Unsolved

This post is more than 5 years old

68 Posts

8309

April 12th, 2008 21:00

Virus - Obfustat.ADXW

Hello,

 

My computer lost it's IP address a while back.  A nice Dell Forum support person helped me solve the problem.  Now that I am back online, my AVG anti-virus software just found this virus right after I installed AVG and ran the update:

 

C:\WINDOWS\system32\colbactd.dll

Virus identified Obfustat.ADXW

 

Can someone help me get rid of it, please?   AVG has a "Heal" function.  Everytime I clicked "Heal" I get a message that says it is successful, but seconds later it pops back up on my computer, again and again for about three, four times.  I have not used my Internet to surf yet and not until I have this problem resolved.  I am using my second computer that you helped me fixed just last month.

 

Thank you very much, I truly appreciate what you do.

 

Intel OptipleX GX270
Intel Pentium 4 CPU 2.4Ghz   2.39GHz
1.00GB Ram
Intel® Pro/1000MT Network Connection
Verizon GT704WG Wireless Modem/Router

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

April 12th, 2008 22:00

first off, please double-check the spelling of that file name:

are you sure it ends with a 'd', colbactd ???

or is it simply colbact   (without the 'd')

 

the latter file, without the 'd', is a module associated with COM Services, from Microsoft Corporation.  

So if AVG is picking up on it, it may well be another FP (False positive) by AVG.

 

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

April 12th, 2008 23:00

I agree.

 

AVG has reportedly a reputation for other false positive Obfustat detections in the past:
http://forums.hexus.net/help-technical-advisory/112716-unknown-virus-obfustat-vg-avg-2.html

 

You might want to get a second-opinion online antimalware scan from ESET Online Scanner:
http://www.eset.com/onlinescan/
Allow it to remove anything it detects.

68 Posts

April 13th, 2008 00:00

THANK YOU FOR HELPING.

 

I know AVG message looked funny with the "d" but that was what it showed.  I actually went online trying to google it, Google came back asking the same question.

 

I opened Window Task Manager just to see what was running because the computer scanned 265 filed in 18 minutes when I tried to run AVG.  Anyway, explorer.exe was using 95 - 99% of the CPU (at the time I had already unplugged the ethernet cable).  I worry that I will not be able to run the onlinescan as you suggested because of it.  The computer is running extremely sluggish.  Should I try anyway?

 

An odd thing about my firewall happened on the lower right hand corner, I kept on getting a message to turn on my "firewall" in Window Security Center.  I know in the past I just turn it on and off, but this time, the message says:

 

Windows Firewall

Windows firewall settings cannot be displayed because the associated service is not running.  Do you want to start the Windows Firewall/Internet Connection Sharing (ICS) service?

 

I have two choices, yes or no, the "X" on the upper right hand corner is grayed out.  I am afraid to click either, how do you suggest I handle this?  Can I just turn off my computer instead?

 

I also got an AVG anti-spyware 7.5 exception:

 

Something bad happened in the application.  Error diagnostic file saved to 'C:\program files\Grisfot\AVG Anti-spyware 7.5\guard.err

 

Here is the error message:

 

//== ===================================
Exception code: C0000005 ACCESS_VIOLATION
Fault address:  004030A0 01:000020A0 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Module Date:    05/30/2007 04:55:10
File Version of C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe: 7.5.1.36
Exception Date: 04/12/2008 17:17:56

MiniDump Information Saved to C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.dmp

Registers:
EAX:00000000
EBX:03B1FEF4
ECX:00000000
EDX:03A20000
ESI:00000000
EDI:03B1FEC6
CS:EIP:001B:004030A0
SS:ESP:0023:03B1FA70  EBP:03B1FED0
DS:0023  ES:0023  FS:003B  GS:0000
Flags:00010246

Intel specific method

Call stack:
Address   Frame     Param 0   Param 1   Param 2   Param 3   Logical addr   Module
004030A0  03B1FED0  03B1FEF4  0044A888  00000090  0386FFA0  0001:000020A0  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

ImageHelp specific method

Call stack:
Address   Frame     Param 0   Param 1   Param 2   Param 3   Symbol/Logical address
004030A0  03B1FED0  03B1FEF4  0044A888  00000090  0386FFA0  0001:000020A0 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

Loaded Modules:
Base       Size     Module
00400000   04E000   7.05.0001.0036      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
7C900000   0B0000   5.01.2600.2180      C:\WINDOWS\system32\ntdll.dll
7C800000   0F5000   5.01.2600.3119      C:\WINDOWS\system32\kernel32.dll
10000000   0DE000   4.02.0000.0019      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll
76780000   009000   6.00.2900.2180      C:\WINDOWS\system32\SHFOLDER.dll
77C10000   058000   7.00.2600.2180      C:\WINDOWS\system32\msvcrt.dll
77DD0000   09B000   5.01.2600.2180      C:\WINDOWS\system32\ADVAPI32.dll
77E70000   092000   5.01.2600.3173      C:\WINDOWS\system32\RPCRT4.dll
77FE0000   011000   5.01.2600.2180      C:\WINDOWS\system32\Secur32.dll
77F60000   076000   6.00.2900.3231      C:\WINDOWS\system32\SHLWAPI.dll
77F10000   047000   5.01.2600.3316      C:\WINDOWS\system32\GDI32.dll
7E410000   090000   5.01.2600.3099      C:\WINDOWS\system32\USER32.dll
76B40000   02D000   5.01.2600.2180      C:\WINDOWS\system32\WINMM.dll
76BF0000   00B000   5.01.2600.2180      C:\WINDOWS\system32\PSAPI.DLL
77C00000   008000   5.01.2600.2180      C:\WINDOWS\system32\VERSION.dll
76D60000   019000   5.01.2600.2912      C:\WINDOWS\system32\iphlpapi.dll
71AB0000   017000   5.01.2600.2180      C:\WINDOWS\system32\WS2_32.dll
71AA0000   008000   5.01.2600.2180      C:\WINDOWS\system32\WS2HELP.dll
774E0000   13D000   5.01.2600.2726      C:\WINDOWS\system32\ole32.dll
77120000   08B000   5.01.2600.3266      C:\WINDOWS\system32\OLEAUT32.dll
76390000   01D000   5.01.2600.2180      C:\WINDOWS\system32\IMM32.DLL
773D0000   103000   5.82.2900.2982      C:\WINDOWS\system32\comctl32.dll
5D090000   09A000   5.82.2900.2982      C:\WINDOWS\system32\comctl32.dll
77690000   021000   5.01.2600.2180      C:\WINDOWS\system32\NTMARTA.DLL
76F60000   02C000   5.01.2600.2180      C:\WINDOWS\system32\WLDAP32.dll
71BF0000   013000   5.01.2600.2180      C:\WINDOWS\system32\SAMLIB.dll
59A60000   0A1000   5.01.2600.2180      C:\WINDOWS\system32\DBGHELP.DLL

//== ===================================
Exception code: C0000005 ACCESS_VIOLATION
Fault address:  004030A0 01:000020A0 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Module Date:    05/30/2007 04:55:10
File Version of C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe: 7.5.1.36
Exception Date: 04/12/2008 17:39:40

MiniDump Information Saved to C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.dmp

Registers:
EAX:00000000
EBX:0396FEF4
ECX:00000000
EDX:007C4004
ESI:00000000
EDI:0396FEC6
CS:EIP:001B:004030A0
SS:ESP:0023:0396FA70  EBP:0396FED0
DS:0023  ES:0023  FS:003B  GS:0000
Flags:00010246

Intel specific method

Call stack:
Address   Frame     Param 0   Param 1   Param 2   Param 3   Logical addr   Module
004030A0  0396FED0  0396FEF4  0044A888  00000100  0386FFA0  0001:000020A0  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

ImageHelp specific method

Call stack:
Address   Frame     Param 0   Param 1   Param 2   Param 3   Symbol/Logical address
004030A0  0396FED0  0396FEF4  0044A888  00000100  0386FFA0  0001:000020A0 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

Loaded Modules:
Base       Size     Module
00400000   04E000   7.05.0001.0036      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
7C900000   0B0000   5.01.2600.2180      C:\WINDOWS\system32\ntdll.dll
7C800000   0F5000   5.01.2600.3119      C:\WINDOWS\system32\kernel32.dll
10000000   0DE000   4.02.0000.0019      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll
76780000   009000   6.00.2900.2180      C:\WINDOWS\system32\SHFOLDER.dll
77C10000   058000   7.00.2600.2180      C:\WINDOWS\system32\msvcrt.dll
77DD0000   09B000   5.01.2600.2180      C:\WINDOWS\system32\ADVAPI32.dll
77E70000   092000   5.01.2600.3173      C:\WINDOWS\system32\RPCRT4.dll
77FE0000   011000   5.01.2600.2180      C:\WINDOWS\system32\Secur32.dll
77F60000   076000   6.00.2900.3231      C:\WINDOWS\system32\SHLWAPI.dll
77F10000   047000   5.01.2600.3316      C:\WINDOWS\system32\GDI32.dll
7E410000   090000   5.01.2600.3099      C:\WINDOWS\system32\USER32.dll
76B40000   02D000   5.01.2600.2180      C:\WINDOWS\system32\WINMM.dll
76BF0000   00B000   5.01.2600.2180      C:\WINDOWS\system32\PSAPI.DLL
77C00000   008000   5.01.2600.2180      C:\WINDOWS\system32\VERSION.dll
76D60000   019000   5.01.2600.2912      C:\WINDOWS\system32\iphlpapi.dll
71AB0000   017000   5.01.2600.2180      C:\WINDOWS\system32\WS2_32.dll
71AA0000   008000   5.01.2600.2180      C:\WINDOWS\system32\WS2HELP.dll
774E0000   13D000   5.01.2600.2726      C:\WINDOWS\system32\ole32.dll
77120000   08B000   5.01.2600.3266      C:\WINDOWS\system32\OLEAUT32.dll
76390000   01D000   5.01.2600.2180      C:\WINDOWS\system32\IMM32.DLL
773D0000   103000   5.82.2900.2982      C:\WINDOWS\system32\comctl32.dll
5D090000   09A000   5.82.2900.2982      C:\WINDOWS\system32\comctl32.dll
77690000   021000   5.01.2600.2180      C:\WINDOWS\system32\NTMARTA.DLL
76F60000   02C000   5.01.2600.2180      C:\WINDOWS\system32\WLDAP32.dll
71BF0000   013000   5.01.2600.2180      C:\WINDOWS\system32\SAMLIB.dll
59A60000   0A1000   5.01.2600.2180      C:\WINDOWS\system32\DBGHELP.DLL

 

 

Many thanks.

68 Posts

April 13th, 2008 00:00

Thank you Joe53.

 

I will do as you suggested.

5 Journeyman

 • 

5.8K Posts

 • 

17.3K Points

April 13th, 2008 00:00

With all that going on, I suspect it is time for another Hijackthis log. I wouldn't try the online scanner, or even connect to the internet.

 

Transfer the HJT logfile to your good PC via a CD or USB memory stick, and post it in the HJT forum. You know the routine, I believe.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

April 13th, 2008 10:00

 "explorer.exe was using 95 - 99% of the CPU (at the time I had already unplugged the ethernet cable)."

 

we need to distinguish between explorer.exe --- which is WINDOWS Explorer ----

and iexplore.exe --- which is INTERNET Explorer.

 

Windows explorer can run at any time, without any internet (eithernet, wireless, modem) connection.

Internet explorer is what goes through the internet.

 

having said that, 95-99% CPU usage is high, even for [offline] windows explorer.

 

if I'm reading your HJT log correctly, the file colbactd.dll (with the 'd') represents a vundo/virtumonde infection.   Please wait for a response in the HJT forum for the best way to fix it... it's best not to try things on your own.    there are only two people "regularly" working that forum, plus a few "occasional" helpers, and some (supervised) "trainees"... [and ALL the "workers" there are volunteers]... so it may take a bit of time till they get to you.

5 Journeyman

 • 

15.6K Posts

 • 

45K Points

April 14th, 2008 10:00

ciwawa,

 

I see that BugBatter has picked up your log... you're in excellent hands now.

 

I'm hoping not to get yelled at for saying anything further, but it appears you've made a critical misinterpretation of the instructions there... and due to the potential severity, i can't just sit by idly and say nothing:

 

BugBatter instructed you to (temporarily) disable your AVG anti-spyware ;

and you replied to let her know that you were going to disable your AVG anti-virus.

 

Disabling the anti-virus will leave you open to immediate infection.  

Please carefully re-read her instructions, and make the appropriate adjustment.

Message Edited by ky331 on 04-14-2008 07:50 AM
No Events found!

Top