Quantcast

mytob worm has pwn3d me.

ALEXIS_DH

Tirelessly Awesome
Jan 30, 2003
6,197
829
Lima, Peru, Peru
well. i have this problem.

started as a little annoyance, computer started to get slow. then everytime i tried to download something thru firefox, but the computer restarted. was like that for a couple days. then just starting firefox would restart the computer. the computer was slow and the hard drive was making sounds like i was copying tens of Gb simultaneously. all resources were used up.

could not connect to any antivirus website. could not download anything .exe.
scanned my pc with my antivirus (per antivirus, a local one), mytob worm was found, erased. rebooted on safe mode no lan, eliminated everything.
went back to the internet, still could not get to download anything. downloaded zonealarm firewall from emule, avg antivirus and adaware.

installed them run them. avg did not detect anything. ad aware neither.
thru zonealarm i clossed connection to lsass.exe, services.exe, svhost.exe and the usual system exes viruses target.
next reboot. my harddrive was scratching like crazy, and the pc was slow again.run avg again, nothing, ad aware, nothing. per antivirus detected and erased the viruses.

downloaded symantec mytob (mydoom) removal tool, but it found nothing.
i have a hardware firewall, plus the xp firewall, plus zonealarm allowing connection to only a handful of programs i know for sure are safe. (

yet on every reboot, my pc seems to get infected again. even after erasing everything with the lan cable disconnected.

i found the source of the browser hijack (even for firefox) with hijackthis and fix it up. but my pc still gets slow, scratches the hard drive like crazy, and seems to gets infected after a few hours of being cleansed. all xp sp2 patches are up to date.

what else can i do?
 

binary visions

The voice of reason
Jun 13, 2002
22,162
1,261
NC
It may have infected the master boot record, you can try a format /mbr.

Best way to do it would be to create a virus scanning startup CD (so Windows doesn't boot - many virus scanning packages will have this as a utility), pull up a command prompt and do "format /mbr", then kill the power to your computer (don't let Windows shut down). Then boot with your startup virus scanning CD.

If that doesn't work, backup everything you absolutely can't live without onto CD.

Format.

Reinstall.

Sometimes, the best efforts will not fully clean a virus infected computer. And you should consider all of your data from your CDs infected - scan and try to clean before moving data back.
 

ALEXIS_DH

Tirelessly Awesome
Jan 30, 2003
6,197
829
Lima, Peru, Peru
binary visions said:
oh yeah.

i´ve checked with 3 antivirus and they said the mbr was fine.
am pretty sure there were a couple files associated with the virus hidden somewhere in my pc, but you were right, it was just more time-efficient to format everything, specially now that i needed to make some hardware upgrades.

i have 2 hard drives for cases like this. fortunately i removed D: (where my docs, mp3 and stuff are) days before getting pwn3d to bring it over to work, so most important stuff is fine.

i formatted the hard drive, reinstalled everything.

i took advantage of starting everything from scratch, and got a new video card, an evga 6600gt agp. which solves my component video problems for good.
so the virus came at a not so bad moment. :thumb: