Author Topic: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????  (Read 4990 times)

0 Members and 1 Guest are viewing this topic.

rapslayer

  • Guest
Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« on: March 10, 2008, 11:08:08 PM »
Can I get a help for this virus Win32:OnLineGames-CUX [trj] (amvo0.dll).......At first I tried to delete it by Avast, but Avast couldn't delete it....I tried to remove manually and it was removed...but every time when I open the Windows Avast shows me that My computer contain the worm that is called Win32:OnLineGames-CUX [trj]....I again opened folder that contain the virus but i can't see it...I opened   FOLDER OPTION  to put it in (SHOW ALL SYSTEM AND HIDDEN FOLDER choice)to see if the virus was hidden, but it wasn't there.
Can really someone help me to remove this virus?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #1 on: March 11, 2008, 01:51:23 AM »
I suggest:

1. Disable System Restore and reenable it after step 3.
2. Clean your temporary files.
3. Schedule a boot time scanning with avast with archive scanning turned on.
4. Use SUPERantispyware and/or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
5. Test your machine with anti-rootkit applications. I suggest Trend Micro RootkitBuster.
6. Make a HijackThis log to post here or, better, submit the RunScanner log to to on-line analysis.
7. Immunize your system with SpywareBlaster or Windows Advanced Care.
8. Check if you have insecure applications with Secunia Software Inspector.
The best things in life are free.

rapslayer

  • Guest
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #2 on: March 11, 2008, 03:28:43 PM »
Thanks for suggest but THIS PROGRAMS(SUPERantispywarem,IObit freeware,AVAST) shows that my computer doesn't contain that worm.but in startup, I still see that AMVO is running.I disabled, I deleted from registry editor, its still appears.NOW I CAN'T TURN TO SHOW ALL ALL FILES SYSTEM OR HIDDEN FILES.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #3 on: March 11, 2008, 06:57:56 PM »
I will need to know how many usb devices and hard drives you have and the drive letters.

Please do not plug in any usb device until you have done the tweakui portion. After you have done that part, please only plug in the devices with the drive letters covered in this fix.  The OTMOVEIT2 fix will only cover drives C,D,E, F, G and H. If there are more or other letters, we will do them separatley.

Download and Install Microsoft's TweakUI: http://www.microsoft.com/windowsxp/downloads/powertoys/xppowertoys.mspx

Obtain and install TweakUI (right hand panel, 147kb in size), and then start TweakUI.

Expand the My Computer branch, then the AutoPlay branch, and then select Drives.

Turn off the checkbox next to every drive letter to disable AutoPlay -- except your CD/DVD drive letters

This will prevent autoruns from running on your computer. Make sure you uncheck all drive letters in the list, except your cd/dvd.

Then

Download "Clean Autoruns":From HERE

http://forums.techguy.org/attachments/103397d1176780296/clean-autoruns.zip

Plug in as many usb storage device you can or have. Phones, ipods etc count.

Save and extract its contents to the desktop. It is a folder containing a Batch file, Clean autoruns.bat, Written by Mosaic1. Once extracted, open the folder and double click on the Clean autoruns.bat to run the fix.
If any autoruns are found, the fix will move them to a backup folder.
If any autoruns are found on the root of your drives, it will kill explorer so that the registry entries in the MountPoint(s) key are fixed.
It will produce two files, Part1.txt and Part2.txt , that will show the state before and after the cleaning.

Please post those.



Please download
 OTMoveIt2 by OldTimer.


Save it to your desktop.

Please double-click OTMoveIt2.exe to run it. Make sure the usb drives are plugged in.


Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

C:\Autorun.inf
D:\Autorun.inf
E:\Autorun.inf
F:\Autorun.inf
G:\Autorun.inf
H:\Autorun.inf
C:\amvo*.* /s
D:\amvo*.* /s
E:\amvo*.* /s
F:\amvo*.* /s
G:\amvo*.* /s
C:\amvo*.* /s
D:\amvo.* /s
E:\amvo.* /s
F:\amvo.* /s
G:\amvo.* /s
H:\amvo.* /s

 


Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste. this fix will not work if the wrong box is used


Click the red Moveit! button.

Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

NOTE: If OTMOVEITE reboots, before you can get the ruslts they can be found here
 C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")

Now to protect those drives, I will need you to down load and run this program, with your usb devices attached.

Download this program, Flash Drive Disinfector by sUBs from

http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe


Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well. Just skip that part.
Wait until it has finished scanning and then exit the program.
Reboot your computer when done.

This utility will do a couple of things. First it will remove any autorun.inf it finds. It will create a SYSTEM protected, read-only, and perfectly harmless Autorun.inf file on any hard drive or removable storage device it finds when run. This file will not only help prevent future autorun infections, it will disable any current Autorun infection its ability to restart.

Please attach the results to your next reply. Use the additional option button on the reply page.

Thanks
 



rapslayer

  • Guest
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #4 on: March 14, 2008, 01:54:04 AM »
Oldman....Avast is not alarming for worm Win32:OnLineGames-CUX [trj] (amvo0.dll)....I think its done..I don't know.(but I still see in startup amvo is trying to run,I disable it(from msconfig))..there are the results of OTMoveIt2.exe...........
< C:\Autorun.inf >
File/Folder C:\Autorun.inf not found.
< D:\Autorun.inf >
File/Folder D:\Autorun.inf not found.
< E:\Autorun.inf >
File move failed. E:\AUTORUN.INF scheduled to be moved on reboot.
< F:\Autorun.inf >
File/Folder F:\Autorun.inf not found.
< G:\Autorun.inf >
File/Folder G:\Autorun.inf not found.
< H:\Autorun.inf >
File/Folder H:\Autorun.inf not found.
< C:\amvo*.* /s >
File move failed. C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\Documents and Settings\Administrator\Recent\amvo0.dll.lnk scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo0.dll
C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo0.dll NOT unregistered.
File move failed. C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo0.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo1.dll
C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo1.dll NOT unregistered.
File move failed. C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo1.dll scheduled to be moved on reboot.
< D:\amvo*.* /s >
File/Folder D:\amvo*.* not found.
< E:\amvo*.* /s >
File/Folder E:\amvo*.* not found.
< F:\amvo*.* /s >
File/Folder F:\amvo*.* not found.
< G:\amvo*.* /s >
File/Folder G:\amvo*.* not found.
< C:\amvo*.* /s >
File move failed. C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\Documents and Settings\Administrator\Recent\amvo0.dll.lnk scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo0.dll
C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo0.dll NOT unregistered.
File move failed. C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo0.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo1.dll
C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo1.dll NOT unregistered.
File move failed. C:\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013500\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013252\_OTMoveIt\MovedFiles\03142008_013004\WINDOWS\system32\amvo1.dll scheduled to be moved on reboot.
< D:\amvo.* /s >
File/Folder D:\amvo.* not found.
< E:\amvo.* /s >
File/Folder E:\amvo.* not found.
< F:\amvo.* /s >
File/Folder F:\amvo.* not found.
< G:\amvo.* /s >
File/Folder G:\amvo.* not found.
< H:\amvo.* /s >
File/Folder H:\amvo.* not found.
 
OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03142008_013843
thanks for trying to help
if it is possible please give a comment about my results

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #5 on: March 14, 2008, 05:13:52 AM »
In order to give you a really good answer, I would have to know the answers to the questions I asked before.

how many usb devices and hard drives you have and the drive letters.


Did you do all the steps in the order posted?

I would also have to see the results of the Clean Autoruns scan. These autoruns are usually acompanied by others.

The amvo you stopped in msconfig, what was it's full name? amvo.dll, amvo.exe ??

Post this info and we'll take it from there.  :)


rapslayer

  • Guest
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #6 on: March 14, 2008, 05:26:45 PM »
1 Usb device (G:),2 hard drives (C:),(D:),2 Dvd drives(F:),(E:)

I Did all the steps in the order posted.

there was no full name of it(you can see it in Unitled-1.JPG), it is written as amvo in msconfig(startup)....but i think it could have a relation with the worm that avast detected (amvo0.dll)...

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #7 on: March 14, 2008, 08:01:22 PM »
Thank you. It looks like we got most of it. Your C and D drives are now protected by Flashdrive disinfecter. Your G drive is not. There is also evidence of of an H drive.

If you expand the middle column (siide it sideways at the top) on the startup screen you posted, it may show us the file name.

I need you to plug in your usb device and run Flashdrive disinfecter. After it has finsihed, check the G:\ drive for an autorun.inf folder. FDD should have placed one there, the file in the floder should have this content.

lpt3.This folder was created by Flash_Disinfector

That is a good one.

It's your G drive that has most of the remaining infection. Leave your usb drive plugged in for the remainder of the fix.

We'll use OTMOVEIT2 again. Remember, the fix goes in the bottom box.

Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

C:\oufddh.exe /s
D:\oufddh.exe /s
G:\oufddh.exe /s
H:\oufddh.exe /s
C:\AdobeR.exe /s
D:\AdobeR.exe /s
G:\AdobeR.exe /s
H:\AdobeR.exe /s
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{48acd14c-c36f-11dc-af45-5050506f4531}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{82117fad-a689-11dc-aeb9-0011d8b8eb36}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e427d4c-a8fb-11dc-aecb-5050506f4531}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cf2fd6f5-e19d-11dc-afac-5050506f4531
 


Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.


Click the red Moveit! button.

Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

NOTE: If OTMOVEITE reboots, before you can get the ruslts they can be found here
 C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")

Then download and run the next program, It should show us if anything is left.

Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • When it has finished, dss will open two Notepads main.txt and extra.txt  -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt.

    Please post the OTMOVEIT2 results and the DSS main log.

    Thanks.

     

rapslayer

  • Guest
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #8 on: March 14, 2008, 08:29:43 PM »
There are the logs of dss.exe and OTmoveIt2.exe....But you didn't explain me how to remove that amvo from msconfig(startup)....

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #9 on: March 14, 2008, 08:46:42 PM »
After you have done this please post back and we'll clean up the tools. Let me know if everything is OK.

This looks good. We will take care of that regkey this time.

WARNING these fixes are designed for this user only and may cause damage if run on an uninfected machine


REGISTRY FIX
Quote
REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amva]

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf2fd6f5-e19d-11dc-afac-5050506f4531}]

Next you will need to create the repair registry fix to do that copy and paste ALL of the above in the quote box to a notepad file.  Ensure there is no space above the REGEDIT4.

Then in notepad go to FILE > SAVE AS and in the dropdown box Set the box at the top Save In to Desktop.
 
Then in the FILE NAME box type (including the " " marks) "fix.reg"

This will create a fix.reg file on your desktop

To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done.


rapslayer

  • Guest
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #10 on: March 15, 2008, 12:11:40 PM »
Oldman thank you very much....I ve done all the steps....I think the worm is completly removed from my PC.

                                                                                                               Best regard
                                                                                                                 Rapsleyer

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Win32:OnLineGames-CUX [trj] (amvo0.dll) need help?????
« Reply #11 on: March 15, 2008, 03:53:07 PM »
You're welcome. Now you can clean up the tools you used.

Open OTMOVEIT2 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet -  allow this.  A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself.

* Create a new restore point

You must be logged on to an administrator account
Go to Start - All Programs - Accessories - System Tools - System Restore.
Click Create a restore point, and then click Next.
In the text box labeled Restore Point Description, type a name for this restore point , click create

* Remove old restore points

- Go to Start - All Programs - Accessories - system tools. Launch the Disk Cleanup tool and let it run. When it finishes a box with tabs will appear, select the more options tab. On this tab you will find a section for System Restore. If you press the Clean Up button for that section, Windows will delete all restore points except for the most recent one.

* If you are using windows firewall, please note that it doesn't provide outbound protection. A third party firewall will.

A discussion on free firewalls can be found here.

http://forum.avast.com/index.php?topic=30808.0

or

http://forum.avast.com/index.php?topic=33530.0


* Check if you have insecure applications with Secunia Software Inspector