Temporary Folder

Discussion in 'Malware Help (A Specialist Will Reply)' started by Toke, Oct 22, 2005.

  1. Toke

    Toke MajorGeek

    Friend has bad virus infections main one is Trojano32 I went over to help and we went to follow sticky removal help. The main prob is that we cannot empty the temp folder. It has 21,000 files + equalling 589 MB. Highlighted all files but when arrow hits 'FILE' to get to delete it freezes. CrapCleaner will freeze also. I tried 'KillBox' and that copies and runs through until it gets to its own temp folder then cannot complete configuration. Carried on with AV progs following instructions but it appears that a virus is in the temp folder as computer is still well infected even though several were detected and deleted but they have returned. One was deleted from registry. Am at a loss now other than a complete format , any suggestions plz..
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try right clicking on the Recyle Bin icon on the Desktop and select Properties. Check the box that says "Do not move files to the Recycle Bin. Remove files immediately when deleteed".

    Then run Windows Explorer and go to the temp folder you are referring to. Just select about 20 or so files and then delete them. Do they delete? Try a larger group like a 100 or so. Do they delete? Try a little larger..... you get the idea?

    Let us know what happens.
     
  3. Toke

    Toke MajorGeek

    Hi chaslang.. yes with yoiur instructions have now emptied the temp folder..
    have now spent several hours using tools provided in sticky and extras. Many Viruses and trojans were found but not one registry entry and I think this comp is still infected .. here is HJT log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to undo that Recycle Bin change now.

    Did you knowingly install MailSkinner? I just recently had major problems with a few malware items named MagicControl.Agent, e-Group, EDGAccess which were due to MailSkinner being installed.

    You should go to Add/Remove programs and uninstall any of the below if found
    MailSkinner
    e-Group
    EDGAccess
    InstantAccess
    PSGuard

    Also is the below something you installed:
    O4 - HKCU\..\Run: [Eraser] "F:\eraser.exe"

    Also run the following and post the log: Smitfraud and PSGuard Removal

    Now attach a new HJT log after doing all the above. Answer questions too.
     
  5. Toke

    Toke MajorGeek

    Hi chaslang have uninstalled/deleted succesfully the progs you listed.. the eraser was installed with prior knowledge. here is the latest log after running 'smitrun' appreciate all your help. Still a few popups that are reluctant to kill using adaware and spybot.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to post the smitfiles.txt log and the new HijackThis log.
     
  7. Toke

    Toke MajorGeek

    Oh bugger I thought the smit was having trouble loading .. I'll have to go back to friends house again and post in a couple of days :-0 one of the popupd I found in startup (vmlib.exe) and have unchecked in msconfig. And of course the HJT log I had totally forgot lol
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Post them as attachments when you get them.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds