Annoying Worm

  • Hey - turns out IRC is out and something a little more modern has taken it's place... A little thing called Discord!

    Join our community @ https://discord.gg/JuaSzXBZrk for a pick-up game, or just to rekindle with fellow community members.

AnTi

Ðøgø
Aug 28, 2002
4,591
83
Poland
Hiya,

I got problem with removing 1 worm, infact i managed to indentify it, see this site; http://www.sophos.com/virusinfo/analyses/w32poebotjt.html
as im using Sophos anti-vir.

It seems like im unable to remove it, as it keep appearing in C:/Windows/System32/ as an .exe file with RANDOM name.

screenie1;
vir1.JPG


I`m also using Kerio PF, everytime the virus comebacks, kerio sends me a massage that it trying to run using CMD. Never allowed it and im not gonna try whats happens after :P
Point is, i`ve deleted tons of such as files already, it sometimes fakes original window files, name is exactly the same, however file itself is 'brighter' smth like hidden file.

My guess is either there is somewhere a 'mother-file' which keeps creating those, or i got a hole in my security and someone keeps sending me new, which is unlikely cause i`d see it in logs :s

Any ideas?

cheers, AnTi

Edit, scanned PC with Norton, Housecall, MKS, Sophos, and also used HijackThis, Spybot, Adaware, F-Force etc nothing has completely removed it :x
 
Last edited:
Had the same worm got it over torrent file

Infected my whole network about 2 days ago, followed Nortons guide + many more for removing it but failed.

So formatted the 2 PC's that had it reloaded windows and loaded norton and it was detected again so formatted all PC's on my network.

They needed a clean anyway
 
Sounds like it is starting up every time you boot into windoze. Have you checked the registry for strange program names in HKLM & HKCU - software - microsoft - windows - current version - run?

Might be some other places too. Try typing msconfig in run box and see what starts up automatically.
 
By the time you had run through all the options on that list you could have reinstalled your PC and completed a 1000 piece jigsaw :P
 
W32/Poebot-JT runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels