Author Topic: help plis!  (Read 3967 times)

0 Members and 1 Guest are viewing this topic.

canon515j

  • Guest
help plis!
« on: October 12, 2007, 06:20:16 PM »
hi alls

first sorry by me bad english, i speack spanish and use translator of google.

Second and most importantly, I have a trojan that my home avast not even acknowledged to date, installed on my drives removable an executable file called ntde1ect.com and their respective autorun.inf appears to be an editor regisatro and something more, blockade "View hidden files and folders" and "learn the system"

I am using XP home and discovered everything when using ubuntu that shows the files on disk window.

If anyone can help me with this trojan thanks

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: help plis!
« Reply #1 on: October 12, 2007, 07:42:17 PM »
You should send a sample of ntde1ect.com to avast.

Send the sample to virus@avast.com zipped and password protected with password in email body and false positive/undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.

Autorun.inf shouldn't be in regular Hard Drives it is normally only found on removable media (like USB flash drive) and that is probably how your system got infected. If you have a USB flash drive you should check for the presence of ntde1ect.com and delete it, also check for autorun.inf. If found open it with Notepad and check if there are any run commands for other files and post the contents of the autorun.inf file here.

See, http://www.prevx.com/filenames/X2769565878543970189-0/NTDE1ECT.COM.html
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

canon515j

  • Guest
Re: help plis!
« Reply #2 on: October 15, 2007, 05:30:30 PM »
Attached and DD formatted ..... The file prevents see hidden files and system through folder options, besides installed in the window partition security system and preventing restore reinstall from the same =\

Thanks for the information, sorry bad english.... powered by google xD

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: help plis!
« Reply #3 on: October 15, 2007, 06:03:22 PM »
I don't know how happy you are working in the registry but this modification should restore the ability to use the unhide files and folders, etc. Before working in the registry you should back-up at least the key you are working on, when you find the key in the quote below, right click on it and select export, choose a meaningful name and location (so you can find it again).

Quote
1. Click “Start” -> “Run…” (or press Windows key + R)

2. Type “regedit” and click “Ok”.

3. Find the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL

4. Look at the “CheckedValue” key… This should be a DWORD key. If it isn’t, delete the key.

5. Create a new key called “CheckedValue” as a DWORD (hexadecimal) with a value of 1.

6. The “Show hidden files & folders” check box should now work normally. Enjoy!

This comes from this link, http://www.neowin.net/forum/index.php?s=6e407ec1e219ee972eb58488f7464f37&showtopic=587995&pid=588872075&st=0&#entry588872075 and there is some other useful things there.
« Last Edit: October 15, 2007, 06:10:17 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help plis!
« Reply #4 on: October 15, 2007, 10:49:48 PM »
As a alternative you could run Combofix and post the log

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it will produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: help plis!
« Reply #5 on: October 16, 2007, 12:12:22 AM »
Does combofix also correct registry entries ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: help plis!
« Reply #6 on: October 16, 2007, 11:36:26 PM »
It will re-enable safe mode, regedit and show exactly how the registry value has been modified

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89686
  • No support PMs thanks
Re: help plis!
« Reply #7 on: October 16, 2007, 11:55:27 PM »
Thanks for the update.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security