Can not boot after Smitfraud/Netsky

Discussion in 'Malware Help (A Specialist Will Reply)' started by likearock, Jan 12, 2010.

  1. likearock

    likearock Private E-2

    Dell Dimension 4700 with XP sp2. Using AVG and SpyBot which ran every day.

    Two days ago I was on a website that had 2 things pop up then something started downloading. I immediately X'd out as much as I can. When the Security/Virus alerts started popping up I knew I was being hit with a virus I had heard about. I shut down and unplugged the router.

    When I turned the computer on again it took me to desktop with no icons where I was unable to do CTL ALT DEL or MSConfig. It said it was disabled by the system administer. I shut down again and this time I was unable to get the desktop at all, it restarted after clicking my user name in an endless loop. I could not get into SAFE mode, another endless loop. Finally I repaired Windows from an older CD with XP sp1 on it. I still can not get passed the Log On screen but I am able to get into Safe mode, where I am right now.

    I was able to do a lot of computer searching and found that I have the SmitFraud and Worm.win32.netsky along with a bunch of others. Apparently my virus software and pop-up stoppers suck. (AVG, SpyBot, PopUp Stopper)

    I have run all the programs recommended here and have the logs to attach. Some programs I could not complete, like removing Java and some stuff that ComboFix was trying to do because of the error "The procedure entry point DecodePointer could not be located in the dynamic library Kernel32.dll" I have tried copying the Kernel32.dll file from the windows CD but it didn't help.

    Can you please help me? I can not lose my computer files. If I can repair it I would rather do that then a complete reinstall.
     

    Attached Files:

    Last edited: Jan 12, 2010
  2. likearock

    likearock Private E-2

    I think these are the other logs I needed
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You still have TeaTimer running.

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Please double-click the RootRepeal.exe previously downloaded.

    * Select File then Scan
    * On the Select Drives form select drive C by "ticking" the box for drive C and click OK
    * When the scan is complete - highlight each of the following file(s) (one at a time if more then one is listed) by left clicking it. Then use right mouse click and select the Wipe File option only for each file.
    c:\windows\temp\euwmhorn.out
    c:\windows\temp\obdwr58p.out
    c:\windows\temp\s5p6wfi0.out
    c:\windows\temp\v4wx6isu.out
    c:\windows\temp\oricxh1t.out
    c:\windows\temp\p4kzn2z5.out
    * After Wiping all files, immediately reboot your pc!

    Now re-run ComboFIx.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!

    You need to update to either SP2 or 3!!
     
    Last edited: Jan 14, 2010
  4. likearock

    likearock Private E-2

    Thank you but it may be too late. I was unable to get in at all and ended up trying to repair Windows but it reinstalled completely. I got into my desktop and saw everything wiped out, back to a fresh install Windows. Crap. I shut down and haven't touched it, hoping to be able to retrieve lost files.

    I could not update to SP2, I had tried but I couldn't do it in Safe mode and i couldn't get in without Safe mode. Once I get it up and running again I will certainly update.

    Any recommendations for data recovery? At the moment I'm thinking of just connecting two computers by Ethernet and trying to retrieve the files. I'm just afraid of transferring any remaining virus to the other computer. This virus took down the PC and 2 laptops, I have one PC left and I am guarding it.

    I need to know why I got it to begin with, I thought I was protected with AVG and SpyBot.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you ended up doing a re-installation ( as opposed to a repair installation ) you wiped out everything. There will not be anything to retrieve.

    As to how this happened:

    There are many vehicles by which people get infected. Downloading and clicking on adverstisments are only two possible ways. Others include but are not limited to

    * NOT KEEPING ALL SOFTWARE UPDATED!!!
    * surfing - usually certain websites are the main problem
    * click links to view pictures or videos, or listen to music....etc
    * not reading what you are clicking on and even if you do it may be worded in a form to trick you into clicking the wrong answer. Sometimes the answer is the opposite of what you think. And sometimes there is no correct answer because it is already too late one the popup has appeared..
    * installing codecs to view videos or sound
    * installing cracks and or illegal software
    * downloading via P2P or Torrent programs
    * downloading from websites that do no check their downloads to see if they are safe and very few actually do this even though they say they do. (We do at Major Geeks!)
    * reading emails from unknown senders especially if you have html enabled and also especially if clicking on any attachments
    * reading emails from friends who don't know they are infected and may not even know they are sending you emails.

    I know that many people like to say that they don't understand how they are getting infected, but the fact remains that in most cases it is by their own doing. I surf more than most people and access all kinds of websites while trying to test various malware. I have to eliminate all of my protection (even my router which has a hardware firewall) and I still have a hard time getting infected and I have to knowingly agree to install things to get infected.

    General Tips for everyone (not just you )

    * If you do not have a router or do not have a router with a hardware firewall, then get one.
    * If you are not using a real bidirectional firewall then install one and only one. The Windows (any version) firewall is not adequate.
    * Install one and only one antivirus program.
    * Install one and only one realtime antispyware protection program
    * Install the below for background protection
    o SpywareBlaster
    o Spybot with SDHelper and use the Immunization feature
    * Do period scans with you AV and AS programs?
    * Use additional scan only programs like SUPERAntiSpyware and Malwarebytes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds