Remedy for core.cache.dsk

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by olli35566, Feb 17, 2008.

  1. olli35566

    olli35566 Private E-2

    Lot's of threads with many postings in each. Made a new thread with my solution instead.
    Moderator; Please copy this to each thread if you think it is better that way.

    This is a nasty little bugger but it turned out it wasn't so hard to get rid of it!
    Most descriptions I found was for a previous version and couldn't be removed by various spyware tools.
    Do this instead:
    1. Do you know or suspect when infection occured?
    2. Boot in safe mode (F8 during start up)
    3. In C:\windows\system32\drivers sort on creation time and lookup the
    date you suspect.
    4. Look for a file that spells whateverR.sys or something11.sys By this I mean
    that the last letter or figure is spelled twice.
    5. See if you have a corresponding file without the last character typed
    twice.
    6. If you have, you have probably found the bugger!
    7. Make a backup of the file in another folder and delete it from the \drivers
    folder (the file with two letters or figures in the end of its name that is)
    8. Reboot normally and check that core.cache.dsk is gone from
    C:\windows\system32\drivers

    It seems that the program copy's the name of a random file in the \drivers folder and repetes the last character in the filename to make its own file to be run on windows start up (not in safe mode though). It then creates the core.cache.dsk and starts its malicious behaviour. This is the reason you can't find it when you run in safe mode.

    I guess there's files and registry entrys left that needs to be removed eventually but at least the file doesn't seem to be active in my system anymore!

    BE CAREFULL WHEN DELETING FILES! I CAN'T TAKE ANY RESPONSABILITY FOR PROBLEMS CAUSED BY THIS SOLUTION.

    Good luck!
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thank you for the imput ....but it is not an accurate tutorial for removal ....which is why we only allow Qualified Malware Removal persons to answer malware threads. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds