Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old February 3rd, 2005, 01:19 PM
ccooll00 ccooll00 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2005
Posts: 1 ccooll00 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 49 m 7 sec
Reputation Power: 0
Possible Trojan???(Dfind.exe)

hello...


Is Dfind.exe some known trojan or a virus?. This program is running on my computer and it is taking up all the CPU. If i look at the tast manager, it is showing that the Dfind.exe is taking close to 80 of the CPU. I ran couple of antivirus software such as zone alarm and also bit defender pro. but none of these were any help..

any suggestion on how to get rid of this..

thanks..

Reply With Quote
  #2  
Old February 3rd, 2005, 11:14 PM
RogueServ RogueServ is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2004
Posts: 102 RogueServ User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 Day 11 h 2 m 31 sec
Reputation Power: 4
Send a message via ICQ to RogueServ Send a message via AIM to RogueServ Send a message via MSN to RogueServ Send a message via Yahoo to RogueServ
Actually, I have no idea. When I search google for it, I get these crazy Chinese sites. The only thing that comes close to even describing it in english is governmentsecurity.org...

Reply With Quote
  #3  
Old February 4th, 2005, 09:17 AM
Grinler Grinler is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 171 Grinler User rank is Private First Class (20 - 50 Reputation Level)Grinler User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 h 24 m 14 sec
Reputation Power: 5
Can you post a hijackthis log so we can take a look?

I need to get samples of some of your files. Please create a folder called c:\submit. Now copy the following files into that directory:

dfind.exe

To copy the files simply navigate to the directory they are in and right click on them and then click on copy. Then paste these files into the c:\submit directory. Once the files are all copied I need you to zip the folder and rename submit.zip to yourmembername.zip (for example grinler.zip). If you are using XP or ME right-click on the folder and click on the Send To option and then send it to a compressed folder. You will now see a file called submit.zip. If you are using another version of Windows, please download a program called Winzip and zip it using that. Then go to http://www.bleepingcomputer.com/submit-malware.php fill in the required fields, and browse to the file. Then click on the Send File button.

Reply With Quote
  #4  
Old June 7th, 2005, 06:42 PM
moonlit moonlit is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2005
Posts: 1 moonlit User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 m 24 sec
Reputation Power: 0
I've had dfind.exe running for quite some time, not knowing what it was.

Turns out its a zombie client of some kind, it opens up a lot of network connections.

It is indeed stored in c:\system volume information\tracking.\, along with some log files and batch files ot start it up.

The contents of my folder is here: http://negerkuk.com/dfind.zip

I'll submit it on the malware site.

Reply With Quote
  #5  
Old June 8th, 2005, 11:29 AM
Grinler Grinler is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2004
Posts: 171 Grinler User rank is Private First Class (20 - 50 Reputation Level)Grinler User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 4 h 24 m 14 sec
Reputation Power: 5
Your computer was hacked at some time and those files are being used to scan the internet for FTP servers and maybe open proxy servers.
Comments on this post
Tom Myboy agrees: Thanks for your input Grinler!

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Possible Trojan???(Dfind.exe)


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway