TempFile and dlls reappearing

Discussion in 'Malware Help (A Specialist Will Reply)' started by txannie, Apr 6, 2009.

  1. txannie

    txannie Private E-2

    I have followed the guide and am still having issues.
    In C:\windows - random named dlls keep appearing as well as TempFile with no extention.

    I have attached the files and thank you in advance for your help!
     

    Attached Files:

  2. txannie

    txannie Private E-2

    Re: TempFile and dlls reappearing - Update

    Sorry for not providing more information - I have been really sick and dealing with this was just too much.

    As far as what caused this, I am not sure - my son was surfing and said he went to download something but deleted it - so I just don't know.

    The TempFile files grows to 8209 Kb and stays that way unless I reboot - which then it is gone and after a short time, reappears and grows again.
    Cannot delete this file. I don't know what it is collecting and don't want to reboot in case it is flushing it somewhere.

    Random named dlls appear every 2 hours and 1 minute to C:\Windows - doesn't matter if I delete them or not. So for example, one right now is called edififin.dll
    The only thing constant is that it is exactly every 2 hours and 1 minute.

    I hope this additional information helps. This is my only computer so let me know what else I can do - other than keep my son away from it :)
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome :)

    We are currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time. In the meantime be sure to update MBAM, scan again and attach the log it generates.

    Kestrel13!
     
  4. txannie

    txannie Private E-2

    Thank you so much!!! I was dyslexic about the times...it is actually 1 hour and 2 minutes that new files appear. I can't disable system restore and my desktop icons disappear and reappear randomly. Also it takes a very long time to shut down the system or start it back up again.

    I really appreciate the help!
     
  5. txannie

    txannie Private E-2

    sorry - forgot to attach the log
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) Please go to add/remove programs and uninstall the following old version of java:

    • Java(TM) 6 Update 11

    2) You have Spybot search and destroy's Teatimer running and it is going to get in the way of my fix, so please disable it and follow the instructions for doing so here before we continue on:

    How to disable Spybot's TeaTimer


    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    Fix if present.. may not be after a reboot(s):


    After clicking Fix exit HJT.



    4) Now we need to use ComboFix to remove a bunch of malware files and tidy up from some dead BHO's.

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    File::
    c:\windows\uxexatab.dll
    c:\windows\TempFile   
    C:\AuResult.ini
    c:\windows\nsvdbtp.dll
    H:\loaderw.exe
    
    DirLook::
    c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
    c:\program files\me
    c:\program files\Me
    C:\SS
    
    Registry::
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EBBD0F6-1F1F-48A0-89DC-C7505D56E92A}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E0019445-4C1F-414D-A70E-AD80F231C584}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2078cee8-e2bc-11dd-b409-0011118a5c9b}]
    
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    5) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    • C:\Documents and Settings\Mom\Local Settings\temp

    6) Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    7) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix.

    8) Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please also note:

    You should uninstall the current version > reboot your machine > and install the most up to date version available here at Majorgeeks.

    SpyBot-Search & Destroy 1.6.2.46
     
  8. txannie

    txannie Private E-2

    I have followed all of your directions.
    Attached are the two requested logs.

    TempFile is back at 8209 Kb - created when I rebooted.
    I still cannot disable System Restore.
    No random dlls ... sometimes it takes a few minutes for them to start appearing - but I am hopeful :)

    If I note any problems, I will post another reply - but I did want to get you the logs as soon as possible.

    Thank you again!
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there, please download the most recent version of combofix and re run my previous script in post # 6 step 4 attach the log it generates into your next reply.

    Thanks Kes
     
  10. txannie

    txannie Private E-2

    I have attached the new log...

    thank you again :)
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    2. Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  12. txannie

    txannie Private E-2

    i have run Avenger and have attached the two requested logs.

    TempFile came back as soon as I rebooted (8209 KB) and I am still unable to disable System Restore <sigh>. I can boot into Safe mode - delete TempFile and disable System Restore and then once I reboot, it all comes back and is enabled again. I even tried disabling the service, rebooted, and it came back - enabled and started. My system is really slow on reboots - much slower since getting infected. No random dlls yet...guess that is positive :)
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You should NOT be attempting to disable system restore until I have given you the final steps and all clean, because even a "dirty" restore point is better than none at all.

    Could you please get this c:\windows\TempFile into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

    Thanks
    Kestrel13!
     
  14. txannie

    txannie Private E-2

    I ran what you requested and it created the zip file, but it did not zip TempFile into it. I get permission denied - could not open for reading: windows/TempFile - zip file empty.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Okay let's try this:

    Please get this: TempFile_.zip into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:

     
  16. txannie

    txannie Private E-2

    Here is the zip file.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The TempFile is nothing to be concerned about. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  18. txannie

    txannie Private E-2

    OHMIGOSH!!! Thank you so much!!! If I know how to thank you officially - I would....all I can say is you are amazing!
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    you're so welcome :) *smiles*

    safe surfing
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds