core.cache.dsk removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by SuzeeH66, Jan 21, 2008.

  1. SuzeeH66

    SuzeeH66 Private E-2

    i have read what you said and have done some but i cant seem to get the RenV to load and go on desktop. when i open it the command.com box shows up than all i get is
    Code:
    Ran on Mon 01/21/2008 - 11:57:13.89
    
    
    in a note pad box. what am i doing wrong and why is it when i start computer the command.com box shows up? i went into safe mode and thought i got rid of the core.cache.dsk but went to look and there it is again. so i know something is running it but have no clue what.
    i really need to get this virus out of my driver so any help would be greatly appreciated.
    thanks
     
  2. SuzeeH66

    SuzeeH66 Private E-2

    HERE IS MY HIJACKTHIS SCAN I FORGOT TO ADD THAT TO MY POST.

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.

    I HAVE TRIED SEVERAL ATTEMPTS TO GET RID OF THIS CORE VIRUS WITH NO LUCK. I READ SOME OF THE OTHER POST BUT SOME THINGS ARE NOT WORKING. I RUN WINDOWS XP PROFESSIONAL AND I GO THROUGH CABLE MODEM.
    I REALLY REALLY NEED HELP FIXING COMPUTER. I SCANNED IN SAFE MODE AND IT TOOK THE CORE INFECTION AWAY BUT AS SOON AS YOU USE COMPUTER THE THING COMES BACK ON. IF YOU NEED ANY OTHER INFO PLEASE LET ME KNOW. THANKS
     
    Last edited by a moderator: Jan 22, 2008
  3. SuzeeH66

    SuzeeH66 Private E-2

    just to let you know i also use firefox . hope that helps i am going to do that bitdefender thing you told someone else to do will post if it helps thanks:confused
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. SuzeeH66

    SuzeeH66 Private E-2

    Removed Inline log
     

    Attached Files:

    Last edited by a moderator: Jan 23, 2008
  6. SuzeeH66

    SuzeeH66 Private E-2

    i did that smitfraudfix and i could take the core.cache.dsk and put in reccle bin but when i go to normal startup low and behold the core.cache.dsk is back in windows. so far everything i have tried that this site says to do has failed. now what???? there has to be something running that is causing it to start back up in normal startup otherwise it wouldn't show up again and again. plus everytime i start up i get a box C:\WINDOWS\SYSTEM32\COMMAND.COM why am i getting that every startup? i so didn't want to have to reformat my computer but if i cant get rid of that darn thing might be only thing to do. any other suggestions????????????? please help

    thanks
     
  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi SuzeeH66



    In Post 4 above the guide from Chaslang needs to be run and the logs requested from that guide need to be attached for anyone to help you remove this pest, reading other peoples post and threads on similar issue will or may not work as your infection maybe slightly different, so please follow what Chaslang posted in post 4 for us to help you, you need to help us.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    fter these are attached our malware experts will review these to see if your OK, if not they will issue you some further removal instructions, plus a guide on how to attach the logs HOW TO: Attach Items To Your Post

    So logs that you will get to attach are:

    MGlogs.zip (which has 5 logs inside it, including Hijackthis, just attach the whole Zip )
    AVG log. ( Which is the report scan txt file )
    Combofix logs.

    http://img117.imageshack.us/img117/829/60272555mm4.jpg
     
  8. SuzeeH66

    SuzeeH66 Private E-2

    That Combofix.exe You Have Needs Updated It Took It All Night And It Was Still Running So Went To Web And Got Update Version And It Took Less Than 20 Mins For The Thing To Do What It Needed To Do And Give Me Log So Here Is Log For Combofix. I Will Be Scanning The Avg Next Than The Other And Will Report Then When Done. Thanks For Help. The First Time It Ran I Know It Said Deleting The Core.cache.dsk So Not Sure If Second Time It Did Or It Was Done First Time!
     
    Last edited by a moderator: Jan 24, 2008
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The operative word was attach.

    See this: HOW TO: Attach Items To Your Post
     
  10. SuzeeH66

    SuzeeH66 Private E-2

    HERE IS AVG REPORT STILL GOT TO DO THE MG ONE WILL DO THAT NEXT AND POST SORRY NOT DOING ALL AT ONCE BUT BUSY.
    "General properties",""
    "Report name","Complete Test"
    "Start time","1/24/2008 3:04:20 PM"
    "End time","1/24/2008 5:05:23 PM (total: 2:01:03.7 hrs)"
    "Launch method","Scanning launched manually"
    "Scanning result","No threats found"
    "Report status","Scanning completed successfully"
    " ",""
    "Object summary",""
    "Scanned","247077"
    "Threats Found","0"
    "Cleaned","0"
    "Moved to vault","0"
    "Deleted","0"
    "Errors","0"
     
  11. SuzeeH66

    SuzeeH66 Private E-2

    Ok Ran The Mgtools And It Didn't Come Up With Anything That I Could See Is There Suppose To Be A Log I Submit To You From It If So Where? LOOKED IN WINDOWS SYSTEM 32 DRIVERS AND YEP CORE.CAHCE.DSK IS STILL THERE NOW WHAT???
     
  12. SuzeeH66

    SuzeeH66 Private E-2

    here is that combofix report i did it again
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The MGLogs is right here:
    C:\MGlogs.zip

    All you need to do is attach that ....and tell me how many anti-virus programs you have running.
     
  14. SuzeeH66

    SuzeeH66 Private E-2

    i enabled the antivirus ware on here. so none running. it said for the combofix to have nothing running while its doing scan so i just went to msconfig and disabled everything on startup til i am done and this computer is fixed. i limit how long i am on so my computer dont get hurt worse than it is. let me know waht to do next cause i know its still there. boy its stubborn thing to get rid of..


    thanks

    actually just looked and its not in windwos\system32\drivers anymore but computer is still not acting right so thinking there is more to this than just that mallware what do you think? i ran superantispyware last night thorough scan and it only found cookies. going to run avast tonight. i do it when i am going to bed cause it takes long time. i am afraid if i reboot that thing will reload so not doing anything else til i hear from you except the virus scans i just said.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go to msconfig and reset it to normal startup ....See this: Dealing with Startup Processes.

    I cant help as much when it is in selective startup ....things don't show!

    The instructions just meant not to be running (actively) any other program while the scan is running.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now re-run ComboFix

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger and the Combofix log.





     
  16. SuzeeH66

    SuzeeH66 Private E-2

    here is the avenger log
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You also needed to attach the new MGLogs.zip ....but tell me how things are running also.
     
  18. SuzeeH66

    SuzeeH66 Private E-2

    tim for some reason it wont allow me to run the combofix again it starts the process but when it reboots no new window comes up nor does it give me a log. i have tried everything even deleted and reinstall it. but can do the mglog in an hour. than will post that. i am wondering if that mallware could have messed up my computer drivers or something else. for some reason my flat screen monitor wants to shut off for now reason. i can be using it and boom goes blank and sometimes it goes on off on off for several mins before it works right again. i asked my son and he said there is no driver for the monitor and says he has no clue why it would do that. he was going to just reformat me yesterday but my cd rom is old so wouldn't take the windows xp startup cd. so since i cant have it reformated any time soon i still need your help fixing this dumb thing.

    thanks
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Two things to try:

    FIRST:
    Please disable your antivirus program while running this scan to avoid running into issues with your existing program conflicting with the online scan.

    Notes:
    • You must use Internet Explorer to run this scan.
    • If you are using Vista, right click IE and "Run as Administrator" or the online scanner will not work properly.
    Click on this ESET Online Scannner to begin the process.
    • Check the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to be installed.
    • Click Start
    • Check below options:
      • Remove found threats
      • Scan unwanted applications.
    • Click Scan
    • Wait for the scan to finish
    • When it finishes it will create a log file here: C:\Program Files\EsetOnlineScanner\log.txt
    • Attach this logfile to your next message.
    SECOND:

    Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  20. SuzeeH66

    SuzeeH66 Private E-2

    here is the new mgtools log. i really dont want to run that bitfender it messes up my computer. any other suggestions. do i have to keep running and downloading all this stuff isn't that thing removed yet??
     

    Attached Files:

  21. SuzeeH66

    SuzeeH66 Private E-2

    i dont know how to find internet explorer to use that thing. i have firefox and thats my main browser window.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean ...however you have both AVG and Avast running ...you should only have one anti-virus program, so please uninstall one of them.

    What problems are you still having?
     
  23. SuzeeH66

    SuzeeH66 Private E-2

    thanks Tim for all the help. I will probably take off avg i really like avast. take care and thanks again.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds