Desktop.ini Trojan Infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Deadshot, Jul 10, 2012.

  1. Deadshot

    Deadshot Private E-2

    Hello all,

    First time poster, hope I followed all of the steps necessary to make my thread here. My antivirus recently ran into three trojans that seem to be causing me some trouble and some concern. I'm not necessarily tech-savy but I can follow directions well. Here is my situation:

    http://www3.picturepush.com/photo/a/8697146/640/8697146.jpg

    Any help would be appreciated. I backed up my PC two days ago but from what I'm reading the files would have been in the system already anyway.

    Thanks in advance!
     
  2. Deadshot

    Deadshot Private E-2

    And here is my FRST.txt file:
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You did not use a current version of FRST. Please follow the below to use a current version and get us a new log.


    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  4. Deadshot

    Deadshot Private E-2

    Thank you for your reply! Here is my FRST file from my new scan:
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Attach the below log:
    • Fixlog.txt
    How are things working now?
     
  6. Deadshot

    Deadshot Private E-2

    Once again - thanks! The computer was working fine before but it was warning me about the three files. I will attach the log here and then run a final scan to see if the files are still there. I have since changed several of my key passwords. Is there anything else I need to do with my machine?
     

    Attached Files:

  7. Deadshot

    Deadshot Private E-2

    Completed the second scan of the PC and I have 2 infected files that are now in the C:\FRST\Quarantine folder.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing to worry about since that is what we put there during the fix. You can delete this folder now and also the FRST.exe program.

    If you are not having any other malware problems, it is time to do our final steps:

    1. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    2. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds