Real virus, fake worm.win32.netsky warning

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by drcarl, Jan 27, 2010.

  1. drcarl

    drcarl Staff Sergeant

    Thanks to previous experiences and mostly to others here on the web, things seem normal after a full day of recovery.

    Whilst doing nothing in particular on my son's computer (which I brought back to life since mine broke)...oh! I was simply composing an e-mail in Yahoo Mail when out of the blue my wallpaper changed to green with a black box advising me that I'd been infected. Of course there were the pop-ups advising me to install (buy) something which I usually close with task manager, but, TM was not operational.

    I removed the laptop battery and disconnected the AC...yet after a reboot I still had the problem. Another site seemed to show some success with the Malwarebytes program so I ran that with some success myself by placing the program on a thumb drive and transferring it to and running it on the infected computer.

    As normal as things looked, I was not deeply satisfied that everything WAS indeed truly normal and clean so I followed the instructions in the README here (including the System Restore toggle) and post my logs for your kind inspection, comments and advice.

    I just ordered a new machine and am glad to be learning this lesson on what is soon to be a mostly obsolete unit. Still...I want to clean it up.

    TIA

    Dr Carl

    (balance of logs attached to next post)
     

    Attached Files:

  2. drcarl

    drcarl Staff Sergeant

    --Second half of log files

    Thank you

    drcarl
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The logs look pretty good to me.

    You should not have been doing this until the final instructions were given to you! A dirty restore point is better than none at all if something were to go wrong.

    I hope you didn't also complete all the final steps with removing the tools, otherwise we may have to start over somewhat.

    Looking at the log from running Malware Bytes it reveals you took no action on the threats it found. Did you indeed fix them after attaching the log or not? If not you then need to open up MBAM > let it update it's databse if it needs to, re-scan > fix all it finds, and attach the log from it into your next reply here.

    let's do the following:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    ______

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\a repair tools
    C:\Documents and Settings\Michael Botefuhr\kbpki
    
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    ______

    • Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter ( the quotes are required).
    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive called "TDSSKiller.txt" please attach this log to your next reply.

    ____________

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Combofix. and also the log from MBAM if you didn't previously fix what it flagged up and the log from TDSSKiller.

    _______

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  4. drcarl

    drcarl Staff Sergeant

    Thank you for looking at my logs and, wow, for everything else, too!

    I thought I just ran Malwarebytes on my own before I made it here to MG for more detailed advice and did let it "fix" everything it found. I believe it made some pretty significant progress, too! (but now I don't know when I let it fix stuff...it's becoming a blur - sorry)

    I also went ahead with the System Restore toggle because everything appeared normal and my computer without problems even through a few reboots. I did not remove any of the tools.

    As much as I want to go through the routine you detailed right now (it is kind of satisfying to clean things up) I don't have the time...so, depending on what tomorrow brings, I may be able to do it then. Either Thursday or Saturday (Friday I'm on a photo shoot).

    Thank you for the code, too...though KILLALL looks kinda scary...(wonder what it will kill)... I suppose you know I created that folder "C:\a repair tools" and have folders for each of the software tools and their logs. I made copies of the ones that must be on the desktop to run and run them from the desktop as advised.

    Will post as soon as I can.

    THANKS!

    drcarl
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. :)

    Well to be absolutely sure it would be worth rescanning.

    This will just attempt to disable any active protection software before running the fix.

    I will be here waiting.
     
  6. drcarl

    drcarl Staff Sergeant

    OK - I'm back (maybe) and am starting to review where we left of and start plowing through for an extra tidy and thorough clean-up.

    I am strongly suspecting immanent hard drive failure. Am experiencing BSODs frequently (4 or 5 times today).

    New computer MAY arrive on the 12th. Still, however weird it may seem since I could just use another available laptop for a week or two, I do actually like getting this one clean.

    I'll start with your MGTools suggestion, then do a full scan with Malwarebytes and will make a log. (I wonder if I can make two, one before and one after letting all be fixed by the software).

    TIA

    drcarl
     
    Last edited: Feb 2, 2010
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, just complete my last instructions to you when you are ready.

    Ahh..well that is something that cannot be resolved here as it is a non malware issue. That can be trouble shooted out in the software forum or the hardware forum.
    You can start with following off from where we left off. Just follow my instructions back in post # 3. Then attach the requsted logs. Do not do anything that isn't asked of you while we are finishing off cleaning the machine. This makes life harder for the both of us ultimately.

    You're welcome. :)
     
  8. drcarl

    drcarl Staff Sergeant

    OK...did everything in Post #3

    I re-ran MWbytes and it found nothing.

    I skipped the Fix step for HJT since I had already done that a couple of days ago.

    For the Combofix step, I ran this with my AV off and nothing else running though I did notice that after the reboot Avast as well as a third party clock app ran. I killed them as fast as I could. I mention this in case that ruins that step, and in case something needs to be added to the instructions, like: "Disable your antivirus [and other 3rd party apps?] from running on startup"

    TDSKiller did not ask for "what to do" if it finds something. That's where I was ready to type "delete," but was not offered that opportunity.

    Attaching logs as directed.

    Thanks some more...

    --drcarl

    PS - Answer for "how things are running now" Surprisingly not as many BSODs today as I ran these routines and, the Malwarebytes program was actually allowed to finish. I have to retry MWB perhaps 5 times due to BSODs. The Hard Drive (I know, for another thread) seems to be quieter although I may be mixing-up fan and drive noises.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your logs are clean, however you should not have been running MGTools.exe from the below location:

    You should have been running it directly from your C Drive. :)

    Any remaining issues should be worked out in other forum(s)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. drcarl

    drcarl Staff Sergeant

    Although I had stored a copy in a freshly created "C\a repair tools\MGTools" folder, I believe very strongly that I did actually run it from the MGTools folder directly on the C: drive.

    I will go through the rest of the steps shortly.

    With anti-virus, anti-malware, and firewalls in mind, I started another post about how to set-up a new system correctly from the beginning and certainly invite your input.

    I suppose there is no such thing as The Best...still, I want it.

    *bows deeply*

    Many Thanks

    --drcarl
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. :) Safe surfing
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds