This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis Log and cf_rbs.dll problem, please review

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, first thanks for your time and your help in advance.

I run Windows Defender, Ad-Aware and EZ Antivirus.

I found some suspicious processes in the autostart with Windows Defender and disables them. After that I get an error message on startup that access to cf_rbs.dll is denied. EZ Antivirus detects this file in system32 as Win32/Cuelox.A and deletes it, but afterwards it is still there. Can't delete the file in Safe Mode either. (same for cf_rbs.sys in system32\drivers)

Apart from that, my PC is actually not really acting up.

Any advice on how I can get rid of that virus and please have a look at the log if there are any other malware processes or programs there.

Thanks again and have a nice day.

Logfile of HijackThis v1.99.1
Scan saved at 09:46:27, on 25.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\Atievxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAV.exe
C:\Documents and Settings\Hainz\Desktop\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Schedule Class - {8B316DA1-9950-4926-B9EA-1AEC124AFA45} - C:\WINDOWS\system32\sscli.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MepYxaix Class - {94F314C8-3F0E-C7D5-0FD9-70E9E5C12281} - C:\WINDOWS\DOWNLO~1\ajwes.dll
O2 - BHO: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O3 - Toolbar: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [dfsf] RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://218.96.3.99/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gaocrystal.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABD34C2D-791C-472B-88A5-265B74F51FB2}: NameServer = 202.106.0.20 202.106.46.151
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptig.dll
O21 - SSODL: WebSecurity - {3DD78ACF-0745-4532-94F8-A574457E1A81} - C:\WINDOWS\system32\PvSec.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
Hi Thorquad and welcome to the forums here at Tom Coyote.

First, you are running HijackThis from the desktop. I recommend that you move HJT to it's own permanent folder so backups will be easy to find if needed.

Please do the following:Create a new permanent folder in a convenient location that you will remember. To do this: Open Windows Explorer.
Select the drive or folder that you would like to put HJT
From the menu select File > New > Folder
Rename the folder to something you will remember (ie HJT, HijackThis, ect…)
Now move HJT to the new folder that you created.

Next, is your OS a Non-Western version, such as a chinese version? If so this file conime.exe may be OK. If not then please let me know, also let me know if you are familiar with the file.

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R3 - URLSearchHook: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O2 - BHO: Schedule Class - {8B316DA1-9950-4926-B9EA-1AEC124AFA45} - C:\WINDOWS\system32\sscli.dll
O2 - BHO: MepYxaix Class - {94F314C8-3F0E-C7D5-0FD9-70E9E5C12281} - C:\WINDOWS\DOWNLO~1\ajwes.dll
O2 - BHO: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O3 - Toolbar: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O4 - HKLM\..\Run: [dfsf] RUNDLL32.EXE C:\WINDOWS\system\Mvvp.dll,DImmcv

Then close all windows except this one and press Fix checked.

Download the Killbox.
Unzip it to the desktop

Double-click Killbox.exe to run it.

Select "Delete on Reboot".
Place the following line (complete path) in bold in the "Full Path of File to Delete" box in Killbox:
C:\WINDOWS\system\Mvvp.dll

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt.
If your computer does not restart automatically, please restart it manually.

Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

C:\WINDOWS\SYSTEM32\cryptig.dll

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html
http://www.virustotal.com/en/indexf.html

Now I would like you to run an online virus scan:

Using Internet Explorer, click on Kaspersky Online Scanner
* You will be prompted to install an ActiveX component from Kaspersky, Click 'Yes'.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save as Text' button:
* Save the file to your desktop.
Please post the Kaspersky report, results from the file upload, and a new HijackThis log. Also let me know how you made out during the fix and how things are running now.

Regards,
Dave
Hi IndiGenus,
thanks for the welcome and thanks for the fast reply.

My Windows version, as far as I know, is an English version. But as I am working in China, I have the East Asian languages installed and use Chinese for non UTF coded software. So maybe that is the reason for the suspicious file.

Used killbox to delete the file.

I did as you said. Here first the result from the Jotti scan.


File: cryptig.dll
Status: INFECTED/MALWARE
MD5 f206d0e93eb3d427c6428ece4d6855c8
Packers detected: -

Scanner results
Scan taken on 26 Jan 2007 00:29:56 (GMT)
AntiVir - Found nothing
ArcaVir - Found nothing
Avast - Found nothing
AVG Antivirus - Found nothing
BitDefender - Found Trojan.Downloader.Agent.ATT
ClamAV - Found nothing
Dr.Web - Found nothing
F-Prot Antivirus - Found nothing
F-Secure Anti-Virus - Found Trojan-Downloader.Win32.Agent.bcd
Fortinet - Found nothing
Kaspersky Anti-Virus - Found Trojan-Downloader.Win32.Agent.bcd
NOD32 - Found nothing
Norman Virus Control - Found nothing
VirusBuster - Found nothing
VBA32 - Found nothing


and here the Kasperski scan.

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, January 26, 2007 1:55:50 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 26/01/2007
Kaspersky Anti-Virus database records: 262073
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
G:\

Scan Statistics:
Total number of scanned objects: 59970
Number of viruses found: 21
Number of infected objects: 50 / 0
Number of suspicious objects: 0
Duration of the scan process: 04:08:13

Infected Object Name / Virus Name / Last Action
C:\!KillBox\Mvvp.dll Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01232007-115824.log Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\cert8.db Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\history.dat Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\key3.db Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\parent.lock Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Hainz\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Logs\Dfsr.log Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Working\database_64C_B607_4CB5_F193\dfsr.db Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Working\database_64C_B607_4CB5_F193\fsr.log Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Working\database_64C_B607_4CB5_F193\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Working\database_64C_B607_4CB5_F193\tmp.edb Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{63D5E94C-313B-4BBE-A84E-8B798D450590} Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows Live Contacts\real\members.stg Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows Live Contacts\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Hainz.dat Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\History\History.IE5\MSHist012007012620070127\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Perflib_Perfdata_30c.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\selcva.dat Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\DDBUO1N4\154[1].exe/stream/data0001 Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\DDBUO1N4\154[1].exe/stream Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\DDBUO1N4\154[1].exe NSIS: infected - 2 skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\HH00PGCO\34[1].exe Infected: Trojan-Downloader.Win32.Small.eat skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\UUSEE_borl_Setup_01.exe Infected: not-a-virus:AdWare.Win32.BHO.bv skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DF66D2.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DF7A9C.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DF7C48.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DF9470.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DFA6E5.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DFA818.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp/stream/data0001 Infected: Trojan-Clicker.Win32.Small.ml skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp/stream Infected: Trojan-Clicker.Win32.Small.ml skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp UPX: infected - 2 skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\Hainz\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Hainz\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\HijackThis\backups\backup-20070126-081732-406.dll Infected: Trojan-Clicker.Win32.Small.ml skipped
C:\HijackThis\backups\backup-20070126-081733-382.dll Infected: not-a-virus:AdWare.Win32.Agent.bk skipped
C:\Program Files\Common Files\UPDAT\update.exe Infected: Trojan-Downloader.Win32.QQHelper.gen skipped
C:\Program Files\UUSee\UUPlayer.exe Infected: not-a-virus:AdWare.Win32.BHO.bv skipped
C:\Program Files\UUSee\UUPlayer_bak.exe Infected: not-a-virus:AdWare.Win32.BHO.bv skipped
C:\Program Files\Yahoo!\Messenger\logs\billing_Hainz.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\client_Hainz.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\network_Hainz.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{FA3121E1-1262-4847-9FC8-366EB01693BF}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\47bdntos.dll Infected: not-a-virus:AdWare.Win32.Agent.bk skipped
C:\WINDOWS\system32\caclib.dll Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\cf_rbs.dll Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\cryptig.dll Infected: Trojan-Downloader.Win32.Agent.bcd skipped
C:\WINDOWS\system32\cryptimg.dll Infected: Trojan-Downloader.Win32.Agent.bcd skipped
C:\WINDOWS\system32\drivers\ast.sys Infected: not-a-virus:AdWare.Win32.Agent.bk skipped
C:\WINDOWS\system32\drivers\cf_rbs.sys Object is locked skipped
C:\WINDOWS\system32\drivers\czlign67.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\IEHelper.dll Infected: not-a-virus:AdWare.Win32.BHO.aj skipped
C:\WINDOWS\system32\res.exe Infected: Trojan-Downloader.Win32.QQHelper.ik skipped
C:\WINDOWS\system32\sconfs.exe Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\WINDOWS\system32\spted.dll Infected: not-a-virus:AdWare.Win32.AdHelper.bq skipped
C:\WINDOWS\system32\ta.tmp Infected: Trojan-Downloader.Win32.QQHelper.ep skipped
C:\WINDOWS\system32\vaselc.dll Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\ta.tmp Infected: Trojan-Downloader.Win32.QQHelper.gq skipped
C:\WINDOWS\system32\wbem\~tmp00001.exe/data0005 Infected: not-a-virus:AdWare.Win32.MyTool.b skipped
C:\WINDOWS\system32\wbem\~tmp00001.exe NSIS: infected - 1 skipped
C:\WINDOWS\Temp\1.exe/stream/data0001 Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\WINDOWS\Temp\1.exe/stream Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\WINDOWS\Temp\1.exe NSIS: infected - 2 skipped
C:\WINDOWS\Temp\20125.exe Infected: Trojan-Dropper.Win32.Small.atr skipped
C:\WINDOWS\Temp\34.exe Infected: Trojan-Downloader.Win32.Small.eat skipped
C:\WINDOWS\Temp\insshell\insshell.exe Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\WINDOWS\Temp\insshell\insshell_698.exe Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\WINDOWS\Temp\sd153.exe Infected: Trojan-Downloader.Win32.Small.efp skipped
C:\WINDOWS\Temp\sd154.exe Infected: Trojan-Downloader.Win32.Small.efp skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\~de2F.tmp Infected: not-a-virus:AdWare.Win32.Boran.z skipped
C:\~de31.tmp Infected: not-a-virus:AdWare.Win32.Boran.x skipped
C:\~de3D.tmp Infected: not-a-virus:AdWare.Win32.Boran.ab skipped
C:\~de3E.tmp Infected: not-a-virus:AdWare.Win32.Boran.ab skipped
C:\~de55.tmp Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\~de56.tmp Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\~de58.tmp Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\~de59.tmp Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\~deA0.tmp Infected: not-a-virus:AdWare.Win32.Boran.y skipped

Scan process completed.

And a new HijackThis report:

Logfile of HijackThis v1.99.1
Scan saved at 15:15:31, on 26.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Atievxx.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\EmEditor\emeditor.exe
C:\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {54a08cb5-3c78-4553-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4553cfsb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O3 - Toolbar: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [sdafdsafds] D;]XJOEPXT]ufnq]te265/fyf
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://218.96.3.99/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABD34C2D-791C-472B-88A5-265B74F51FB2}: NameServer = 202.106.0.20 202.106.46.151
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptig.dll
O21 - SSODL: WebSecurity - {3DD78ACF-0745-4532-94F8-A574457E1A81} - C:\WINDOWS\system32\PvSec.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe




Still get the message from my Virusscanner about cf_rbs.sys and cf_rbs.dll to be infected by Win32/Cuelox.A. But I saw it was skipped by the scan as it was locked.
How do I get rid of that one?

Thanks for the continued help in advance.

Markus
Hi IndiGenus,
thanks for the welcome and thanks for the fast reply.

My Windows version, as far as I know, is an English version. But as I am working in China, I have the East Asian languages installed and use Chinese for non UTF coded software. So maybe that is the reason for the suspicious file.

Used killbox to delete the file.

I did as you said. Here first the result from the Jotti scan.


File: cryptig.dll
Status: INFECTED/MALWARE
MD5 f206d0e93eb3d427c6428ece4d6855c8
Packers detected: -

Scanner results
Scan taken on 26 Jan 2007 00:29:56 (GMT)
AntiVir - Found nothing
ArcaVir - Found nothing
Avast - Found nothing
AVG Antivirus - Found nothing
BitDefender - Found Trojan.Downloader.Agent.ATT
ClamAV - Found nothing
Dr.Web - Found nothing
F-Prot Antivirus - Found nothing
F-Secure Anti-Virus - Found Trojan-Downloader.Win32.Agent.bcd
Fortinet - Found nothing
Kaspersky Anti-Virus - Found Trojan-Downloader.Win32.Agent.bcd
NOD32 - Found nothing
Norman Virus Control - Found nothing
VirusBuster - Found nothing
VBA32 - Found nothing


and here the Kasperski scan.

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, January 26, 2007 1:55:50 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 26/01/2007
Kaspersky Anti-Virus database records: 262073
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
G:\

Scan Statistics:
Total number of scanned objects: 59970
Number of viruses found: 21
Number of infected objects: 50 / 0
Number of suspicious objects: 0
Duration of the scan process: 04:08:13

Infected Object Name / Virus Name / Last Action
C:\!KillBox\Mvvp.dll Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01232007-115824.log Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\cert8.db Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\history.dat Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\key3.db Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\parent.lock Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Hainz\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Hainz\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Logs\Dfsr.log Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Working\database_64C_B607_4CB5_F193\dfsr.db Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Working\database_64C_B607_4CB5_F193\fsr.log Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Working\database_64C_B607_4CB5_F193\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Messenger\SharingMetadata\Working\database_64C_B607_4CB5_F193\tmp.edb Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{63D5E94C-313B-4BBE-A84E-8B798D450590} Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows Live Contacts\real\members.stg Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Microsoft\Windows Live Contacts\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Application Data\Mozilla\Firefox\Profiles\ywjioc11.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Hainz.dat Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\History\History.IE5\MSHist012007012620070127\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Perflib_Perfdata_30c.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\selcva.dat Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\DDBUO1N4\154[1].exe/stream/data0001 Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\DDBUO1N4\154[1].exe/stream Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\DDBUO1N4\154[1].exe NSIS: infected - 2 skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\HH00PGCO\34[1].exe Infected: Trojan-Downloader.Win32.Small.eat skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\UUSEE_borl_Setup_01.exe Infected: not-a-virus:AdWare.Win32.BHO.bv skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DF66D2.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DF7A9C.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DF7C48.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DF9470.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DFA6E5.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~DFA818.tmp Object is locked skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp/stream/data0001 Infected: Trojan-Clicker.Win32.Small.ml skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp/stream Infected: Trojan-Clicker.Win32.Small.ml skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp NSIS: infected - 2 skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp UPX: infected - 2 skipped
C:\Documents and Settings\Hainz\Local Settings\Temp\~dl1E6.tmp PE_Patch.UPX: infected - 2 skipped
C:\Documents and Settings\Hainz\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Hainz\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Hainz\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\HijackThis\backups\backup-20070126-081732-406.dll Infected: Trojan-Clicker.Win32.Small.ml skipped
C:\HijackThis\backups\backup-20070126-081733-382.dll Infected: not-a-virus:AdWare.Win32.Agent.bk skipped
C:\Program Files\Common Files\UPDAT\update.exe Infected: Trojan-Downloader.Win32.QQHelper.gen skipped
C:\Program Files\UUSee\UUPlayer.exe Infected: not-a-virus:AdWare.Win32.BHO.bv skipped
C:\Program Files\UUSee\UUPlayer_bak.exe Infected: not-a-virus:AdWare.Win32.BHO.bv skipped
C:\Program Files\Yahoo!\Messenger\logs\billing_Hainz.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\client_Hainz.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\network_Hainz.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{FA3121E1-1262-4847-9FC8-366EB01693BF}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\47bdntos.dll Infected: not-a-virus:AdWare.Win32.Agent.bk skipped
C:\WINDOWS\system32\caclib.dll Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\cf_rbs.dll Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\cryptig.dll Infected: Trojan-Downloader.Win32.Agent.bcd skipped
C:\WINDOWS\system32\cryptimg.dll Infected: Trojan-Downloader.Win32.Agent.bcd skipped
C:\WINDOWS\system32\drivers\ast.sys Infected: not-a-virus:AdWare.Win32.Agent.bk skipped
C:\WINDOWS\system32\drivers\cf_rbs.sys Object is locked skipped
C:\WINDOWS\system32\drivers\czlign67.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\IEHelper.dll Infected: not-a-virus:AdWare.Win32.BHO.aj skipped
C:\WINDOWS\system32\res.exe Infected: Trojan-Downloader.Win32.QQHelper.ik skipped
C:\WINDOWS\system32\sconfs.exe Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\WINDOWS\system32\spted.dll Infected: not-a-virus:AdWare.Win32.AdHelper.bq skipped
C:\WINDOWS\system32\ta.tmp Infected: Trojan-Downloader.Win32.QQHelper.ep skipped
C:\WINDOWS\system32\vaselc.dll Infected: Trojan-Downloader.Win32.Agent.bcc skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\ta.tmp Infected: Trojan-Downloader.Win32.QQHelper.gq skipped
C:\WINDOWS\system32\wbem\~tmp00001.exe/data0005 Infected: not-a-virus:AdWare.Win32.MyTool.b skipped
C:\WINDOWS\system32\wbem\~tmp00001.exe NSIS: infected - 1 skipped
C:\WINDOWS\Temp\1.exe/stream/data0001 Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\WINDOWS\Temp\1.exe/stream Infected: Trojan-Downloader.Win32.Agent.bey skipped
C:\WINDOWS\Temp\1.exe NSIS: infected - 2 skipped
C:\WINDOWS\Temp\20125.exe Infected: Trojan-Dropper.Win32.Small.atr skipped
C:\WINDOWS\Temp\34.exe Infected: Trojan-Downloader.Win32.Small.eat skipped
C:\WINDOWS\Temp\insshell\insshell.exe Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\WINDOWS\Temp\insshell\insshell_698.exe Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\WINDOWS\Temp\sd153.exe Infected: Trojan-Downloader.Win32.Small.efp skipped
C:\WINDOWS\Temp\sd154.exe Infected: Trojan-Downloader.Win32.Small.efp skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\~de2F.tmp Infected: not-a-virus:AdWare.Win32.Boran.z skipped
C:\~de31.tmp Infected: not-a-virus:AdWare.Win32.Boran.x skipped
C:\~de3D.tmp Infected: not-a-virus:AdWare.Win32.Boran.ab skipped
C:\~de3E.tmp Infected: not-a-virus:AdWare.Win32.Boran.ab skipped
C:\~de55.tmp Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\~de56.tmp Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\~de58.tmp Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\~de59.tmp Infected: not-a-virus:AdWare.Win32.Boran.w skipped
C:\~deA0.tmp Infected: not-a-virus:AdWare.Win32.Boran.y skipped

Scan process completed.

And a new HijackThis report:

Logfile of HijackThis v1.99.1
Scan saved at 15:15:31, on 26.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Atievxx.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\EmEditor\emeditor.exe
C:\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {54a08cb5-3c78-4553-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4553cfsb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O3 - Toolbar: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [sdafdsafds] D;]XJOEPXT]ufnq]te265/fyf
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://218.96.3.99/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABD34C2D-791C-472B-88A5-265B74F51FB2}: NameServer = 202.106.0.20 202.106.46.151
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptig.dll
O21 - SSODL: WebSecurity - {3DD78ACF-0745-4532-94F8-A574457E1A81} - C:\WINDOWS\system32\PvSec.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe




Still get the message from my Virusscanner about cf_rbs.sys and cf_rbs.dll to be infected by Win32/Cuelox.A. But I saw it was skipped by the scan as it was locked.
How do I get rid of that one?

Thanks for the continued help in advance.

Markus
Hi Markus,

We need to make sure all hidden files are showing so please:
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.
Please reverse this process once the fix is complete.

Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop. Do not run this yet, we will do so later in the fix.

Reboot your computer in Safe Mode by restarting your computer and tap the F8 key just before Windows starts to load. This will bring up the Advanced Options Menu.
Select the first option, to run Windows in Safe Mode, then press Enter.
Select the Operating System that you would like to start and press Enter (note: if there is only one simply press Enter).

Stay in Safe Mode for the remainder of this fix. If you are forced to reboot go back to Safe Mode.

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R3 - URLSearchHook: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O2 - BHO: (no name) - {54a08cb5-3c78-4553-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4553cfsb.dll
O2 - BHO: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O3 - Toolbar: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O4 - HKLM\..\Run: [sdafdsafds] D;]XJOEPXT]ufnq]te265/fyf
O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptig.dll

Then close all windows except this one and press Fix checked.

Still in Safe Mode.

Please delete the following files if found (if you're not sure how to do this then see the example in red text below):

Delete these files:
C:\Program Files\Common Files\UPDAT\update.exe
C:\Program Files\UUSee\UUPlayer.exe
C:\Program Files\UUSee\UUPlayer_bak.exe
C:\WINDOWS\system32\47bdntos.dll
C:\WINDOWS\system32\caclib.dll
C:\WINDOWS\system32\IEHelper.dll
C:\WINDOWS\system32\res.exe
C:\WINDOWS\system32\sconfs.exe
C:\WINDOWS\system32\spted.dll
C:\WINDOWS\system32\ta.tmp
C:\WINDOWS\system32\vaselc.dll
C:\WINDOWS\system32\cf_rbs.dll
C:\WINDOWS\system32\drivers\cf_rbs.sys
C:\WINDOWS\SYSTEM32\cryptig.dll
C:\WINDOWS\system32\cryptimg.dll

As an example:
To delete C:\WINDOWS\filetogo.bye
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'

Double-click ATF Cleaner.exe to open it.

Under Main select the following:
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

There's one more file here that I'm not sure on and would like you to upload and check. Also upload that Conime file to have it checked.

Reboot back into Normal Mode now.
Please go to http://virusscan.jotti.org, click on Browse, and upload the following files for analysis:

C:\WINDOWS\system32\PvSec.dll
C:\WINDOWS\system32\conime.exe

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

If Jotti is too busy you can try these.

http://www.kaspersky.com/scanforvirus.html
http://www.virustotal.com/en/indexf.html

Now reboot if you haven't already, post a new HJT log, results from the file scan, and let me know how you made out with the fix and how things are running now.

Regards,
Dave
Hi Dave,
first the results of the file scan. Conim.exe seems to be OK, but PcSec.dll seems to be infected.

File: conime.exe
Status: OK(Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 054df8f752497c6b74dd7b65cca61132
Packers detected: -
Scanner results
Scan taken on 27 Jan 2007 02:40:11 (GMT)
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
VirusBuster Found nothing
VBA32 Found nothing


File: PvSec.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 544548e209c0219057d4587bfa294fbe
Packers detected: -

Scanner results
Scan taken on 27 Jan 2007 02:42:47 (GMT)
AntiVir Found TR/Dldr.Age.36864.5
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found Trojan.DownLoader.15901
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
VirusBuster Found nothing
VBA32 Found Trojan.DownLoader.15901


did as you said, but seems like some of the problems are still there. Especially the cf_rbs.dll and cf_rbs.sys file coudn't be deleted. Causing still the error message on log on (Access Denied).

also this O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptig.dll seems to be still there.


New Hijack This log

Logfile of HijackThis v1.99.1
Scan saved at 16:39:01, on 27.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\Atievxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\EmEditor\emeditor.exe
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {54a08cb5-3c78-4553-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4553cfsb.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O3 - Toolbar: 5a94 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\47bdntos.dll
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [sdafdsafds] D;]XJOEPXT]ufnq]te265/fyf
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.icbc.com.cn
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://218.96.3.99/dana-cached/setup/NeoterisSetup.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gaocrystal.spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptig.dll
O21 - SSODL: WebSecurity - {3DD78ACF-0745-4532-94F8-A574457E1A81} - C:\WINDOWS\system32\PvSec.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe


So, what's next? :)

Hope you are having a nice weekend,

Markus
Hi Markus,

The conime.exe file is probably fine and is related to your asian language settings. The other file is definitely bad. What concerns me is nothing seems to be getting fixed as we go along here. Either in normal or safe mode. Did you run HJT in safe mode on the last try? If so did it seem to run OK? Sometimes stubborn infections will re-appear if we don't get everything in one shot. And that may be the case here :scratch:

Let me do a little more research on this whole infection and perhaps have an expert look in on it too for me. Give me a little time and I'll get back to you with another set of instructions that will hopefully help us make some progress.

I'll get back to you as soon as I can.

Dave
Hi Dave, your little combofix tool f%&@-up my PC pretty badly. First I was already surprised how rudely it rebooted my PC (no ask to save open windows, no shutdown, only a black screen suddenly…) then during reboot, windows is started and during the wolcome window, I get a blue screen, dumping the physical memory to disk. Starting in Safe Mode worked. I tryed to get the combofix processes out of the Autostart, but still that didn't work. Then I ran a system repair from the windows XP installation disk. The repair finished, but no change. Only that the physical memory dump is getting bigger with each reboot (from 50 pages to 80 to over a 100 and so on). Right now I am trying to install XP new, without formatting. As I can't backup all my data to be able to format my disk. Good thing is, if this installation is successful, I got rid of most of the malware too. :) If that was your intention in the first place, why you didn't just say so :P If you have any other tip, would be glad if you could share that with me. Please understand that I most likely will not run combofix again. Wish you a better start into the new week then I have. Markus
Hi Markus, I apologize greatly for any issues that we may have caused here. Combofix is not my tool. It is a tool put together by one of the developers on these forums and has been in use for some time now. I have not ever seen any issues caused by simply running the tool. I have contacted the developer and asked him to take a look to see what's going on. I take what I do here pretty seriously and make it a priority to never do more harm then good. Do keep in mind that when working on computers that have serious issues, such as yours here, things can go wrong. This issue may have nothing to do with that tool and may or may not have occurred in any case. We will look into that. I will do whatever I can to help you get back up and running. Sometimes a format and re-install is the best way to go but I try to make that a last resort and only recommend it when I see a serious security breach from the start. Please give the developer some time to look things over and we'll get back to you. Again, sorry for any inconvenience that this has caused you. Regards, Dave
Hello Markus,

I have contacted the tool developer and he has taken a look at the situation. You have multiple infections on board. Most of them deploy Malware drivers. This is likely what's causing the problems. The Combofix was not the cause of your computer crash. I would appreciate it if you would post an apology to the developer sUBs here. We did not infect your computer, you have yourself to blame for that.

If you would still like some help with getting your computer back I'm willing to do that.

First, do you still have this folder:
c:\sUBs folder. It contains logs which may reveal what actually transpired. If it's still there, please archive it & upload to:
http://www.bleepingcomputer.com/submit-malware.php?channel=4

If you would still like help and can do this then:

Please download this tool > System Repair Engineer
  • Extract it to it's own folder & double click SREng.exe to run it
  • Select 'Smart Scan' & tick "Verify Digital Signatures"
  • Click on the [Scan] button
  • When finished, click on the [Save Reports] button & save the log to Desktop
  • Attach the log in your next reply. Dont post it.
Note: You may have to rename SREngLog.log to SREngLog.txt before attaching.

Let us know what you would like to do.
Regards,
Dave
Hi Dave, I know that you and all here are taking this very seriously. And I appreciate your help greatly. I am sorry if you or the developers of combofix got the impression that I blame you for anything that happened. I don't and I know that things can go wrong and do. I hope that my feedback of the behavior will help to improve the software and will help with other similar cases. I will run the tool later as I am little busy now. After reinstalling XP, my PC runs for now normal but I am still not sure if all the infections have been deleted by the re-installation. Actually I doubt it as they have proven to be quite resistant. I will get back to you as soon as I can. Again, my apologizes and thank you very much for all the help. Cheers, Markus
Hi,
after reading the last reply again I could write a looooong answer. But I will leave it to that. Playing around with an infected system, especially one as mine was (hopefully was) can generate results which are not predictable. And I most certainly would not blame anybody for what had happened. End of story. There's a good old saying… %^&$ happens… ;)

Ok, back to the actual problem. I am sorry, I don't have the sUBs folder anymore. Searched the whole hard disk but couldn't find it. Must have deleted it when I cleaned out the disk. To bad that I saw that part of the post too late. Would have been happy to help to understand and prevent that from happening to others.

So here is the scan from SREng.exe:

2007-01-30,19:19:37

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 2 (Build 2600)
 - Administrative User - Completed Functions Allowed

Follow item(s) have been choosed:
	All Boot Items (Including Registry, Startup Folders, Services and so on)
	Browser Add-ons
	Runing Processes (Including process model information)
	File Associations
	Winsock Provider
	Autorun.Inf
	HOSTS File


Boot Items
Registry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
	  [(Verified)Microsoft Corporation]
	  [(Verified)Safer Networking Limited]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
	<>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
	<"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
	  [(Verified)Microsoft Corporation]
	  [(Verified)Microsoft Corporation]
	<"C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe">  [(Verified)Computer Associates International, Inc.]
	<"C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe">  [(Verified)Computer Associates International, Inc.]
	<"C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe">  [(Verified)Computer Associates International, Inc.]
	<"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe">  [(Verified)Zone Labs, LLC]
	  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
	  [(Verified)Microsoft Corporation]
	  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
	<>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
	  [(Verified)Microsoft Corporation]

==================================
Startup Folders
N/A

==================================
Services
[CAISafe / CAISafe][Running/Auto Start]
  
[Human Interface Device Access / HidServ][Stopped/Disabled]
  %SystemRoot%\System32\hidserv.dll>
[VET Message Service / VETMSGNT][Running/Auto Start]
  
[TrueVector Internet Monitor / vsmon][Stopped/Auto Start]
  

==================================
Drivers
[atimtai / atimtai][Running/Manual Start]
  
[ESS Maestro 3 Audio Driver (WDM) / maestro][Running/Manual Start]
  
[Direct Parallel Link Driver / Ptilink][Running/Manual Start]
  
[Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver / rtl8139][Running/Manual Start]
  
[Secdrv / Secdrv][Stopped/Manual Start]
  
[SMC IrCC Miniport Device Driver / SMCIRDA][Running/Manual Start]
  
[srescan / srescan][Running/Boot Start]
  <\SystemRoot\system32\ZoneLabs\srescan.sys>
[uigxrdr / uigxrdr][Running/System Start]
  
[vsdatant / vsdatant][Running/System Start]
  

==================================
Browser Add-ons
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} 
[]
  {53707962-6F74-2D53-2644-206D7942484F} 
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} 
[&Recherchieren;]
  {92780B25-18CC-41C8-B9BE-3C9C571A8263} 
[]
  {e2e2dd38-d088-4134-82b7-f2ba38496583} <%windir%\Network Diagnostic\xpnetdiag.exe, N/A>
[Messenger]
  {FB5F1910-F110-11d2-BB9E-00C04F795683} 
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} 
[Java Plug-in 1.4.2_04]
  {8AD9C840-044E-11D1-B3E9-00805F499D93} 
[Java Plug-in 1.4.2_04]
  {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} 
[AcroIEHlprObj Class]
  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} 
[Microsoft Office Control]
  {4453D895-F2A1-4A38-A285-1EF9BD3F6D5D} 
[]
  {53707962-6F74-2D53-2644-206D7942484F} 
[WUWebControl Class]
  {6414512B-B978-451D-A0D8-FCFDF33E833C} 
[Windows Live Sign-in Helper]
  {9030D464-4C02-4ABF-8ECC-5164760863C6} 
[Shockwave Flash Object]
  {D27CDB6E-AE6D-11CF-96B8-444553540000} 
[Nach Microsoft &Excel; exportieren]
  

==================================
Running Processes
[PID: 1636][\SystemRoot\System32\smss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1912][\??\C:\WINDOWS\system32\csrss.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 592][\??\C:\WINDOWS\system32\winlogon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 760][C:\WINDOWS\system32\services.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 820][C:\WINDOWS\system32\lsass.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 1408][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1616][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 2024][C:\WINDOWS\System32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 516][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 1124][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 1248][C:\WINDOWS\Explorer.EXE]  [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
	[C:\WINDOWS\System32\uigxnp.dll]  [GMX GmbH, 2.0.332]
	[C:\WINDOWS\system32\l3codeca.acm]  [Fraunhofer Institut Integrierte Schaltungen IIS, 1, 9, 0, 0305]
	[C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
	[C:\Program Files\GMX\GMX Upload-Manager\SHNDLERS.DLL]  [GMX GmbH, 2.0.332]
	[C:\Program Files\WinRAR\rarext.dll]  [N/A, N/A]
	[C:\PROGRA~1\Filzip\fzshext.dll]  [, 3.0.1.45]
	[C:\Program Files\EmEditor\emedshl.dll]  [N/A, N/A]
	[C:\WINDOWS\avshlext.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll]  [Adobe Systems Incorporated, 6.0.0.2003051500]
	[C:\PROGRA~1\SPYBOT~1\SDHelper.dll]  [Safer Networking Limited, 1, 4, 0, 0]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 1428][C:\WINDOWS\system32\spoolsv.exe]  [Microsoft Corporation, 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)]
	[C:\WINDOWS\system32\mdimon.dll]  [Microsoft Corporation, 11.3.1897.0]
	[C:\WINDOWS\System32\spool\PRTPROCS\W32X86\mdippr.dll]  [Microsoft Corporation, 11.3.1897.0]
[PID: 1336][C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe]  [Computer Associates International, Inc., Version 2.0.1.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\CaLic.dll]  [Computer Associates International, Inc., Version 2.0.1.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\CAISSFrm.dll]  [Computer Associates International, Inc., Version 2.0.1.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\caISSProd.dll]  [Computer Associates International, Inc., 2.0.1.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\caISSRes.dll]  [Computer Associates International, Inc., Version 2.0.1.0]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 1188][C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVScan.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\DriverIf.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVFrm.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\iSafProd.dll]  [Computer Associates International, Inc., Version 12.0.0.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\EZAVLic.dll]  [Computer Associates International, Inc., Version 2.0.1.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVProd.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVres.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
[PID: 1516][C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVFrm.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVProd.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVres.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
[PID: 1776][C:\WINDOWS\system32\ctfmon.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
[PID: 1888][C:\Program Files\GMX\GMX Upload-Manager\DAVSRV.EXE]  [GMX GmbH, 2.0.332]
	[C:\Program Files\GMX\GMX Upload-Manager\RootCom.dll]  [GMX GmbH, 2.0.332]
	[C:\Program Files\GMX\GMX Upload-Manager\BaseCom.dll]  [GMX GmbH, 2.0.332]
	[C:\Program Files\GMX\GMX Upload-Manager\SettingsUI.dll]  [GMX GmbH, 2.0.332]
	[C:\Program Files\GMX\GMX Upload-Manager\MFC71U.DLL]  [Microsoft Corporation, 7.10.3077.0]
	[C:\Program Files\GMX\GMX Upload-Manager\MSVCR71.dll]  [Microsoft Corporation, 7.10.3052.4]
	[C:\Program Files\GMX\GMX Upload-Manager\MSVCP71.dll]  [Microsoft Corporation, 7.10.3077.0]
	[C:\Program Files\GMX\GMX Upload-Manager\Update.dll]  [GMX GmbH, 2.0.332]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
	[C:\WINDOWS\System32\uigxnp.dll]  [GMX GmbH, 2.0.332]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 328][C:\WINDOWS\system32\Atievxx.exe]  [Microsoft Corporation, 5.1.2482.0 (Lab01_N(ericks).010524-2202)]
[PID: 1688][C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafServ.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\iSafProd.dll]  [Computer Associates International, Inc., Version 12.0.0.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\Arclib.dll]  [Computer Associates International, Inc., 7.3.0.8]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafeEngine.dll]  [Computer Associates International, Inc., Version 30.4.1.0]
[PID: 492][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 1684][C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\DriverIf.dll]  [Computer Associates International, Inc., Version 7.1.6.0]
	[C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetNtMsg.dll]  [N/A, N/A]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\iSafProd.dll]  [Computer Associates International, Inc., Version 12.0.0.0]
[PID: 2956][C:\WINDOWS\System32\alg.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 1044][C:\Program Files\Mozilla Firefox\firefox.exe]  [Mozilla Corporation, 1.8.1.1: 2006120418]
	[C:\Program Files\Mozilla Firefox\js3250.dll]  [Netscape Communications Corporation, 4.0]
	[C:\Program Files\Mozilla Firefox\nspr4.dll]  [Netscape Communications Corporation, 4.6.4]
	[C:\Program Files\Mozilla Firefox\xpcom_core.dll]  [Mozilla Foundation, 1.8.1.1: 2006120418]
	[C:\Program Files\Mozilla Firefox\plc4.dll]  [Netscape Communications Corporation, 4.6.4]
	[C:\Program Files\Mozilla Firefox\plds4.dll]  [Netscape Communications Corporation, 4.6.4]
	[C:\Program Files\Mozilla Firefox\smime3.dll]  [Mozilla Foundation, 3.11.4 Basic ECC]
	[C:\Program Files\Mozilla Firefox\nss3.dll]  [Mozilla Foundation, 3.11.4 Basic ECC]
	[C:\Program Files\Mozilla Firefox\softokn3.dll]  [Mozilla Foundation, 3.11.4 Basic ECC]
	[C:\Program Files\Mozilla Firefox\ssl3.dll]  [Mozilla Foundation, 3.11.4 Basic ECC]
	[C:\Program Files\Mozilla Firefox\xpcom_compat.dll]  [Mozilla Foundation, 1.8.1.1: 2006120418]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
	[C:\Program Files\Mozilla Firefox\components\myspell.dll]  [Mozilla Foundation, 1.8.1.1: 2006120418]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\Program Files\Mozilla Firefox\components\jar50.dll]  [Mozilla Foundation, 1.8.1.1: 2006120418]
	[C:\PROGRA~1\MOZILL~1\extensions\[removed]\components\qfaservices.dll]  [Mozilla Foundation, 1.8.1.1: 2006120418]
	[C:\PROGRA~1\MOZILL~1\extensions\[removed]\components\FULLSOFT.DLL]  [Full Circle Software, Inc., 2.2.unofficial]
	[C:\Program Files\Mozilla Firefox\freebl3.dll]  [Mozilla Foundation, 3.11.4 Basic ECC]
	[C:\Program Files\Mozilla Firefox\nssckbi.dll]  [Mozilla Foundation, 1.62]
	[C:\Program Files\Mozilla Firefox\components\spellchk.dll]  [Mozilla Foundation, 1.8.1.1: 2006120418]
	[C:\WINDOWS\System32\uigxnp.dll]  [GMX GmbH, 2.0.332]
[PID: 2396][C:\WINDOWS\system32\svchost.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
[PID: 2604][C:\Program Files\BitComet\BitComet.exe]  [www.BitComet.com, 0.63.]
	[C:\Program Files\BitComet\dbghelp.dll]  [Microsoft Corporation, 6.3.0011.3 (DbgBuild.040120-1256)]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\WMVCore.DLL]  [Microsoft Corporation, 9.00.00.3265 (xpsp_sp2_qfe.061206-2330)]
	[C:\WINDOWS\system32\msdmo.dll]  [N/A, N/A]
[PID: 384][C:\WINDOWS\system32\conime.exe]  [Microsoft Corporation, 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
[PID: 3440][C:\Program Files\eMule.de\emule.exe]  [http://www.emule-project.net, 0.46.2 Unicode]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
	[C:\Program Files\eMule.de\lang\de_DE.dll]  [http://www.emule-project.net, 0.46.2]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
[PID: 2652][C:\sreng2\SREng.EXE]  [Smallfrogs Studio, 2.3.13.690]
	[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll]  [GMX GmbH, 2.0.332]
	[C:\WINDOWS\system32\VetRedir.dll]  [Computer Associates International, Inc., Version 8.0.5.0]
	[C:\WINDOWS\system32\ISafeIf.dll]  [Computer Associates International, Inc., Version 8.0.5.0]

==================================
File Associations
.TXT  Error. [emeditor.txt]
.EXE  OK. ["%1" %*]
.COM  OK. ["%1" %*]
.PIF  OK. ["%1" %*]
.REG  OK. [regedit.exe "%1"]
.BAT  OK. ["%1" %*]
.SCR  OK. ["%1" /S]
.CHM  OK. ["C:\WINDOWS\hh.exe" %1]
.HLP  OK. [%SystemRoot%\System32\winhlp32.exe %1]
.INI  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.INF  OK. [%SystemRoot%\System32\NOTEPAD.EXE %1]
.VBS  OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.JS   OK. [%SystemRoot%\System32\WScript.exe "%1" %*]
.LNK  OK. [{00021401-0000-0000-C000-000000000046}]

==================================
Winsock Provider
CA ISafe LSP over [MSAFD Tcpip [TCP/IP]]
	C:\WINDOWS\system32\VetRedir.dll(Computer Associates International, Inc., CA ISafe LSP DLL)
CA ISafe LSP over [MSAFD Tcpip [UDP/IP]]
	C:\WINDOWS\system32\VetRedir.dll(Computer Associates International, Inc., CA ISafe LSP DLL)
CA ISafe LSP over [MSAFD Tcpip [RAW/IP]]
	C:\WINDOWS\system32\VetRedir.dll(Computer Associates International, Inc., CA ISafe LSP DLL)
CA ISafe LSP
	C:\WINDOWS\system32\VetRedir.dll(Computer Associates International, Inc., CA ISafe LSP DLL)

==================================
Autorun.Inf
[E:\]
[Autorun]
open=Iexplores.exe
[F:\]
[Autorun]
open=Iexplores.exe

==================================
HOSTS File
127.0.0.1	   localhost

==================================
API HOOK
N/A

==================================




OK, hope we can figure out now if all the malware is gone.

I have now installed the whole bunch of tools and helpers (zone alarm, spybot, ad-aware, still CA Antivirus). Even though they slow down my notebook a little. But I think that is the lesser evil. I have learned my lesson.

That brings me to my next question. Is it normal that lsass.exe is connecting to the internet. Zonealarm notified my once about it. I scanned the file with jotti but nothing was found.

Ok. Looking forward to hear from you and thanks in advance.

Markus

P.S.: One more thing, which free AV tool would you suggest and what are most of the people using here. My CA license will expire very soon and it didn't proof to be very effective either. So I am looking for something new. Any suggestion would be appreciated. THX
Hi Markus,

That brings me to my next question. Is it normal that lsass.exe is connecting to the internet. Zonealarm notified my once about it. I scanned the file with jotti but nothing was found.

This is from the Microsoft website regarding lsass.exe:

This is the local security authentication server, and it generates the process responsible for authenticating users for the Winlogon service. This process is performed by using authentication packages such as the default Msgina.dll. If authentication is successful, Lsass generates the user's access token, which is used to launch the initial shell. Other processes that the user initiates inherit this token.

So that would be a yes, it's normal.
———————————————-

P.S.: One more thing, which free AV tool would you suggest and what are most of the people using here. My CA license will expire very soon and it didn't proof to be very effective either. So I am looking for something new. Any suggestion would be appreciated. THX

I don't know what most of the people here use but personally I use AVG and Avast, both free versions. I use Avast now on my main 2 machines (I have 5 in my house) but still have AVG running on the "family" machines. Both are good in my opinion and do not use excessive system resources. I think Avast is a little more robust though in it's protection. Hope that helps.
———————————————–
I'll have a look through your System Repair Engineer log and get back to you.
———————————————–

How did you end up re-installing Windows? Did you do a full re-install with a format or a repair?

How are things running now?

Post a fresh HJT log and I'll take a look.

Regards,
Dave
Hi Markus,

A couple of notes from your System Repair Engineer log:

Drivers
[uigxrdr / uigxrdr][Running/System Start]


==================================
Running Processes
[PID: 1248][C:\WINDOWS\Explorer.EXE] [Microsoft Corporation, 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)]
[C:\Program Files\GMX\GMX Upload-Manager\ExplorerHook.dll] [GMX GmbH, 2.0.332]
[C:\WINDOWS\System32\uigxnp.dll] [GMX GmbH, 2.0.332]
[C:\Program Files\GMX\GMX Upload-Manager\SHNDLERS.DLL] [GMX GmbH, 2.0.332]

Have you any idea what GMX GmbH is? It may very well be legit. and all the info. I could find on the web was in German, which I cannot read obviously.

But these…not good.

Autorun.Inf
[E:\]
[Autorun]
open=Iexplores.exe
[F:\]
[Autorun]
open=Iexplores.exe

Looks like your flash drives are infected. Here is a link with some info. on this.
http://www3.ca.com/securityadvisor/virusin…s.aspx?id=47709

Regards,
Dave

NOTE: Thank you to sUBs for all the support and help on this fix up to now. We appreciate it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI