![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Hello
I keep having a MSSI popping up with 2 Trojans located c:\Windows\assembly\GAC_32\Desktop.ini and it keeps sayinh removed have to reboot but nothing. MSSI Dectected Items: Trojan:Win32/Sirefef.AB Trojan:Win32/Sirefef.P Both in the location: c:\Windows\assembly\GAC_32\Desktop.ini I have followed http://forums.majorgeeks.com/showthread.php?t=139681 and here I am. Combofix did not run when I did the steps requested but I did runit before asking for help here so I attached that log file. This was picked up when my son went on a site that looked like youtube and on the flashscreen it had your Adobe Flash player need to be updated and when he clicked it and ran the file he got it. This was about a week ago. Thank you |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
I want you to run TDSSKiller so refer to the below for how to do so.
TDSSkiller - How to run Please also download MBRCheck to your desktop
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
Gemini II (05-30-12) | ||
|
#3
|
|||
|
|||
|
Thank you for the reply.
Here are the files requested. thank you |
|
#4
|
||||
|
||||
|
No problem.
Now we need to use ComboFix
Code:
KILLALL::
File::
C:\windows\assembly\GAC_32\Desktop.ini
C:\windows\assembly\GAC_64\Desktop.ini
C:\windows\SysNative\drivers\cxadnzlq.sys
Folder::
C:\ProgramData\Ask
Registry::
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{04CD4AEE-FAFE-4047-9129-D3A2ED337B87}]
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#5
|
|||
|
|||
|
Hello
When I drag the file onto ComboFix it does its file extraction but thats it. No ComboFix.txt file no Stages. Thank you |
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Download and run OTM.
Download OTM by Old Timer and save it to your Desktop.
Code:
:reg
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{04CD4AEE-FAFE-4047-9129-D3A2ED337B87}]
:files
C:\windows\assembly\GAC_32\Desktop.ini
C:\windows\assembly\GAC_64\Desktop.ini
C:\windows\SysNative\drivers\cxadnzlq.sys
C:\ProgramData\Ask
:Commands
[emptytemp]
[Reboot]
NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#7
|
|||
|
|||
|
Hello
Thank you here are the files requested. Is this all me are doing? Can i re-enable MSSE? |
|
#8
|
||||
|
||||
|
Quote:
Quote:
I don't know why OTM could not delete that file. Let's try again.
Code:
:Processes explorer.exe :files C:\windows\assembly\GAC_32\Desktop.ini C:\windows\assembly\GAC_64\Desktop.ini :Commands [emptytemp] [Reboot]
NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#9
|
|||
|
|||
|
Hello
np thank you for all your help I just thought that was all as at the end of the post you put let me know how things are running now! Should i uninstall MSSE i tried to remove those files with it so that might be holding them somehow? Here are the new files. |
|
#10
|
||||
|
||||
|
That's done it.
![]() How is everything running now? Ready for final steps?
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Looks like everything is working fine my redirects have stoped WHOOO HOOO.
Ok ready for the final step. Thank you |
|
#12
|
||||
|
||||
|
If you are not having any other malware problems, it is time to do our final steps:
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#13
|
|||
|
|||
|
Just wanted to say thank you again it is working great
![]() |
|
#14
|
||||
|
||||
|
Well, from one Gemini, to another, "You are most welcome"
![]()
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| GAC_32/GAC_64 desktop.ini help | thepspgamer | Malware Removal | 38 | 05-29-12 15:46 |
| Help, I have zeroaccess rootkit / GAC_32 desktop.ini virus | masumane | Malware Removal | 4 | 05-26-12 12:55 |
| Removing GAC_32 and 64\Desktop.ini | dislocatedkarma | Malware Removal | 16 | 05-24-12 21:08 |
| GAC_64\Desktop.ini, assembly\temp\u\00000002.$/@ and assembly\temp\u\80000032.@ HELP | scybez | Malware Removal | 1 | 04-24-12 13:29 |
| (c:\Windows\assembly\GAC_32\Desktop.ini) Keeps me off Internet: Partially Removed? | talent4theworld | Malware Removal | 22 | 02-09-12 14:54 |