This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Worm.Win32.NetSky

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I restarted my computer after some crazy things started happening and got a message saying: Security Warning! Worm.Win32.NetSky detected on you machine. This virus is distributed via the Internet through e-mail and Avtive-x objects… A message pops up in the system tray saying "Your computer is infected! Windows has detected an infection of spyware! It is recommended to use special antispyware tools to prevent data loss. Windows will now download and install the most up-to-date antispyware for you." It has also changed my background to a green background with a B.S. message displayed on it. Task manager won't run and ERUNT and MBAM won't run all due to an access denied error message. I was unable to save the GMER report but I can try to run it again if necessary. I'm running Windows XP Pro SP 3 with 1.7 GHz processor and 512 MB RAM. Thank you in advance, Kevin DSS.txt: DDS (Ver_09-06-26.01) - NTFSx86 NETWORK Run by [removed] at 22:06:57.54 on Sun 01/31/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.113 [GMT -5:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch C:\WINDOWS\system32\svchost -k rpcss C:\WINDOWS\system32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\smss32.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Administrator\Desktop\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mWinlogon: Userinit=c:\windows\system32\winlogon32.exe BHO: c:\windows\system32\bh995a96hy.dll: {c4bf49a2-94f1-42bd-f034-3604811c807d} - c:\windows\system32\bh995a96hy.dll EB: IE Developer Toolbar: {a202b231-ef71-4a08-bdb9-4ce5ae8bde0a} - c:\program files\microsoft\internet explorer developer toolbar\IEDevToolbar.dll EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet explorer\iedvtool.dll uRun: [Google Update] "c:\documents and settings\administrator\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [smss32.exe] c:\windows\system32\smss32.exe uRun: [asg984jgkfmgasi8ug98jgkfgfb] c:\docume~1\admini~1\locals~1\temp\setup.exe uRun: [sefjhf98jfoidsfoishgoiusgdgfgd] c:\docume~1\admini~1\locals~1\temp\vbynq5m.exe uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\NPSWF32_FlashUtil.exe -p mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [M-Audio Taskbar Icon] c:\windows\system32\M-AudioTaskBarIcon.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Iwakiyixevo] rundll32.exe "c:\windows\acobesitef.dll",Startup mRun: [smss32.exe] c:\windows\system32\smss32.exe mRun: [wununemor] Rundll32.exe "c:\windows\system32\gevimasi.dll",a mRunOnce: [wextract_cleanup0] rundll32.exe c:\windows\system32\advpack.dll,delnoderundll32 "c:\docume~1\admini~1\locals~1\temp\ixp000.tmp\" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\77557.lnk - c:\documents and settings\administrator\local settings\temp\a32pasop.exe StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\8614335.lnk - c:\documents and settings\administrator\local settings\temp\dllhosts.exe uPolicies-explorer: NoSetActiveDesktop = 1 (0x1) uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) uPolicies-explorer: NoFolderOptions = 1 (0x1) uPolicies-system: DisableTaskMgr = 1 (0x1) uPolicies-system: DisableRegistryTools = 1 (0x1) mPolicies-explorer: NoSetActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: EnableLUA = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - {CC962137-2E78-4F94-975E-FC0C07DBD78F} - c:\program files\microsoft\internet explorer developer toolbar\IEDevToolbar.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Trusted Zone: buy-internet-security10.com Trusted Zone: is-soft-download.com Trusted Zone: is-software-download.com Trusted Zone: is-software-download25.com Trusted Zone: buy-internet-security10.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab TCP: {9CDB6A12-40B2-4027-A71E-C20DD5AB6E68} = 83.149.115.157,4.2.2.1,65.32.5.111 65.32.5.112 TCP: {B1E76BD9-84C5-4370-B53D-0A3ADB3DF11D} = 83.149.115.157,4.2.2.1,68.87.74.166 68.87.68.166 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll AppInit_DLLs: wunezozo.dll c:\windows\system32\gevimasi.dll SSODL: rokunekot - {64a7ffbc-abec-4863-9d24-6265d03f5e69} - c:\windows\system32\gevimasi.dll STS: c:\windows\system32\bh995a96hy.dll: {c4bf49a2-94f1-42bd-f034-3604811c807d} - c:\windows\system32\bh995a96hy.dll STS: ThreadingModel - No File STS: jugezatag: {64a7ffbc-abec-4863-9d24-6265d03f5e69} - c:\windows\system32\gevimasi.dll LSA: Notification Packages = scecli inenshe.dll nozepelo.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\t3uqor0c.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\documents and settings\administrator\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: XULRunner: {60033ED6-F154-4323-935C-E0B59F1742FB} - c:\documents and settings\administrator\local settings\application data\{60033ED6-F154-4323-935C-E0B59F1742FB} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664] S1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [2008-10-23 14464] S2 BtwSvc;BtwSvc;c:\windows\system32\svchost.exe -k netsvcs [2004-8-12 14336] S3 MADFU;MADFU;c:\windows\system32\drivers\MADFUXP.sys [2008-7-1 16512] S3 MAUSBXP;Service for M-Audio Xponent (WDM);c:\windows\system32\drivers\mausbxp.sys [2008-9-15 131712] S3 ndismgr;ndismgr;c:\windows\system32\ndismgr.sys [2004-8-12 2304] =============== Created Last 30 ================ 2010-01-31 17:54 28,552 a——- c:\windows\system32\drivers\pavboot.sys 2010-01-31 17:52 –d—– c:\program files\Panda Security 2010-01-31 17:39 34,304 a——- C:\U.exe 2010-01-31 17:39 664 a——- c:\windows\system32\d3d9caps.dat 2010-01-31 17:36 –d—– c:\docume~1\admini~1\applic~1\Malwarebytes 2010-01-31 17:36 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-31 17:36 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-01-31 17:36 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-01-31 17:36 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-01-31 17:16 2,713 —sh— c:\windows\system32\mavasoze.dll 2010-01-31 17:11 1,283,584 a——- c:\windows\system32\IS15.exe 2010-01-31 17:11 28,672 a——- c:\windows\system32\helper32.dll 2010-01-31 17:11 648 a——- c:\windows\system32\uses32.dat 2010-01-31 17:11 100 a——- c:\windows\system32\flags.ini 2010-01-31 17:10 2,931 a——- c:\windows\system32\warning.html 2010-01-31 17:10 34,304 a——- c:\windows\system32\winlogon32.exe 2010-01-31 17:10 34,304 a——- c:\windows\system32\smss32.exe 2010-01-31 17:10 34,304 a——- C:\hhth.exe 2010-01-31 17:10 153,600 a——- C:\vitbtmc.exe 2010-01-31 17:10 52,224 a——- C:\wpqv.exe 2010-01-31 17:10 20,000 a——- c:\windows\system32\bh995a96hy.dll 2010-01-31 17:10 37,376 a——- C:\ydnjyo.exe 2010-01-31 16:58 0 a——- c:\windows\Jhunuracanari.bin 2010-01-31 16:58 120 a——- c:\windows\Nbabunu.dat 2010-01-13 06:16 471,552 -c—— c:\windows\system32\dllcache\aclayers.dll ==================== Find3M ==================== 2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll 2009-11-21 10:51 471,552 a——- c:\windows\apppatch\aclayers.dll 2009-01-21 21:39 80 a——- c:\docume~1\admini~1\applic~1\tintsnft.sys 2008-11-19 14:37 167 a——- c:\documents and settings\administrator\udownload.dat 2003-08-05 10:41 53,248 a——- c:\windows\inf\ap561.exe 2002-11-26 15:24 32,768 a——- c:\windows\inf\Remove561.exe 2002-11-22 14:56 118,784 a——- c:\windows\inf\ShowBmp.exe 2002-10-29 17:07 36,864 a——- c:\windows\inf\Setup8a.exe 2002-10-01 13:43 119,798 a——- c:\windows\inf\spca561.sys 0000-00-00 00:00 23,552 a–sh— c:\windows\system32\bibuwoge.dll 0000-00-00 00:00 93,184 a–sh— c:\windows\system32\gevimasi.dll 0000-00-00 00:00 52,224 a–sh— c:\windows\system32\nozepelo.dll 0000-00-00 00:00 52,224 a–sh— c:\windows\system32\toyipivo.dll 0000-00-00 00:00 45,568 a–sh— c:\windows\system32\wogiregu.dll 0000-00-00 00:00 52,224 a–sh— c:\windows\system32\wunezozo.dll 2008-08-13 11:50 16,384 a–sh— c:\windows\system32\config\systemprofile\cookies\index.dat 2008-08-13 11:50 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat 2008-08-13 11:50 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081320080814\index.dat 2008-08-13 11:50 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat ============= FINISH: 22:07:16.15 ===============
[external image: Posted Image]

Vista users:
1. These tools MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator") every time you run them



1) exeHelper
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


Next:

Download Combofix from any of the links below but rename it to ABCD.exe before saving it to your desktop.

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Link 1
Link 2


Double click on the ABCD.exe ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI