A really bad thing!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by NZRic, Oct 19, 2006.

  1. NZRic

    NZRic Private E-2

    Hi Everyone,

    Clear understanding okay (hehehe) - this is not my computer. It acutally belongs to a very nice family and I am trying my best to help.

    Okay - something bad is happening - else I wouldn't be here.

    1) Cannot right click on my computer - no menu pops up as supposed to. DblClick on my computer - nothing happens.
    2) Cannot access regedit
    3) Despite settings via WinExplorer - when there is a click on a *.txt file, nothing happens
    4) Cannot access control panel - no action occurs when attempting add/remove programs, or user settings/passwords
    5) As above, cannot access via Start/File/Run.... processes
    6) Desktop settings (right click on desktop) cannot be accessed.
    7) System time (double click on the clock) cannot be accessed.
    8) Cannot access safe mode
    9) Cannot uninstall norton (expired)
    10) Cannot install AVG correctly
    11) Cannot install firewall
    12) I have a trillion IE helper bars and want them removed (see add/remove above)


    Running the 'do this before you ask...' via the MalWare thread ran into severe problems:
    a - no safe mode
    b - WinDefender did not work initially
    c - Some scans would not work
    d - SunJava had problems getting in


    I have found (I think) the culprit. A review of the Windows and Windows System32 shows:
    1) a dialer.ini and system.ini curiously created at exactly the same time (windows)
    2) a inetmodl.exe file (windows/system32)
     

    Attached Files:

  2. NZRic

    NZRic Private E-2

    More about a very bad thing..

    Logs Attached
     

    Attached Files:

  3. NZRic

    NZRic Private E-2

    Re: More about a very bad thing..

    REM: this is the second part of the thread 'A really bad thing' in this forum. Please see that one first before telling me 'What the &@*($*#@ are you thinking..' Ta
     
  4. matt.chugg

    matt.chugg MajorGeek

    YOu have attached the wrong bitdefender log. That is the scan summary. I need to see the actual log as that will tell me which files are infected with the malware it says it has found.

    Are you trying to install AVG AV whilst notron AV is installed? You should not run 2 resident AV scanners at the same time. This is explained in the read and run me. Remove Norton AV first and then install AVG

    your HJT log shows that you have components of both installed.

    You need to sort this out before we can procede.
     
  5. NZRic

    NZRic Private E-2

    Hi Matt,

    Thanks for the reply - I just remembered I never posted the thanks as I should. After you last - I read the correct log and figured out where the root/boot hijack occured.

    I was aware of the AVG/Norton problem - it was because of the hijack I couldn't get either to uninstall.

    All's well now - I had to recover the admin password via the UK WWW service, but otherwise not major burden one you told me I was looking at the wrong log. That was a good pointer and it helped.

    Ta,

    Ric
     
  6. matt.chugg

    matt.chugg MajorGeek

    Glad you got it sorted, if you'd like me to check your logs to make sure everythings gone just post them.
     
  7. NZRic

    NZRic Private E-2

    Well, once I followed on I had a great time cleaning up... really the problem was the inetmodl.exe - always a bear to kill correctly... I appreciate the offer and when they (the computer owners) return, I shall get some new logs for you to review...

    Ric
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds