cant shake this: core.sys and core.cache.dsk

Discussion in 'Malware Help (A Specialist Will Reply)' started by clarson, Sep 16, 2008.

  1. clarson

    clarson Private E-2

    it appears to me i need to send a log file after reading many other post about this pain in the butt program...i'm new here & to all sites like this, so someone please help!

    i've got a wife who wants me to run for dinner now, but will be back soon!

    thanks!

    chuck
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. clarson

    clarson Private E-2

    ok, here's what i've tried so far...
    from reading others' problems and tring several times to run: super antispy free edition, spybot search & destroy, to no avail. then i did the 'avenger' program, which says it deletes the files, but when i reboot, they're still there: mine are not located in the windows directory, rather the winnt\system32\drivers, the files it says it deleted are: core.cache.dsk & stream.sys. but it really didn't. bummer. so then i tried the boot to safe mode, and that is missing or corrupt, as well, it loads what looks to be about half, then locks up. bummer bummer. so the next thing i tried, unsuccessfully, is the combofix.exe noted here, which i'll try to attach the log file for your review. i don't know what else to do, getting very frustrated. oh, by the way, i uninstalled the javaruntime and with the help of spybot advanced tab, taken alot of the startup items out of the equation as well.

    hope you can help!

    thanks

    chuck
     

    Attached Files:

    • log.txt
      File size:
      11.1 KB
      Views:
      3
  4. clarson

    clarson Private E-2

    these attached files are the log texts requested
    LOOKS LIKE IT FINALLY WORKED!! YEAH! BUT WHAT ABOUT THE PROBLEM OF NOT BEING ABLE TO SAFE MODE BOOT?
     

    Attached Files:

    Last edited: Sep 17, 2008
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to disable Spybot's Teatimer as requested in the READ & RUN ME and you must put your system into Normal Startup mode with MSconfig as requested in step 1 of the READ & RUN ME.

    You need to attach the requested log from MGtools. Make sure this is a new log after doing the above two items.

    Also do not do anything else unless except what we ask you to do.
     
  6. clarson

    clarson Private E-2

    appreciate all the info on the site, the read & do me first actually finally fixed the problem with the core.cache, but how about not being able to safe mode boot?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Will will get to it when you finish attaching the required logs after Teatimer is disabled and your system is in Normal Startup mode. Until you do this, we cannot even attempt a fix for your safe boot mode issue.
     
  8. clarson

    clarson Private E-2

    i dunno what treatimer is, my system seems fine, the core.cache problem is gone, it works in normal startup mode. I just through trying to fix the core.cache came across the problem of not being able to safe boot.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It was explained in the READ & RUN ME where you were give this link: How to disable Spybot's TeaTimer

    If you are not going to complete my last instructions and attach the last requested log from Mgtools, there is nothing else I can do for you.
     
  10. clarson

    clarson Private E-2

    OK, DISABLES THE TREATIMER, FOLLOWED ALL THE INSTRUCTIONS ON THAT PAGE, AND AM ATTACHING THE LASTEST LOG FILE AS REQUESTED....THANKS AGAIN.! WHEN I RAN THE MGTOOLS TO ATTACH THE LOG FILE, I GET THIS MESSAGE:
    16 bit MS-DOS Subsystem
    C:\WINNT\system32\cmd.exe
    C:\WINNT\SYSTEM32\AUTOEXEC.NT. The system file is not suitable for running MS-DOS and Microsoft Windows applications.
    Choose 'Close' to terminate the application.
    then after clicking ignore... the dos box : the process cannot access the file because it is being used by another process. NOTE: Ignore any error messages about not finding registry keys! Just wait for the program to finish running!...so i clicked ignore again...and again & again, but kept getting this: the process cannot acces the file because it is being used by another process...(over & over, until i clicked close)
    by the way, i ran this mgtools befor, just forgot to send the log file... here it is again.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you know that your Norton Antivirus program is broken and that you are running without protection?

    Your logs still show Teatimer being loaded. Make sure it has been disabled. Also you are still using Msconfig to control startups. You need to put your PC into Normal Startup mode with MSconfig as requested in step 1 of the READ & RUN ME.

    Also uninstall the below software as was requested in step 1 of the READ & RUN ME:
    Java 2 Runtime Environment, SE v1.4.2
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    Now reboot your PC after ALL of the above has been completed.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    This error message was explain in the Using MGtools link given in the READ & RUN ME. You need to apply the fix that was provided and then run MGtools again. Due to the error you received, your logs were incomplete.
     
    Last edited: Sep 19, 2008
  12. clarson

    clarson Private E-2

    believe it or not, i did read your instructions & disabled the teatimer befor, but i didn't reboot, anyway, i made sure that was not running, deleted all the programs you said to do, re-installed the java, ran the xphome file,which i previously installed to: c:\winnt\system32, but when i run the mgtools, i still get the same error message i refrenced earlier...here is the new log file.
    thanks for your help---again! dunno if it matters, but i found a "command.com" file in c:\windows\system23, should i run the xphomefile from there as well?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you extracting ALL of the files from the XPHomeFile.exe into your C:\WinNT\System32 folder? The fix will not work if all the files are not extracted to the default suggested folder which is your system32 folder.

    All of the below files need to be in your system32 folder:
    Config.nt
    Autoexec.nt
    Command.com
     
  14. clarson

    clarson Private E-2

    There are only three files extracted, i even re ran this with the check box cleared for overwriting automatically, but i noticed that the windows\system32 dir. Has command.exe file in it as well...what now?
    (btw...i'm never able to sucessfully update windows sp3) the location of xphomefile.exe is c:\winnt\system32\...
     
  15. clarson

    clarson Private E-2

    I coppied all three of those files to the winnt/system32 folder and am going to re-run the mgtools and send you another logfile
     
  16. clarson

    clarson Private E-2

    Here's the new log file
    seemed to work as expected this time...(i replaced all three of those files)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Norton/Symantec Antivirus program appears to be totally broken. Did you try to uninstall this? If you did, it was not completed properly. You have no antivirus protection right now.

    Are the below things you knowingly installed?
    Games Add-in for Windows Liver Toolbar
    Search Preview Add-in for MSN Search Toolbar


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O8 - Extra context menu item: &Search - ?p=ZZ
    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
    O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} (Java Plug-in 1.4.2) -


    After clicking Fix, exit HJT.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Copy the bold text below to notepad. Save it as SBCfix.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now! Can you boot in safe mode now?
     
  18. clarson

    clarson Private E-2

    Hey, thanks for all your help so far, i really appreciate it! The core problem is gone, i didn't get any errors when i updated the registry, am attaching the combofix.text & mglogs.zip, i will let you know if i can boot safe now...dunno if it matters, but the games button in live toolbar was installed along time ago, but i haven't been able to get the live toolbar to work since befor the core.cache problem...will update you soon

    thanks again

    chuck
     
  19. clarson

    clarson Private E-2

    Heres the files i forgot to attach...
     

    Attached Files:

  20. clarson

    clarson Private E-2

    so i tried to safe boot, locks up at this line:
    multi(0)disk.(0)partition(1)\winnt\system32\drivers

    then when i unplugged power for 10 sec & rebooted, i first get this message:
    svchost.exe applicaion error
    the instructions @ "0x688e3742" refrenced memort at "0xffffffff"
    ok to term, or cancel to debug, i first hit debug, another error & then termintated...
     
    Last edited: Sep 24, 2008
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the below then reboot. After reboot run it one more time.

    Norton Removal Tool (SymNRT)

    Now put your PC into Normal Startup mode as was requested in step 1 of the READ& RUN ME.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop (yes you should over write the previous file). Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  22. clarson

    clarson Private E-2

    ok, thanks again for your help, i did those things, but havent tried safe mode yet, will keep you informed.
    attached are the files

    thanks again

    chuck

    ps

    wouldnt let me uploat the combofix,txt file, said i already had...
    will try later
    late for football now
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not have installed McAfee while we are trying to fix your PC. As stated in the READ & RUN ME, once you start the process, you must only do what we ask you to do and nothing else.

    That means you did not successfully run the fix I gave to you. If you had, the combofix.txt log would be different. Look inside of the combofix log that you are trying to attach and you will probably see the below line which is that date from the previous run:

    ComboFix 08-09-16.01 - Mary 2008-09-24 10:29:11.3 - NTFSx86

    Try the whole fix again and make sure you do not allow anything to block ComboFix from running. More than likely McAfee is now getting in your way.
     
    Last edited: Sep 27, 2008
  24. clarson

    clarson Private E-2

    ok, thanks again,i re-ran all the instructions and am sending to log files

    will let you know if i can't safe mode boot

    thanks

    chuck
     

    Attached Files:

  25. clarson

    clarson Private E-2

    still can't safe boot

    still locks up at:
    mulit(0)disk.(0)partition(1)winnt\system32\drivers\agp440.sys

    let me know

    thanks

    chuck

    i did install a virus protection from cox.net (mcafee security suite) and updating windows to sp3 never completes either
     
    Last edited: Sep 27, 2008
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware problem. See the below and post in the Software Forum for any addition questions related to this:

    http://support.microsoft.com/kb/324764


    Also a topic for the Software Forum.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds