win30.tmp alert

Discussion in 'Malware Help (A Specialist Will Reply)' started by dnicu26, Apr 15, 2006.

  1. dnicu26

    dnicu26 Private E-2

    Hello,

    Since this morning, I have had a problem with some files in C://Windows/temp. I ran Ccleaner and it cleared everything except for the files shown in the print screen. I ran the computer in safe mode and deleted the file, as it wouldn't work otherwise. It says the program is in use or is read-only. It's not read-only and I cannot see it in the proccesses list. Spybot, adware detects nothing.

    At an earlier Norton warning, it said something about a dialer. I'm not sure if this has anything to do with it. It just keeps reappearing. Even if I select BLOCK ALWAYS, it copies itself with a different name win345.tmp for example.

    I also changed the filename from win30.tmp to win30, removing the extension and therefore I managed to delete it. After a while, it was back there.
    Microsoft Defender doesn't detect anything.
    Will attach the bitdefender ;log when I get it. Any ideas until then? :(
    http://img97.imageshack.us/img97/4503/untitled2la.jpg
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. dnicu26

    dnicu26 Private E-2

    Hi, I'm back with the scan reports. I have followed all the steps in that sticky. As I said before, when I delete it in safe mode, it keeps coming back.

    I haven't met anything like it before.
    The bitdefender online scan took over 2 hours. I'm not sure if it's meant to take that long.
     

    Attached Files:

  4. dnicu26

    dnicu26 Private E-2

    Sorry, I forgot the hijackthis log
     

    Attached Files:

  5. dnicu26

    dnicu26 Private E-2

    Sorry for the triple posting but I have just gotten another report from symantec that it detected a dialer. This happened while I was typing in Microsoft Word, all my browsers were closed for the last 30-40 minutes. So it means that I still have it somewhere on my computer and I suspect it may have something to do with the program reproducing in the Temp folder.
    Even though it says it's deleted, I got this same dialer (same name) a few hours before. I would restart it in safe mode and delete it from there but I don't know where to start (what do delete). :(

    http://img405.imageshack.us/img405/5835/ps9bo.jpg
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in step 6 for creating the Bitdefender log. It should be a file with HTML code in it. Don't worry about it now but this makes my job more diffcult reading it the way you posted it.

    You also did not install HijackThis as instructed in step 7. Please follow those directions exactly as written now because you have it running exactly how we specify not to run it. And that is directly from the ZIP file. DO THIS NOW!

    You also did not empty your Norton AntiVirus\Quarantine folder as instructed in step 0 of the READ & RUN. Empty this quarantine now! Also empty your Recycle Bin next and if you have that stupid Nprotect feature from Norton, empty it too as per step 0 of the Read Me.

    Please follow directions properly to save you and me time.

    Start by downloading two tools we will need:

    - Process Explorer

    - Pocket KillBox

    Extract them to their own folder somewhere that you will be able to locate them later.

    IMPORTANT: You should print or save the below locally, so you can refer to them while offline. You must exit all browsers before running the below steps and it would be best if you actually physically unplug your cable to the internet, reboot, and do not run anything but what I give you to do. Also it would be good to exit all processes and items in your System tray.

    Do the above before continuing! Okay unplug your cable now.

    Make sure you have rebooted in Normal Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of winjvd32.dll once and then click the kill button. After you have killed all of the winjvd32.dll under winlogon click ok. (If you do not find the dll, just continue on.)

    Next double click on explorer.exe and again click once on each instance of winjvd32.dll and kill it.

    Now just exit Process Explorer.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O20 - Winlogon Notify: winjvd32 - C:\WINDOWS\SYSTEM32\winjvd32.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion…say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note some of the files listed below may not exist but we need to check for them anyway.
    C:\WINDOWS\SYSTEM32\winjvd32.dll

    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    After reboot locate the below with Windows Explorer and delete them:
    C:\WINDOWS\SYSTEM32\winjvd32.dll <-- Killbox should have gotten it already
    C:\WINDOWS\temp <-- delete all files in this temp folder! You may have problems deleting ones with todays date, just skip them and delete all others.

    Now attach a new HJT log and tell me how the steps went.
    Make sure you tell me how things are working now!
     
  7. dnicu26

    dnicu26 Private E-2

    Sorry for making this hard for you but at first I saved it as .html but it said I can't attach it to this post as the extension is not supported. I have re-installed hijackthis.exe in the right location now. Thanks for pointing that out.

    To date, everything works OK. The only files I couldn't delete are the ones in the print screen below:
    http://img85.imageshack.us/img85/70/untitled2de.jpg

    Here's the HJT log you requested :). I can still see however the O20 - Winlogon .... The file is gone from system32 folder but how come it still appears here? Is this normal? :(

    Thanks for helping and Happy Easter.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But the directions clearly explain that to you.
    Why did you install this Kontiki stuff especially while still having malware issues:
    O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
    O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe

    This crud was not in your previous log. It is not really malware but do you really want this junk wasting your system resources and downloading stuff in the background. I would uninstall it unless you really need it. But it was not there before! Why do you need it now.

    Have HJT fix the remnant line you mentioned:
    O20 - Winlogon Notify: winjvd32 - winjvd32.dll (file missing)

    Then just make sure by check your log to see that it is gone.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  9. dnicu26

    dnicu26 Private E-2

    Kintiki belongs to a program called Sky by Broadband (Sky) which is also the satelite tv network in the UK. It's a new service that basically allows you to download some movies that are on the tv so you can watch them on your PC. I don't know what you might think it is but it only downloads movies when I launch the Sky program. It doesn't really work like a P2P software as far as I know.

    Thanks for helping me solve this. I have one more question:
    I have Norton Internet Security 2006 installed. I also used to have ZA Pro installed but uninstalled it as other people adviced me to. I don't really know what the deail with IS is. At the moment, it's the only real time software protecting my pc. Would buying Spy Sweeper or Spyware Doctor conflict with it?

    Thanks You again, Nick!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it only downloads when you need it, then why does it always need to be running on your PC. It should only be run when you are downloading. This software is wasting valueable resources and could be doing stuff in the background. See the below:

    http://www.bleepingcomputer.com/startups/kdx-2404.html
    http://castlecops.com/s1758-KHost_exe.html
    http://www.liutilities.com/products/wintaskspro/processlibrary/khost/


    Spy Sweeper is a good choice and should have no problems working with NIS. I assume you were told to uninstall ZA because NIS includes a firewall. Personally I would not have uses NIS, but that's your decision.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds