UNSOLVED

SEMANA

updated

22 years ago

S

SEMANA

2 Intern

197 Posts

0

4448

March 6th, 2004 09:00

Virus messages

Yesterday I got this message in my email:

Caltrans virus detection software has found an infected file sent from your email address. Files that have been successfully cleaned are delivered.

Files that cannot be cleaned are not delivered.

(oaksmtp02)

 

Date: 03/05/2004 12:27:57 PM

Subject: Re: Your product

Virus: WORM_NETSKY.D

File: your_product.pif

From: semana777@yahoo.com

To: 35.00525000@dot.ca.gov

Action: Uncleanable, Quarantined;

Scanned by ScanMail for Lotus Notes 2.5

with scanengine 6.860-1001

and patternfile lpt$vpn.801

 

I don't know who it's from, but it appears to be some government organization.

I have Norton Anti Virus with live update and Norton Internet Security Pro 2004. I scan weekly and also scan with Spybot and Ad-aware.

After getting this message I scanned with Norton and 2 files showed up as questionable, although I don't know if these were the ones referred to in the message above.

I have a problem with Norton. After scanning and showing files as questionable it seems none of the options are available - quarantine, delete, etc. All I can do is click "finish" or "next" and then it tells me I haven't done anything to these files - but there isn't anything that will work.

Writing (emailing) to Norton never brings any response of course, as is true with all companies these days. Thank goodness for this forum.

semana

  • Yellowhammer

    725 Posts

    188

    0

    Posted March 6th, 2004 10:00

    Semana,

    It looks like your email address was used by the virus to send itself out.  It was sent from someone's computer that has your email address in their address book or whever the virus is finding email addresses.  If your virus definitions are up to date and your scan did not find anything then you are OK.

  • SEMANA

    2 Intern

    197 Posts

    188

    0

    Posted March 6th, 2004 20:00

    Thanks. I did everything. Hope it helps.
  • SEMANA

    2 Intern

    197 Posts

    188

    0

    Posted March 6th, 2004 23:00

    I went through an installed the recommended programs. Now everything is messed up. My Norton Internet Security and Norton Anti Virus won't load. Nothing works. I can't download pictures from my camera. My email doesn't work. Good grief. I can't download my tax return from TurboTax. What a mess.
  • Yellowhammer

    725 Posts

    188

    0

    Posted March 6th, 2004 23:00

    I have never heard of these programs causing trouble of this type.  Did you by any chance run hijackthis and fix everything?  If so you need to run it again, click on the config button, then the backups button and restore everything.  If that is not what you did then Uninstall the programs one at a time and see which one caused the problem.   
  • Yellowhammer

    725 Posts

    188

    0

    Posted March 7th, 2004 11:00

    It looks like newdot net.  See if this is listed in your add/remove programs and remove it from there.
  • SEMANA

    2 Intern

    197 Posts

    188

    0

    Posted March 7th, 2004 11:00

    Thanks. But I'm gun-shy now. I did a "System Restore" to 24 hours before and things are back to normal now. I don't know which program caused the problem, but it sure worried me for a while.

    I still have no idea what the original email was about or where it came from.

    And when I do a Norton Anti Virus Pro virus scan there are two "Adware.NDotNet" threat alerts which will not delete. When I try I always get "delete failed."

    Here's what the Norton log shows. It's the same for both entries in the log.

    Source: C:\My Downloads\newnet_1.exec

    Description: The file C:\My Downloads\newnet_1exe is a Adware threat. Click for more information about this threat: Adware.NDotNet

    Here's what Symantec says about this particular threat - oops - apparently I can't paste a url into posts on this forum (???)

    I guess if you go to Symantec's website and search for Adware and then NDotNet you will find their explanation of this particular threat.

    Why can't you paste a url into messages on this forum???

  • SEMANA

    2 Intern

    197 Posts

    188

    0

    Posted March 7th, 2004 12:00

    Thanks. No, it's not listed in the Add/Remove Programs listing.

  • Yellowhammer

    725 Posts

    188

    0

    Posted March 7th, 2004 13:00

    It is NewDotNet.  Why don't you post a hijackthis log?  You probably have one or more O10 Items in the list that were caused by New Dot Net.  If so, there is a tool that will fix them.  There are probably several more items as well.

     

     

  • SEMANA

    2 Intern

    197 Posts

    188

    0

    Posted March 9th, 2004 11:00

    HijackThis - Log - 03.09.04

    Logfile of HijackThis v1.97.7
    Scan saved at 6:01:49 AM, on 3/9/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\AdvTools\NPROTECT.EXE
    C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\SAVScan.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\BCMSMMSG.exe
    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\Program Files\Common Files\Dell\EUSW\Support.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\traywc.exe
    C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
    C:\unzipped\hijackthis1977\HijackThis.exe
    C:\Program Files\Messenger\msmsgs.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
    O2 - BHO: (no name) - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security Professional\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security Professional\UrlLstCk.exe
    O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\NORTON~1\AdvTools\ADVCHK.EXE
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [Microsoft Works Update Detection] ???????\WkDetect.exe
    O4 - Global Startup: traywc.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Print Using ClickBook (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: MoneySide (HKLM)
    O16 - DPF: symsupportutil - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/symsupportutil.CAB
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cab
    O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
    O16 - DPF: {466FE5FE-9B04-4BD8-9993-C4FBDAEB7122} (JMWiseCam Control) - http://user:passw0rd@webcam.pr.erau.edu/JMWiseCam.cab
    O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/161b002aed60a3bd7306/netzip/RdxIE601.cab
    O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
    O16 - DPF: {763C10EE-E4C6-49AA-9325-F15ABF1C52B0} (X1 DownloadControl Class) - http://www.x1.com/download/X1WebInstall.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {9184D21C-9835-42C5-A883-EA8BE7FC048D} (Downloader Class) - http://www.shop.intuit.com/commerce/account/downloads/executables/ie/IDA.cab
    O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://autos.msn.com/components/ocx/survid/MSSurVid.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37632.6581365741
    O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/mail/ymmapi.cab
    O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
    O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurround Object) - http://autos.msn.com/components/ocx/exterior/Outside.cab
    O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
    O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553580000} - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/ActiveData.cab
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup144.cab
    O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://photo.walmart.com/photo/upload/XUpload.ocx

     

  • Yellowhammer

    725 Posts

    50

    0

    Posted March 9th, 2004 21:00

    Your system is pretty clean.  You do have a couple of items to fix.

    Close all windows and have hijackthis fix the following:

    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.5.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/161b002aed60a3bd7306/netzip/RdxIE601.cab

     

    Message Edited by Yellowhammer on 03-09-2004 05:50 PM