Unsolved

This post is more than 5 years old

3806

September 27th, 2005 13:00

Help with Zotob variants

Hello - So, while I was switching broadband accounts I missed the whole patching thing, and, lo and behold, have aquired a worm that acts very similarly to Zotob. It blocks access to Paypal, eBay, security sites, etc - the problem is that I've run every AV program I could find online (for both Mytob and Zotob) and they all have not found an instance of the virus. What else could this be?

I'm running 2000 and for some reason - perhaps related? - f8 won't bring up the Safe Mode menu. Any ideas? Thanks!

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 27th, 2005 13:00

if you run a specialized tool (such as one specifically intended for zotob), it may not find another virus/worm that "acts very similarly to Zotob".   So the first thing you need to determine is precisely what you have:  have you run an overall anti-virus scan on your system, to see what it finds?  
 
 
 
Also, have you tried Microsoft's  Malicious Software Removal Tool (which looks for SEVERAL threats, including zotob):

Message Edited by ky331 on 09-27-2005 11:48 AM

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 27th, 2005 14:00

Stinger (from what I see here http://vil.nai.com/vil/stinger/   ) is also a specialized tool, only looking for the specific viruses indicated therein.
 
you also mentioned AVG... is that your main/resident anti-virus?  (if not, what is?)  regardless of which resident AV you're using, have you run a COMPLETE system scan with it?
 
there are also several free, ONLINE scans available, including
[be advised that this scan takes "forever" to download/run, if you have a dial-up modem]
 
IF you can determine the specific name/type of virus, THEN you can try to find a specialized tool to remove it.
 
Alternatively, you can download the latest version of HJT(hijackthis) (version 1.99.1) from

http://majorgeeks.com/download3155.html

you must create a separate folder and place it there.... people commonly use C:\HJT.   Note:  Please do *NOT* use a TEMP (temporary) folder, *NOR* your DESKTOP, as HJT will be generating log files and backup files in the folder from which it is run... you risk accidentally losing these if you use a TEMP folder, and you will generate extreme clutter if you use your DESKTOP.

The file above comes as a compressed .ZIP file... you have to UNzip it (hopefully, you have an UNzip utility built into your Windows Explorer.   If for any reason, you're unable to UNzip it, you can download the already-unzipped .EXE file from http://downloads.malwareremoval.com/HijackThis.exe )

After Unzipping, double click on HiJackThis.EXE

Click on  Do a System Scan and Save a LogFile

This will automatically open NotePad

Copy the entire file from NotePad:  EDIT/SelectAll, EDIT/Copy

Then go to the new forum dedicated for HiJack This logs (**NOT** back here), and  PASTE the results there:

http://forums.us.dell.com/supportforums/board?board.id=si_hijack

Be sure to include a detailed description of any problems/errors/warnings you are encountering.

Hopefully, one of the HJT experts will get to it as quickly as possible.

 

WARNING:  HiJack This is a VERY POWERFUL tool.  Do *NOT* do anything else (in particular, do NOT use it to delete any entries) until you are advised to do so!!   Improper use of this tool can severely damage your system.
 
 
Supplemental note:  The procedure as worded above has been carefully edited over time, so as to expedite the process of helping people.   Nevertheless, it seems that many individuals try to be "creative", and make some variations.  It really would be to your benefit if you follow these directions EXACTLY as stated... because certain changes on your part can result in slowing-down the help process. 
Specifically, the following are 3 very common BAD deviations which will cause delays:
a)  BAD:  using an older/outdated version of HiJackThis...
The experts only work with the current version.   So if you make a post with an older version, you'll simply be advised to get the latest version, re-run it, and re-post your log.
b) BADusing a TEMP directory or your DESKTOP for HJT....
Some experts may insist you move HJT before they'll begin working with you.   Others will start the repair process, advising you to move HJT as one of the very first steps.   Failure to do so can result in losing potentially critical information.   So please,  just use the suggested  C:\HJT  directory, rather than try to be creative.
c) BAD:  posting your log in the wrong forum...
if you post your log back here, in the Virus/SpyWare forum, it will "sit idly", either until the forum moderator gets around to move it for you... or until you decide to repost your log...  in the HiJackThis forum.
 
 

Message Edited by ky331 on 09-27-2005 12:25 PM

September 27th, 2005 14:00

So far I've run McAfee's Stinger and the Microsoft Malicious Software Removal Tool - which I was hoping would be updated today, but no - and AVG (although I do see that they have an update from last night which I have not yet run which has "Added detection of new variants of I-Worm/Mytob, I-Worm/Bagle, I-Worm/Zafi, I-Worm/Netsky, Worm/Lewor." Do any of those display similarities to my problem?)

Finding out exactly what this worm is is harder than I thought - the AV programs don't seem to detect it, and a google search only comes up with Mytob and Zotob as having symptoms similar to what I'm experiencing. Any suggestions on what other worm could do that?

Thanks for the assistance ky331!

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 27th, 2005 17:00

hopefully, the resident COMPLETE-scan by AVG [ make sure you update your program before doing the scan], and/or the online scan from housecall, will at least IDENTIFY [if not quarantine/remove] the problem...
 
HiJackThis is a general tool, which will reveal every program that's automatically running every time you start up your machine.   if any trojan/virus is running on your system, it should show up in HiJackThis.  

September 27th, 2005 17:00

Thanks ky - I'll try those out when I get home this evening and let you know how it goes - AVG is my resident anti-virus. If http://housecall.trendmicro.com/ doesn't do it, then I'll try out the Hijack This method - thanks so much for your assistance!

September 28th, 2005 01:00

Hey ky - well - a full system scan with an updated AVG did locate and remove an instance of SdBot along with a couple of files it had downloaded/infected - however, I'm still blocked from those aforementioned sites. I ran the web-based one and it found nothing - so I've posted a Hijack This! log here:
http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=14832

thanks for all the assistance!

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 28th, 2005 14:00

i see RKinner did very nicely by you.  
No Events found!

Top