Spyware Warrior Spyware Warrior
Help with Spyware, Hijacking & Other Internet Nuisances
 
FAQ :: Search :: Memberlist :: Usergroups :: Register
Profile :: Log in to check your private messages :: Log in

Strip Viruses:W32/Netsky-J

 
Post new topic   Reply to topic    Spyware Warrior Forum Index -> Virus, Worm &Trojan Alerts
View previous topic :: View next topic  
Author Message
bobbob10
Newbie


Joined: 03 Mar 2004
Last Visit: 03 Aug 2004
Posts: 6

PostPosted: Thu Apr 22, 2004 8:40 am    Post subject: Strip Viruses:W32/Netsky-J Reply with quote

Hi

I'm using outlook express, and got this email today!!,

I nothiced also on my yahoo account i was getting tonnes of these pif file attachment bullshit.
















This is an automated delivery status notification from mailsrv2
running server version 3.4.3.

Our Email Virus filter has detected a virus contained in an email sent
from your address. We have removed the virus from the email before
forwarding to the recipient.

The original message was received on Thu, 22 Apr 2004 13:08:31 -0700

---------------------------------------------------------------------------

ATTACHMENT REMOVED

From: thesellingman@ihug.co.nz
To: [EDIT - Address removed - admin]
Subject: Re: Your picture




The message attachment was removed for the following reason:
Virus and Spam Protection Mode::Strip Viruses:W32/Netsky-J;

The following attachments were removed:
Content-type: application/octet-stream
Filename: your_picture.pif
Size: 30.2k
Back to top
View user's profile Send private message MSN Messenger
CalamityKen
Warrior Addict


Joined: 06 Mar 2004
Last Visit: 26 Aug 2004
Posts: 611
Location: Ont. Canada

PostPosted: Thu Apr 22, 2004 11:21 am    Post subject: Reply with quote

bobbob10, remove the Netsky worm.

NEVER open any email without varifying the person who sent it to you has no viruses/worms/trojans.

http://securityresponse.symantec.com/avcenter/venc/data/w32.netsky@mm.removal.tool.html

It could be that someone you know has the Netsky worm and has you in their Address Book.
_________________
Install IE-SPYAD and SpywareBlaster updated regularly available in the following links .
How did I get infected? http://boards.cexx.org/viewtopic.php?t=957
Calendar Of Updates http://www.dozleng.com/updates/index.php?&act=calendar
member
Back to top
View user's profile Send private message
bobbob10
Newbie


Joined: 03 Mar 2004
Last Visit: 03 Aug 2004
Posts: 6

PostPosted: Thu Apr 22, 2004 4:21 pm    Post subject: Reply with quote

trust me i didn't open anything that was dodgy,

But thank you so much, i'll try and get rid of it. Embarassed
Back to top
View user's profile Send private message MSN Messenger
bobbob10
Newbie


Joined: 03 Mar 2004
Last Visit: 03 Aug 2004
Posts: 6

PostPosted: Thu Apr 22, 2004 4:25 pm    Post subject: Reply with quote

Hi

Just had a look at that first link, they don't seem to have netsky j

* W32.Netsky.B@mm
* W32.Netsky.C@mm
* W32.Netsky.D@mm
* W32.Netsky.E@mm
* W32.Netsky.K@mm
* W32.Netsky.P@mm
* W32.Netsky.Q@mm
* W32.Netsky.S@mm
* W32.Netsky.T@mm
* W32.Netsky.X@mm
* W32.Netsky.Y@mm

????
Back to top
View user's profile Send private message MSN Messenger
CalamityKen
Warrior Addict


Joined: 06 Mar 2004
Last Visit: 26 Aug 2004
Posts: 611
Location: Ont. Canada

PostPosted: Thu Apr 22, 2004 5:20 pm    Post subject: Reply with quote

bobbob10, I believe that worm disables itself after March 10th.

Try online scans:
http://housecall.trendmicro.com
http://www.mcafee.com/myapps/mfs/default.asp

Please post a HijackThis log for further help.
Important: Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT.
Move HijackThis.exe into this folder.
http://www.majorgeeks.com/download.php?det=3155

Run Scan and then save the log.

When you run HijackThis from C:\HJT folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary.
_________________
Install IE-SPYAD and SpywareBlaster updated regularly available in the following links .
How did I get infected? http://boards.cexx.org/viewtopic.php?t=957
Calendar Of Updates http://www.dozleng.com/updates/index.php?&act=calendar
member
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Spyware Warrior Forum Index -> Virus, Worm &Trojan Alerts All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group