This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

TMP file virus

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I honestly have never had to post for help on anything before. I can usually get a virus out pretty good, but this thing is awful! I just was downloading a file from Limewire last night (dumb me), and all of a sudden my computer went nuts! My anti virus kicked in and I traced it back to the file. I did delete all my temporary internet files (thats where it went) and the file the virus went in can not be removed. It is now creating TMP files on my desktop, and they can't be deleted. It keeps trying to hide itself as well. Also when I of course tried to come on for any help, my web page will not go to the page I am requesting! It goes to some spam page, so of course I shut down my computer and turned off the wireless router in the hosue LOL. Is this thing going to eat my hard drive??? How do I possibly get it out when I cant even go on a webpage from that computer??? PLEASE anyone that can help me, I will be forever grateful! Thanks!!!! :pullhair:
Posted Image

Download the tools needed to a flash drive or other removable media, and run them from the USB device.



DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your USB device.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
Thank you, I will do today when I get home from work and post results tonight. With all this, would I just be better reformatting? I'm really good at reformatting LOL
Thank you, I will do today when I get home from work and post results tonight. With all this, would I just be better reformatting? I'm really good at reformatting LOL Also, will this work for XP as well?

Thank you, I will do today when I get home from work and post results tonight.

With all this, would I just be better reformatting? I'm really good at reformatting LOL

Also, will this work for XP as well?

Yes it will work for XP.
If you have all your important data backed up and your OS CD, a reformat might be the best choice.
Thank you so much! My computer seems to be running better right now. I can actually go to a webpage, and it takes me to where I requested. It really looks like that little jerk got me though! Here is the log….. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4533 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 9/2/2010 10:04:14 PM mbam-log-2010-09-02 (22-04-14).txt Scan type: Quick scan Objects scanned: 142559 Time elapsed: 6 minute(s), 15 second(s) Memory Processes Infected: 1 Memory Modules Infected: 3 Registry Keys Infected: 9 Registry Values Infected: 1 Registry Data Items Infected: 2 Folders Infected: 2 Files Infected: 19 Memory Processes Infected: C:\Documents and Settings\Owner\Application Data\SystemProc\lsass.exe (Trojan.Tracur) -> Unloaded process successfully. Memory Modules Infected: C:\WINDOWS\system32\catsrvps32.dll (Trojan.Tracur) -> Delete on reboot. C:\WINDOWS\system32\E7.tmp (Trojan.Tracur) -> Delete on reboot. C:\WINDOWS\system32\d3d832.dll (Trojan.Tracur) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\3c8853df989 (Trojan.Tracur) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{dd838fc5-b09b-4076-18b6-586fe92d7ab8} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{dd838fc5-b09b-4076-18b6-586fe92d7ab8} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{dd838fc5-b09b-4076-18b6-586fe92d7ab8} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{35d5440a-c242-4def-b41d-30adcda86b5d} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{35d5440a-c242-4def-b41d-30adcda86b5d} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35d5440a-c242-4def-b41d-30adcda86b5d} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35d5440a-c242-4def-b41d-30adcda86b5d} (Trojan.Tracur) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rthdbpl (Trojan.Tracur) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\catsrvps32.dll -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\catsrvps32.dll -> Delete on reboot. Folders Infected: C:\Documents and Settings\Owner\Application Data\SystemProc (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32 (Worm.Archive) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\catsrvps32.dll (Trojan.Tracur) -> Delete on reboot. C:\WINDOWS\system32\E7.tmp (Trojan.Tracur) -> Delete on reboot. C:\WINDOWS\system32\d3d832.dll (Trojan.Tracur) -> Delete on reboot. C:\Documents and Settings\Owner\Application Data\SystemProc\lsass.exe (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\cliconfg32.dll (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\mu1725041029v4.kwd (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\mu1725041029v5.kwd (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\mu1725041029v6.kwd (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\mu1725041029v7.kwd (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\wu1725041029v0 (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\wu1725041029v0.kwd (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\wu1725041029v1 (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\wu1725041029v1.kwd (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\wu1725041029v2 (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\wu1725041029v2.kwd (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\wu1725041029v3 (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\SysWoW32\wu1725041029v3.kwd (Worm.Archive) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sl221876509 (Trojan.Tracur) -> Quarantined and deleted successfully. C:\WINDOWS\GnuHashes.ini (Malware.Trace) -> Quarantined and deleted successfully.

oops….looks like I didn't follow the directions! I forgot to uncheck the boxes with C:\WINDOWS…..is thaT going to be a bad thing?

That should be OK.

Run a new MBAM scam and post the results.

Also let me know how it's running.
Thank you so much! Looks all clear. Here is the next log…. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4533 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 9/3/2010 2:14:52 PM mbam-log-2010-09-03 (14-14-52).txt Scan type: Quick scan Objects scanned: 144881 Time elapsed: 4 minute(s), 47 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI