Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection > HijackThis Logs (finished)

 
 
LinkBack Thread Tools Display Modes
Old 01-21-2005, 05:20 PM   #1 (permalink)
Newb Techie
 
Join Date: Jan 2005
Posts: 3
Angry Difficult virus!

Hi All,

I have a Windows 2000 server running Symantec Corp Edition 8.0. The daily scan picked up a backdoor.trojan in a file named userbin.dll. The anti-virus won't clean, quarentine or delete the file. It also doesn't tell me much about it.

I've tried running a bootable McAfee Virusscan CDROM with the latest defs and same thing, won't get rid of it.

I ran an online scan using www.ravantivirus.com. However, this scan found the little known win32/sfind virus in scan.exe...but it didn't find find the virus in userbin.dll. Similarly, the Symantec product can find the backdoor.trojan in userbin.dll, but not the win32/sfind in scan.exe....weird!!

I've searched the Internet high and low for anything that might give me a lead with the userbin.dll file, but I haven't found anything. Similarly, win32/sfind isn't very common and there's not much out there on that one either.

Lastly, used pandavirus online and Panda does not find ANY viruses. Ok, someone please tell me that I am not loosing my mind. Any and all suggestions will be greatly appreciated

Patrick
oreganp is offline  
Old 01-21-2005, 06:22 PM   #2 (permalink)
True Techie
 
Join Date: May 2003
Posts: 221
Default

What you need t o know is the path to the userbin.dll file. It should have been reported by Norton.
Now set the system to show hidden files and folders as per http://www.spyware911.net/showhiddenfiles.htm


Then open windows explorer, find , copy and paste the dll to the desktop. Zip it up with winzip or winrar then email it to me here moboATspyware911.net

I can have itr analyzed and get back to you..
__________________
Security Tools | Spyware Scan | Prevention 101
mobo is offline  
Old 01-25-2005, 07:16 AM   #3 (permalink)
Multicellular Eukaryote
 
Apokalipse's Avatar
 
Join Date: Jun 2003
Location: Melbourne, Australia
Posts: 12,878
Default

after you email him the .dll, you might be able to delete it by using a bootable Linux CD (windows viruses don't affect Linux)
you can use a bootable Linux CD to do a lot of repair work.
although if your hard drive is NTFS, getting it to write to NTFS can be difficult at first.
__________________

1 + 1 = 3 if you define 3 as a result of 1 + 1
Apokalipse is offline  
Old 01-25-2005, 08:04 AM   #4 (permalink)
Newb Techie
 
Join Date: Jan 2005
Posts: 3
Default Unable to copy userbin.dll

Well, I'm not exactly sure what the userbin.dll file is used for, and perhaps I should install HiJack, but I am unable to copy the file to submit.

Any suggestions?
oreganp is offline  
Old 01-25-2005, 08:26 AM   #5 (permalink)
Monster Techie
 
Join Date: Nov 2004
Posts: 1,346
Send a message via AIM to southernlady Send a message via Yahoo to southernlady
Default

Since you can't email the dll file, try running HiJack This. Liz
southernlady is offline  
Old 01-27-2005, 09:59 AM   #6 (permalink)
Newb Techie
 
Join Date: Jan 2005
Posts: 3
Default

Folks, thanks for all the replies. In the end, it was a new variant of a virus, discovered on 19 January. The virus was called backdoor-AZF.dll. I've since removed the virus from my server. Thanks again for your comments and response!!
oreganp is offline  
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 06:44 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0