Greetings:
My AVAST! boot scan detected the Win32:BHO-KD virus/worm in C:\windows\system32\dlcicubj.dll[upx]
After coming to the forum and reading many of the posts concerning this issue, I have downloaded ComboFix and HJT per the Oldman’s instructions to so many previous visitors. Pasted below is the ComboFix log file. HTJ shall follow under separate post. Additionally, I have not “fixed anything yet” via HTJ.
I look foward to your response and thank you in advance for your assistance.
Kind Regards,
CTBlax7
ComboFix 08-02-14.1 - Todd Breithaupt 2008-02-13 20:14:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1452 [GMT -7:00]
Running from: C:\Documents and Settings\Todd Breithaupt\Desktop\ComboFix.exe
- Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Todd Breithaupt\g2mdlhlpx.exe
C:\WINDOWS\system32\danimk.dll
C:\WINDOWS\system32\dlcicubj.dll
C:\WINDOWS\system32\drivers\opumrtny.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NOBCGEGH
-------\LEGACY_NZEDFFRQ
-------\nobcgegh
-------\nzedffrq
((((((((((((((((((((((((( Files Created from 2008-01-14 to 2008-02-14 )))))))))))))))))))))))))))))))
.
2008-02-13 16:38 . 2008-02-13 16:38 d-------- C:\Program Files\Alwil Software
2008-02-13 16:38 . 2007-12-04 06:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-02-13 16:38 . 2004-01-09 02:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-02-13 16:38 . 2007-12-04 05:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-02-13 16:38 . 2007-12-04 07:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-13 16:38 . 2007-12-04 07:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-13 16:38 . 2007-12-04 07:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-13 16:38 . 2007-12-04 07:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-13 16:38 . 2007-12-04 07:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-13 14:44 . 2008-02-13 15:53 d-------- C:\Program Files\Enigma Software Group
2008-02-13 14:16 . 2008-02-13 14:16 1,188,375 --a------ C:\WINDOWS\system32\libeay32.dll
2008-02-13 14:16 . 2008-02-13 14:16 741,632 --a------ C:\WINDOWS\system32\ktzdjndq.dat
2008-02-13 14:16 . 2008-02-13 14:16 246,545 --a------ C:\WINDOWS\system32\libssl32.dll
2008-02-13 14:16 . 2008-02-13 14:16 42,752 --a------ C:\WINDOWS\system32\lqqdlrtn.dat
2008-02-13 14:16 . 2008-02-13 14:16 36,608 --a------ C:\WINDOWS\system32\tagtcyib.dat
2008-02-13 14:16 . 2008-02-13 14:16 35,072 --a------ C:\WINDOWS\system32\ezmwzaiw.dat
2008-02-13 08:32 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-12 14:12 . 2008-02-12 14:12 120,576 --a------ C:\WINDOWS\system32\mwtreqzs.dat
2008-02-12 12:52 . 2008-02-12 14:30 d-------- C:\WINDOWS\system32\AppCert
2008-02-12 12:52 . 2008-02-13 09:00 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-12 12:52 . 2008-02-12 12:52 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-08 08:54 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2008-02-08 08:54 . 2004-08-03 23:07 59,264 --a------ C:\WINDOWS\system32\dllcache\usbaudio.sys
2008-02-08 08:54 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-02-08 08:54 . 2004-08-04 00:56 21,504 --a------ C:\WINDOWS\system32\dllcache\hidserv.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-14 03:17 --------- d-----w C:\Program Files\Dl_cats
2008-02-13 23:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-02-13 15:32 --------- d-----w C:\Program Files\Java
2008-02-10 17:11 --------- d-----w C:\Documents and Settings\Todd Breithaupt\Application Data\U3
2008-02-05 13:23 --------- d-----w C:\Program Files\FTP Commander
2007-12-18 19:05 --------- d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-18 19:03 --------- d-----w C:\Program Files\WinSCP
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“DellSupport”=“C:\Program Files\DellSupport\DSAgnt.exe” [2007-03-15 10:09 460784]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 09:24 1694208]
“GoToMeeting”=“C:\Program Files\Citrix\GoToMeeting\198\g2mstart.exe” [2007-08-17 09:13 31816]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 03:00 15360]
“tqi1kkfcf”=“C:\WINDOWS\system32\tqi1kkfcf.exe”
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2007-05-27 20:14 8429568]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 01:11 132496]
“RTHDCPL”=“RTHDCPL.EXE” [2007-06-13 18:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
“ISUSPM Startup”=“C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe” [2006-10-03 09:35 221184]
“ISUSScheduler”=“C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” [2006-10-03 09:37 81920]
“RoxWatchTray”=“C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe” [2006-11-05 09:22 221184]
“RoxioDragToDisc”=“C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe” [2006-08-17 07:00 1116920]
“PDVDDXSrv”=“C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe” [2006-10-20 15:23 118784]
“D-Link RangeBooster G WDA-2320”=“C:\Program Files\D-Link\RangeBooster G WDA-2320\AirPlusCFG.exe” [2005-12-15 11:21 2490368]
“ANIWZCS2Service”=“C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe” [2005-11-30 09:35 49152]
“DLCICATS”=“C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItime.dll” [2006-02-24 00:30 73728]
“dlcimon.exe”=“C:\Program Files\Dell AIO Printer 946\dlcimon.exe” [2006-02-13 12:26 430080]
“Acrobat Assistant 8.0”=“C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe” [2007-05-10 21:46 624248]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-06-29 05:24 286720]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 06:00 79224]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 20:05:26 29696]
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-02-16 17:40:52 6379080]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
appsecdll REG_EXPAND_SZ C:\WINDOWS\system32\AppCert\wsil32.dll
R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 08:35]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);“c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe” [2006-04-14 08:07]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2005-08-25 14:00]
R3 dlci_device;dlci_device;C:\WINDOWS\system32\dlcicoms.exe [2006-05-11 00:22]
S3 PNDIS5;PNDIS5 NDIS Protocol Driver;D:\PNDIS5.SYS
S3 SQLWriter;SQL Server VSS Writer;“c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe” [2006-04-14 08:04]
.
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-13 20:18:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Citrix\GoToMeeting\198\g2mcomm.exe
C:\Program Files\Citrix\GoToMeeting\198\g2mlauncher.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe
C:\Program Files\TechSmith\SnagIt 8\SnagPriv.exe
.
.
Completion time: 2008-02-13 20:19:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-14 03:19:25
.
2007-11-15 14:38:47 — E O F —