Posting Freak
Posts: 4,490
Threads: 167
Joined: 2008-07
How much trouble am I in?
I ran my weekly Ad-Aware scan and found I had some malware called "Backdoor.Bifrose"...Ad-Aware quarantined it but how do I know I have got rid of it from my system?
...and reformating isnt an option as I have not backed up my pc and I cant lose what I have on it.
Help would be much appreciated.
Posting Freak
Posts: 3,015
Threads: 118
Joined: 2008-07
Just use these 3 programs, they're free:
- Ad-Aware (you have that one already)
- Spybot (Almost the same as Ad-Aware, but 2 of them can't really harm you  )
- AVG Free Virus Scanner
Let those 3 scan your system, reboot a (couple!!!) of times, then scan again. If they don't find anything anymore, you can be 99% sure it's not on your system anymore...
Posting Freak
Posts: 4,490
Threads: 167
Joined: 2008-07
Scanned with AVG and again with Ad-Aware and it didnt come up...I hope I got rid of it before anything happened...If my char gets cleaned out I'll know I was key logged somehow.
Posting Freak
Posts: 2,820
Threads: 130
Joined: 2008-07
Might be related to my situation: http://www.southperry.net/forums/showthread.php?t=6812
I hate being paranoid about this stuff but I pretty much did avg + adaware. avg on medium speed found a good amount of stuff and i did a slow scan overnight [5~6 hrs] and it found nothing so i hope my computer is clean. I'm still being wary over the situation but most people reassured me avg + system restore + adaware will keep me safe based on the results it gave.
Won't Be Coming Back
Posts: 623
Threads: 46
Joined: 2008-09
if it quarantined it then it obviously doesnt exist anymore. the problem is that people who get infected with a virus usually get themselves infected more than once, which raises the chances you have other malware on your computer.
Posting Freak
Posts: 3,015
Threads: 118
Joined: 2008-07
Chameleonic Wrote:Scanned with AVG and again with Ad-Aware and it didnt come up...I hope I got rid of it before anything happened...If my char gets cleaned out I'll know I was key logged somehow. What you can do is:
- Start Windows
- Click start
- Click Run...
- Type: cmd
- Click OK
- Type: netstat
- Hit ENTER
Type the data below Foreign Adress and post it into this thread. It shows all your active connections to/from your PC.
Posting Freak
Posts: 4,490
Threads: 167
Joined: 2008-07
2008-12-17, 11:37 AM
(This post was last modified: 2008-12-17, 11:46 AM by Chameleonic.)
I only use Firefox, and AVG/Ad-Aware didnt find any other threats.
I'm not feeling that confident about logging on to Maple after the patch now...
edit...lol I cant disclose any info that would make me vulnerable can I?
Posting Freak
Posts: 4,490
Threads: 167
Joined: 2008-07
I think this is what you want...
Active Connections
Foreign Address State
localhost:1042 ESTABLISHED
localhost:1041 ESTABLISHED
localhost:1044 ESTABLISHED
localhost:1043 ESTABLISHED
a-61-9-129-185.deploy.akamaitechnologies.com:http TIME_WAIT TCP
a-61-9-129-185.deploy.akamaitechnologies.com:http TIME_WAIT TCP
138-181-111-65.serverpronto.com:http TIME_WAIT
Posting Freak
Posts: 3,015
Threads: 118
Joined: 2008-07
Chameleonic Wrote:I think this is what you want...
Active Connections
Foreign Address State
localhost:1042 ESTABLISHED
localhost:1041 ESTABLISHED
localhost:1044 ESTABLISHED
localhost:1043 ESTABLISHED
a-61-9-129-185.deploy.akamaitechnologies.com:http TIME_WAIT TCP
a-61-9-129-185.deploy.akamaitechnologies.com:http TIME_WAIT TCP
138-181-111-65.serverpronto.com:http TIME_WAIT localhost = your own pc = safe
Akamai = http://en.wikipedia.org/wiki/Akamai_Technologies = safe
serverpronto.com = Not sure about this one, do you host anything yourself there? And did you do the netstat directly after you restarted your pc? Does it still show this after 15 minutes? Does it still show after a restart?
Posting Freak
Posts: 4,490
Threads: 167
Joined: 2008-07
After restarting I get nothing listed.
Only get listings after I open up Firefox.
Soooo does that mean I'm safe?
Posting Freak
Posts: 3,015
Threads: 118
Joined: 2008-07
Chameleonic Wrote:After restarting I get nothing listed.
Only get listings after I open up Firefox.
Soooo does that mean I'm safe? For as far I can see you're safe now...
Unless someone has any other idea's how to do a more thourough scan?
Posting Freak
Posts: 2,820
Threads: 130
Joined: 2008-07
I did the same thing as him and other than local host i got
- Adelphiacom.net [some cable provider, time warner took it over]
- yahoo
- earthlink
- cpe-66-75-159-196.socal.rr.com:http [no idea what this is but i live in socal so might be something related to it]
- southperry's IP
- the serverpronto thing
- 192.168.1.1:51855 [i think this is my own ip]
Serverpronto thing might be common on all comps? idk
Posting Freak
Posts: 3,015
Threads: 118
Joined: 2008-07
Kaasoljoyyx Wrote:I did the same thing as him and other than local host i got
- Adelphiacom.net [some cable provider, time warner took it over]
- yahoo
- earthlink
- cpe-66-75-159-196.socal.rr.com:http [no idea what this is but i live in socal so might be something related to it]
- southperry's IP
- the serverpronto thing
- 192.168.1.1:51855 [i think this is my own ip]
Serverpronto thing might be common on all comps? idk Do it again when you -JUST- booted up your pc, and dont open your internet browser first. This keeps away the normal harmless HTTP connections.
And serverpronto, well it is a dedicated server hoster (they sell server space to anyone), it's most likely nothing, but on the other hand it also could be a central log file database from keylogger clients...
But I did a quick search on Google, and it's not known for the BiFrose troyan atm... So it's most likely nothing...
Posting Freak
Posts: 2,820
Threads: 130
Joined: 2008-07
Well i had to come here to re-read the instructions f3 but anyway
Here's the only things that aren't localhost
- 68.237.164.177:http TIME_WAIT
- 192.168.1.101:netbios-ssn TIME_WAIT
and my problem is from this one http://www.southperry.net/forums/showthread.php?t=6812
Posting Freak
Posts: 3,015
Threads: 118
Joined: 2008-07
2008-12-17, 02:25 PM
(This post was last modified: 2008-12-17, 02:29 PM by Devil.)
Kaasoljoyyx Wrote:Well i had to come here to re-read the instructions f3 but anyway
Here's the only things that aren't localhost
- 68.237.164.177:http TIME_WAIT
- 192.168.1.101:netbios-ssn TIME_WAIT
and my problem is from this one http://www.southperry.net/forums/showthread.php?t=6812 Netbios is just windows local network and the other seems to be a normal http request (browser) to something in Los Angeles.
Edit: Hmmm didn't read that post... Does Zafi.B still get detected after a restart and scans with Ad-Aware/Spybot/AVG?
Posting Freak
Posts: 2,820
Threads: 130
Joined: 2008-07
I system restored it prior avg
I looked at the list on avg/adaware and that zafi.b didn't even show up.
The command prompt --> netstat was done today, that zafi.b came up yesterday, most likely due to internet explorer problem
Posting Freak
Posts: 2,130
Threads: 176
Joined: 2008-08
You should look at your quarantine logs and see where this was detected. It might just be a keygen.
Posting Freak
Posts: 4,490
Threads: 167
Joined: 2008-07
I hope my system is free of this malware...if I get cleaned out I'll know I wasnt...
Posting Freak
Posts: 1,919
Threads: 68
Joined: 2008-07
To save yourself some panic, you should check if it's active or not. Panda's antivirus encyclopedia is a good place to start. I'm not saying you shouldn't get it removed, but it's good to know how dangerous it is to your computer.
All entries of the Backdoor "Bifrose" come up as inactive in the Panda encyclopedia.
|