This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Backdoor-cgb

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

These past few days I've been having some trouble with what McAfee is referring to as BackDoor-CFB trojan. The file it is listing is variations of logo.dll in my System32 folder (I'm running XP Pro). My problem is, I am unable to delete or clean the file as it is saying I don't have the rights to the file (something to that effect, I'm sure you know the message). A couple weeks ago I seemed to fix a frustrating startpage virus and I don't know if this is connected to that problem or not. To try to fix this, I have ran SpyBot, CWShredder (just in case), and my McAfee virus scan. When I get the virus warning message from McAfee, I get it in groups of like 4-5 at the same time (same exact thing too, just variations on how the file name is listed - see log below). These messages come up practically every time a file or folder is opened, unless I hit "EXCLUDE" and then I don't get the messages anymore. I have also tried running McAfee while in safe mode, however, it is not even finding the virus while in safe mode. FILE LOCATIONS ACCORDING TO MCAFEE J:\WINDOWS\System32\logo.dll => logo.dll J:\WINDOWS\System32\logo.dll => logo.dll J:\WINDOWS\SYSTEM32\LOGO.DLL => LOGO.DLL J:\WINDOWS\SYSTEM32\LOGO.DLL => LOGO.DLL J:\WINDOWS\System32\logo.dll => logo.dll I've looked repeatedly for this file (both manually and by searching) and have not yet found a file (I have hidden files included too), so unable to delete manually. What can I do to get rid of this file? I have Hijackthis if that log file would help any. Thanks! Brian
Greetings and welcome to TomCoyote.com!

May your day be blessed by those you love and those you love be blessed by HIM. - Coyote


Please post your Hijack This! log file. :)
Here it is, thanks!


Logfile of HijackThis v1.97.7
Scan saved at 8:19:38 PM, on 7/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\Explorer.EXE
J:\WINDOWS\system32\spoolsv.exe
J:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
K:\Zone Labs\ZoneAlarm\zlclient.exe
J:\WINDOWS\System32\ctfmon.exe
K:\VirusScan\Avsynmgr.exe
J:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
J:\WINDOWS\System32\nvsvc32.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\ZoneLabs\vsmon.exe
K:\VirusScan\VsStat.exe
K:\VirusScan\Vshwin32.exe
K:\VirusScan\Avconsol.exe
J:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
K:\VirusScan\Webscanx.exe
J:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://drudgereport.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - J:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - j:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] J:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE J:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Zone Labs Client] "K:\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PCDRealtime] J:\WINDOWS\realtime.exe
O4 - HKLM\..\Run: [QuickTime Task] "J:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] J:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://J:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://J:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://J:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight - K:\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - K:\GetRight\GRbrowse.htm
O8 - Extra context menu item: Si&milar Pages - res://J:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://J:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.ipswitch.com/_installs/wsftp_le/setup.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - http://ftp.hp.com/pub/automatic/player/isetupML.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…8153.7571527778
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…367/mcfscan.cab
Please try these 3 online virus scanners/removers.

Trend-Micro:
http://housecall.trendmicro.com/housecall/start_corp.asp

Panda:
http://www.pandasoftware.com/activescan/co…n_principal.htm

Etrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

Let them delete any infections found. Reboot after each scan.

After trying the online scans, try your resident virus protection again. If the same infection appears in the same file, I believe we may have a tool to delete it for you.

When complete, reboot and post a new log file. :)
Ok, here's my log file. I also have some info below the file on my process.

Logfile of HijackThis v1.97.7
Scan saved at 9:56:18 PM, on 7/9/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\Explorer.EXE
J:\WINDOWS\system32\spoolsv.exe
J:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
J:\WINDOWS\System32\ctfmon.exe
K:\VirusScan\Avsynmgr.exe
J:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
J:\WINDOWS\System32\nvsvc32.exe
J:\WINDOWS\System32\svchost.exe
K:\Internet Security\tmproxy.exe
K:\VirusScan\VsStat.exe
K:\Internet Security\PccPfw.exe
K:\VirusScan\Avconsol.exe
J:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://drudgereport.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - J:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - j:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] J:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE J:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [PCDRealtime] J:\WINDOWS\realtime.exe
O4 - HKLM\..\Run: [QuickTime Task] "J:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] J:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &Google Search - res://J:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://J:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://J:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight - K:\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - K:\GetRight\GRbrowse.htm
O8 - Extra context menu item: Si&milar Pages - res://J:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://J:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.ipswitch.com/_installs/wsftp_le/setup.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} (InstallShield International Setup Player) - http://ftp.hp.com/pub/automatic/player/isetupML.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…8153.7571527778
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…367/mcfscan.cab




OK. I ran all 3 scans, they did not find anything. However, from the top link, I downloaded PC-cillan and installed it, it was finding the same trojan file and also was unable to delete it. Also, I have diasbled McAfee while the PC-cillan is running, so only 1 VS is running at a time. Any suggestions? The virus message is getting quite annoying :angry:

Thanks!

Brian
::KNOCK ON WOOD:: Looks like I may have got it. Running PC-cillan, I clicked on the link listing the virus and it took me to their website which had a "fixit" program. I downloaded and ran it and it seems to have fixed my problem (at least that's how it appears for the moment). Thanks for all the help and I'll let you know if it comes back. Thanks! Brian
I am glad that we were able to help! I am closing this topic now, but if you need it reopened, please send an email to the following link(Click for address) with the Subject line of the email "Reopen".
To receive a response, please include in your email: the user name used in the post, details of why you need it reopened, and a valid link to the post.

Emails with bad links to the post, emails that are not from the original poster, and emails that do not have "ReOpen" as the subject line, will be deleted without being opening.

Please start a New Topic if this is not your thread. Thank-you for your co-operation.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI