View Full Version : Desktop.ini infected with GAC_64/32 trojan
Sugaree
August 1st, 2012, 06:53 PM
Recently ran a quick scan with McAfee and got this:
http://prntscr.com/d2s3u
For the last two hours, I've been trying to find an actual solution, but because of the virus, all search engines are redirecting me to ad sites (which I swear was not happening yesterday). So what can I do? This is really confusing me.
Wayne92
August 1st, 2012, 07:27 PM
If you can't manual remove the virus, your best bet is to reformat your computer. Do you have your files backed up?
Sugaree
August 1st, 2012, 07:30 PM
If you can't manual remove the virus, your best bet is to reformat your computer. Do you have your files backed up?
Always do. Guess I'll try reformatting.
Commander Thor
August 1st, 2012, 07:47 PM
Any chance you can get rstrui.exe running? (System restore)
Since desktop.ini is a system file, performing a restore should be able to 'fix' it. Then do a full system scan afterwards to be sure nothing is left of it.
Cblood
August 1st, 2012, 11:43 PM
Before Reformating Try these steps:
Manual Trojan.zeroaccess.B Removal
Reboot the PC and keep pressing F8 key on the keyboard before Windows launches. Hit the arrow keys to choose “Safe Mode with Networking” option, and then tap Enter key to enter Safe Mode with Networking.
Step1: Open Task Manager and end all the malicious processes created by Trojan.zeroaccess.B. ( Methods to open Task Manager: Press CTRL+ALT+DEL or CTRL+SHIFT+ESC or Press the Start button->click on the Run option->Type in taskmgr and press OK.)
Step 2: Go to Regitry Editor and delete malicious registry entries related to Trojan.zeroaccess.B:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\random
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run\ random
Step 3: Search and Remove malicious files of Trojan.zeroaccess.B:
C:\WINDOWS\assembly\GAC\Desktop.ini
C:\WINDOWS\system32\ping.exe
Rayquaza
August 2nd, 2012, 09:09 AM
You could try launching windows in safe mode and then start McAfee and remove the virus.
(Pressing F8 during boot sequence)
Telkanis
August 3rd, 2012, 07:22 PM
Another thing you can do is install Linux to a USB drive and boot the computer from the USB drive. Then find a virus checker and the virus checkers on your windows drive/partition. Linux puppy is pretty small and good for the task.
Sugaree
August 12th, 2012, 06:16 PM
Any chance you can get rstrui.exe running? (System restore)
Since desktop.ini is a system file, performing a restore should be able to 'fix' it. Then do a full system scan afterwards to be sure nothing is left of it.
Unfortunately I didn't make a backup image of the system beforehand. So I'm unable to do a system restore.
Before Reformating Try these steps:
Manual Trojan.zeroaccess.B Removal
Reboot the PC and keep pressing F8 key on the keyboard before Windows launches. Hit the arrow keys to choose “Safe Mode with Networking” option, and then tap Enter key to enter Safe Mode with Networking.
Step1: Open Task Manager and end all the malicious processes created by Trojan.zeroaccess.B. ( Methods to open Task Manager: Press CTRL+ALT+DEL or CTRL+SHIFT+ESC or Press the Start button->click on the Run option->Type in taskmgr and press OK.)
Step 2: Go to Regitry Editor and delete malicious registry entries related to Trojan.zeroaccess.B:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\random
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run\ random
Step 3: Search and Remove malicious files of Trojan.zeroaccess.B:
C:\WINDOWS\assembly\GAC\Desktop.ini
C:\WINDOWS\system32\ping.exe
Tried this. Go to regedit, couldn't find anything that appeared malicious because it was all stuff I recognized. I also went into assembly and couldn't find GAC, which struck me as odd.
Commander Thor
August 12th, 2012, 11:56 PM
Unfortunately I didn't make a backup image of the system beforehand. So I'm unable to do a system restore.
Unless you disabled it (WHY WOULD YOU?!?!?), System Restore should have had at least a few restore points from recent times. This is not like Windows Backup where you have to tell it to make an image, this should be running automatically.
Usually a restore point is created every time a Windows Update is applied, or when most software is installed. So you /should/ have a point or two to go back to.
Sugaree
August 13th, 2012, 01:16 AM
Unless you disabled it (WHY WOULD YOU?!?!?), System Restore should have had at least a few restore points from recent times. This is not like Windows Backup where you have to tell it to make an image, this should be running automatically.
Usually a restore point is created every time a Windows Update is applied, or when most software is installed. So you /should/ have a point or two to go back to.
Well, I do have one point, but it's yesterday and I've had this issue since August 2nd/3rd.
http://prntscr.com/dp5vu
Tried looking for more, but nothing turned up. This concerns me, considering I never tamper with System Restore settings.
root
August 13th, 2012, 10:44 PM
So which of these guys solution have you tried? It seems that you have only tried to system restore. Do what shadow said and boot into safe mode. This will be either F8, F9 or F11 depending on you're machine. You'll get a black screen with white letters. Use the arrow keys to highlight over the thing that says safe mode with networking. Once you got your desktop, open your browser and go to this link. This is a direct link for a free version of malwarebytes.
http://software-files-a.cnet.com/s/software/12/64/24/02/mbam-setup-1.62.0.1300.exe?token=1344925767_f526dd9c1ca5d36332a19e50d349f930&lop=link&ptype=3001&ontid=8022&siteId=4&edId=3&spi=de0a5546efdcd2ac5f12f1a1073c4de3&pid=12642402&psid=10804572&&fileName=mbam-setup-1.62.0.1300.exe
Click it and wait for it to download. Install it then run a quick scan. Wait for it. It should take ike 10 minutes but the time varies. Once it's done, it will pop-up with how many malicious items and etc. Click the option to remove all threats and you're good to go. Restart and then boot to normally
Scarface
August 14th, 2012, 10:19 PM
go to bleepingcomputer.net and go to download search ComboFix. I had the same thing and its gone. It worked for me.
vBulletin® v3.8.9, Copyright ©2000-2021, vBulletin Solutions, Inc.