scan, so here it is on the attachment.

    RL
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  11. RichLiv

    RichLiv Private E-2

    THANK YOU SO MUCH!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

    :D

    :major
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds