worm.win32.netsky Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by BuzzBait, Dec 3, 2007.

  1. BuzzBait

    BuzzBait Private E-2

    I believe I was infected threw activeX install. Then I get a red start page, warning pop ups with worm.win32.netsky and many pop ups. Had some in the family look at it. They removed the red start page and pop ups but still got warning pop ups. But he ran out time So I did a internet search and found House Call ran it and found
    ask it to remove it then was told to it manually. Went to a site for help did there did there removel tools ATC-cleaner, AUG Anti-Spyware, Super AntiSpyware, and all windows updates. After a couple days of no help I ran into your site. Ran your Windows XP Cleaning Procedure and it fond things.here are the logs
     

    Attached Files:

  2. BuzzBait

    BuzzBait Private E-2

    after a few hours of thing not pop up after running spyware tools. there back with 3 icons privacy protector, spyware protetion and error cleaner with a new folder shopping report on my desk top here my new hjck report
     
  3. BuzzBait

    BuzzBait Private E-2

    mist the hjth loge
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the proper logs from the READ & RUN ME. It does not ask for a separate HijackThis log to be attached. It does ask you to attach the C:\MGlogs.zip file from running MGtools and you still need to attach it.
     
  5. BuzzBait

    BuzzBait Private E-2

    i can not seem topull up MGlogs.zip file can you help windows XP
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you mean. When you ran MGtools.exe it should have created a file named C:\MGlogs.zip are you looking in the C:\ root folder or are you looking in the C:\MGtools folder which is not where you should be looking?
     
  7. BuzzBait

    BuzzBait Private E-2

    holp this is it
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First Disable Spybot's TeaTimer as requested in the READ & RUN ME
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    Now I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.




    Now also run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also make sure that you have attach both rapport.txt logs from SmitFraudFix.

    Make sure you tell me how things are working now!
     
    Last edited: Dec 5, 2007
  9. BuzzBait

    BuzzBait Private E-2

    Here is the log report
     

    Attached Files:

    Last edited by a moderator: Dec 5, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not post logs inline. Remember to attach them just like you did in your first messages!
     
  11. BuzzBait

    BuzzBait Private E-2

    Thanks chaslang
    Things seem to be running well a little slow which I believe is from all the programs I installed to fix my problem there is a folder on my desk top that was not there before called shopping report should I just delete this folder? And I lost my picture on my desk top back ground I assume I just reinstall that? What is the best way to remove this programs I installed to fix my computer ? thanks for all the help chaslang hope the logs I am sending you to read are clean!
    Thanks for the help
    :)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!

    This is due to cleaning out your infection.


    For things you actually installed, uninstall them via Add/Remove programs.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {03B121E9-6152-48b5-BB38-B642B21C62BD} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    Also since you are concerned with your PC running slow, have HJT fix the below three unnecessary satrtups. BigFix is a huge waste of resources.
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

    After clicking Fix, exit HJT.

    Delete the below file:
    C:\WINDOWS\nethop.exe

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.


    Make sure you tell me how things are working now!
     
  13. BuzzBait

    BuzzBait Private E-2

    Ha chaslang
    I did what you ask but when I tryed to down load new java my system shut down to a blue sceen saying windows stop error and did a memory dump?
    java is now suspended! i did run MGtool
     

    Attached Files:

  14. BuzzBait

    BuzzBait Private E-2

    just a update looking around fond System Restore was turn off sorry when all this happened!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you reboot after uninstalling ....before installing the new version? Based on your log, Sun Java does show installed; however it does not appear to be running. See if you can uninstall it, reboot and then reinstall.

    Are you going to fix the below lines I mentioned last time?
    O3 - Toolbar: (no name) - {03B121E9-6152-48b5-BB38-B642B21C62BD} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
     
  16. BuzzBait

    BuzzBait Private E-2

    was not a bull to find this to delete, need direction

    yes I did reboot after uninstalling ....just at the end of java install it went to blue sceen window stop error. in add and remove tried to uninstall it and got a (internal error 2753, Reg Utils)

    Done ...here is new MGtool log
     

    Attached Files:

  17. BuzzBait

    BuzzBait Private E-2

    chaslang I still canot remove java via add/ remove program i get a error 2753.RegUtils
    there is a touch pad with a slide bar up/down wich dose not work now how do i trun it back on?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Neither of these issues has anything to do with your malware problems. It would appear that you have some kind of registry corruption that is beyond the scope of things we discuss in the Malware Forum. You really would be better off discussing these in the the Software Forum. You may need to perform some registry cleaning to remove all aspects of Sun Java related info from your registry to resolve this error. But again this is something we do not get into in this forum. I do however recommend that before you even think about making any changes to the registry, that you create a backup of the registry first. Most good registry cleaning programs will do this for you before making changes. I would only suggest cleaning up things related to Sun Java.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds