![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
OK i did read the official "read me" topic but the reason it won't help, is because I've tried mostly everything in there already.... I'm running Windows 7, and I fully updated MBAM, TDSSKiller, Spybot S&D and SuperAntiSpyware. None of them can find the problem.
However, Hitman Pro is able to find it... It's desktop.ini in Windows/assembly/GAC_32 and also Windows/assembly/GAC_64. It just can't seem to get rid of it, even when I allow it to reboot my computer. I've tried running all these programs in safe mode too, but they can't get rid of whatever seems to be redirecting my google searches and constant popups. And finally, the last thing I should mention is I have tried Combofix (in safe mode, too) but the problem with it is it finishes extracting files and then it just closes. I think it's time I bust out the heavy weapons and get some advice from you guys. I would greatly appreciate any help, and hope to be rootkit free by tomorrow. |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
I just ran ENODs online scanner, it found 26 infected files, automatically quarantined them and I saved a log.. Here it is (Im using windows 7 64 bit)
By the way I'm guessing all the other topics I'm seeing on the front page about desktop.ini and whatnot are people who also got the virus from some jerk who posted on demonoid... At least he's banned now I think :b |
|
#3
|
||||
|
||||
|
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
|
#4
|
|||
|
|||
|
Thanks Tim. Here are the logs that were requested on that page, from Goored and MBRcheck... Also, Kapersky TDSSKiller did not fix the redirecting (and yep I ran it as administrator)
|
|
#5
|
||||
|
||||
|
I need the following logs:
TDSSKiller SAS MBAM ComboFix C:\MGLogs.zip
__________________
Major cake licker. YCLAHTW, BYCMHD!! Major Geeks on Facebook Major Geeks Newsletter |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| GAC_32/GAC_64 desktop.ini help | thepspgamer | Malware Removal | 38 | 05-29-12 15:46 |
| Removing GAC_32 and 64\Desktop.ini | dislocatedkarma | Malware Removal | 16 | 05-24-12 21:08 |
| Infected with Rootkit.ZeroAccess on desktop | zamorazeke | Malware Removal | 25 | 04-26-12 22:28 |
| (c:\Windows\assembly\GAC_32\Desktop.ini) Keeps me off Internet: Partially Removed? | talent4theworld | Malware Removal | 22 | 02-09-12 14:54 |
| Help for a NOOB - Rootkit.ZeroAccess Virus | riveraider | Malware Removal | 1 | 01-26-12 19:36 |