Author Topic: quite a few things that i need help with  (Read 2248 times)

0 Members and 1 Guest are viewing this topic.

Offline Geowil

  • Jr. Member
  • **
  • Posts: 64
quite a few things that i need help with
« on: March 08, 2006, 05:06:23 AM »
I was sent here from Avasts forums, they said that you people could help me get my comp :exorcize:d

So, heres what i posted a their forums, ill say a few things at the end.

Well, where to begin, lets start with that i have Avast 4.6 home edition and its fullly updated, actually, better to list all of my virus/spyware stuff first:

Avast 4.6
Spybot search & destroy
Miscrosoft Spyware Scanner
AVG
Ad-ware SE

Now, I have been plauged fir the last 4 days with some spyware, little did i know that was only the small picture.  Lately my comp has been acting up and downloading slowly (im on my notebook right now).  I have Free Zonealarm firewall installed on my computer, and its been on for the past month, the settings for the firewall are high.  Now, yesterday i was doing a spyware scan with Microsoft's scanner because of the spyware that was annoying me from the past few days, it finished, found 129 things, which came as a surprize because that previous monday i had nothing on my comp, anyway i deleted everything and did anoter scan, once again it found some stuff, 37 this time,i deleted them, and scanned again.  This time it found only 3 things, i deleted em scanned again but the 3 things i had deleted were still there.  So i said tomyself, now this is damn strange.....  I loaded up avast, scanned, and nothing came up, used avg, it found a trojan, i deleted it off.  I ran avast again, still nothing.  So, i decided to let it slip and went about running my online game server.  Now, about 3  or 4 hours later, the on access scanner reported about 3 trojan viruses.  When i tried to delete them it said it oculdnt and i schedualed a boot time scan.  So, when i went to bed that night i restarted my computer and let the boot time scan run.  Got up in the morning and logged in...... first thing that happened was that the on access scanned spammed me with about 8 trojan visrus warnings.  When i tried to delete the first one, my computer restarted itself.  Now im geting mad, I have never bended over backwards to a virus, and i srue aint gona start, so i disconnect from the internet, and scan scan scan, delete delete delete anything that i found..... well, its been 2 days now, and i still can get this thing called Zolob off of my comp.  Avast donest ever read the infected file (i found this file with Microsoft's scanner, it registered a bad registry key that after 5 deletions was still present, so i went and checked it out, copied the file path down, J:\WINDOWS\System32\drfgsrv.exe) as a virus when i scan it.  Miscrosofts scanner called it a trojan downloader.  Despite everything i have tried it wont be deleted, and i dont want to reformat my hard drive either, so can anyone help me?

i just did an online scan of that file using Kaspersky and heres the virus name:

Trojan-Downloader.Win32.Zlob.hw

i have windows XP SP2, and yes, as far as i know its the only thing left, full path is:
J:/WINDOWS/System32/drfgsrv.exe (same path a before).  I dowloaded kaspersky's virus scanner and an scanning my sys32 folder right now, see if anything else can be found besides that.

Well, Kaspersky cant delete it, so im going to try a boot scan with it.

Also, wheni try to put it into qarantine it saus access denied or insufficiant rights (this account i am on is set to system admin).

i dont know if its relevant or not, but right before this all started, something calledSpyFalcon was installed on my computer from god knows where, i was looking around my gaming servers site and this message said now downloading and installing SpyFalcon..

now, with all that heres that i am having trouble with.  That trojan downloaer will not be deleted for all the :hug:s in the world! i have tried using avasts scanner to do a boot sca, that didnt get rid of it, it wont quarantine, and i can delete it.  Also, that SpyFalcon thing is starting to worry, me, the guy who reffered me here said that SpyFalcon ment big trouble......  and i also wanna know how all this #!@* got by my router and zonealarm, cuz my routers firewall is set to normal and zonealarm is on high.  I really could use some help here lol, i dont wanna reformat because im running a online game on this comp, would put me back a couple of weeks if i had to reformat.

Offline Skittles

  • Hero Member
  • *****
  • Posts: 769
Re: quite a few things that i need help with
« Reply #1 on: March 08, 2006, 08:44:07 AM »
It sounds like it is time for HJT (hijack this)...a wonderful program.

Please click here to find out more about this, and how to post your first log.

http://www.landzdown.com/index.php?topic=423.0

Then post your log in a new thread....at the hjt logs room.  Do not post your hjt log here in this thread.

Create a new thread for your log here.  http://www.landzdown.com/index.php?board=26.0

Our malware experts will be with you as soon as they can.  I am sure they will be able to help you.

BUT most importantly.....Do NOT attempt to FIX anything with HIJACK THIS until you are instructed to do so, by a hjt expert!

And  :welcome2:


Offline Skittles

  • Hero Member
  • *****
  • Posts: 769
Re: quite a few things that i need help with
« Reply #2 on: March 08, 2006, 08:53:40 AM »
I forgot to add....

you will notice that you already have done or have some of the programs suggested for you to download and run prior to your posting your first hjt log.  Just go past the ones you have already done. 

Also you need to disable any real time monitoring programs you may be running.

Click here for instructions on that.

http://www.landzdown.com/index.php?topic=422.0

Offline Tarnak

  • Hero Member
  • *****
  • Posts: 502
Re: quite a few things that i need help with
« Reply #3 on: March 08, 2006, 09:08:27 AM »
i dont know if its relevant or not, but right before this all started, something calledSpyFalcon was installed on my computer from god knows where, i was looking around my gaming servers site and this message said now downloading and installing SpyFalcon..



 I just googled spyaxe/spyfalcon and saw the following interesting link.



http://www.freedomlist.com/forum/viewtopic.php?t=24856

Offline Skittles

  • Hero Member
  • *****
  • Posts: 769
Re: quite a few things that i need help with
« Reply #4 on: March 08, 2006, 09:59:16 AM »
Yes that is a good one Tarnak.  Written by our own, Corrine.

Another good one is http://forums.security-central.us/showthread.php?t=464&highlight=spyfalcon

Altho I still think it is best to run the hjt log first and have our team help you get rid of it correctly, rather then trying to do it yourself.

Afterwards I am sure we would like to welcome you to post about your experience with this at Malware Complaints.

But we will talk more about that, when the time comes, and we have helped you get this off of your pc.

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11541
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: quite a few things that i need help with
« Reply #5 on: March 08, 2006, 04:56:59 PM »
Hi, Geowil.  As of right now, there is only one removal process for SpyFalcon.  You most likely have SpyFalcon in Program Files and if you are familiar with HijackThis, you will see this file in Program files (or as a 04 in HijackThis):

O4 - HKLM\..\Run: [SpyFalcon] C:\Program Files\SpyFalcon\SpyFalcon.exe /h

In that case, you will need to download FixSF.reg to your desktop by right clicking on the link below, selecting "Save Link As" or "Save File" as, depending on your browser.

FixSF.reg Download Link

See the tutorial here.

After following the tutorial, post a HijackThis log here as a reply so we can see how you're doing.

Thanks.  :rose:
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.