Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

worm.win32.netsky infection


  • This topic is locked This topic is locked
5 replies to this topic

#1 noobrts

noobrts

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:14 PM

Posted 27 January 2010 - 12:58 AM

I was browsing the web when all of a sudden my desktop background changed to say that i had worm.win32.netsky virus. I could not do ctrl-alt-delete, and immediately shut down my computer, rebooted in safe-mode. Upon starting in safe mode i had the worm.win32.netsky pop message saying my comp was infected, and still could not use ctrl-alt-delete or system restore. I rebooted in safe mode again, and clicked "no" to do a system restore and some how it worked without any errors. I rebooted in safe mode again to run restore to an earlier time then before, just to be safe. My comp booted just fine with no errors and everything works correctly. I did some searching and deleted a regestry file called worm.netsky. I also used spy-bot search and destroy with no errors. I just want to make sure my computer is clean. Thanks for your help and time, much appreciated.




DDS report -


DDS (Ver_09-12-01.01) - NTFSx86
Run by ininjai at 23:21:50.51 on Tue 01/26/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1113 [GMT -6:00]


============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\SBAudigy4\Volume Panel\VolPanlu.exe
C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\SBAudigy4\Entertainment Center\EAXLoadr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\mrt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ininjai\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [Creative MediaSource Go] "c:\program files\creative\mediasource5\go\CTCMSGoU.exe" /SCB
mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll"
mRun: [VolPanel] "c:\program files\creative\sbaudigy4\volume panel\VolPanlu.exe" /r
mRun: [CTDVDDET] "c:\program files\creative\sbaudigy4\dvdaudio\CTDVDDET.EXE"
mRun: [RCSystem] "c:\program files\creative\shared files\module loader\DLLML.exe" RCSystem * -Startup
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15106/CTPID.cab
TCP: {B70DA6BD-AFB9-477C-AC69-A217786ADD89} = 24.159.193.40,68.115.71.53
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ininjai\applic~1\mozilla\firefox\profiles\3ycpukpj.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\documents and settings\ininjai\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\ininjai\application data\move networks\plugins\npqmp071505000011.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

S3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\commonfx.sys --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\commonfx.sys --> c:\windows\system32\drivers\COMMONFX.SYS [?]
S3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\ctaudfx.sys --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\ctaudfx.sys --> c:\windows\system32\drivers\CTAUDFX.SYS [?]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\cterfxfx.sys --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\cterfxfx.sys --> c:\windows\system32\drivers\CTERFXFX.SYS [?]
S3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\ctsblfx.sys --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\ctsblfx.sys --> c:\windows\system32\drivers\CTSBLFX.SYS [?]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2009-11-16 33792]
S3 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\drivers\xPADFL02.sys [2009-11-16 27904]
S4 Apache2.2;Apache2.2;c:\program files\apache software foundation\apache2.2\bin\httpd.exe [2008-12-10 24636]
S4 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-11-13 464264]
S4 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-11-13 234888]
S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]

=============== Created Last 30 ================

2010-01-27 03:41:18 0 d-----w- c:\windows\system32\wbem\Repository
2010-01-27 03:39:12 0 d--h--w- C:\jexepackres
2010-01-27 03:19:13 1 ----a-w- C:\s
2010-01-22 02:59:36 9047 ----a-w- c:\windows\system32\nvinfo.pb
2010-01-22 02:59:36 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-22 02:59:36 4104192 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-22 02:59:36 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-22 02:59:36 2259560 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-22 02:59:36 14458880 ----a-w- c:\windows\system32\nvoglnt.dll
2010-01-22 02:59:34 2283526 ----a-w- c:\windows\system32\nvdata.bin
2010-01-22 02:59:34 182888 ----a-w- c:\windows\system32\nvcodins.dll
2010-01-22 02:59:34 182888 ----a-w- c:\windows\system32\nvcod.dll
2010-01-22 02:59:34 11632640 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-22 02:59:34 1081344 ----a-w- c:\windows\system32\nvapi.dll
2010-01-22 02:42:05 91035488 ----a-w- C:\196.21_desktop_winxp_32bit_english_whql.exe
2010-01-19 07:32:26 0 d-----w- C:\images
2010-01-19 07:32:25 0 d-----w- C:\css
2010-01-18 01:45:55 0 d-----w- c:\program files\FileZilla
2010-01-17 19:27:07 16868 ---ha-w- c:\windows\system32\mlfcache.dat
2010-01-15 21:00:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 04:17:44 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-01-12 04:17:44 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-01-12 04:17:44 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-01-12 04:17:44 13666408 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-12 04:17:44 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-12 04:17:40 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-01-12 04:17:30 65332 ----a-w- c:\windows\system32\NvwsApps.xml
2010-01-12 04:17:30 271490 ----a-w- c:\windows\system32\NvApps.xml
2010-01-09 01:11:21 0 d-----w- c:\program files\PKR
2009-12-31 23:58:41 0 d-----w- c:\program files\NoPayPOKER

==================== Find3M ====================

2010-01-12 04:03:33 6359168 ----a-w- c:\windows\system32\nv4_disp.dll
2010-01-12 04:03:33 10276768 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-12-22 23:59:32 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-12-21 02:49:22 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-12-02 06:32:41 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-12-02 06:32:32 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-11-19 04:56:17 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-11-19 04:56:17 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-11-19 04:56:17 12067 ----atw- c:\windows\system32\SIntf16.dll

============= FINISH: 23:22:00.95 ===============

Attached Files


Edited by noobrts, 27 January 2010 - 01:04 AM.


BC AdBot (Login to Remove)

 


#2 noobrts

noobrts
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:14 PM

Posted 27 January 2010 - 03:23 PM

the worm.win32.netsky popped up again and i was unable to access anything. i tried to run spy-bot in safe mode and it found a few viruses and some registry entries. I saved the log file and deleted the entries and all but one was deleted because it was in use. Spy-bot asked me if it could run on start up to delete the last entry and i clicked yes. Now, i am stuck in a windows log in loop and it will not let me log in. I saved the file for spy-bot to post on these logs and was going to make a new dds report and ark file, but unable to log into my os. Thanks for any help.

#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:14 PM

Posted 02 February 2010 - 06:24 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

Do you still require help?

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:14 PM

Posted 06 February 2010 - 02:58 PM

Hello.

Are you still there? Do you still require help?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#5 noobrts

noobrts
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:07:14 PM

Posted 07 February 2010 - 08:06 AM

Sorry for the inconvenience, but i fixed my problem myself. If i have any new issues i'll be sure to come back to this forum. Thanks for your time.

#6 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:14 PM

Posted 08 February 2010 - 08:05 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed. Glad we could help smile.gif
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users