Author Topic: Need help removing TMZ virus  (Read 7665 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Need help removing TMZ virus
« on: January 16, 2015, 08:58:44 PM »
Uh, I'm basically just copying another person's post but you'll understand why, I would have attached all the logs and such but I'm not sure if the procedure would still be identical or if the responses he got would be up-to-date

I have recently acquired the virus trz.tmp and have been worrying about it for the past few hours. I recently came across the knowledge that this virus is specific to each machine and has to be handled specifically; and with me and my limited knowledge i have no clue what to do so i was wondering if you of you lovely people would be kind enough to help.  :D

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing TMZ virus
« Reply #1 on: January 16, 2015, 09:09:29 PM »
Could you attach the logs please :)

REDACTED

  • Guest
Re: Need help removing TMZ virus
« Reply #2 on: January 17, 2015, 01:52:17 AM »
Mbam took ages to scan, now that I'm trying to install Farbar I'm having more issues - every time I click the download link (from bleepingcomputer.com, the first google result that comes up) avast tells me the website is suspicious, went through and downloaded it anyways, once the download finished (all three times, from a number of sites) avast and avira both told me that the file was malicious and recommended I quarantine it. Should I just ignore this?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Need help removing TMZ virus
« Reply #3 on: January 17, 2015, 11:35:22 AM »
Yes, ignore it
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Need help removing TMZ virus
« Reply #4 on: January 17, 2015, 11:48:42 AM »
Quote
  avast and avira both told me   
So you have avast and Avira installed ...... never install multiple AV

Why Using Multiple Antivirus Programs is a Bad Idea   http://blog.kaspersky.com/multiple-antivirus-programs-bad-idea/

General: Uninstalling a third-party antivirus software  https://www.avast.com/en-eu/faq.php?article=AVKB11#artTitle

REDACTED

  • Guest
Re: Need help removing TMZ virus
« Reply #5 on: January 17, 2015, 10:20:43 PM »
Uninstalled Avira, still having issues downloading FRST. Pretty sure the only way I'll be able to actually download the file is by switching Avast's shields off but I feel that with TMZ detections attacking me every other minute this probably isn't the wisest idea.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Need help removing TMZ virus
« Reply #6 on: January 17, 2015, 10:45:50 PM »
Quote
Pretty sure the only way I'll be able to actually download the file is by switching Avast's shields off     
That is exactely what you have to do so essexboy can get those logs and fix your issue......


REDACTED

  • Guest
Re: Need help removing TMZ virus
« Reply #7 on: January 18, 2015, 07:10:07 PM »
Well, three days later and my computer finally finished the freakin scans

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing TMZ virus
« Reply #8 on: January 18, 2015, 07:29:28 PM »
Hi you also have AVG installed, either that or Avast will need to go

Could you post a screenshot of the Avast popup please

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
C:\Program Files\GUT28C9.tmp
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Need help removing TMZ virus
« Reply #9 on: January 18, 2015, 07:41:25 PM »
oops, had AVG deactivated for so long I forgot that I even had it. uninstalled. fixlog seems quite inconclusive.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing TMZ virus
« Reply #10 on: January 18, 2015, 09:17:52 PM »
Did you copy all in the quotes to the fixlist as it appears to be empty

REDACTED

  • Guest
Re: Need help removing TMZ virus
« Reply #11 on: January 18, 2015, 09:22:35 PM »
i did, that's why i mentioned how inconclusive it was

REDACTED

  • Guest
Re: Need help removing TMZ virus
« Reply #12 on: January 18, 2015, 09:23:25 PM »
im still trying to get a result

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help removing TMZ virus
« Reply #13 on: January 18, 2015, 10:06:11 PM »
Something weird is happening that I am not seeing

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

REDACTED

  • Guest
Re: Need help removing TMZ virus
« Reply #14 on: January 19, 2015, 01:36:17 AM »
k, farbar gave me some output now, but of course i'm having more issues

combofix didn't produce a log - either in c:/, or on the desktop where the executable's located.

i did, however, have to download combofix twice and the second time it saved as ComboFix(1).exe. I ran the executable under that name, it scanned fine but afterwards i got an error saying "you cannot rename ComboFix as CombiFix(1)" and it renamed itself back to ComboFix. i don't know if that had anything to do with the log?