Start a Conversation

Unsolved

This post is more than 5 years old

9014

March 21st, 2008 01:00

Worm attack- Worm.Win32.NetSky

I am getting popups warning of worm.win32.netsky infection. It has installed icons on my desktop and continually opens IE windows to "antispyware download sites" I am using the kid's computer to post this. Mine is virtually unusable. Can anyone help?

2 Intern

 • 

2.7K Posts

March 21st, 2008 10:00

Clear your System Restore Files also.
"Users of Windows Me and Windows XP should temporarily turn off System Restore. Windows Me/XP uses this feature, which is enabled by default, to restore the files on your computer in case they become damaged. If a virus, worm, or Trojan infects a computer, System Restore may back up the virus, worm, or Trojan on the computer."

2 Intern

 • 

2.7K Posts

March 21st, 2008 10:00

Here is a removal guide to help you rid your computer of this infection.

3 Apprentice

 • 

20.5K Posts

March 21st, 2008 14:00

My SiteHound will not allow me to go to that removal guide. Is it safe?????

baroncornelius, try running MBAM and if that does not work, post a Hijackthis log on the Hijackthis Board here: http://www.dellcommunity.com/supportforums/board?board.id=si_hijack
to start your own thread requesting assistance.
Please download to your desktop Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process; if asked to restart the computer, please do so immediately.

March 21st, 2008 21:00

Is there anything I can do to stop the pop ups while I try to download. There are so many, I am unable to download anything. I tried the task manager and it is disabled. I tried pslist from the command prompt and it tells me that is not an internal command. When I try to open my IE, it takes me to an "anti-spyware/malware" site, and I can't go anywhere else.

3 Apprentice

 • 

20.5K Posts

March 22nd, 2008 02:00

If you are now posting from another computer, download MalwareBytes' Anti Malware setup to a CD or USB stick. Transfer it to the infected computer and install it on there so you can run a scan. If the malware has disabled the Task Manager, you probably have a serious infection.
I also suggest that you download HijackThis and post a HijackThis log on the HJT Board here for a follow-up evaluation.
Download HJT Installer from Here to your desktop.
If not available use this alternate link: Here

Click the Download button.
When the Trend Micro HJT install box appears, double click on the HJTInstall.exe.
Click on Install.

It will be installed by default here: C:\Program Files\Trend Micro\HijackThis
A shortcut to the application will also be placed on your Desktop.
The program will open automatically after installation.
You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder.
The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.

Close all open windows except HijackThis.
Click on " Do a system scan and save logfile" When the log pops up in Notepad copy and paste that file as a NEW MESSAGE on the HijackThis Board.

Before closing HJT, please click on the Analyze This button. "Analyze This" is for Trendmicro use, and does not mean "Analyze My Log". You must post on the forum in order to receive an analysis of your log.

Close the web page that appears and then close the program HJT.

Posting Your Log:

1. Just click the New Message button in the HijackThis forum here: http://www.dellcommunity.com/supportforums/board?board.id=si_hijack
to start your own thread requesting assistance.
2. In the Message Body window that opens, simply Right-Click and select Paste.
3. Please add text to describe your symptoms.
4. Include in the message subject line a description of your problem. For example, "Popups warning of infection".
5. Make certain you post the entire log by clicking the Preview Post link at the bottom of the window and comparing it to the log from your scan before you click Submit Post

** Note: "The box next to Automatically convert carriage returns to HTML line breaks" should be checked if that appears at the bottom of your Message Body when composing your post.


* DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or required.
No Events found!

Top