sfx hack tool

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by coboy, Nov 29, 2004.

  1. coboy

    coboy Private E-2

    hi all, everytime that i run my NAV it yields a result that says that there is one file that is of risk. it is calles a 'zip.sfx hacktool.hide window'. i have searched ggole, this site and symantec itself but there is no answer. my virus definition is nearly update, there is WMI update that will not install, i dont know if this will be of any use as the NAV already detects soemthing there. but the problem is that it always sais that the delete has failed. i dont kno why, the system backup is not activated, and i am trying it in safe mode too.
    does any body have any ideas what i can do.
    any help is appreciated and welcome.
    thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal
    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.
     
  3. Dritz

    Dritz Private E-2

    I'm having the same problem and have searched for a solution for the past few hours. Any case the same as this always seemed to have fell after the 24th and it was detected by Nortan Antivirus and no other antiviruses. I think it's probably some mistake in the definitions but obviously I don't want to take that risk.

    The file zip.sfx in my scan is assosiated with winrar330 which I downloaded months ago and it was straight off of winrar's site. It's kind of strange but my free trial for it expired long ago but yet I'm still able to use it without using any err questionable methods. Somehow I doubt it's the winrar peoples extracting revenge on me.

    I'm not exactly the best at dealing with these kind of situations as I rarely find myself with any kind of threat to my computer so I'm kind of in a panic as to what this could do to my system.

    A scan with Spybot revealed nothing, Ad-Aware gave me the usual few IECache data miner things which I seem to always have even though I never use IE (that's a question for another day though). A few topics on this in other places directed me to Hijackthis which I'm a total newbie with since as I mentioned before I never encounter situations such as this. So if anyone could tell me exactly how to use it and what to post here to help in my problem I'd appreciate it (I didn't see anything on hijackthis in the read me first post).

    Also the Trend Micro scan gave me nothing.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Dritz,

    sfx files are self extracting files. That is why the file was associated with WinRAR. When you installed WinRAR, it changed file associations for all compressed file types that it recognizes to be associated to WinRAR. I'm not sure at this point whether the zip.sfx file is infected or not. It could be! But it could also be a false positive.

    If it is a true virus, it is unlikely that most spyware type scanners will say anything about it since they are not true virus scanners (though in some cases certain trojan and virus are picked up because they relate to some form of spy/ad ware).

    Hijack This is mention in step 6 of the READ ME FIRST.

    If you want to discuss any issues you are having, you should start your own thread. However, discussions directly related to Coboy's problem are okay but not if they attempt to sidetrack attention to your system.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Dritz & Coboy,

    Both of you should go to the below website and have that zip.sfx file scanned.

    http://www.virustotal.com/flash/virustotal_en.html

    It will run a bunch of different scans on it. Let me know if it finds anything.

    Just click the Browser button at the top an locate your file. Then select Open. Then select the Send button. It takes a little while to run thru all the scanners.
     
  6. Dritz

    Dritz Private E-2

    Virus total detected nothing

    I think I'll do all the scans and tips from the Read this first post one more time and officially call this a false report thank you for your time.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You were supposed to run the scan on the file zip.sfx not on wrar330.exe
     
  8. Dritz

    Dritz Private E-2

    There doesn't appear to be any zip.sfx on my computer but when I did the Nortan scan I believe when I moused over the name it gave me a location that pointed to wrar330.exe. Anyways I've done so many scans with so many other antivirus tools and such that I'm certain that it's just a false alarm.

    Thanks for your help
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normally a virus scan application points to a file when it finds a problem. Running an NAV scan should tell you if it still finds one. If so, what is the full path and filename?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds