Spyware / Malware / Virus Removal
TMP file virus
6 min read
Kristin
Topic Starter
Hello,
I honestly have never had to post for help on anything before. I can usually get a virus out pretty good, but this thing is awful!
I just was downloading a file from Limewire last night (dumb me), and all of a sudden my computer went nuts! My anti virus kicked in and I traced it back to the file. I did delete all my temporary internet files (thats where it went) and the file the virus went in can not be removed. It is now creating TMP files on my desktop, and they can't be deleted. It keeps trying to hide itself as well.
Also when I of course tried to come on for any help, my web page will not go to the page I am requesting! It goes to some spam page, so of course I shut down my computer and turned off the wireless router in the hosue LOL.
Is this thing going to eat my hard drive??? How do I possibly get it out when I cant even go on a webpage from that computer???
PLEASE anyone that can help me, I will be forever grateful!
Thanks!!!! 
LDTate
Download the tools needed to a flash drive or other removable media, and run them from the USB device.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
I suggest you do this:
Next:
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Next:
Please download Malwarebytes' Anti-Malware to your USB device.
- Double-click mbam-setup.exe and follow the prompts to install the program.
- At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform quick scan, then click Scan.
[external image: Posted Image] - When the scan is complete, click OK, then Show Results to view the results.
- [external image: Posted Image]
- Then click Remove Selected .
- When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
- Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also please describe how your computer behaves at the moment.
Please don't attach the scans / logs, use "copy/paste". .
Kristin
Thank you, I will do today when I get home from work and post results tonight.
With all this, would I just be better reformatting? I'm really good at reformatting LOL
Kristin
Thank you, I will do today when I get home from work and post results tonight.
With all this, would I just be better reformatting? I'm really good at reformatting LOL
Also, will this work for XP as well?
LDTate
Yes it will work for XP.Thank you, I will do today when I get home from work and post results tonight.
With all this, would I just be better reformatting? I'm really good at reformatting LOL
Also, will this work for XP as well?
If you have all your important data backed up and your OS CD, a reformat might be the best choice.
Kristin
Thank you so much! My computer seems to be running better right now. I can actually go to a webpage, and it takes me to where I requested. It really looks like that little jerk got me though! Here is the log…..
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4533
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
9/2/2010 10:04:14 PM
mbam-log-2010-09-02 (22-04-14).txt
Scan type: Quick scan
Objects scanned: 142559
Time elapsed: 6 minute(s), 15 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 3
Registry Keys Infected: 9
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 2
Files Infected: 19
Memory Processes Infected:
C:\Documents and Settings\Owner\Application Data\SystemProc\lsass.exe (Trojan.Tracur) -> Unloaded process successfully.
Memory Modules Infected:
C:\WINDOWS\system32\catsrvps32.dll (Trojan.Tracur) -> Delete on reboot.
C:\WINDOWS\system32\E7.tmp (Trojan.Tracur) -> Delete on reboot.
C:\WINDOWS\system32\d3d832.dll (Trojan.Tracur) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\3c8853df989 (Trojan.Tracur) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{dd838fc5-b09b-4076-18b6-586fe92d7ab8} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{dd838fc5-b09b-4076-18b6-586fe92d7ab8} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd838fc5-b09b-4076-18b6-586fe92d7ab8} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{35d5440a-c242-4def-b41d-30adcda86b5d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{35d5440a-c242-4def-b41d-30adcda86b5d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35d5440a-c242-4def-b41d-30adcda86b5d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35d5440a-c242-4def-b41d-30adcda86b5d} (Trojan.Tracur) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rthdbpl (Trojan.Tracur) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\catsrvps32.dll -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\catsrvps32.dll -> Delete on reboot.
Folders Infected:
C:\Documents and Settings\Owner\Application Data\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32 (Worm.Archive) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\catsrvps32.dll (Trojan.Tracur) -> Delete on reboot.
C:\WINDOWS\system32\E7.tmp (Trojan.Tracur) -> Delete on reboot.
C:\WINDOWS\system32\d3d832.dll (Trojan.Tracur) -> Delete on reboot.
C:\Documents and Settings\Owner\Application Data\SystemProc\lsass.exe (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\cliconfg32.dll (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1725041029v4.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1725041029v5.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1725041029v6.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\mu1725041029v7.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1725041029v0 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1725041029v0.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1725041029v1 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1725041029v1.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1725041029v2 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1725041029v2.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1725041029v3 (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\SysWoW32\wu1725041029v3.kwd (Worm.Archive) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sl221876509 (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\WINDOWS\GnuHashes.ini (Malware.Trace) -> Quarantined and deleted successfully.
Kristin
oops….looks like I didn't follow the directions! I forgot to uncheck the boxes with C:\WINDOWS…..is thaT going to be a bad thing?
LDTate
That should be OK.oops….looks like I didn't follow the directions! I forgot to uncheck the boxes with C:\WINDOWS…..is thaT going to be a bad thing?
Run a new MBAM scam and post the results.
Also let me know how it's running.
Kristin
Thank you so much! Looks all clear. Here is the next log….
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4533
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
9/3/2010 2:14:52 PM
mbam-log-2010-09-03 (14-14-52).txt
Scan type: Quick scan
Objects scanned: 144881
Time elapsed: 4 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
LDTate
How's it running now?
Kristin
Everything seems to be pretty smooth now. I cant thank you enough for your help! I am donating for sure!!!!!
LDTate
You're more than welcome.
Glad we were able to help
Peace be with you 
LDTate
If you did, I didn't get it.Everything seems to be pretty smooth now. I cant thank you enough for your help! I am donating for sure!!!!!
LDTate
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI