W32.Allim Virus- Please help remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by nv178177, May 10, 2005.

  1. nv178177

    nv178177 Private E-2

    I received this virus through aim. I got a message from someone on my buddy list, but it wasn't really them. The message said "Hey check out this." I clicked on the link and it downloaded an exe file. I ran it and nothing happened. Now my virus scan shows that I have this virus, and msiexec.exe is infected. I've updated my virus protection software and tried to clean it, but it failed.

    Please help if you can.

    Thank you
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fix.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the fix.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge, click YES!


    NEXT:
    Download Pocket KillBox

    Now, Copy and Paste C:\WINDOWS\System32\winimsg.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES.

    Reboot into Safe Mode w/ Networking

    After you have booted into Safe Mode, run these online scans posting your results as what was found and if it was removed.

    TrendMicro Online Scan
    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan

    After you complete these scans, remove all found infections!

    Reboot into Normal Mode and attach a current HJT log.
     
  3. nv178177

    nv178177 Private E-2

    Thank you for your response and help.

    I have done what you told me to do. The scans did not show up with anything. I do, however, get an error when I startup that says that it can't find the file: msiexec.exe.

    I have attached the HJT log.

    Thank you again for your help.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    F2 - REG:system.ini: Shell=Explorer.exe C:\Windows\msiexec.exe

    O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Do a search for the file ltmsg.exe and delete when found! If you cant delete this in normal mode, reboot into Safe Mode and delete it.

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    After doing ALL of the above, reboot scan with HJT and attach a fresh HJT log. Also, let me know what problems if any remain.
     
  5. nv178177

    nv178177 Private E-2

    Here is the new HJT log. The computer seems to be running fine so far. I'll keep you updated on its progress if something weird happens.

    Thank you so much for your help.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Program and uninstall the following:

    Viewpoint

    Now, navigate to and delete the following folder if it still remains:

    C:\Program Files\Viewpoint

    After doing the above, your log will be clean. Are you having any further problems?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds