Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Backdoor.Bifrose ?!
#1
How much trouble am I in?Eek

I ran my weekly Ad-Aware scan and found I had some malware called "Backdoor.Bifrose"...Ad-Aware quarantined it but how do I know I have got rid of it from my system?

...and reformating isnt an option as I have not backed up my pc and I cant lose what I have on it.Frown

Help would be much appreciated.
Reply
#2
Just use these 3 programs, they're free:

- Ad-Aware (you have that one already)
- Spybot (Almost the same as Ad-Aware, but 2 of them can't really harm you Tongue)
- AVG Free Virus Scanner

Let those 3 scan your system, reboot a (couple!!!) of times, then scan again. If they don't find anything anymore, you can be 99% sure it's not on your system anymore... Smile
Reply
#3
Scanned with AVG and again with Ad-Aware and it didnt come up...I hope I got rid of it before anything happened...If my char gets cleaned out I'll know I was key logged somehow.Tongue
Reply
#4
Might be related to my situation: http://www.southperry.net/forums/showthread.php?t=6812

I hate being paranoid about this stuff but I pretty much did avg + adaware. avg on medium speed found a good amount of stuff and i did a slow scan overnight [5~6 hrs] and it found nothing so i hope my computer is clean. I'm still being wary over the situation but most people reassured me avg + system restore + adaware will keep me safe based on the results it gave.
Reply
#5
if it quarantined it then it obviously doesnt exist anymore. the problem is that people who get infected with a virus usually get themselves infected more than once, which raises the chances you have other malware on your computer.
Reply
#6
Chameleonic Wrote:Scanned with AVG and again with Ad-Aware and it didnt come up...I hope I got rid of it before anything happened...If my char gets cleaned out I'll know I was key logged somehow.Tongue
What you can do is:
- Start Windows
- Click start
- Click Run...
- Type: cmd
- Click OK

- Type: netstat
- Hit ENTER

Type the data below Foreign Adress and post it into this thread. It shows all your active connections to/from your PC.
Reply
#7
I only use Firefox, and AVG/Ad-Aware didnt find any other threats.

I'm not feeling that confident about logging on to Maple after the patch now...

edit...lol I cant disclose any info that would make me vulnerable can I?
Reply
#8
I think this is what you want...

Active Connections

Foreign Address State
localhost:1042 ESTABLISHED
localhost:1041 ESTABLISHED
localhost:1044 ESTABLISHED
localhost:1043 ESTABLISHED

a-61-9-129-185.deploy.akamaitechnologies.com:http TIME_WAIT TCP

a-61-9-129-185.deploy.akamaitechnologies.com:http TIME_WAIT TCP

138-181-111-65.serverpronto.com:http TIME_WAIT
Reply
#9
Chameleonic Wrote:I think this is what you want...

Active Connections

Foreign Address State
localhost:1042 ESTABLISHED
localhost:1041 ESTABLISHED
localhost:1044 ESTABLISHED
localhost:1043 ESTABLISHED

a-61-9-129-185.deploy.akamaitechnologies.com:http TIME_WAIT TCP

a-61-9-129-185.deploy.akamaitechnologies.com:http TIME_WAIT TCP

138-181-111-65.serverpronto.com:http TIME_WAIT
localhost = your own pc = safe
Akamai = http://en.wikipedia.org/wiki/Akamai_Technologies = safe

serverpronto.com = Not sure about this one, do you host anything yourself there? And did you do the netstat directly after you restarted your pc? Does it still show this after 15 minutes? Does it still show after a restart?
Reply
#10
After restarting I get nothing listed.

Only get listings after I open up Firefox.

Soooo does that mean I'm safe?
Reply
#11
Chameleonic Wrote:After restarting I get nothing listed.

Only get listings after I open up Firefox.

Soooo does that mean I'm safe?
For as far I can see you're safe now... Smile

Unless someone has any other idea's how to do a more thourough scan? Smile
Reply
#12
I did the same thing as him and other than local host i got

- Adelphiacom.net [some cable provider, time warner took it over]
- yahoo
- earthlink
- cpe-66-75-159-196.socal.rr.com:http [no idea what this is but i live in socal so might be something related to it]
- southperry's IP
- the serverpronto thing
- 192.168.1.1:51855 [i think this is my own ip]

Serverpronto thing might be common on all comps? idk
Reply
#13
Kaasoljoyyx Wrote:I did the same thing as him and other than local host i got

- Adelphiacom.net [some cable provider, time warner took it over]
- yahoo
- earthlink
- cpe-66-75-159-196.socal.rr.com:http [no idea what this is but i live in socal so might be something related to it]
- southperry's IP
- the serverpronto thing
- 192.168.1.1:51855 [i think this is my own ip]

Serverpronto thing might be common on all comps? idk
Do it again when you -JUST- booted up your pc, and dont open your internet browser first. This keeps away the normal harmless HTTP connections. Smile

And serverpronto, well it is a dedicated server hoster (they sell server space to anyone), it's most likely nothing, but on the other hand it also could be a central log file database from keylogger clients...

But I did a quick search on Google, and it's not known for the BiFrose troyan atm... So it's most likely nothing... Smile
Reply
#14
Well i had to come here to re-read the instructions f3 but anyway

Here's the only things that aren't localhost

- 68.237.164.177:http TIME_WAIT
- 192.168.1.101:netbios-ssn TIME_WAIT

and my problem is from this one http://www.southperry.net/forums/showthread.php?t=6812
Reply
#15
Kaasoljoyyx Wrote:Well i had to come here to re-read the instructions f3 but anyway

Here's the only things that aren't localhost

- 68.237.164.177:http TIME_WAIT
- 192.168.1.101:netbios-ssn TIME_WAIT

and my problem is from this one http://www.southperry.net/forums/showthread.php?t=6812
Netbios is just windows local network and the other seems to be a normal http request (browser) to something in Los Angeles.

Edit: Hmmm didn't read that post... Does Zafi.B still get detected after a restart and scans with Ad-Aware/Spybot/AVG?
Reply
#16
I system restored it prior avg

I looked at the list on avg/adaware and that zafi.b didn't even show up.

The command prompt --> netstat was done today, that zafi.b came up yesterday, most likely due to internet explorer problem
Reply
#17
You should look at your quarantine logs and see where this was detected. It might just be a keygen.
Reply
#18
I hope my system is free of this malware...if I get cleaned out I'll know I wasnt...
Reply
#19
To save yourself some panic, you should check if it's active or not. Panda's antivirus encyclopedia is a good place to start. I'm not saying you shouldn't get it removed, but it's good to know how dangerous it is to your computer. Tongue

All entries of the Backdoor "Bifrose" come up as inactive in the Panda encyclopedia.
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)