rb13.tmp in the recycler bin

Discussion in 'Malware Help (A Specialist Will Reply)' started by vvgomez, Apr 12, 2009.

  1. vvgomez

    vvgomez Private First Class

    I updated norton with the last version and it detected and deleted a troyan. All looked good when I noticed that the recycler bin had this files

    rb13.tmp 0 kb
    rb14.tmp 0 kb

    I can delete them but when I reboot the computer they are created again after a few second of the start up, with the system restore on or off.

    I have 3 pc in net, the two with the norton updated present this files in the recycler bin, and only one was detected with the troyan, I attached the last logs of this one...

    Thank you in advance
     

    Attached Files:

  2. vvgomez

    vvgomez Private First Class

    one more thing... I turned off the norton, deleted the tmp files in the recycle bin, reboot and the files didn't create again... but as soon as I open norton they appear..

    I attached the combofix log to see if that can be related to some kind of virus in the background
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didnt attach the C:\MGLogs.zip.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now attach the MGLog.zip
     
  4. vvgomez

    vvgomez Private First Class

    I was out from my computer so I couldn't answer sooner... I uploaded the mglogs.zip

    I would like you to check them out before doing the notepad file...

    I also noticed that I have in quarantine some files in the qoobox folder...

    thank you for your time

    vv
     

    Attached Files:

  5. vvgomez

    vvgomez Private First Class

    I couldn't wait and I did the fixme.reg file on the desktop... and yes, I received a successful message...

    do I need to post a new MGLogs.zip?

    and again I got some quarantine files in the qoobox folder, should I delete them?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean.....if you are referring to the combo quarantine files, we will remove that in a moment.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  7. vvgomez

    vvgomez Private First Class

    one more thing... between the last logs and today my malwarebytes Anti malware found a couple of infected files... so I posted new logs to see if I can bother you a little more and you could check if I could clean my computer...


    the tmps in the recycler bin still appearing... as much as I could research, it seems that are created for my AV... (recently my internet provider changed the protection from Norton to Radialpoint and I am having that tmp files since then...)

    thank you again...
     

    Attached Files:

  8. vvgomez

    vvgomez Private First Class

    ... one more log ...
     

    Attached Files:

  9. vvgomez

    vvgomez Private First Class

    Help!!! ROGUE SECURITY SOFTWARE TROYAN is still in my computer and I can't get rid of it!!!

    it attacks the antivirus... spyware, malwarabyte antimalware can't be updated, and are not detected...

    still waiting for the logs to be checked, please...

    thanks
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    At the rate you keep bumping your thread, it would probably never get answered.

    Your logs are clean!! SpyBot reports nothing and your other logs are malware free.

    What are you yelling about?

    Want is reporting this and where do they report it to be?
     
  11. vvgomez

    vvgomez Private First Class

    sorry for bother you... but I have the malaware anti malaware detected this troyan. rogue security software... I wait to see if my log are clear and then do the system restore, but when I reboot I notice that before enter to windows the system looks for the last restore point...

    I can't update the m anti malware, or the superantispy or even the anti spy of yahoo that also detected this troyan.

    an false window of antivirus window center open up asking to activated the firewall or antivirus

    don't know may be as soon as I reboot the virus reinstall itself and you only could saw the clean logs before it happen...
     
  12. vvgomez

    vvgomez Private First Class

    Ok I know you must saying .... oh no! this girl again..! She must be in huge need of attention!

    so I am posting this last reply to let you know what I did and give a close to this post before you kill me

    I run yahoo anti-spy toobar...
    detected the rogue.security.software put it in quarantine and I delete it from the browser and from the recycler bin.

    (malwarebyte anti malware had been dectected it as Rogue.MalwareCleaner and gaopdxserv.sys (Trojan.Agent) but then the false security center showed up)

    at this point the false security center disappeared but couldn't update any antivirus ...

    I restarted and ... a pop up showed up saying that this aplication couldn't be find: rpsinstallerfinder.exe

    during the start up the black screen before open windows select the last configuration where the computer opened ok

    when windows started again all the antivirus and antispy started running ok, but not the yahoo one...
    I reinstalled it and could updated again and all seem good so far...

    Thank you for your patience... or lost of it... I really appreciate your volunteer work trying to help us to protect and fix our working tools... I really do.

    vv
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem, :) If you think that you are re-infected, you just need to run the scans again and attach the logs and tell me what is being reported, where it is located and what is reporting it.

    Do let me know if you need further assistance. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds