Temperror32.dat and Ebates keys help

Discussion in 'Malware Help (A Specialist Will Reply)' started by DeathtoSpyware, Jun 13, 2005.

  1. DeathtoSpyware

    DeathtoSpyware Private E-2

    So I runned Ad-Aware a couple of days ago and found out that I had Ebates reg-key. I tried to delete it but it kept coming back, later I found out with Norton scanner that I had tempError32.dat.

    Couldnt delete it. I was running Hijackthis but I there are many stuff I dont know which one to delete, so I ask for your help thx in advanced.

    Edit by bjgarrick: Unrequested, Inline HJT log removed!

    I already did the sticky thread guide I didnt work for this one specifically.
    Umm any info you might need just ask me.
     
    Last edited by a moderator: Jun 13, 2005
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    There are no signs of the online scans listed in the READ ME. So lets start by running the below online scans:

    TrendMicro Online Scan
    Bitdefender online scan
    RavAntivirus online scan <-- select Auto Clean then click Scan My PC
    TrojanScan online scan
    Panda Online Scan

    After you have completed the online scans above, reboot and post a fresh HJT log as an attachment to your post.
     
  3. DeathtoSpyware

    DeathtoSpyware Private E-2

    OK Well I jjust woke up after scaning for 8 hours, it was 11 am when I started. here is my log


    Edit by chaslang: Inline log removed
     
    Last edited by a moderator: Jun 14, 2005
  4. DeathtoSpyware

    DeathtoSpyware Private E-2

    oops It was supposed to be an attachment..
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    -Please download Ewido Security Suite

    - Install and get any updates!
    - Run a full scan on Local Disk C:\
    - Remove ALL found infections

    After you complete the above, post a fresh HJT log along with the log from the scan above.
     
  6. DeathtoSpyware

    DeathtoSpyware Private E-2

    OK here they are but I just checked the C:\Windows\system32 folder and its still there --;


    NOTE: Im sorry for taking so long I had my connection cut off.
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, disable Spybot's TeaTimer so it will not block anything we try and fix.

    Also, be sure you close ALL browsers while running HJT and any other fixes!


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 170.222.120.200:8000
    (Keep this one if you need it)

    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteyzx32.exe

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner

    You must get the updates for Ewido, it will remove all of the elite files. It doesnt appear you have the updates. After you get the updates do another scan and attach the log.
     
  8. DeathtoSpyware

    DeathtoSpyware Private E-2

    So I did everything you told me.

    Disabled Tea-Timer, all browsers, all fixers like Ewido, Norton, and spywareBlaster. After that I runned HJT and deleted what you told me even the proxy. So after that I runned CCleaner, then I runned HJT again and saved the loglife, but it appears the Eliteyzx is still there and I dont know what else to do.

    NOTE: I have the latest updates for Ewido and it only detects the Eliteyzx no more than that. The only problem I have is that when I close messenger in the Task manager it keeps coming back after a minute or so, maybe Im doing something wrong but that piece of spyware keeps coming back no matter what I use =/
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    (Don't run it yet)

    Now look in Add/Remove Programs and uninstall Ewido. Also, disable any antivirus and antispyware programs you have running so it will not block any of this fix.


    Now scan with HijackThis and Check the Boxes for the following:

    O4 - HKLM\..\Run: [checkrun] C:\windows\system32\eliteyzx32.exe

    Make sure All Browser Windows are Closed when you Click FIX.


    Locate PocketKillbox
    (Procede with this step even if they do not show in blue)

    Now, Copy and Paste C:\windows\system32\eliteyzx32.exe into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES.

    Allow Killbox to reboot your system. After you have rebooted and windows has loaded attach a fresh HJT log.
     
  10. DeathtoSpyware

    DeathtoSpyware Private E-2

    hehehe I just got an update from Ewido and I tried to scan again and got like 5 elite bugs -_-;; so now I think I'm clean I'll post the Log in a couple of minutes.
     
  11. DeathtoSpyware

    DeathtoSpyware Private E-2

    Ok. I just read your post BjGarrick, should I still download Pocket kill box?

    Look at the Log from Ewido:

    NOTE: I just looked at HJT and it doesnt show me the Eliteyzx anymore :D


    Thanks Garrick for your help!
     

    Attached Files:

  12. janiea

    janiea Private E-2

    I'm new 2 major geeks but I had the same problem. I'm no computer whiz but I just ran 'search' in safe mode and deleted temperror32. It hasnt come back since. Also ran Spybot and Ad aware to make sure.
     
  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Yes, procede with my latest fix even if it doesnt show in blue.

    After you complete that reboot and attach a fresh HJT log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds