Upon Logging "system32/1.tmp doesn't exist" error

Discussion in 'Malware Help (A Specialist Will Reply)' started by copernic, Oct 4, 2007.

  1. copernic

    copernic Private E-2

    Hello,

    When I log in XP, I get the following message:

    1.
    The path C:\WINDOWS\system32\1.tmp does not exist or is not a folder.

    I click OK, then I get the following message:

    2.
    Windows does not find 'C:\WINDOWS\system32\1.tmp'. Check that you entered the name correctly and try again. To search for a file, click on Start>Search.

    History:
    I ran the Malware Removal Guide Step by Step yesterday and today.
    This PC is not mine but I've been its sole user for some months. I return it this week end so I would like it to be clean!!
    A few months ago, I read the topic "How to protect yourslef from malware", because there was not appropraite protection on the PC (and there was this annoying 31.tmp" stuff). I followed the steps and chose Avast, Comodo' Firewall and BOClean.


    Thanks for your help!!



    PS: When the system will be clean and I do Step 8 (a restore point) should I keep Normal Startup in msconfig?
    PS2: PandaActiveScan has a new domain name and site structure, you may wish to update the links of the thread.
     

    Attached Files:

  2. copernic

    copernic Private E-2

    GetRunKey, ShowMe and analyse (aka HighJackTHisThis) logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach a new log for:
    HJT
    Avenger
     
  4. copernic

    copernic Private E-2

    Thanks for your instructions!

    1.
    I was prompted, and another window popped up, with the message:

    "Location of startup: FILE
    C:\\WINDOWS\SYSTEM32\DRIVERS\XLNTJFVP.sys
    This trojan horse was found on your machine. It has been shut down, but the FILE from which it started still remains and can be started up again.
    Do you want the file removed also?"
    Yes/No buttons

    I choose Yes.

    2.
    After the reboot, the messages about 1.tmp did not appear :)
    (But the explorer opened a window for My Documents)

    3.
    I could not find any log of avenger. There was nothing in C:\\; C:\\Avenger folder was empty; I did a search for avenger.txt on the C drive, but it did not find anything.

    New HJT log is attached.


    PS: CounterSpy is started at boot, should I disable it because of possible conflicts (I have Avast, Comodo's BOClean (and Firewall))?
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.


    Use windows explorer to find and delete:
    C:\\WINDOWS\SYSTEM32\DRIVERS\XLNTJFVP.sys

    Yes, you should not have Counterspy running along side of Avast.

    Tell me how things are running.

    Attach a new HJT log.
     
  6. copernic

    copernic Private E-2

    1. I couldn't find C:\\WINDOWS\SYSTEM32\DRIVERS\XLNTJFVP.sys with the explorer, so I did a search on MyComputer but it did not come up either.

    Just in case you didn't notice my comment in the preceding post, last time I rebooted (after avenger), the 1.tmp messages did not appear anymore. So it *appears* to be fixed, although, of course, I have no clue what's going on under the hood!

    2. question unrelated to this problem: when the problem is fixed, and the PC can thus be considered malware-free, can I run CCleaner to get rid of any references to BitDefender and PandaScan's online scans that it finds (as well as any remnants of CoutnerSpy after I uninstall it) BEFORE doing Step 8 of the Removal Guide, namely before creating a restore point?
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes....

    Run CCleaner ...the cleaner and the issues (make the backup when prompted) ...this will fix bad registry items.

    To Reset Web Settings:

    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.


    Your logs look clean. You may uninstall any programs we had you download (including CounterSpy, etc).

    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
    * go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  8. copernic

    copernic Private E-2

    Thanks, I did all that (well, all that applies), including regoing through the thread "How to prevent yourslef from malware".

    Two little things remain from the cleaning:
    1. I could not uninstall avenger: it does not appear in the Panel Configuration uninstall utility, nor does it have a folder in Start>Programs.
    2. At boot, Windows Explorer opens MyDocuments. How can I disable this?

    ----
    Unrelated to this problem:
    --
    I'm going to return this PC to his owner, so I ordered (and just received!) a new machine. It has Vista. I will go though the thread "How to prevent yourself from malware" first thing. I downloaded Avast, a-squared, Comodo Personnal Firewall, CCleaner, Comodo BOClean, SpyBot Search & Destroy and Spyware blaster on a USB key, so that I can install them on the new machine offline. I don't plan to run the initial virus/spyware scans though, because the machine is brand new (I didn't even turn it on yet), so, hopefully, it's malware-free! I would think that updating them and running the scan in a couple of weeks instead should be enough. Is that correct?

    --
    The thread How to protect yourslef from malware, as well as "Disable Unneeded Services In Windows XP" ( http://forums.majorgeeks.com/showthread.php?t=25835 ) are geared towards pre-Vista Windowses.
    A sample of what I'll go through with Vista soon is:
    *I ll install Linux besides it (on the same HDD). But the Vista partition utility doesn't shrink things much, and many (free?) partitionners seem (from what I gathered on the net) not to work well with Vista.
    *Vista's MBR is different than XP's, so I don't know if "HOWTO: Make an NTFS bootdisk" (
    [URL="http://forums.majorgeeks.com/showthread.php?t=35319"[/URL ] ) applies to Vista at all.

    Basically, I wonder if there are some Vista-specific ressources that you would recommend, a specialized MajorGeeks.com!
    --
    ----
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    For the My Document problem:
    Run regedit and navigate to:

    HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon

    In there there should be a value (on right hand side of screen) called Userinit.

    The data for this value is probably something similar to:

    C:\windows\system32\userinit.exe,C:\windows\system32\userinit.exe,

    If you do see a duplicated string in there similar to the above - simply double click on the Userinit value and edit the data so as to delete everything to the right of the first comma (,). In the case above you would leave only:

    C:\windows\system32\userinit.exe,

    Exit registry edit and reboot.
    http://support.microsoft.com/kb/555294
    Do a search for Avenger ....my guess is that it never installed properly as you had no logs for it.
    As to Vista....we are currently compiling a list of software that is Vista compatible.
    You should ask the dual boot questions in the software section.

    Tell me if the above fixed your problem.
     
  10. copernic

    copernic Private E-2

    Fixed, thanks!

    Avenger doesn't come up at MS, but its author says that the .exe selfloads at boot. So I simply deleted it together with the (empty) folder that it had been created.

    Ok, I will be watching for your list when it's out!
    I haven't gotten the internet connection running on my Vista laptop yet(!!), but FYI, when asking Comodo's FireWall to update, Vista says that the user doesn't have enough privileges, instead of just asking for the admin password, like it does for 100% Vista-compatible programs.

    Thanks a lot for all your dedication in solving this!! :) :)Voluntary & experienced antimalware expertise is a great help to the community, thumbs up! :) :)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're quite welcome ....post the Vista connection problems in software ..there are a few very savvy people that will be able to help.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds