This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Worm.Win32.Netsky

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys!

I started my laptop the other day to be greeted by a message saying:
Security Warning!
Worm.Win32.Netsky detected on your machine.
This virus is distributed via the Internet through email and Active-x
objects.
The worm has its own smtp engine which means it gathers
emails from your local computer and re-distributes itself.
In worst cases this worm can allow attachers to access your
computer, stealing passwords and personal data.
Viruses can damage your confidential data and work on your
computer.
Continue working in unprotected mode is very dangerous.


My wallpaper has changed to bright green with a black box saying:
YOUR SYSTEM IS INFECTED!
System has been stopped due to a serious malfunction. Spyware activity has been detected. It is recommended to use spyware removal tool to prevent data loss. Do not use the computer before all spyware is removed."


I googled it and found these instructions to remove it: Link Removed: LDT
but when I boot to safe mode and run SmitfraudFix I get a message saying: Application cannot be executed. The file is infected. Please activate your antivirus software.


I really don't know what to do now. Any help would be very much appreciated!
Hello adam707 and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.

  • Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
  • This may cause a delay in response time, but I will do my best to keep it as short as possible.
  • I am checking over your log, and I will post back shortly with instructions.
Hello adam707

when I boot to safe mode and run SmitfraudFix


Please do not run any more tools unless specifically asked to do so.

Before we begin I would like you to scan your system so I can get a better idea of what is happening on your machine. Please work your way through the following steps:


  • exeHelper


    • Please download exeHelper by clicking here and save the file (called exeHelper.com) to your desktop.
    • Double click on exeHelper.com to run the fix.
    • A black window should pop up. Press any key to close once the fix is completed.
    • Post the contents of log.txt (it Will be created in the directory where you ran exeHelper.com).
    • NOTE: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

  • Please perform the following scan


    • Please download DDS from here or here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    • Please download GMER from here and save the file to your desktop.
    • NOTE: The saved ".exe" file will have a completely random name. This is normal.

    • You can also download the zipped GMER program from here, here or here.
    • If you download GMER from one of the zipped links, unzip the file (called gmer.zip) to your desktop.

    • Before scanning, please make sure that all other running programs are closed and that no other actions (such as a scheduled antivirus scan) will occur while the scan is being performed. Do not use your computer for anything else during the scan.
    • Double click on the "randomname.exe" or unzipped "gmer.exe" to run the program.

    • Caution! These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT" entries unless advised!
    • If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
    • Click on "NO".
    • In the right panel, you will see a number of boxes that have check marks placed next to them.
    • Leave these boxes as they are, but please ensure that the "Show all" box is un-checked.
    • Now click the "Scan" button.
    • Once the scan is complete, you may receive another notice about rootkit activity. This is normal.
    • Click on "OK".
    • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt".
    • Save the file where you can easily find it, such as your desktop.
    • Post the contents of GMER.txt in your next reply.

    In your next reply, please post the contents of the exeHelper log, the DDS logs and the GMER log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI