Unsolved

This post is more than 5 years old

5 Posts

3936

September 11th, 2005 04:00

I have a worm--Need help ASAP!

So, my antivirus software has found a virus that it can't remove. The file name is: sory.exe.Worm.Mytob.T-2
It is on drive C:/ and I don't know what to do to remove it, I've never had a virus that my antivirus software couldn't remove. For right now, I have run the scan again, except this time I told it to quarantine any infected files. If anyone knows what I can do, or if not, where I can get support, that would be AWESOME!! Thanks!

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 11th, 2005 11:00

WHICH anti-virus program found that worm?  
 
the reason why I'm asking:  Different anti-virus programs are using various "aliases" to name/define worms.  I tried a web-search for the name you indicated, in hope of locating an appropriate removal tool.   But I found (too-)many results, all of which offered OTHER [primary] names for that particular worm....
 
also, please indicate what operating system you're using (98/ME/2000/NT/XP/other)

Message Edited by ky331 on 09-11-2005 10:03 AM

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 11th, 2005 12:00

Interesting:
 
Symantec [Norton] offers many "specialized" virus removal tools.
 
their "main" MYTOB tool is described here:
 
 
the actual removal tool:
 
however, i do not see mytob.T [nor T-2] on that list... 
 
============
 
symantec offers a 2nd mytob-variation tool as well:
 
 
 
which again, does not mention mytob .T
 
============
 
in my experience, the symantec tools are safe to try, in the sense that, if the particular virus/variation isn't present, it will simply tell you that, and not cause you any other problems.  
 
============
 
IMPORTANT:   according to what i've read, one of the "properties" of Mytob is that it may attempt to block you from going to any anti-virus web-site... if so, you might not be able to access the above symantec tools.   if that's the case, you should go to another "clean" PC (at work, or a friends), download the tool, copy them to a floppy [or CD/RW or memory stick; depending on what you have available on your machines], transfer the file back to your "infected" machine, and run it.
 
===========
 
regardless of whether or not the above tool can help you, I suggest you follow-up your disinfection attempt by using HiJackThis.   this will help look for ALL virus/malware problems you might have:
 
Download the latest version of HJT(hijackthis) (version 1.99.1) from

http://majorgeeks.com/download3155.html

you must create a separate folder and place it there.... people commonly use C:\HJT.   Note:  Please do *NOT* use a TEMP (temporary) folder, *NOR* your DESKTOP, as HJT will be generating log files and backup files in the folder from which it is run... you risk accidentally losing these if you use a TEMP folder, and you will generate extreme clutter if you use your DESKTOP.

The file above comes as a compressed .ZIP file... you have to UNzip it (hopefully, you have an UNzip utility built into your Windows Explorer.   If for any reason, you're unable to UNzip it, you can download the already-unzipped .EXE file from http://downloads.malwareremoval.com/HijackThis.exe )

After Unzipping, double click on HiJackThis.EXE

Click on  Do a System Scan and Save a LogFile

This will automatically open NotePad

Copy the entire file from NotePad:  EDIT/SelectAll, EDIT/Copy

Then go to the new forum dedicated for HiJack This logs (**NOT** back here), and  PASTE the results there:

http://forums.us.dell.com/supportforums/board?board.id=si_hijack

Be sure to include a detailed description of any problems/errors/warnings you are encountering.

Hopefully, one of the HJT experts will get to it as quickly as possible.

 

WARNING:  HiJack This is a VERY POWERFUL tool.  Do *NOT* do anything else (in particular, do NOT use it to delete any entries) until you are advised to do so!!   Improper use of this tool can severely damage your system.
 
 
Supplemental note:  The procedure as worded above has been carefully edited over time, so as to expedite the process of helping people.   Nevertheless, it seems that many individuals try to be "creative", and make some variations.  It really would be to your benefit if you follow these directions EXACTLY as stated... because certain changes on your part can result in slowing-down the help process. 
Specifically, the following are 3 very common BAD deviations which will cause delays:
a)  BAD:  using an older/outdated version of HiJackThis...
The experts only work with the current version.   So if you make a post with an older version, you'll simply be advised to get the latest version, re-run it, and re-post your log.
b) BADusing a TEMP directory or your DESKTOP for HJT....
Some experts may insist you move HJT before they'll begin working with you.   Others will start the repair process, advising you to move HJT as one of the very first steps.   Failure to do so can result in losing potentially critical information.   So please,  just use the suggested  C:\HJT  directory, rather than try to be creative.
c) BAD:  posting your log in the wrong forum...
if you post your log back here, in the Virus/SpyWare forum, it will "sit idly", either until the forum moderator gets around to move it for you... or until you decide to repost your log...  in the HiJackThis forum.
 

Message Edited by ky331 on 09-11-2005 10:41 AM

5 Posts

September 11th, 2005 12:00

I am using Norton's Microantivirus program and Microsoft Windows XP Home Edition as the operating system.

11 Posts

September 11th, 2005 17:00

Also try going to ewido.net They have an excellent free suite that is pretty good at finding and eliminating worms. Download it and run it before trying HijackThis. You can't mess things up at least trying Ewido. However, while HijackThis is an excellent tool (and sometimes the only thing that helps), you can really mess your registry up if you use it blindly. Also try the castlecops website forums. They offer some really good free technical help. Castlecops.org

5 Posts

September 12th, 2005 00:00

Alright, I tried the two worm removal tools and it said I had neither. I also went to the majorgeeks site and downloaded all the software and followed the instructions. I'm not sure if I want to use the hijackthis tool because I feel like I am a blind user and I definitely don't want to damage my computer using something I'm not sure about. Anyways, there is a positive note. By following the instructions on majorgeeks (the procedure before you opt to use hijackthis), I found the file that has the virus in it. It was in a hidden file labeled: sory.exe However, the file will not let me delete it or move it in any way (why is that not surprising?) So, what should my next step be? Thanks for all of your help btw, I REALLY appreciate it!
 
--there is one thing I didn't mention in my other post. Whenever I boot up my computer, a website pops up. The address is: www.0x90-team.com/~diablo/index.html (<-- NO ONE GO TO THIS SITE!!!!)
It is a blank web page except for the message: Forbidden-you do not have permission to access the requested file on this server
 

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 12th, 2005 01:00

krystl,

that the 2 symantec tools didn't find the worm is not completely surprising since, as i indicated, while they claimed to remove various strains of Mytob, neither tool specifically indicated mytob.T (or T-2)

as for using HiJackThis, certainly the decision about whether or not to proceed is yours.   but just to clarify:  the [potential] danger is only when you use hijackthis to REMOVE/FIX entries --- there is no danger in simply running hijackthis to scan your system, and to generate/post your log.  HiJackThis has the advantage that it's a highly GENERIC tool:  hopefully, the experts will be able to locate not only your Mytob.T-2 problem, but also the 2nd problem you've now mentioned, of the bad website that pops up whenever you boot up your machine.

by the way, the ewido suite that bytzeme suggested has been used frequently by the experts in the HiJackThis forum, to assist their analysis/resolution of certain problems (in particular, something known as Aurora/NAIL --- that's NOT to say you have these problems).

You also wrote:  "By following the instructions on majorgeeks (the procedure before you opt to use hijackthis), I found the file that has the virus in it. It was in a hidden file labeled: sory.exe However, the file will not let me delete it or move it in any way (why is that not surprising?) So, what should my next step be?"   I'm not sure exactly what instructions you are referring to... when I listed the majorgeeks download site, all i intended for you to do was simply download the HiJackThis program from there.   Anyway, I went back to the site, and upon further inspection, I assume you were referring to the instructions they offered on the following page:

http://forums.majorgeeks.com/showthread.php?t=35407 

is that what you were referring to?   if so, which of the steps/programs there [or elsewhere, in case you were referring to a different site] allowed you to find the virus in the hidden file sory.exe ?   while it may tell me something, I'm not sure how much more help i'll be able to offer, other that what i've already said.

 

Message Edited by ky331 on 09-12-2005 11:02 AM

5 Posts

September 12th, 2005 22:00

Thanks again for all your help.. I think I will try the hijack this tool, now that I know what not to do. That was the forum of instructions I followed. The specific instructions where I found the file on my computer were these:
 
3: Enable viewing of hidden files and folders and extensions; Some programs can hide this way by not being visible in Windows. Start Windows Explorer and click on your main hard drive, usually c:\. Then select Tools from the top of Windows Explorer and then Folder Options. Go to the View tab. Scroll down to the folder icon that says Hidden files and folders and check show hidden files and folders. Also, right below this option, uncheck the hide file extensions for known types. Also for Win NT, 2000, & XP systems, uncheck the Hide protected operating system files (recommended) option. Not doing this could allow file extensions commonly used by trojans and spyware to be hidden, for example a file ending in .exe or dll making manually finding it, if needed, difficult to impossible.
Do you suggest that I call someone to come and look at my computer and if so who would you recommend? maybe a Dell customer support employee?

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 13th, 2005 00:00

Since you've indicated " I think I will try the hijack this tool, now that I know what not to do ", that's precisely my recommendation:   follow the directions I specified above, to generate and post your HiJackThis log [in the HiJackThis forum, NOT back here].   There are several [volunteer] experts "living" there, who will do their best to assist you.   And the help there is free!   In contrast (depending, of course, on what type of service-contact you have), you'll probably have to pay "a king's ransom" to any official DELL support employee who offers you software/virus support --- either over the phone (if you can get through) ---- and all the more so, if they make a "house call".
 
good luck with HiJackThis.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 16th, 2005 12:00

just a follow-up...
 
i see that several days have past, and that you haven't posted an HJT log... have you decided not to proceed?

5 Posts

September 16th, 2005 16:00

Yes, I did post mt hijackthis log on the majorgeeks forum under support for spyware/viruses. The guy who replied to me said he didn't see the spyware software under my log, so i dunno what's going on. I'm starting to feel like this problem is never gonna get resolved :-/

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

September 16th, 2005 17:00

Krystal,
 
while I access [and recommend]  the MajorGeeks site for the purpose of downloading files (and it's a wonderful site to use), I have no knowledge of the HiJack forum that they run THERE --- rather, I've always sent people over to the DELL forum.   It's entirely possible that DELL won't find anything either, but (other than a few minutes time) you have nothing to lose by posting your log at the DELL forum
 
 
doing another web search, I found the following:
the file sory.exe can be picked up as
Adware Downloader ;
Trojan Lowzones.BW ; or
Trojan Agent.RD
 
 
in each of the above cases, IF the trojan is actually running, it should appear in a HiJackThis Log, under either Running Processes, and/or the O4-Startup Section.   if the MajorGeeks person was correct, that the file doesn't appear anywhere in your HiJack Log, this could mean the virus is " dormant" --- it's just sitting on your machine, idly, doing nothing.
 
the only other suggestion i have, is to see if another company (besides Symantec) can clean the virus.   I'll give you a link to one such tool from Sophos:
Actual "RESOLVE" removal tool:    http://www.sophos.com/support/cleaners/mytobgui.com
 
Sophos appears to be a reliable company... in fact, i just downloaded and ran the tool, as a test, and it simply didn't find the worm on my PC.   but since i have only this one test/experience with it, you're on your own if you decide to proceed further.
 

Message Edited by ky331 on 09-16-2005 03:13 PM

No Events found!

Top