Avast WEBforum

Other => Viruses and worms => Topic started by: moonbaby755 on June 14, 2013, 04:55:34 AM

Title: trz.tmp files
Post by: moonbaby755 on June 14, 2013, 04:55:34 AM
this is my first time posting...hope I got this in the right spot. trz.tmp files have taken over my computer and won't allow me to do anything. They just keep opening. i'm using computer in safe mode right now. is that a problem? Help!! pls!
Title: Re: trz.tmp files
Post by: jeffce on June 14, 2013, 05:01:01 AM
Hi and Welcome!!   

My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your operating system and losing all your programs and data.

Having said that....   (http://i1224.photobucket.com/albums/ee380/jeffce74/vegeta_zps7f4345cf.gif)   Let's get going!! 
----------

If you are only able to run these tools in Safe Mode that is just fine.  :)

Please download DDS from either of these links

LINK 1 (http://download.bleepingcomputer.com/sUBs/dds.com)
LINK 2 (http://download.bleepingcomputer.com/sUBs/dds.scr)

and save it to your desktop.
---------------------------------------------------
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
----------

(http://i1224.photobucket.com/albums/ee380/jeffce74/aswmbr-1-1.jpg) Please download aswMBR (http://public.avast.com/~gmerek/aswMBR.exe) to your desktop.

(http://i1224.photobucket.com/albums/ee380/jeffce74/aswmbrscan.jpg) (http://i1224.photobucket.com/albums/ee380/jeffce74/aswmbrscan.jpg)
Click the image to enlarge it
----------
Title: Re: trz.tmp files
Post by: moonbaby755 on June 14, 2013, 09:16:05 PM
it won't let me post all the attachments at once, says it's too large, so I will attach them separately. thx
Title: Re: trz.tmp files
Post by: moonbaby755 on June 14, 2013, 09:17:09 PM
here's the next log
Title: Re: trz.tmp files
Post by: moonbaby755 on June 14, 2013, 09:18:29 PM
here's the next one
Title: Re: trz.tmp files
Post by: moonbaby755 on June 14, 2013, 09:26:47 PM
can't attach the dds. says it is too long.
Title: Re: trz.tmp files
Post by: moonbaby755 on June 14, 2013, 09:27:48 PM
oops! my bad! the aswMBR wasn't done. it just keeps going. I will resend when it's done. thx
Title: Re: trz.tmp files
Post by: jeffce on June 14, 2013, 09:51:44 PM
Quote
can't attach the dds. says it is too long.
You are being told that the attachment is too large?
Title: Re: trz.tmp files
Post by: moonbaby755 on June 14, 2013, 09:52:23 PM
here u go.
Title: Re: trz.tmp files
Post by: moonbaby755 on June 14, 2013, 09:54:06 PM
yes. when I try to post the dds it says - 413 request entity too large.
Title: Re: trz.tmp files
Post by: jeffce on June 14, 2013, 10:02:58 PM
Ok....if the file is too large I need for you to go to the MediaFire found here >> https://www.mediafire.com/ssl_login.php?type=login

Open an account (it is free) and then upload the DDS.txt to the site.  Once uploaded...look to the right of the file and you will see a dropdown arrow.  Select that arrow and then select Copy Link and then post that link here so that I can review the file.
Title: Re: trz.tmp files
Post by: moonbaby755 on June 15, 2013, 01:10:32 AM
http://www.mediafire.com/download/79bhaqnru6ud2yp/dds.txt
Title: Re: trz.tmp files
Post by: jeffce on June 15, 2013, 03:57:06 AM
Good job!  :)

ComboFix

Download Combofix from either of the links below, and save it to your desktop. 
Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.forospyware.com/sUBs/ComboFix.exe)

**Note:  It is important that it is saved directly to your desktop**
If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.


--------------------------------------------------------------------

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here  (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html)

--------------------------------------------------------------------

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
Title: Re: trz.tmp files
Post by: moonbaby755 on June 15, 2013, 08:33:59 PM
combo fix
http://www.mediafire.com/view/smh21srxj7yjah8/log.txt
Title: Re: trz.tmp files
Post by: jeffce on June 15, 2013, 09:31:22 PM
ComboFix
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------

Attach the new ComboFix log and let me know how your system is running now.  :)
Title: Re: trz.tmp files
Post by: moonbaby755 on June 15, 2013, 10:52:44 PM
Here you go, thank you.
Title: Re: trz.tmp files
Post by: jeffce on June 16, 2013, 02:19:11 AM
Please go to: VirusTotal (http://"http://www.techsupportforum.com/forums/redirect-to/?redirect=http%3A%2F%2Fwww.virustotal.com")
On the page you'll find a "Choose File" button.
Click on the Choose File button.
In the Choose File to Upload window which opens, copy and paste this into the File Name box.

c:\windows\SysWow64\jmdp\stij.exe

Next, click the Open button.
Then click the "Scan It!" button just below.
This will scan the file. Please be patient.
If you get a message saying [COLOR="Blue"]File has already been analyzed:[/COLOR] click Reanalyze file now
Once scanned, copy and paste the link to the results page in your next reply.
----------
Title: Re: trz.tmp files
Post by: moonbaby755 on June 16, 2013, 02:58:51 AM
my system seems to be running fine now. awesome!! thank you so much for your help!
Title: Re: trz.tmp files
Post by: moonbaby755 on June 16, 2013, 03:04:39 AM
my avast! won't turn on now. says - No valid license found.
Title: Re: trz.tmp files
Post by: moonbaby755 on June 16, 2013, 03:50:54 AM

SHA256: 419967c0703fca52f6a4d1dfa680ee28457301100775e4aa36fc401917dda643
 
 
 
File name: stij.exe
 
Detection ratio: 1 / 46 
Analysis date: 2013-06-16 01:48:25 UTC ( 0 minutes ago ) 


 



1




2



More details
 Analysis
 File detail
 Additional information
 Comments
 Votes






Antivirus

Result

Update


Agnitum    20130615 
AhnLab-V3    20130615 
AntiVir    20130615 
Antiy-AVL    20130615 
Avast    20130616 
AVG    20130616 
BitDefender    20130616 
ByteHero    20130613 
CAT-QuickHeal    20130615 
ClamAV    20130616 
Commtouch    20130616 
Comodo    20130616 
DrWeb  Adware.SweetIM.27  20130616 
Emsisoft    20130616 
eSafe    20130613 
ESET-NOD32    20130615 
F-Prot    20130615 
Fortinet    20130616 
GData    20130616 
Ikarus    20130615 
Jiangmin    20130615 
K7AntiVirus    20130614 
K7GW    20130614 
Kaspersky    20130616 
Kingsoft    20130506 
Malwarebytes    20130615 
McAfee    20130616 
McAfee-GW-Edition    20130615 
Microsoft    20130616 
MicroWorld-eScan    20130616 
NANO-Antivirus    20130615 
Norman    20130615 
nProtect    20130615 
Panda    20130615 
PCTools    20130521 
Rising    20130614 
Sophos    20130615 
SUPERAntiSpyware    20130615 
Symantec    20130616 
TheHacker    20130615 
TotalDefense    20130614 
TrendMicro    20130616 
TrendMicro-HouseCall    20130616 
VBA32    20130615 
VIPRE    20130616 
ViRobot    20130615 




















 
































 


 
































 




















































































































       
 
   
 
 
















 Blog |  Twitter |  contact@virustotal.com
Title: Re: trz.tmp files
Post by: jeffce on June 17, 2013, 01:20:43 AM
ComboFix
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
----------
Title: Re: trz.tmp files
Post by: jeffce on June 19, 2013, 01:52:02 PM
Still with me?
Title: Re: trz.tmp files
Post by: edysuperb on October 15, 2013, 10:46:32 AM
I have a solution,, hope its work..
i already try,, and its work for me..


first add "take ownership" to your pc...
http://www.howtogeek.com/howto/windows-vista/add-take-ownership-to-explorer-right-click-menu-in-vista/

second go to file location of trz.tmp file.
 Example [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]

right click of file and "Take ownership"

last delete all trz file..


Hope it helpfull..

Title: Re: trz.tmp files
Post by: Marco POLO on November 04, 2013, 07:00:15 PM
I have a solution,, hope its work..
i already try,, and its work for me..


first add "take ownership" to your pc...
http://www.howtogeek.com/howto/windows-vista/add-take-ownership-to-explorer-right-click-menu-in-vista/

second go to file location of trz.tmp file.
 Example [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]

right click of file and "Take ownership"

last delete all trz file..


Hope it helpfull..

Thanks for your hint: it worked for me (http://emoticon.gregland.net/emoticon/@GregLand/ay.gif)  > this bloody "trz*.tmp" installed itself in one of "My Documents" files, on an external hard disk, and used to "eat" all of my ram (http://emoticon.gregland.net/emoticon/@GregLand/aq.gif)  . As it was Avast who alerted me, I tried a complete scan with it (with my own deep requirements); then, I used Spybot... did a full scan disk... CCleaner... Glary... with no results but stopping all the alerts  > however, it was still where Avast told me (got to know about it by pointing the name in the alert with my mouse (it would be time Avast finds a solution since, on all fora I went, all victims of this malware used this antivirus). (http://emoticon.gregland.net/emoticon/@GregLand/dk.gif)

Following your advise, I downloaded "Take Ownership" and operated as you indicated: I at least could remove the last "trz*.tmp" without it replicating. (http://emoticon.gregland.net/emoticon/@GregLand/em.gif)

Thanks a lot, (http://emoticon.gregland.net/emoticon/@GregLand/ad.gif)
Marco
Title: Re: trz.tmp files
Post by: Marco POLO on November 06, 2013, 04:26:58 PM
Hi edysuperb and jeffce,

Bad news: trz*.tmp still are there, in my external Hard Drive in "$RECYCLE.BIN", and still memory eating. (http://emoticon.gregland.net/emoticon/Triste/triste_1.gif)
Title: Re: trz.tmp files
Post by: Marco POLO on November 11, 2013, 04:08:51 PM
Hi edysuperb and jeffce,

Bad news: trz*.tmp still are there, in my external Hard Drive in "$RECYCLE.BIN", and still memory eating. (http://emoticon.gregland.net/emoticon/Triste/triste_1.gif)

In fact, as far as I am concerned, the solution was quite simple: since windows updates last month, there was quite a few of those I could not install... due to only one security program. I had to install those "compatible" updates one by one to find out only one does not work and, now, no more remains of "trz*.tmp" in CCleaner. (http://emoticon.gregland.net/emoticon/@GregLand/ad.gif) (http://emoticon.gregland.net/emoticon/@GregLand/ay.gif)