Need Help With Win32.tiny.abk!!!!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by petepablo55, Apr 7, 2008.

  1. petepablo55

    petepablo55 Private E-2

    Hello, I am new to this forum but am computer knowledgeable and I need some help. I have been infected with the win32.tiny.abk virus. It causes my computer to send mass spam emails about 100 per minute as soon as I connect to the internet. I'm running XP with Norton Systemworks Premier 2008. NAV notifies me about the outgoing emails. NAV does not recognize the virus whatsoever but I have spybot search and destroy which recognizes and deletes the problem (in safe mode) but it pops back up every time I reboot the computer. I have the Hijackthis, AVG, and Spybot programs on my computer, i've read similar posts and they seem to be needed to fix the problem. I have read a million posts on the topic and have tried EVERYTHING. I am at your mercy, please help. The next step for me is to format and start fresh which would be a huge pain in the a**.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. petepablo55

    petepablo55 Private E-2

    I Need Help With Win32.tiny.abk!!!!!!!

    This is the second thread I'm posting, I followed all your instructions in the malware removal guide already and I am attaching the logs. One note however, I followed your combofix instructions verbatim and for some reason the batch file begins to load up and then immediately closes. Nothing else happens after that and there is no log file. I didn't touch the keyboard or the mouse and nothing was running in the background? Anyway, I'll restate my problem. I was recently infected with the win32.tiny.abk virus, i'm guessing from using utorrent to download a movie. It sends massive amounts of spam emails a minute everytime I connect to the internet and NAV keeps popping up saying there's outgoing emails. I ran the superantispyware program and it didn't find anything. I ran spybot s & d and it found the win32.tiny.abk virus and deleted it. I rebooted the computer and the problem was still occuring. I ran spybot again and it found the virus again. Apparently it can't be deleted. I ran malwarebytes and it found about 10 infections. I tried using the internet again and the same problem came up. Then I tried combofix and it didn't work, then finally mgtools. My computer uses windows xp, i connect to the internet through a wireless router, and i have norton systemworks premier 2008. If there is anything else you need from me I'll be more than happy to let you know. I thank you for your time and consideration in helping me with this problem. I'm not as computer-knowledgeable as yourself but I do know a decent amount about them if that helps any.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I'm not seeing any malware ...could you tell me exactly where :
    The exact path to "the problem."
     
  5. petepablo55

    petepablo55 Private E-2

    I ran spybot again and the win32.tiny.abk didn't come up this time but something else did.



    "Microsoft Security Center Disabled"
    Path: HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\WSCSVC\START



    I checked to see if I still had a problem with the spam emails and I do, they keep popping up the instant I connect to the internet. Would posting a Hijackthis log help any?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Having a firewall will automatically disable the windows firewall. Please re-run Malwarebytes and attach a new log.

    Then Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  7. petepablo55

    petepablo55 Private E-2

    I re-ran malware bytes and posted it. I was not able to use bitdefender's online scanner because my isp warned me that until I get the problem fixed I had better not use the internet with my infected computer (I'm using my roomates to write you) or they would ban me for the excessive spam mail virus spreading. I did however download bitdefender's internet security program and transfer it to my infected computer. I ran the program and saved the log. It is attached with the malware bytes log. I apologize for not being able to use the online scanner but I can't get banned, so if there's any way for future fixes that can be downloaded here and transfered over that would be ideal. I can transfer large programs by burning them on cd, that isn't a problem. Thank you for taking the time to help me, I'm sure you guys are very busy :
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Apparently we need to clean out your temp files ..
    These two need to go bye bye:
    C:\WINDOWS\Temp\7CF28762C38CA0D4.tmp
    C:\WINDOWS\Temp\AE8AB41F91F72503.tmp

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Did you open any email attachments or click on any email links before this occurred?
     
  9. petepablo55

    petepablo55 Private E-2

    I ran atf cleaner and then tried connecting to the internet, no dice. The same problem kept happening. I rebooted and tried it again, still didn't work. I didn't open any emails, the only thing I can think of is that I downloaded a movie on utorrent that night. I deleted the movie off of my computer though. I've gotten a virus from time to time before, but never this stubborn.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you attempted a system restore to before this occured? That might be the best solution at this point as I can't pinpoint the problem.
     
  11. petepablo55

    petepablo55 Private E-2

    I tried restoring my computer several times initially, even back to the first possible restore point, but it kept coming up. I guess I'm just going to have to format it and start fresh. Thanks for your help, I do appreciate it.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    One more thing I want you to try:

    Download SDFix and save it to your Desktop.

    * Run the SDFix.exe by double clicking on it.
    * Allow it to install into the default location which is normally c:\SDFix
    * Now please reboot your computer into Safe Mode (see this if you don't know how: Starting your computer in Safe mode. )
    * When you have booted into safe mode, open the C:\SDFix folder and double click RunThis.bat to start the script.
    * Type Y to begin the cleanup process.
    * It will remove any Trojan Services or Registry entries found and then prompt you to press any key to Reboot.
    * Press any Key and it will restart the PC.
    * When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    * Attach the Report.txt file to your next message.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I want you to do this:
    Then re-run ComboFix and attach that log also.
     
  14. petepablo55

    petepablo55 Private E-2

    Tim, I just want to say that you are the man! I ran sdfix and it found and deleted a trojan. I tried using the internet to see if the problem was solved and it was! I rebooted twice just to make sure and it worked perfectly everytime. I ran the kaspersky online scanner and it said that it found some infections however. I don't know if they're related but i'm attaching it just to be safe. I also was able to run combofix this time without a problem. The computer seems to be working ok now, the email pop ups have stopped, but I'm concerned about the infections that kaspersky found.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sweet......you can delete this:
    C:\Documents and Settings\Peter Kelchner\My Documents\Nero 8 Ultra Edition 8.2.8.0+Keymaker

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  16. petepablo55

    petepablo55 Private E-2

    Tim thank you so much for helping, I was completely lost without you man. It would have been such a pain in the a** to format this and start over. I'd buy you a beer if I could my friend, thanks again!


    Pete
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds