Need help with core.cache.dsk

mamcintyre

New Member
Somehow I have become infected with popups.
However today, somewhere along the line (i think from an advertistment on a regularly visited site), I have become infected!

Spybot found that I have core.cache.dsk located in windows/system32/drivers.

Spybot can't remove it even after reboot.

I don't see it when i boot in safe mode.


I have followed all instructions found here with no success
http://www.pchell.com/support/poweredbyzedo.shtml



Please help
 
Your log reveals a backdoor trojan. These can severely compromise personal information which could lead to identity theft.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC may already be compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

If you wish to remove the infections present, please do the following:

Please run HijackThis and choose Do a system scan only.

Place a check next to the following entries:
  • O4 - HKCU\..\Run: [Windows Kernel 64] C:\WINDOWS\System32\kernal64.exe
  • O4 - HKUS\S-1-5-18\..\Run: [nVidia Drivers] nVidiaDrvers.exe (User 'SYSTEM')
Please close all open windows except for HijackThis and choose Fix checked

Please delete the following files:
C:\WINDOWS\System32\kernal64.exe
C:\WINDOWS\System32\nVidiaDrvers.exe


Once done, please do the following:
1. Please download this file - ComboFix to your desktop
2. Double click ComboFix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply together with a new HijackThis log.

Note:
Do not mouseclick ComboFix's window whilst it's running. That may cause it to stall
 
OK, I ran hijack this. Checked the two entries.

I could not find the two files you mentioned. I copied and pasted what you sent ( filenames ) nothing showed up in windows. I then searched all of C drive. In your reply kernel was spelled kernal so i tried kernel also.

I ran combofix after fixing the registry with hijack this.

Here are my logs.

Thanks for the help i still have the pesky popups. They go to a blank page.

I also get a alert from spybot ever so often saying a registry entry is trying to be changed.

Category browser page
old data
http://www.google.com/ie
new data www.microsoft.com/isapi/redir.dll?prd=iear=iesearch

also another

Category browser page
old data http://www.google.com/ie
new data
http://ie.search.msn.com/{SUB_RFC1776}/srchasst/srchasst.htm


I have been denying the changes via spybot
 

Attachments

I have decided to bag this hard drive. Its my wifes computer and really needs an upgrade anyhow. So I'll trade her 60G for a 320G ultra ATA 100 ($85 onnewegg ). There isn't anyway a virus can penetrate farther than the harddrive is there. They can't squirrel something in the CMOS can they??

I took your suggestion and took it off my home network!!!

The turning point for me is now I can't boot in safe mode.

Thanks for the heads up!!
 
Glad to help. They can't infect the CMOS, or anything else other than your hard drive, so with a new hard drive and clean install you should be virus free.
 
Back
Top