I think I have worm.win32.netsky virus

Virus warnings popping up. Security Alert, Advanced Virus Remover. I've tried a couple of removal tools and it won't let them download. I can't download McAfee Security. I can't do a syatem restore. I downloaded Hijackthis but can't get it to open. I can't get to add/remove programs in control panel. It just says "please wait while the list is being populated". Please help. I am not at my computer a lot so it may be some time between my responses.

Comments

  • edited December 2009
    Hey there. :)

    A few things before we start....
    1. Please Read All Instructions Carefully.
    2. If you don't understand something, stop and ask! Don't keep going on.
    3. Please do not run any other tools or scans whilst I am helping you.
    4. If you have to go away for an extended period of time, let me know.
    5. Please continue to respond until I give you the "All Clear".
    (Just because you can't see a problem doesn't mean it isn't there)



    Please download Malwarebytes' Anti-Malware by clicking the link below:
    http://www.besttechie.net/tools/mbam-setup.exe

    Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform Quick Scan", then click Scan.
    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    * You'll be required to post the contents of this log later.

    Please Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



    Next let's have you download ComboFix.exe. Please visit this webpage for downloading and instructions for running the tool:

    Go here ======> A guide and tutorial on using ComboFix <====== Go here

    Please ensure you read this guide carefully and install the Recovery Console first.This applies to XP Pro and XP Home users only.If you have SP3 installed you will need to use the download meant for SP2.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should get a prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:

    (1) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    (2) Click Yes to allow ComboFix to continue scanning for malware.

    When the tool is finished, it will produce a report for you.


    Please include the MBAM log and C:\ComboFix.txt for further review, so that we may continue cleansing the system.


    Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Misuse can cause serious computer problems.
  • edited December 2009
    When I click on the link http://www.besttechie.net/tools/mbam-setup.exe it goes to the Google Toolbar Page - OOPS! This Link Appears Broken. I can't complete the first step of your instructions. What do I do?
  • edited December 2009
    Perhaps that was a temporary problem. Seems to work fine for me now. Try it again.

    Alternatively, use this link:
    http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
  • edited December 2009
    I seem to be having the same problem except I cannot do much of anything except internet exploer and Firefox. When I log into windows a screen comes up and says I am infected with Worm.win32.netsky. Warnings come up and backgroud goes crazy. But I cannot get to task manger and I also cannot try to get to task manger before it fully loads as many people say I should. It says "Windows cannot access the specified device path, or file. You may not have the appropriate permissions to access the item." In fact it says this when I try to load pretty much anything. I cannot install anything and I cannot change anything. In safe mode I have problems too. The same screen comes up when I first load into safe mode saying I am infected with Worm.win32.netsky. I cannot get into task manger. I cannot get into user accounts. The only difference here is when I click on something to open it whether it be in control panel or an exe it just turns into an hourglass like it is loading and then it does nothing. So I can also do nothing safe mode! What can I do? I have free avg installed, and when i run it in safe mode, one of the few things that will come up in safe mode, it will only do a command line scan, whatever that is. Do I have to resort to a full restart? Thanks for any help. I have been reading all over the internet and it seems no one has my problem.
  • edited December 2009
    I figured out why could not open some programs. If I right click on it and then click "run as", I can uncheck "Protect my computer and data from unauthorized program activity". But even after malware and avg loaded, it would not actually run the scan. I restarted the computer and now when I log in to windows it imediatley logs me off. So I can not even get in. Any suggestions? Good thing I took the Liberty to get all documents and pictures off of the main drive and on a external hard drive.
  • edited December 2009
    Hi imp6525,

    If you have a problem, please start a new thread and I'll attend to your issue as soon as I can. Thanks.
  • edited December 2009
    I've loaded Malwarebytes' Anti-Malware but it won't start. When I click on the icon it just flashes and stays on my desktop page. I tried run as and it did the same thing.
  • edited December 2009
    Try renaming the file to xxx.exe. Then run it again.
  • edited December 2009
    I'm not sure if I did that right. It still wouldn't run. Tell me how to rename the file and exactly which file to rename. -OR- As an alternative possibility, since I don't have very much important information on this computer, would you suggest reloading my operating system from the restore disks and would that get rid of the problem.
  • edited December 2009
    What you have to rename is the executable file. Simply put, that is the MBAM icon on your desktop (if you installed it this way).

    The file should be called mbam.exe. Rename it to xxx.exe and double-click on the renamed file.
  • edited December 2009
    I came in today and my computder wouldn't boot up. I tried several times with no luck so I used my restore disks and did a format and restore. I don't know if the virus could still be hiding somewhere, though. I was also able to install McAfee Security after the restore. Everything seems to be working fine now. Do you think I need to do anything else?
  • edited December 2009
    No problem.

    If you want, you can try installing MalwareBytes now and run a full scan with it. Let me know if it comes up with anything.
  • edited December 2009
    I ran Malwarebytes and it reported no malicious items found. Thanks so much for your help and your willingness to help people like me. It's nice to know there are good people to help combat the TRASH that has nothing better to do than cause problems for others. Thanks again!
  • edited December 2009
    You're welcome.

    Since the problem is resolved, I will move it to the appropriate place now.
Sign In or Register to comment.