Status
Not open for further replies.

karnivore

in your face..
A couple of days back i had a trojan attack [windeil32.dll]. Though i was able to clean my system i started having a weird problem. everytime i was booting my computer, "My Computer" was opening automatically after the booting was over. Then suddenly it stopped and new thing started. Now while booting it is flashing "netconfig.exe" is loading my network setting and i can see from Task Manager that "netcmd.exe" is running.

HOW DO I STOP THIS FROM HAPPENING.
 
OP
karnivore

karnivore

in your face..
Dont get me wrong guys...............but i hav my reservations. once i had a trojan attack and Avast failed to clean it [ i forgot the name of the trojan]. after that i installed SpywareDr [ cracked version of course] and it worked fine for me till now.
But if u guys r saying so............i will reinstall it.

Thx
 
OP
karnivore

karnivore

in your face..
i guess so..............it seems a single anti-virus/spyware is not adept in handling all the threats, paid or freeware.
Now this sux big time. :mad:
__________
Nope........Avast did not work, just as i thought.

This is what i hav figured:
"netconfig.exe" does not exist at all.
"netcmd.exe", however exists in "C:\WINDOWS\system32". Running this command only flashes the "About Windows" splash screen showing the WinXP version. Other than the fact that it uses up about 6 MB system memory,it, apparently, does not do anything else.

This is what i hav done:
Cleaned "Prefetch" file in "c:\WINDOWS"
Deleted "netcmd.exe"
Removed all trace of "netconfig" and "netcmd" from windows registry.
Now, everytime i am starting my system, "My Computer" is opening up automatically.

Man, am loosing my mind. Can anybody HELP.
 
Last edited:

Kiran.dks

Technomancer
Your system is infected with W32.HLLW.Gaobot.BE worm. This is called as W32/Gaobot.worm by McAfee. McAfee will remove it. The problem is this worm disables the functions of Antivirus s/w.

Proceed exactly as follows:

1. Disable "System Restore" option in Windows
2. Reboot the system and log on to Windows in "Safe Mode"
3. Open Task Manager
In the Processes tab, look for netcmd.exe and click "End Process"
4. Close Task Manager
5. Update McAfee Virus definitions
6. Perform "Full system Scan". Make sure you do include all folders without missing anyone.
7. McAfee will detect the worm. Click "Delete" the file and proceed with the process.
8. After completion of full scan, reboot Windows
9. Enable "System Restore" option.
 
OP
karnivore

karnivore

in your face..
Kiran_tech_mania said:
Your system is infected with W32.HLLW.Gaobot.BE worm. This is called as W32/Gaobot.worm by McAfee. McAfee will remove it. The problem is this worm disables the functions of Antivirus s/w.

Proceed exactly as follows:

1. Disable "System Restore" option in Windows
2. Reboot the system and log on to Windows in "Safe Mode"
3. Open Task Manager
In the Processes tab, look for netcmd.exe and click "End Process"
4. Close Task Manager
5. Update McAfee Virus definitions
6. Perform "Full system Scan". Make sure you do include all folders without missing anyone.
7. McAfee will detect the worm. Click "Delete" the file and proceed with the process.
8. After completion of full scan, reboot Windows
9. Enable "System Restore" option.

Nope..................it did not work :confused:
 

Kiran.dks

Technomancer
It should have worked...seems like there is some problems with the registry.
Run Hijackthis and post the report here for analysis.
 
OP
karnivore

karnivore

in your face..
Kiran_tech_mania said:
It should have worked...seems like there is some problems with the registry.
Run Hijackthis and post the report here for analysis.

listen............i hav already deleted this "netcmd" and it will not show up in the log of HJT. It seems i hav messed up my reg.

One more thing..............i cant Restore it from a previous restore point. In fact i cant even go back from Jan 07 to Dec 06

Thx for the response though
 
Status
Not open for further replies.
Top Bottom