Worm.Win32.Netsky infected..HELP!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by metallica79us, Nov 15, 2007.

  1. metallica79us

    metallica79us Private E-2

    My notebook has been infected with worm.win32.netsky virus and its been really slow and I have constant security pop ups and system alerts. Please let me know how to remove this virus. I already scanned my computer with Norton 360 but it can't detect the virus.HELP!!!
     
    Last edited: Nov 15, 2007
  2. metallica79us

    metallica79us Private E-2

    Here is my log file. Any help will be highly appreciated.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. metallica79us

    metallica79us Private E-2

    Thanks for the reply but I got it fixed. I went to Safe Mode and did system restore from few days ago and it worked. Thanks anyways.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That may only be masking the symptoms. It did not remove the infected files from your PC.
     
  6. metallica79us

    metallica79us Private E-2

    Thanks for your reply. Just to make sure all the infected files are not in my PC, I will follow Read and Run instructions and attach the files in the next post over the weekend.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Yes that would be a good idea just to be on the safe side.
     
  8. metallica79us

    metallica79us Private E-2

    Hello there, here are the log files. If I need anything else, please let me know. Thanks.
     

    Attached Files:

  9. metallica79us

    metallica79us Private E-2

    More logs..
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not run the steps in the link I gave you in message # 3. You could have saved a load of time by following the directions I gave you as it is a much faster procedure and automatically runs various tools and puts the logs into a ZIP file for easy upload. Don't worry about it now but just remember in the future to click the given links. You did run a copy of the READ & RUN ME but an older than what I gave you.

    Also you did not install and rename HijackThis as requested and as such the log is not as useful as it would be if properly renamed. You need to rename it now.

    It looks like you are in pretty good shape but I do have a few things for you to do.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_05


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    You can uninstall the CounterSpy trial now since we are finished with it. And then delete the below folders which may be left behind.
    C:\Documents and Settings\Kissco2006\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software



    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  11. metallica79us

    metallica79us Private E-2

    Hi there, I did all the things that you requested. My PC is running smoothly. Is there anything else left to do? Thanks for your assistance.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. As long as you have done what was in the How to protect yourself link, you are done!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds