trojan has removed ....

Discussion in 'Malware Help (A Specialist Will Reply)' started by ncc1701dhhr, Mar 1, 2008.

  1. ncc1701dhhr

    ncc1701dhhr Private First Class

    Hi I have downloaded all programs in the (do this first) sticky but have a question But first (computer is a Dell 1 gig ram, pentum 4 processor about 2 years old and was running norton av (but this got in anyway?)

    On my friends computer we cant accsess - windows explorer, or control panel
    or add and remove. Also when trying to install some programs it says i dont have administrator rights. I can get around by going to run and hitting browse
    it lets me in to see the files on the drives (i have deleated some Known spyware that way and used C Cleaner to remove registry items after reboot in to safe mode. (by the way even safe mode dosnt act correctly)
    Also it keeps saying missing(C:\Windows\system32\rundll32.exe)
    I am taking my windows XP cd with me in hopes of a repair install after I run the do this first programs from your sticky above. Any ideas or just wait till i can do reports if i can get that far?(I cant get to the internet but some thing is trying to as when i un plugged the DSL modem from computer i keep getting pop ups asking to work off line)
    Any ideas or help apreciated
    Herb
     
  2. ncc1701dhhr

    ncc1701dhhr Private First Class

    well I can't seem to get in to anything!! get a pop up stating that I dont have admin privlages (i am logged in as the admin) but I cant get to user
    accounts to check if it has been changed? says rundll32.exe not found
    (i was able to get to the windows folder and rundll32.exe is there)
    this is frustrating
    I cant even install the programs from the above sticky:cry
    Any Ideas??
    any help please
    Herb
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try running both Combofix and the MGTools.exe in safe mode.
     
  4. ncc1701dhhr

    ncc1701dhhr Private First Class

    Ok I will try sunday when I go over there I'll let you know
    thank you
     
  5. ncc1701dhhr

    ncc1701dhhr Private First Class

    no joy combofix wont run MGTools wont run eather This looks more and more like a nuke and pave job is the only answer!
    Every program i try to run looks like it is loading(displays hour glass) but it just stops. and other times it says rundll32.exe missing, Or that i dont have administrater privlages.:***
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    rundll32.exe is not supposed to be in the Windows folder. It needs to be in the C:\windows\system32 folder. Do you really have one in the C:\windows folder? If so, what is the file size and date?

    Do you have c:\windows\system32\rundll32.exe ? If so, what is the file size and date.

    What Service Pack level is on this PC?
     
  7. ncc1701dhhr

    ncc1701dhhr Private First Class

    Sorry yes it is in C:\windows\system32 folder.
    It is windows XP home with service pack 2,
    A good friend was able to pull critical files off the hard drive to a thumb drive
    so now I am just going to wipe the drive and reinstall, Thank you for all suggestions,
    Oh one more question - The system restore is on same drive in (fat 32 ) it should be safe to use this right??
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly, I wouldn't trust your system restore files.....if you are going to wipe it, do a full format and re-install.....or a repair install and continue with us on the malware issues (as they will remain after a repair install.)
     
  9. ncc1701dhhr

    ncc1701dhhr Private First Class

    I may be saying it wrong?
    I am going to re format c drive and reinstall, But from the factory installed
    hidden fat 32 System restore. It is used to replace the normal restore CD's(it is supposed to bring it back to like it was when first bought.)
    If that is a bad Idea then I guess he will have to get a new coppy of XP and
    go from there.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now I understand....no, you should be fine doing it that way.
     
  11. ncc1701dhhr

    ncc1701dhhr Private First Class

    Well It is done and all seems well now just re installing all the extra programs and (hopeing he has saved all the Keys)
    but thank you for all help.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds