worm.win32.skynet- ???

Discussion in 'Malware Help (A Specialist Will Reply)' started by banana_slama109, Dec 15, 2007.

  1. banana_slama109

    banana_slama109 Private E-2

    The other day i was playing a game and i received a message talking about how my computer contained a worm.win32.netsky and that i should remove it, I would have clicked remove but than i realized that this was probably the virus talking. Folowing this first pop up i prmptly received sevral other popups basicaly telling me to run all sorts of virus programs. I am not sure what to do i also looked on my dektop and found three new internet shortcuts (privacy protector, error cleaner and spyware and malware protection) i tried to ctr-alt-del but windows gives me a message teling me that it has been disabled by my admin. I am a very experienced computer user but i have never seen this befor. Any help would be, well helpfull.
     
  2. abri

    abri MajorGeek

    Hi banana_slama!
    Welcome to Major Geeks!


    I would like to have you run some of our older tools and then switch over to the newer collection to post your logs to us. I'll have you install 3 programs which you can run one after the other once they're all installed.

    1) Before you begin, please be sure that MSconfig is not being used to control Startups. Note: That some Window's OSs (like Win 2K) do not have MSconfig!
    • MSConfig Startup Mode
      Please go to Start > Run > type msconfig and click OK!
      Select the General tab and select Normal Startup.
    Thenclick Apply and OK and reboot PC before continuing.​
    2) Also, you need to have your Hidden files and folders visible.
    Some programs hide themselves by making their files invisible in normal Windows settings. Run the steps in the below link (has steps for ALL Win OS's) to make them easier to find. Not doing this would allow file extensions commonly used by trojans and spyware to be hidden, for example a file ending in .exe or dll making manually finding it, if needed, difficult to impossible.

    3) The first of the three programs I want you to download and install is CCleaner

    • [*]MAKE SURE you download from the above link to avoid getting the Yahoo Toolbar version. We do not want to install any unnecessary baggage.
    4) Next, I would like for you to download Spybot. If you already have this on your system, please be sure that Teatimer is turned off.

    SpyBot - Search & Destroy
    • PLEASE leave all settings at default except Teatimer (make sure you uncheck the option during installation)!!
    • During the install, do the search for updates now and get any updates
    • Also look for the Immunize feature in Spybot and use it.
    • Again, do not use the Teatimer function.

    5) Finally download and install Counterspy

    CounterSpy
    • If you had previously used a CounterSpy trial, you may not be able to run it again. If this is the case or if you just cannot get CounterSpy to run, then run the below AVG Antispyware Removal procedure and attach the log later.
    6) Now, run each of these programs in the following order:

    1) CCleaner (run in the default position on the Windows tab. When you double click on the program to start it, a window will open. Over in the lower right-hand corner you will see the button "RUN CLEANER". Click on this. You will get a warning that this will permanently delete files. Say ok and allow it to run. Do not do anything with any of the other tabs or buttons. When it finishes, just close it.

    2) Run Spybot Search and Destroy and have it fix whatever it finds.

    3) Run Counterspy and have it FIX - DELETE OR QUARANTINE- whatever it finds and get the log at the end. Counterspy is a lengthy scan and can take 1-2 hours to run, but it will get rid of a lot of the problems you have described.

    7) After you finish the above, I want you to get one more piece of information for us. Please go to READ & RUN ME FIRST and scroll down to the bottom of the page where you will see links to instructions for your operating system. Choose the one that applies and then look for the directions for the MGTools.exe. Do not run Combofix or AVG Antispyware at this time. Simply follow the instructions for the MGTools.exe
    This is a much shorter scan, usually taking less than a minute.

    8) When you finish, please post the following:

    - Counterspy log
    - MGlogs.zip

    If you have questions, please ask. Let me know how your computer is running.

    abri
     
  3. banana_slama109

    banana_slama109 Private E-2

    I am very, very sorry for not replying in a long time, but I have been away with family maters.

    I ran eveything you asked for and I have one of the two logs you reqested but I cant seem to locate the other one I have the MGlogs but I dont know where to find the other one so here is the one you requested and if you could tell me where the other one is that would be great, thank you very much for all the help so far.

    Banana_slama
     

    Attached Files:

  4. banana_slama109

    banana_slama109 Private E-2

    Opps, it seems as thoug my sister has added a few new programs and a program called "bonjour" has been added im not sure what this is but there are a few other programs she has added so i will send you an updated log sorry for the inconvinience. I would take these programs off but im not sure this is the right to do because i have already created the log ( Mglogs I still have not found the othe log you requested) and if there is still something wrong with my log, you will give me an answer to what might nolonger be on my computer so I will leave them on my computer and not open them, because they are not farmiliar and who Knows what sort of thing (good or bad) may be there.

    Thank you very much and sorry for the double post.
    Banana_slama
     

    Attached Files:

  5. banana_slama109

    banana_slama109 Private E-2

    The good, the bad and the ugly.

    Well a little while ago i asked for some help on removing a virus.

    The Good,

    I was told to run three programs and than to follow some more instructions, and than to post a log. I was away for a while so i just posted the log.
    Anyway I have not gotten a response saying my log is clean, but it seemed at least "visually" to be fixed. This Virus had installed programs on my desktop and wouldnt let me use the comand prompt. I can now use command prompt and no more mystery progrmas. So as far as I can tell Its preety good.
    Well that was that problem.

    The Bad

    One of the programs I was told to install (counter spy) Worked great, and it showed me a whole bunch of stuff that had never popped up on my other antivirus (Norton). So this is a great program and it also fixed a few other problems I had, so thanks for that. One problem it works too good.
    Now I have more problems than I originally thought.

    The Ugly

    Well now that i have a good program that removes lots of junk and what-not
    i am also seeing other programs. i was looking thru the setings and i found the windows host files, I am still not sure what they are but to my understanding, if i want to go to a certain website it redirects that website to me???? I wouldnt be so concerned except for there is a whole bunch of websites on that list that i have never been too, so how did they get there.
    I am also finding at least on spyware and a a few viruses since i installed this program why is my normal antivirus which as far as I know is Good quality (norton antivirus). Do you have any recomendations for a new antivirus/firewall (cost is not a problem)? And although I am a advance coputer user I cant figure out where im getting all this spyware/ viruses.

    Thank you, and sorry if this is the wrong forum but i wasnt sure what the Windows host list thing would be put under.

    Banana_slama
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: The good, the bad and the ugly.

    What specific problems are you referring to?

    What you have is a redirection to 127.0.0.1 which is to your PC. That is how bad websites are blocked. Those addresses were added by Spybot or a similar program to protect you. They are not problems unless you they do not say 127.0.0.1.

    I don't understand what this is supposed to be saying or asking.


    In our final steps (when we finish your cleanup) you will see a link to another sticky thread call How to protect yourself from malware which gives lots of things to do including recommendations.



    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 5

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines (some of the ones from SpybotDeleting will probably be gone already) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: The retnsrp - {941FB260-9D22-480E-84D6-10DB7849180E} - C:\WINDOWS\retnsrp.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7180] command /c del "C:\WINDOWS\retnsrp.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC4224] cmd /c del "C:\WINDOWS\retnsrp.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA2473] command /c del "C:\WINDOWS\leorop.dll_old"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC763] cmd /c del "C:\WINDOWS\leorop.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB9018] command /c del "C:\WINDOWS\retnsrp.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8454] cmd /c del "C:\WINDOWS\retnsrp.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3274] command /c del "C:\WINDOWS\leorop.dll_old"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD8955] cmd /c del "C:\WINDOWS\leorop.dll_old"
    O15 - Trusted Zone: http://*.trymedia.com (HKLM)
    O21 - SSODL: leorop - {7453B8AD-9CDE-4AEE-A7D5-9A5242123C96} - C:\WINDOWS\leorop.dll (file missing)
    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\HP_Administrator\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds