Question:
I got a virus on my pc (worm.win32.netsky)?
Yahies
2009-12-14 14:39:03 UTC
I downloaded the software HiJack This from File Hippo. Below is what the software detected, but I don't what i should fix/delete. Please Help!!!!........



R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.mywebsearch.com/mywebsearch/default.jhtml?ptnrS=GRxdm020VRUS&ptb=THF9I6xAWZxhnOWNOxmEjQ
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon86.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: C:\WINDOWS\system32\mh3t1p.dll - {C5B24B16-23F2-41AD-F4E4-00ABC39C0004} - C:\WINDOWS\system32\mh3t1p.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background
O4 - HKLM\..\Run: [notepad] rundll32.exe C:\WINDOWS\system32\notepad.dll,_IWMPEvents@0
O4 - HKLM\..\Run: [iinjug] RUNDLL32.EXE C:\WINDOWS\system32\msilojzb.dll,w
O4 - HKLM\..\Run: [yawekesav] Rundll32.exe "c:\windows\system32\yohirema.dll",a
O4 - HKLM\..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
O4 - HKCU\..\Run: [notepad] rundll32.exe C:\DOCUME~1\NETWOR~1\ntload.dll,_IWMPEvents@0
O4 - HKCU\..\Run: [asg984jgkfmgasi8ug98jgkfgfb] C:\DOCUME~1\jeff\LOCALS~1\Temp\win16.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [notepad] rundll32.exe C:\DOCUME~1\LOCALS~1\ntload.dll,_IWMPEvents@0 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [notepad] rundll32.exe C:\DOCUME~1\LOCALS~1\ntload.dll,_IWMPEvents@0 (User 'Default user')
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name)
Three answers:
cbgerry
2009-12-14 16:03:47 UTC
Quick Analysis..... (I do these logs here now http://tech.groups.yahoo.com/group/Anti-Malware/ )



POSSIBLE/PROBABLE THREAT DISCOVERED



LINE:

O4 - HKLM\..\Run: [notepad] rundll32.exe C:\WINDOWS\system32\notepad.dll,_IWMPEve…



ThreatExpert's awareness of the file "ntload.dll":

http://www.threatexpert.com/files/ntload.dll.html

Across all ThreatExpert reports, the file "ntload.dll" was mostly identified as a threat.



NTLOAD.DLL

http://www.prevx.com/filenames/1036472234377312938-X1/NTLOAD.DLL.html

BRIEF:

DANGER:

The process is hooked into all running processes which could allow it to take control of the system or record keyboard input, mouse activity and screen contents....

File Name Aliases...

NOTEPAD.DLL -- NF4CD.TMP -- NTLOAD.DLL__DELETE_ON_REBOOT -- SCANDISK.DLL -- KXHFRCZ.TMP



Zlob.PornAdvertiser.ba

http://www.pcthreat.com/parasitebyid-6842en.html

Zlob.PornAdvertiser.ba may look like original Windows alert but IT IS NOT!!!! Zlob.PornAdvertiser.ba can get into users computer system through security exploits by Trojan like Trojan Zlob, malware or Virus.....

FILES Associated.....

winsrc.dll

herjek.exe

lost.exe.exe

lbeomldh.exe

ntload.dll

zfe2.exe

zfe4.exe

zfe5.exe

njgpldlp.exe

HQ porn video.URL

Sex videos.URL

Uncensored porn.URL



POSSIBLE/ PROBABLE THREAT....

O4 - HKLM\..\Run: [iinjug] RUNDLL32.EXE C:\WINDOWS\system32\msilojzb.dll,w

THREAT INFO:

msilojzb.dll

http://www.threatexpert.com/report.aspx?md5=cb379b9b6ac89482d2f6b53af592cfab





Stopping here and recommending Full Scan.....



CLEAN THE MACHINE FIRST.....



a-squared trojan remover (Free Working Version for life and Proactive Premium Version) [NOW WITH IKARUS ANTIVIRUS] [wrkx w/ Netbooks]

http://www.emsisoft.com/en/software/free/

a-squared (a-squared) is a complementary product to antivirus software and desktop firewalls on MS Windows computers. Antivirus software specializes in detecting classic viruses. Many available products have weaknesses in detecting other malicious software (Malware) like Trojans, Dialers, Worms and Spyware (Adware). a-squared fills the gap that malware writers exploit. Automatic updates: In a-squared Free the updater must be run manually. The auto-update feature of a-squared Personal checks hourly for new available updates and installs them automatically. a-squared Free is freeware! You can download and use it completely for free.



INSTALL REAL TIME PROTECTION PRODUCTS TO BLOCK INFECTIONS...



Windows OneCare Antivirus is now Free from Microsoft and very highly rated, West Coast Labs Certified and has won the VB100 Award ! Now called Microsoft Essentials.....

About Microsoft Security Essentials (5* Stars!) (FULL) [wrkx w/ Netbooks]

http://www.microsoft.com/security_essentials/

Microsoft Security Essentials provides real-time protection for your home PC that guards against viruses, spyware, and other malicious software. Microsoft Security Essentials is a free* download from Microsoft that is simple to install, easy to use, and always kept up to date so you can be assured your PC is protected by the latest technology. It’s easy to tell if your PC is secure — when you’re green, you’re good. It’s that simple.

Microsoft Security Essentials runs quietly and efficiently in the background so that you are free to use your Windows-based PC the way you want—without interruptions or long computer wait times.



Comodo Free Anti Virus Software Internet Security

Free Antivirus Software from Comodo eliminates viruses, spyware, and other malware from desktops and networks fighting against Internet security threats.



Microsoft AntiSpyware is now Windows Defender 4-5* (FULL) [wrkx w/ Netbooks]

[working-freeware from Microsoft]

http://www.microsoft.com/athome/security/spyware/software/default.mspx

Windows Defender is a free program that helps protect your computer against pop-ups, slow performance, and security threats caused by spyware and other unwanted software. It features Real-Time Protection, a monitoring system that recommends actions against spyware when it's detected, and a new streamlined interface that minimizes interruptions and helps you stay productive.



FURTHER....

O7 - HKCU\Software\Microsoft\Windows\CurrentV… DisableRegedit=1



This apparently indicates malware installation as blocks User entry into the Windows Registry for manual inspection and removals of malwares. This is achieved by opening the Windows Registry ......

Start > Run > type in "regedit" (without parenthesis) and OK....

If registry does not open - machine is infected (virus, trojan, other).



Run the Microsoft Malicious Software Removal Tool first or if you can not use others.
anonymous
2016-05-26 10:53:11 UTC
First off, stop using Limewire, torrents are a bit safer but you're never safe without an antivirus program. Get Windows Live OneCare until the 90 days runs out, and if you don't wanna buy it when that runs out get AVG and use that until Microsoft releases Morro around halfway through 2009, which will basically be OneCare but free.
Keyano Reev
2009-12-14 23:02:36 UTC
Worm.Win32.Netsky can be removed manually by following the steps below.



1. With all programs closed, click the Start Menu and go to the Control Panel



2. Locate the Add/Remove Programs icon and double click it.



3. Locate Worm.Win32.Netsky in the list of programs. If you find it, select it and remove it. If you cannot find Worm.Win32.Netsky, you can continue to step 5.



4. Restart your computer.



5. Close all open programs and windows on your desktop.



6. Open your registry editor (regedit) program by going to Start Menu, type in regedit, and click OK.



7. Find all of the following registry entries and delete them. If you do not know how to do this, then you can read how to edit the registry in Windows.



8. You may need to return to this removal process for removing Worm.Win32.Netsky. You can do this easily by bookmarking or adding a favorite to this page by clicking here. If you are using the FireFox web browser you can press the keys Ctrl and D simultaneously to bookmark this page.



9. Delete all of the following files that are associated with Worm.Win32.Netsky from your computer.



If you need a better understanding on how to search for these files then you can read how to find and search for files and folders here.



If you have issues deleting any of the previously listed files that are associated with Worm.Win32.Netsky, you can try rebooting your computer into safe mode. Booting into safe mode may allow certain malicious files to be deleted. If you are wondering how to boot into safe mode, you can read our process for starting a computer in safe mode here.



10. After locating and deleting the previous files you must remove all directories associated with Worm.Win32.Netsky by going to the C:\ProgramFiles\Worm.Win32.Netsky folder, select it, and delete it. In some cases you may not be able to find this directory. You can still continue to the next step.



11. Restart your computer. You do not need to boot into safe mode at this point. You should have removed Worm.Win32.Netsky completely from your computer. If you find that Worm.Win32.Netsky is still on your computer, you can repeat the steps again or go to the automatic Worm.Win32.Netsky removal process.


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...