Hello,
I commented on something of the same nature in another EE post:-
http://www.experts-e
H
Michael
A computer in our office appears to be infected with Malware that is causing many problems with the system.
The machine is running Windows XP SP3 and each time he boots, he gets more messages stating that globalroot\system32\gasfky
We have Kaspersky, which identifies it as a Trojan Virus. It tries to disinfect or delete the file, reboots, and the same messages reappear.
We have started in Safe Mode and run SpyBot Search & Destroy, which tried to clean it as well.
I ran chkdsk c:\ which states it can only run on reboot... however, upon reboot it does not run.
Does anyone have a solution to this problem?
Thanks,
Brian
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hello,
I commented on something of the same nature in another EE post:-
http://www.experts-e
H
Michael
It's definitely a bad file... whether it's gone or not it's still hooked with executables.
Try running Fixswen and or UnHookExec.inf
Download and run FixSwen
http://www.geekstog
* Download Fixswen and save it to your desktop
* Right-click on the file and choose "install"
http://download.n
Download the file UnHookExec.inf and save it to your Windows desktop.
http://securityresponse.sy
Right-
Also try running MalwareBytes or Combofix(rename the files prior to saving them to the desktop) you can even change the extensions to .com if it still won't run.
1. Download MalwareBytes:
http://downlo
N
Once MBAM is installed, you then locate and rename mbam.exe to mbam.com
Click on the renamed file to run it and then perform a quickscan.
Allow it to delete what it finds and then allow the computer to reboot.
This will allow MBAM to run and remove the rogue install + repair the hijack on the running of other exe files.
2. OR, download ComboFix by sUBs:
http://download.bleep
NOTE: You need to rename Combofix to CF.bat prior to saving the file to your desktop.
Make sure the 'Save as Type:' is "All Files"
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Malware Bytes ended up solving the problem, then I needed to go into the Startup folder and anywhere else where this existed.
It apparently arose with the "Personal Antivirus" malware that infected the system and started causing all of these problems. Kaspersky could see it, but didn't seem to do anything about it.
Malwarebytes found it, removed it, and ran chkdsk, Kaspersky, SpyBot S&D, and Malwarebytes again and the computer is clean.
Business Accounts
Answer for Membership
by: optomaPosted on 2009-09-22 at 12:54:01ID: 25396842
Try kasperskys live cd -labs.com/ devbuilds/ RescueDisk /
http://devbuilds.kaspersky
May delete trojan