Backdorr.Bifrose ffx07.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by lakmalvbj, Jun 27, 2008.

  1. lakmalvbj

    lakmalvbj Private E-2

    Hi All,
    I got a virus from my external hard disk. First time it was scanning the hard disk and show me there is a backdoor.bifrose ffx.exe. Then I cannot open any antivirus software. Even I cannot open the folders which contains the name related to virus (Antivirus, Spyware, Malware etc)
    When I search anything related to anti virus from google, my browser is automatically closed. This is a headache. I did lots of things recommended by Symantech. But nothing was success. The biggest problem is I cannot run any anti virus software or malware, spyware softwares.
    When I check i found ffx07.exe, ffx[0].exe, ffx[1].exe files created in c:\windows derectory. I checked registry and couldn't find anything related to this.

    Please help me,

    Janaka
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am assuming that you have removed the external hard drive. At which point I would suggest that you boot into safe mode and attempt to first run ComboFix....and then see if you can run the other scans.
     
  3. lakmalvbj

    lakmalvbj Private E-2

    Not success. I am going to format the PC. But I cannot format my External HD. It is having lots of valuables. Is there any way to remove that ugly virus from it.

    Thanks,
    Janaka
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you rename ComboFix? Can you at least run the MGTools.exe?
    Even if you reformat, once you hookup the external, you will probably be re-infected, so it would be best to try to clean you now. You could also start by removing the files you mentioned.
     
  5. lakmalvbj

    lakmalvbj Private E-2

    Yes, You are correct. I will try to rename it and run.

    Thanks,
    Janaka
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Either rename to cf or combo-fix......let me know how you make out.
     
  7. lakmalvbj

    lakmalvbj Private E-2

    Hi ,
    Thank you so much. Sorry for the delay. I run Combofix and I could run Symantec. I think now i am not having that virus. But now I am running the full system scan. Please tell me now how I can remove that virus from External hard disk. Now my PC is clean.


    Combolog,




    Thanks,
    Janaka
     

    Attached Files:

    Last edited by a moderator: Jul 2, 2008
  8. lakmalvbj

    lakmalvbj Private E-2

    Hi ,
    I noticed my Symantech is not updated to current date. So I removed it and tried to install new version. Now it is saying symantech service cannot be started. I did a foolish work by uninstalling the symantech. Please help me.

    Thanks,
    janaka
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not clean......

    Let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    C:\WINDOWS\up.txt012
    C:\WINDOWS\up.txt0
    C:\WINDOWS\up.txt01
    C:\WINDOWS\ffx14.exe012
    C:\WINDOWS\ffx14.exe01
    C:\WINDOWS\up.txt01234
    C:\WINDOWS\up.txt0123
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now ATTACH the new log from ComboFix and continue with the instructions here:
    READ & RUN ME FIRST. Malware Removal Guide
     
  10. lakmalvbj

    lakmalvbj Private E-2

    Hi Tim,
    I followed your instructions.
    Please find the attached log file. Still I cannot install the Symantec.
    It gives me same Error 1920: Symantec Services cannot be started. Make sure you have previlages to start system services.

    I checked online scan. But no virus found. Now I can run spyware softwares. But no any software could find the problem.

    Thanks,
    Janaka
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have AVG8 installed..so there is no reason to install Symantec.

    You can use the removal tool HERE
     
  12. lakmalvbj

    lakmalvbj Private E-2

    As I couldn't install Symantec I tried AVG8. But our company is not having relicense for AVG. We have only Symantec license. Now I want to uninstall AVG8 and install Symantec. please help me.

    Thanks,
    Janaka
     
  13. lakmalvbj

    lakmalvbj Private E-2

    Dear Tim,
    I uninstalled AVG8 and followed your instructions.
    Please find attached log file.

    Thanks,
    Janaka
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is your only problem left re-installing Symnatec? You say your company has license for it...is this on a domain....and is the program installed from a company server?
     
  15. lakmalvbj

    lakmalvbj Private E-2

    Dear Tim,
    Yes my only problem is reinstalling Symantec. The Symantec client should be installed in my pc which is in our domain. In the server Symantec server has been installed and my pc should be updated through server.
    I have no anti virus software installed now.
    Thanks,
    janaka.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If the error you get is that you may not have privileges to install, then I would suggest you contact your IT person to do it. You would need to have an administrative accout in order to start the service I suspect.

    You can find out by going to start / run / and type "services.msc" without qoutes and scroll down to the symantec service and see if you can change it to either manually start or auto start.
     
  17. lakmalvbj

    lakmalvbj Private E-2

    Dear Tim,
    I have enough privileges to do anything in my computer.
    Yesterday I install Symantec and when I see that error massage I restart the computer without clicking "Yes" or "No" in the message box. Then it restarted and Symantec has been installed. But it have not been updated through our serve. So i did live update. Hope now it is ok.

    Could you please let me know how to remove same virus from my external hard disk. I am afraid to connect it to computer as it is giving virus.

    Thanks for all the helps.

    Janaka
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Unfortunately, the only way to remove a virus from the external hard drive is to connect it and run the SAS and Malwarebtyes scans with the external as the target. You can also then run an online scan with BitDefender. You need to do it using IE.

    Go to Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds