Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 27-12-2005, 03:46 PM   #1 (permalink)
Broken In
 
mohanty1942's Avatar
 
Join Date: Aug 2004
Location: Nasik
Posts: 131
Default Quick help: sfx.exe- Virus ?


OS- Win 2000 with SP4 installed in C: drive

Each time I connect to internet through dial up, the file named sfx.exe get downloaded silently to c:\ (root) within few minutes .(I notice - although I don't open any page after connection the My connection icon at the right bottom corner shows indication of data transfer)

Norton Antivirus 2003 with updated defs doesn't detect this file (sfx.exe)as virus. Once the file is seen in C: drive then it can be seen running in the Ctrl +Alt +Del list (taskmanager). I can't terminate this application. The only thing I do is reboot to DOS using 98 bootable & delete the file. But the next time I connect to net I again get that file recreated at c:\.

Now I have both adaware & spybot S&D installed with update & killed several entries all those were detected . But the above said problem continues .
Please help to solve. I get no error message. But background data transfer reduces my internet speed & I get too late response even after double clicking "My Computer ".
__________________
No Terms : Just One Condition
mohanty1942 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 27-12-2005, 03:55 PM   #2 (permalink)
Commander in Chief
 
QwertyManiac's Avatar
 
Join Date: Jul 2005
Posts: 6,658
Default

Try this > http://www.f-secure.com/v-descs/roro.shtml
__________________
Harsh J
www.harshj.com
QwertyManiac is offline  
Old 27-12-2005, 04:16 PM   #3 (permalink)
Broken In
 
mohanty1942's Avatar
 
Join Date: Aug 2004
Location: Nasik
Posts: 131
Default

Now my system doesn't have any of the trace described at > http://www.f-secure.com/v-descs/roro.shtml.

But still sfx.exe is getting recreated silently after connection is established.
__________________
No Terms : Just One Condition
mohanty1942 is offline  
Old 27-12-2005, 06:54 PM   #4 (permalink)
Alpha Geek
 
Join Date: Feb 2005
Posts: 959
Default

wel, it has both possibilities of being and not being a virus. post your hijack this file preferably before and after getting connected to net... and i wud recommend u to use lspfix and see how many entries do u find in it... also check your msconfig startt-> run -> type msconfig -> startup. since i hav no clue, i suggest these details wud help with me and many otehrs to spot out

edit: also try replacing your system files using SFC. go here

/legolas
__________________
A computer lets you make more mistakes faster than any invention in human history - with the possible exceptions of handguns and tequila.
legolas is offline  
Old 27-12-2005, 09:47 PM   #5 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default

interseting problem.
do post ur hijackthis log here, pls.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 27-12-2005, 09:52 PM   #6 (permalink)
Broken In
 
Join Date: Apr 2005
Location: Patna
Posts: 176
Default

yeah!!.... i would like to know more too!!!
__________________
Ravi.
-----------------------------------------
http://ravishchandra.blogspot.com/
-----------------------------------------
Ravi+ish is offline  
Old 27-12-2005, 11:13 PM   #7 (permalink)
Human Spambot
 
swatkat's Avatar
 
Join Date: Mar 2004
Location: India
Posts: 2,033
Default

Download HijackThis and unzip it to dedicated folder (like C:\HijackThisFolder\hijackthis.exe). Run it and click the button Do a System scan and save log file. HijackThis will perform a scan and gives you a log. Post its complete contents here.
__________________
http://swatrant.blogspot.com/
swatkat is offline  
Old 27-12-2005, 11:29 PM   #8 (permalink)
Broken In
 
Join Date: Nov 2005
Location: Behind You...
Posts: 190
Default

Hmmmm...
I think I heard about this problem somewhere...

Its like a trozen...
__________________
Computer.
Whats that.
Is it some kind of frog.. turr turr turrr...
con_tester is offline  
Old 27-12-2005, 11:43 PM   #9 (permalink)
Alpha Geek
 
__Virus__'s Avatar
 
Join Date: Sep 2005
Location: Hyderabad
Posts: 560
Default

When your system starts and sfx.exe connects, do ad-aware scan it will surely list all the process running information and it will also list the dlls that are running. Once the scan is completed make a log file and check all the dlls listed. Check version from properties and if you find anything suspicious delete it. I did the same and got the issue resolved. Be careful with dlls though.
__Virus__ is offline  
Old 28-12-2005, 01:31 PM   #10 (permalink)
Wise Old Owl
 
JGuru's Avatar
 
Join Date: Dec 2005
Location: Space-time continuum
Posts: 1,646
Default

Delete the file manually. Install ZoneAlarm Pro in your
System. ZoneAlarm monitors your PC for in-coming
and outgoing net requests. If this file sfx.exe asks to
access certain location on the Web click on 'Deny' button
and check the CheckBox 'Remember my Answer'

Hope this solves your problem.
JGuru is offline  
Old 20-01-2006, 07:09 PM   #11 (permalink)
Broken In
 
mohanty1942's Avatar
 
Join Date: Aug 2004
Location: Nasik
Posts: 131
Default

Sorry for : I couldn't post the 'Hijack this' file in time. Because The Spybot S&D's teatime scanner detected (after establishing connection) a registry entry which had some relation to c:\sfx.exe. I deleted the registry entry. On next boot after connection Spybot's teatime again detected the same entry. Instead of analysing the problem I installed Norton Internet Security 2005 & couldn't face the situation again.
mohanty1942 is offline  
Old 20-01-2006, 11:50 PM   #12 (permalink)
Alpha Geek
 
__Virus__'s Avatar
 
Join Date: Sep 2005
Location: Hyderabad
Posts: 560
Default

Good for u that the problem is over now.
__Virus__ is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by chris

Advertisement




All times are GMT +5.5. The time now is 02:41 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2