Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Automatic Updates keeps incorrectly diagnosing Mydoom, Zindos, Doomjuice infection

Reply
Thread Tools Display Modes

Automatic Updates keeps incorrectly diagnosing Mydoom, Zindos, Doomjuice infection

 
 
XxLicherxX
Guest
Posts: n/a

 
      06-13-2005
Hello everyone,

I am hoping someone out there can help me solve this problem. Twice
automatic updates have downloaded the Mydoom, Zindos and Doomjuice
removal tool, saying that my system is most likely infected by this
worm.

I believe that this is a false positive, because I have Symantec
Antivirus with up to date definitions running. It runs a full system
scan every night and does not find anything. I have also downloaded and
ran Microsoft's Malicious software tool. Again, this tool found
nothing. Lastly, I have looked at the registry, hosts file, etc for any
signs of these worms, but have not found anything.

What could be causing Windowsupdate to incorrectly identify my machine
as being infected with one of these worms?

 
Reply With Quote
 
 
 
 
Maurice N ~ MVP
Guest
Posts: n/a

 
      06-13-2005
Would you write down the "verbatim" text you're getting about infections
from Windows Update, and post that back.

Norton/Symantec AV will not, by itself, catch all malware --- other than the
viruses it has signatures for in "your local" definitions in NAV.

When it comes to cleaning up on malware, you cannot rely on only 1 tool.
I recommend an article at Aumha.org on ways to cleanup parasites.
Follow the quick-fix protocol.
http://aumha.org/a/quickfix.htm

Here are 2 tools from SysInternals that may help you get an insight on
what's running on your system, including any "malware" startups.
Autoruns (checks & shows what's set to auto-load at Windows startup)
http://www.sysinternals.com/ntw2k/fr...autoruns.shtml

Process Explorer http://www.sysinternals.com/ntw2k/fr.../procexp.shtml

You likely will have to do cleanups in Safe mode, once you have downloaded
current definitions.
You should even use Safe Mode with Networking to do all this work.
Press F8 Function key as the pc is booting up so that you can see bootup
choices.


--
Maurice N
MVP Windows - Shell / User
---
"XxLicherxX" wrote
> Hello everyone,
>
> I am hoping someone out there can help me solve this problem. Twice
> automatic updates have downloaded the Mydoom, Zindos and Doomjuice
> removal tool, saying that my system is most likely infected by this
> worm.
>
> I believe that this is a false positive, because I have Symantec
> Antivirus with up to date definitions running. It runs a full system
> scan every night and does not find anything. I have also downloaded and
> ran Microsoft's Malicious software tool. Again, this tool found
> nothing. Lastly, I have looked at the registry, hosts file, etc for any
> signs of these worms, but have not found anything.
>
> What could be causing Windowsupdate to incorrectly identify my machine
> as being infected with one of these worms?
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Mydoom, Zindos, and Doomjuice Worm Removal Tool (KB836528) keeps coming back!! Robert Gardner Windows Update 0 11-24-2004 03:14 PM
Re: Mydoom, Zindos, and Doomjuice Worm Removal Tool (KB836528) Torgeir Bakken \(MVP\) Windows Update 1 11-16-2004 10:44 PM
Mydoom, Zindos, and Doomjuice Worm Removal Tool (KB836528) Ian Windows Update 4 08-13-2004 01:37 PM
Mydoom, Zindos and Doomjuice Worm Removal (KB836528) George Mayer Jr. Windows Update 1 08-12-2004 09:12 PM
Updates install incorrectly Julsie Windows Update 3 07-19-2004 10:29 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59