Solved

Removal of ali.exe, wierd startup freeze, Windows error sound just before shutdown

Posted on 2006-07-22
13
7,233 Views
Last Modified: 2010-08-05
Hey everyone,

I have 3 problems I was hoping you could help me with.

1) There is a file ali.exe that is supposed to be some kind of installation file for a trojan on my computer and I cannot get rid of it and it is causing me all sorts of problems. When I start up the computer I get a little windows box on the top left corner saying "Windows is initializing the following: "C:Windows\System32\ali.exe" " and then it would disappear. I tried deleting this file on its own but it would re-produce itself again and again. Also when I'm shutting down or restarting, I always get an error saying "ali.exe could not initalize because the windows station is shutting down" and that windows error window reproduces itself everytime it gets closed until windows forces the process to end.

Any help in the removal of this would be appreciated. If you want HiJackThis log files I can post as well.


2) Next problem is (literally) every other time I startup my computer, I freeze on the Welcome screen of Windows XP and no process on my computer continues to work.


3) And finally, I think this might be connected to the ali.exe problem but after finally closing all the processes, but just before going into the Windows Logging off/saving user settings screen, I hear the standard Windows Error Message ding and this is really starting ot get annoying.

So Anyways, all in all, I don't want to have to restore or re-install Windows XP as this is a new computer (Laptop actually) so any solutions you can provide will be greatly appreciated! Thanks in advance!
0
Comment
Question by:TheFuteballer
  • 6
  • 6
13 Comments
 
LVL 32

Expert Comment

by:r-k
ID: 17160435
Here is what I suggest:

(0) If running XP Home, boot in safe mode, if XP Pro, then start with step (1)

(1) Right click on the file (ali.exe) in Windows Explorer or My Computer, select Properties

(2) Click on the Security tab.

(3) Click on the Advanced button.

(4) Uncheck the box labeled "Inherit from Parent...", then click "Remove"

(5) Close all windows.

(6) Reboot (into normal mode)

After reboot the file will be unable to run (because no one can access it any more). The symptoms should be gone.

At this point you can clean up with a standard anti-spyware program. A good choice is to run the online scan from http://safety.live.com/site/en-us/default.htm
Another good choice is to install the trial version of Ewido and run that (http://www.ewido.net/)

In any case, I would also suggest the following:

Download and run HijackThis from http://www.hijackthis.de/
Copy-and-paste the resulting log back to that same web site (not here)
Click on "Analyze", and then click on "Save Analysis" at the bottom of the next page.
Finally post a link here to the saved analyzed page.

0
 
LVL 2

Expert Comment

by:stevendawson
ID: 17160445
Hi,

Obvious questions to begin with.

What Antivirus software do you have installed?

Have you made sure the virus definitions are up to date and run a FULL scan? (all files hidden & system as well)

Download this program - SpyBot - http://www.safer-networking.org/en/download/index.html and let it do a full scan. It will make certain reccomendations that its usually correct about however you should always make sure you have a backup before doing something like this.

and I would recommend you Download and install the Microsoft Anti Spyware program as well http://www.microsoft.com/athome/security/spyware/software/default.mspx

Let me know how you get on,

Steve

0
 
LVL 1

Author Comment

by:TheFuteballer
ID: 17160453
Here is the HiJackThis log

http://www.hijackthis.de/logfiles/fce37b000773e8a4b0ec7aae5763f17e.html



r-k I do not have a security tab when I go into the properties of ali.exe
0
 
LVL 1

Author Comment

by:TheFuteballer
ID: 17160454
I have McAfee Virus scan and yes it is fully updated.

I will download both of them and let you know how it goes
0
 
LVL 32

Expert Comment

by:r-k
ID: 17160458
" I do not have a security tab when I go into the properties of ali.exe"

(1) If you have XP Pro then start Windows Explorer:
     Tools -> Folder Options -> View
     and "un-check" the box that says "Use Simple File and Printer Sharing..."

(2) If you have XP Home, then just boot in safe mode and the Security tab will appear.
0
 
LVL 32

Accepted Solution

by:
r-k earned 500 total points
ID: 17160486
After you have disabled ali.exe as suggested in my first post, do the following:

Run HJT again, and have it fix the following entries:

O4 - HKLM\..\RunOnce: [*Bandook] C:\WINDOWS\system32\ali.exe
O4 - HKCU\..\Run: [Bandook] C:\WINDOWS\system32\ali.exe
O20 - Winlogon Notify: IfxWlxEN - C:\WINDOWS\SYSTEM32\IfxWlxEN.dll

Also locate the file C:\WINDOWS\ABLKSR\ABLKSR.exe and right-click on it, select Properties -> Version and see who created it. If the version tab is missing then have HJT clean the following entry also:

O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe

Then reboot and run HJT again and make sure the above four entries are really gone.

All symptoms should be gone if that is the case.
0
Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

 
LVL 1

Author Comment

by:TheFuteballer
ID: 17160506
I have unchecked "Use Simple File Sharing" yet I still do not have a security tab.. I've closed all explorer windows and started again.. by the way I have windows XP Pro
0
 
LVL 32

Expert Comment

by:r-k
ID: 17160526
Very odd - try booting in safe mode and see if the Security tab appears then.

Remember, you have to right-click on the file (in Windows Explorer or "My Computer") then select "Properties", then look for the Security tab.
0
 
LVL 1

Author Comment

by:TheFuteballer
ID: 17160556
Just tried it in safe mode and no security tab either
0
 
LVL 32

Expert Comment

by:r-k
ID: 17160628
Very odd. Is the Security Tab missing for all files, or just for ali.exe?

In any case, you can download Killbox from:

 http://www.downloads.subratam.org/KillBox.zip

and use that to delete ali.exe and ABLKSR.exe on reboot.
I am assuming you did not find a version tab for ABLKSR.exe.
0
 
LVL 1

Author Comment

by:TheFuteballer
ID: 17160636
Security Tab is missing for all files

ABLKSR.exe is a file that is part of my laptop.. from ASUS

I am deleting with killbox right now
0
 
LVL 1

Author Comment

by:TheFuteballer
ID: 17160722
Great. this worked perfectly! Thanks alot, this has seemed to fix problems 1 and 3 so far. Number 2 is still up for grabs though


It seems that this only happens when I have my external hard drive connect by USB port
0
 
LVL 32

Expert Comment

by:r-k
ID: 17160946
That's great. I was gone for a while and glad things are better.

It might pay to run HJT and make sure the entries:

 O4 - HKLM\..\RunOnce: [*Bandook] C:\WINDOWS\system32\ali.exe
 O4 - HKCU\..\Run: [Bandook] C:\WINDOWS\system32\ali.exe
 O20 - Winlogon Notify: IfxWlxEN - C:\WINDOWS\SYSTEM32\IfxWlxEN.dll

are really gone. If not then have HJT remove them.

Re. the USB port causing a possible hang, you can try the following:

 (1) Leave external disk disconnected for a while and see if problem goes away.
 (2) If it does, then try a different USB port and/or USB cable.
 (3) If no luck with that, then go into Device manager, right-click on each of the USB hub entries, select uninstall, then reboot and let XP reinstall the USB drivers automatically. (Do all this with the USB drive disconnected).

Hope one of these will improve things. Also if you have any AV program try disabling that a while and see if that helps with the USB/hang problem.

0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Can I legally transfer my OEM version of Windows to another PC?  (AKA - Can I put a new systemboard in my OEM PC?) Few of us are both IT and legal experts but we all have our own views of Microsoft's licensing rules and how they apply.  There are…
Migration of Exchange mailbox can be done with the ExProfre.exe tool. But at times, when the ExProfre.exe tool migrates the Exchange Server user profile, it results in numerous synchronization problems. Synchronization error messages appear in the e…
It is a freely distributed piece of software for such tasks as photo retouching, image composition and image authoring. It works on many operating systems, in many languages.
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now