PCWorld Forums

PCWorld Forums: Unresolved Issues - PCWorld Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Unresolved Issues

#1 User is offline   mjd420nova 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 3,007
  • Joined: 05-August 06
  • Location:Fremont, California

Posted 09 August 2012 - 08:51 AM

While doing a weekly MacAfee scan of my daughters hard disk, the scan completed but had two unresolved issues, both with the same file. DESKTOP.INI. I'm at a loss on how to correct this. It's a Lenovo laptop with WIN7 installed. There are no other issues and all appears to be normal with that exception. Any ideas??
0

#2 User is offline   ElfBane 

  • Senior Member
  • PipPipPipPipPip
  • Group: Members
  • Posts: 587
  • Joined: 25-September 09
  • Location:Florida

Posted 09 August 2012 - 09:14 AM

Check McAfee's website and see if they are the reporting the desktop.ini as a false positive.
0

#3 User is offline   Flashorn 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 4,401
  • Joined: 19-May 07
  • Location:Canada

Posted 09 August 2012 - 01:49 PM

Hey mjd !

I had that problem in a post some time ago and I know it's not a big issue.

Do you have the the option "Hidden Files" opened (Unhide) in Folder Options?
If yes, I would close (Hide) those files in the same Folder Options in Control Panel.

Desktop.ini is a file used to either customize or alter certain settings. It's like a memory
for the settings you input on some program or if you change the icon on a folder.

You can delete that file but, the settings you changed will revert back to Default settings.

Do you have the path of that .ini file.

Did you try another scanner and did they report any other issues? This is usually not
a target of malware but, you never know these days.



FLASHORN.
Posted Image Posted Image

Posted Image

Eurocom Scorpius: 3840QM-2.8 GHz-Ivy Bridge ; ATI 7970M Crossfire ; Intel SSD 520 series 480GB ; Seagate Momentus XT 750 GB,7200RPM ; 16 GB Corsair Vengeance 9 9 9 24 ; Sound Blaster X-Fi MB2 ; THX True Studio Pro.

Patience is Life.
0

#4 User is offline   mjd420nova 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 3,007
  • Joined: 05-August 06
  • Location:Fremont, California

Posted 09 August 2012 - 02:27 PM

A new development has now cropped up. It has MacAfee installed and it is saying that the firewall is turned off. I use MacAfee toturn it back on and it turns itself right back off again. Very strange. Malware bytes found five files and was able to delete them. It seems MWB always finds something or other and always in the temporary files. These were just thumbnails from a KBB site.
0

#5 User is offline   Flashorn 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 4,401
  • Joined: 19-May 07
  • Location:Canada

Posted 09 August 2012 - 02:59 PM

In McAfee, go to the History tab and write down the Path to those files and copy here pls.

Run CCleaner (Broom Only)
in Advanced menu (bottom) make sure you have these
two check marked
Old Prefetch Data
IIS Log Files

Run SUPERAntiSpyware in safe mode.

Then,

Type in the Start menu search box "MRT" (without the quotes).
This is the Malware Removal Tool from MS. give it a quick scan.
Right Click to Run as Administrator.

Then,

Download and run this utility pls. ADWCleaner
http://general-changelog-team.fr/images/jdownloads/downloadimages/bouton-telecharger.png
This is the site but, it's in French. I thought you might just want the download button.

http://general-chang...de/2-adwcleaner

Could you post the logs from all of them pls.



FLASHORN.

This post has been edited by Flashorn: 09 August 2012 - 03:02 PM

Posted Image Posted Image

Posted Image

Eurocom Scorpius: 3840QM-2.8 GHz-Ivy Bridge ; ATI 7970M Crossfire ; Intel SSD 520 series 480GB ; Seagate Momentus XT 750 GB,7200RPM ; 16 GB Corsair Vengeance 9 9 9 24 ; Sound Blaster X-Fi MB2 ; THX True Studio Pro.

Patience is Life.
0

#6 User is offline   johhny 

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 102
  • Joined: 07-August 12

Posted 09 August 2012 - 10:31 PM

Try scanning the hard disk with Avira, surely will help you out.
0

#7 User is offline   mjd420nova 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 3,007
  • Joined: 05-August 06
  • Location:Fremont, California

Posted 20 August 2012 - 02:19 PM

It's been a while to get access to the machine. The path for the file is Windows\assembly\GAC_32\desktop.ini It resisted malwarebytes, superantispyware. Macafee was able to identify but was unable to purge the file. I have to look into the specs to see if it has a flash bios. Some rootkits I've seen exhibited the same flakyness.
0

#8 User is offline   Flashorn 

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 4,401
  • Joined: 19-May 07
  • Location:Canada

Posted 20 August 2012 - 06:17 PM

Hey mjd !

OK, well, that's what an .ini file does. It keeps your settings meaning, in this case the infection is keeping you from
either deleting it or has other instructions. And yes, it does seem like it's an infected file.

Try TDSSKiller from Kaspersky TDSSKiller.exe to see if a rootkit has installed itself.

http://support.kaspe.../?qid=208283363

If nothing is found then run ComboFix. Make absolutely sure to follow these instructions to the letter though.

http://www.bleepstatic.com/download/dl-buttons/download.png




http://www.bleepingc...to-use-combofix



FLASHORN.
Posted Image Posted Image

Posted Image

Eurocom Scorpius: 3840QM-2.8 GHz-Ivy Bridge ; ATI 7970M Crossfire ; Intel SSD 520 series 480GB ; Seagate Momentus XT 750 GB,7200RPM ; 16 GB Corsair Vengeance 9 9 9 24 ; Sound Blaster X-Fi MB2 ; THX True Studio Pro.

Patience is Life.
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users