It is currently Tue Sep 01, 2026 4:24 pm


Cannot Delete annoying pup up CORE.CACHE.DSK

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Cannot Delete annoying pup up CORE.CACHE.DSK

Postby photoITguy » Mon Jan 21, 2008 5:41 pm

I'm having trouble deleting a system driver file called "core.cache.dsk". This file appears to be some type of malware/spyware that creates annoying pop-ups in Internet Explorer, even though I'm using Firefox as my default browser.
The file location is "C:\WINDOWS\System32\drivers\core.cache.dsk". I've tried using everything you can think of, from going in to safe mode and manually deleting, to using adaware, kaspersky, avg, spyware doctor, spyware blaster, delete on reboot, etc. And nothing seems to work. Most of them are able to locate it, and claim to delete it, but upon reboot it re-creates itself each time. If you attempt to manually delete it, you receive an error stating it's in use by a program already, if you go in to safe mode you can delete it, but when you reboot it re-appears in normal mode.

please help! I do not want to re-install windows vista again, but as a last resort I will.
here is my HiJack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:38, on 2008-01-21
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Name of App] C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe r
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 5317 bytes
photoITguy
Newbie
Newbie
 
Posts: 3
Joined: Mon Jan 21, 2008 5:30 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Tue Jan 22, 2008 12:04 am

Hello photoITguy, and welcome to our forum.

Please download to your desktop.

Double click combofix.exe and follow the prompts.

When it's done running it will produce a log for you. Please post that log in your next reply.

Important Note - Do not mouseclick combofix's window while it's running, that may cause it to stall.
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

ComboFix Log

Postby photoITguy » Tue Jan 22, 2008 12:17 am

Here is my combo fix log..I'm not sure if this is right but I hope it helps. There were 3 text documents in the Combo Fix folder, here they are


text document - "comboxfix"
ComboFix 08-01-20.1 - Josh 2008-01-21 12:40:35.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.1.1033.18.542 [GMT -5:00]
Running from: C:\Users\Josh\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

text document - ComboDel
Files to Move:
C:\ProgramData\Microsoft\Network\Downloader\qmgr0. dat|C:\QooBox\Quarantine\C\ProgramData\Microsoft\N etwork\Downloader\qmgr0.dat.vir
C:\ProgramData\Microsoft\Network\Downloader\qmgr1. dat|C:\QooBox\Quarantine\C\ProgramData\Microsoft\N etwork\Downloader\qmgr1.dat.vir
C:\Windows\system32\drivers\core.cache.dsk|C:\QooB ox\Quarantine\C\Windows\system32\drivers\core.cach e.dsk.vir
C:\Windows\system32\drivers\core.cache.dsk|C:\QooB ox\Quarantine\C\Windows\system32\drivers\core.cach e.dsk.vir
C:\ProgramData\Microsoft\Network\Downloader\qmgr0. dat|C:\QooBox\Quarantine\C\ProgramData\Microsoft\N etwork\Downloader\qmgr0.dat.vir
C:\ProgramData\Microsoft\Network\Downloader\qmgr1. dat|C:\QooBox\Quarantine\C\ProgramData\Microsoft\N etwork\Downloader\qmgr1.dat.vir
C:\Windows\system32\drivers\core.cache.dsk|C:\QooB ox\Quarantine\C\Windows\system32\drivers\core.cach e.dsk.vir
C:\Windows\system32\drivers\core.cache.dsk|C:\QooB ox\Quarantine\C\Windows\system32\drivers\core.cach e.dsk.vir
C:\ProgramData\Microsoft\Network\Downloader\qmgr0. dat|C:\QooBox\Quarantine\C\ProgramData\Microsoft\N etwork\Downloader\qmgr0.dat.vir
C:\ProgramData\Microsoft\Network\Downloader\qmgr1. dat|C:\QooBox\Quarantine\C\ProgramData\Microsoft\N etwork\Downloader\qmgr1.dat.vir


text document - Pend
\??\C:\ntdetect.com\0\0
\??\C:\boot.ini\0\0
\??\C:\ntldr\0\0
\??\C:\Windows\0\0
\??\C:\Windows\explorer.exe\0\0
\??\C:\Windows\system32\csrss.exe\0\0
\??\C:\Windows\system32\lsass.exe\0\0
\??\C:\Windows\system32\services.exe\0\0
\??\C:\Windows\system32\smss.exe\0\0
\??\C:\Windows\system32\svchost.exe\0\0
\??\C:\Windows\system32\userinit.exe\0\0
\??\C:\Windows\system32\winlogon.exe\0\0
\??\C:\Windows\system32\hal.dll\0\0
\??\C:\Windows\system32\ntdll.dll\0\0
\??\C:\Windows\system32\config\0\0
\??\C:\Windows\system32\drivers\0\0
\??\C:\Windows\system32\wbem\0\0


hope that helps :?
photoITguy
Newbie
Newbie
 
Posts: 3
Joined: Mon Jan 21, 2008 5:30 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Tue Jan 22, 2008 1:41 am

photoITguy

The log I need to see should be located in the root of your OS drive.

You need to copy and paste from this file C:\ComboFix.txt

My computer > local disk C: > look for the file ComboFix.txt
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top

No combofix.txt appearing.

Postby photoITguy » Wed Jan 23, 2008 12:52 am

I ran combo fix a couple more times and it isn't creating the .txt file in my main C:\ directory where you're stating it should. On my desktop it does create a zipped directory labeled "catchme"

inside the zipped directory of "catchme" are 6 files-

"catchme" (directory)
core.cache.dsk (DSK File 163KB)
qmgr0.dat (DAT File 1kb)
qmgr0.dat.1 (1 File 1KB)
qmgr0.dat.2 (2 File 1KB)
qmgr1.dat (DAT File KB)
qmgr1.dat.1 (1 File KB)


I also have ran Spybot Search & Destroy, it is able to find the file C:/windows/system/drivers/core.cache.dsk
It says it removes it too, and even prompts to authorize the registry change, but it too doesn't completely remove it.
At least right now when the pop-up internet explorer boxes come up they are just blank white pages with nothing in them.

I really would like this to STOP, and i really am getting tempted to just re-install windows Vista.
photoITguy
Newbie
Newbie
 
Posts: 3
Joined: Mon Jan 21, 2008 5:30 pm

Thanks given:0
Thanks received:0
Top

Postby Gecko » Wed Jan 23, 2008 11:49 am

photoITguy,

Download and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :

* Restart your computer
* After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
* Instead of Windows loading as normal, the Advanced Options Menu should appear;
* Select the first option, to run Windows in Safe Mode, then press Enter.
* Choose your usual account.

* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
* Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).
* Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
User avatar
Gecko
Super Moderator
Super Moderator
 
Posts: 5209
Joined: Thu Oct 25, 2001 1:00 am
Location: Florida, USA

Thanks given:1
Thanks received:23
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron