Worm.win32.netsky problem

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Spybegone, Dec 7, 2007.

  1. Spybegone

    Spybegone Private E-2

    Hi, my machine keeps telling me I have the worm.win32.netsky virus.
    I have gone through the entire "Read & Run me first, malware removal guide

    My system still has the 3 icons to download privacy protector, etc. and I keep getting a pop up saying have have the worm as listed above.

    The system is very slow. I have downloaded and run trend micro hijackthis exe and have a log to upload.

    Can anyone help

    Thanks,
    newbeeee
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks

    Not really! The READ ME stated the below
    Thus since you are still having problems, why haven't you attached the requested logs.
     
  3. Spybegone

    Spybegone Private E-2

    Thanks for the reply chaslang, I was waiting to be asked for them 1st.

    Please see attached logs. Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why does the date on your PC say It's Mon February 23, 2004 01:43:30 AM You need to fix this right now. It messed up all of the scans making the logs unnecessarily longer.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.1_02
    Java 2 Runtime Environment, SE v1.4.2
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Toolbar <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Startup: PowerReg SchedulerV2.exe
    O21 - SSODL: pmkret - {7AECBFD0-B24F-4625-A8EB-3482C8D00E2C} - C:\WINDOWS\pmkret.dll
    O21 - SSODL: gormet - {34633394-7245-4704-977D-716F98E699C7} - C:\WINDOWS\gormet.dll

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  5. Spybegone

    Spybegone Private E-2

    Sorry about the clock, my system battery was low and the time was changed.
    I missed the Viewpoint (as you pointed out) in my initial scan of the system when I tried to get everything off during the cleanup process.

    Ok, first of all let me say this has helped a great deal Chaslang. You have done wonders for me. My computer has quieted down and is much much happier. Thank you!

    I no longer get the pop-ups about having a virus every 30 seconds. I deleted the 3 icons on my desktop and they have NOT come back. IE 7.0 does not try to open up every 2-3 minutes. This is wonderful.

    Now, I did notice and you will read it in the Avenger log, one reg key was not deleted :
    Could not delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|pmkret
    Deletion of registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad|pmkret failed! Status: 0xc0000034

    Everything else worked just as you said. Great instructions by the way.

    I do have a couple of questions:
    1. I have a maxtor one touch backup drive, will the virus come back when I plug this in?

    2. I run Norton Antivirus software, should I un-install AVG now? Or keep it on my machine.

    3. And should I keep the other software that has been installed on the PC while removing this worm, or should these be un-installed as well? Like CCleaner, AVG, Avenger, MGtools, etc.

    4. The system boots up a little slow, but maybe thats because of all of the other stuff running on the PC. Once it's up and running, it seams pretty responsive now. Any suggestions on speeding it up...I'm all ears.

    Thanks again for your wonderful support Chaslang.

    Spybegone!




     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    It was fixed anyway by HJT.

    If you do a restore of infected files or the registry from this drive, then yes. Otherwise no.

    Norton is an antivirus. You installed AVG Antispyware not AVG Antivirus so there is no conflict. AVG Antispyware is a useful scanner to keep.

    I think my final instructions (further down) should address most of this.

    I cannot easily answer this for you since what I would keep and what I would use would be different than what you may need. I definitely would not be using Norton which could be your biggest cause of slow startup. But you also have other items that I consider unnecessary, but again you need to decide. Examples:

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  7. Spybegone

    Spybegone Private E-2

    All is well in our household. The PC is back to normal thanks to your wonderful advise and guidance. You are the BEST!

    Happy Holidays to all.

    Spybegone!



     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds