XP - A Virus named Nethood and Moose about to lose his Manhood!

Mortymoose

Honorary Master
Joined
May 26, 2013
Messages
13,287
Xp Nethood virus and The Missing Shortcuts!

So TIFU, bigtime.....

I'm an old geezer, who use to tinker around with DOS , 3.1, W95 and peaked with the XP os about 13 years ago.....

That was then , this is now...

Upstairs in one of the offices, resides an old XP machine, free from the internet , with a single printer plugged into it.... Steadfastly, humming away in the corner, avoiding the modern world, old faithful.....

with a dark secret.... a very dark secret....

Many years ago, an employee looking for s free printing resource for a child's school project unwittingly plugged in a flash drive..... at the same time copying over the ancient nethood virus... remember the one that jumps onto any flashdrive plugged into the machine , corrupting everything on the flash..... from that day forth......?

Back in the day it did not bother me too much, machine was never online, besides, no more staff took the chance of getting free printouts in the office afterhours, when one of their colleagues inadvertently found a childs month long project erased and corrupted...

SO for years, we carried on using it Pastel and minor excel documents....

This morning, the new printer arrived, I went to install it, The XP machine revealing her evil side that had laid dormant for so long.... not allowing me to install the drivers from the installation , throwing up Code 31 Errors ....Me being the clever guy tried putting the drivers on the usb, but Nethood awoke and spawned the crap out of that...

It was then that the day decided to take a turn for the worse....

I decided, that after hibernating on it for 10 years, that I, the old rusty novice, would look on the grand old web on how to delete the NETHOOD virus forever , allowing me to install the printer drivers...

So a few websites, told me .... no forced, coerced me into looking for irregular looking lines in the regedit...

WIndows->Current Version->Run and I found three entries, the one, was the normal one, the other two were diicing with death, they looked wrong, strange, their binary rapidly coming to an imminent end...

on C: ApplicationData\CIIZGF~1.vbs and wscript.exe //B"C"\Documents&Settings\User\Application Data\ozkvgpcbtp.vbs

I Know, I know .... I should have (1) back up (2) Researched further (3) Walked Away..... But I wanted to impress the English HO sitting across from me.... So, I deleted those tow strings in the registry..... then went to where thay had pointed to and deleted those files...

And rebooted....

Somewhere in my mind I could hear the words, "Let The Games Begin". my anus crawling back up inside as the desktop revealed herself to show most of the shortcuts( to Office documents) and the documents that reside on the desktop all faded out, the shortcut to Pastel was also faded out, I clicked Pastel , that started ,"Phew!", then I clicked on the one of the excel documents, it opened, "Nae! Bother, " I muttered under my muted breath, I closed off the excel spreadsheet and then the pigeons came home to roost.....All the shortcuts and documents on the desktop had gone, including the one to the Pastel, added to the dilemma, the English HO noticed the sweat running down the back of my blue t-shirt... I shuffled on the chair as she came over.... She pointed out that some of the other shortcuts to perform the Pastel backups were also missing.... She would now no longer be able to backup her pastel....

After playing around with the view options to display Hidden folders, the icons (but not the pastel shortcut for backups) reappeared, but once again, opening and closing the document made them all go away....

I kept stammering, "The stuff is still there, you just can't see it" , She was not amused, you know the anger that your bed partner get's when they are so angry, that they seem way too calm, talking softly..... I was nervous and afraid...

It is with this in mind, that I turn to my older brethren in this here forum, that know the XP operating system to assist, no advice me....

What the feck did I deleted in the registry, and how can I get it back.

For what it's worth, I have a brand new W10 laptop sitting on the table for the last 5 months waiting for the latest Pastel updates, as we planned to move over to the new PC end of last year...

Added to this, I can use the Pastel but not find the backup utility, called management something or other, as that disappeared with the faded desktop icons..

What I can do, is open the faded icons and then SAVE AS into my documents folder, where they regain their normal look and feel and do not disappear when the rest do...

If you are bored and have heard of such a thing and can assist me.... Please do, I t will be appreciated...

On the other hand, if I have just changed a minor setting and can not see it, please point it out and have a good laugh at me....

I thank you during this very difficult afternoon of my current life...

Moose. :crying:
 

Sinbad

Honorary Master
Joined
Jun 5, 2006
Messages
81,151
Can you not find the backup utility via the start menu?

Also, check other registry keys - runonce I think... and check in multiple hives as there are system wide ones and user specific ones
 

Electron1

Expert Member
Joined
Jan 29, 2009
Messages
4,219
Not great situation. My suggestion is to take out the hard drive (probably is a IDE drive though) and connect it to another computer that has fully up to date antivirus, and copy all the backup and data folders. The idea here is that the virus will not be active and you will have a copy of all important data before proceeding.

From there you could set up the new machine, hopefully install the old version of Pastel and check everything is ok. Then check with Pastel support on how to migrate to newest version. Not worth spending time on old hardware that will cause more grief as time passes.

NB Backup everything you can (hopefully via the method above) before doing anything else!
 

Sinbad

Honorary Master
Joined
Jun 5, 2006
Messages
81,151
Not great situation. My suggestion is to take out the hard drive (probably is a IDE drive though) and connect it to another computer that has fully up to date antivirus, and copy all the backup and data folders. The idea here is that the virus will not be active and you will have a copy of all important data before proceeding.

From there you could set up the new machine, hopefully install the old version of Pastel and check everything is ok. Then check with Pastel support on how to migrate to newest version. Not worth spending time on old hardware that will cause more grief as time passes.

NB Backup everything you can (hopefully via the method above) before doing anything else!

also very good advice.
 

Mortymoose

Honorary Master
Joined
May 26, 2013
Messages
13,287
Can you not find the backup utility via the start menu?

Also, check other registry keys - runonce I think... and check in multiple hives as there are system wide ones and user specific ones

Thanks for showing sympathy as my marriage rapidly falls apart, the joys of married couples grafting in the same business. :erm:

In addition to the shortcuts all disappearing after the first one is opened and closed, some of the shortcuts on the Start Menu also decide to vanish, funny thing is, some of the other desktop shortcuts do remain, like Recycle Bin etc...

Gonna wait till the HO goes home, then go upstairs and do what you suggest, Runonce and see what it turns up....
 

Rickster

EVGA Fanatic
Joined
Jul 31, 2012
Messages
20,431
And what happens if you try install an antivirus on the infected PC via CD?
 

Sinbad

Honorary Master
Joined
Jun 5, 2006
Messages
81,151
Thanks for showing sympathy as my marriage rapidly falls apart, the joys of married couples grafting in the same business. :erm:

In addition to the shortcuts all disappearing after the first one is opened and closed, some of the shortcuts on the Start Menu also decide to vanish, funny thing is, some of the other desktop shortcuts do remain, like Recycle Bin etc...

Gonna wait till the HO goes home, then go upstairs and do what you suggest, Runonce and see what it turns up....

I once accidentally low level formatted the hard drive of my gf at the time's PC, containing her honours thesis.

I feel your pain.
 

akescpt

Honorary Master
Joined
Aug 12, 2008
Messages
22,456
ja swaar. we have all did this. **** it. XP. cant you create an inoculation disk from the web. still at work so don't have a chance now to google intensely. not sure where it will lead. i know back in the day that was one way to recover from a virus.

regedit. ****ing cowboy. those were the days.
 

Mortymoose

Honorary Master
Joined
May 26, 2013
Messages
13,287
Not great situation. My suggestion is to take out the hard drive (probably is a IDE drive though) and connect it to another computer that has fully up to date antivirus, and copy all the backup and data folders. The idea here is that the virus will not be active and you will have a copy of all important data before proceeding.

From there you could set up the new machine, hopefully install the old version of Pastel and check everything is ok. Then check with Pastel support on how to migrate to newest version. Not worth spending time on old hardware that will cause more grief as time passes.

NB Backup everything you can (hopefully via the method above) before doing anything else!

This is good advice, IDE, yes, But I will first run it by the HO, she does not want me near the machine, PASTEL will be starting brand new on the new machine in two weeks time, with a clean slate and all, so she want's to just hope for the best that the old machine holds out for more weeks,

I have a shrewd suspicion that she will not like the idea of me , remove HDD and transplanting it into another machine, even though we know it is the safest bet.....

With regard to the new PAstel, she just needs to manually transfer final figures over onto the new machine...'

I just hate the fact that the virus is sitting on that machine, in all likelyhood telling the Ram and the Soundcard how it got me screwed today...

Oh! I see I was right with ozkvgpcbtp.vbs that is a virus...

wonder what the other string CIIZGF~1.vbs did? :erm:
 

backstreetboy

Honorary Master
Joined
Jun 15, 2011
Messages
37,555
What is the specs of the machine? Can you not upgrade it to Windows Vista and take it from there?
 
Last edited:

Praeses

Expert Member
Joined
Oct 29, 2005
Messages
4,932
Run Combofix on that system - should hopefully remove some nasties! :)
 

cyberbob1979

Expert Member
Joined
Jun 19, 2007
Messages
1,250
I remember using Hirens Boot CD for the scanners and utilities it has to do recoveries etc... it is an option for your PC
 

Rickster

EVGA Fanatic
Joined
Jul 31, 2012
Messages
20,431
This is good advice, IDE, yes, But I will first run it by the HO, she does not want me near the machine, PASTEL will be starting brand new on the new machine in two weeks time, with a clean slate and all, so she want's to just hope for the best that the old machine holds out for more weeks,

I have a shrewd suspicion that she will not like the idea of me , remove HDD and transplanting it into another machine, even though we know it is the safest bet.....

With regard to the new PAstel, she just needs to manually transfer final figures over onto the new machine...'

I just hate the fact that the virus is sitting on that machine, in all likelyhood telling the Ram and the Soundcard how it got me screwed today...

Oh! I see I was right with ozkvgpcbtp.vbs that is a virus...

wonder what the other string CIIZGF~1.vbs did? :erm:

As Cyberbob said, boot into hirens boot CD then load Mini XP and try find the files.
 

Mortymoose

Honorary Master
Joined
May 26, 2013
Messages
13,287
Ok! She went home, so I went a tinkering,

I see that the IDE drive is 20GB, using 18gb, so I plugged in a 1TB external USB and the virus, does not jump onto the drive, Reckon it might find the drive a wee bit intimidating, or does not like NTFS .... Anyhow, good old XP, still has that backup utility, so setup a backup to run onto the external, off she goes, in two hours, I will have all the important stuff backed up....

Then I will ask the HO if I can unplug the drive and plug into a machine that has a legal full version of AVG .... remove the virus, and mirror image it, then put it back into the box, and then see what gives...

Good evening fellow keyboard types...

Moose thanks you!
 

Rickster

EVGA Fanatic
Joined
Jul 31, 2012
Messages
20,431
Ok! She went home, so I went a tinkering,

I see that the IDE drive is 20GB, using 18gb, so I plugged in a 1TB external USB and the virus, does not jump onto the drive, Reckon it might find the drive a wee bit intimidating, or does not like NTFS .... Anyhow, good old XP, still has that backup utility, so setup a backup to run onto the external, off she goes, in two hours, I will have all the important stuff backed up....

Then I will ask the HO if I can unplug the drive and plug into a machine that has a legal full version of AVG .... remove the virus, and mirror image it, then put it back into the box, and then see what gives...

Good evening fellow keyboard types...

Moose thanks you!

But AVG is kek, use Avast Free.
 

MickeyD

RIP
Joined
Oct 4, 2010
Messages
139,117
Moose, Moose, Moose
Playing with XP registry fast and loose
Your old Goose is gonna stick your gonads in a noose.
 
Top