Today, AVG FREE detected the virus Trojan Horse BHO.IZO
in the following files:
"C:\System Volume Information\_restore{A7AC940B-0789-4D34-9930-4FB47791E0A9}\RP177\A0058946.dll
"C:\System Volume Information\_restore{A7AC940B-0789-4D34-9930-4FB47791E0A9}\RP177\A0058946.dll
"C:\System Volume Information\_restore{A7AC940B-0789-4D34-9930-4FB47791E0A9}\RP177\A0058948.dll
it was detected "on open" of process system root\system32\cidaemon.exe process ID 7624
Just like user "kuchi" said in his post, I can't find any info on this virus so I'm not sure what to do next.
please help!?
as suggested to user "kuchi" by "jpshortstuff" I've downloaded DDS.exe and I'm including this log.
__________________________________________________________________________
DDS.txt
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 17:32:15.12 on 19/06/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.376 [GMT -6:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\WINDOWS\system32\WTablet\Wacom_TabletUser.exe
C:\WINDOWS\system32\Wacom_Tablet.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\HDD Thermometer\HDD Thermometer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Michelle\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
mStart Page = about:blank
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {238D3403-0761-4B4D-851C-050A3A0AC40A} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [RSD_HDDThermo] c:\program files\hdd thermometer\HDD Thermometer.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\citrus~1.lnk - c:\program files\citrus alarm clock\Citrus Alarm Clock.exe
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
============= SERVICES / DRIVERS ===============
R1 atitray;atitray;c:\program files\radeon omega drivers\v3.8.252\ati tray tools\atitray.sys [2005-11-13 12032]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-2 325896]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-3-2 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-2 108552]
R1 GizmoDrv;Gizmo Virtual Drive Device Driver;c:\windows\system32\drivers\gizmodrv.sys [2008-1-24 16787]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-2 298776]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [2008-2-21 1373480]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?]
S1 SCPDFReadSpool;SolidConverterPDFReadSpool;c:\windows\installer\MSI3B.tmp [2009-5-16 189696]
S3 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-3-9 425080]
S3 jswimd;jswimd Service;c:\windows\system32\drivers\jswimd.sys –> c:\windows\system32\drivers\jswimd.sys [?]
S3 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2008-7-21 193888]
S3 UCharger;Energizer Usb Charger Driver;c:\windows\system32\drivers\UCharger.sys [2007-5-15 13765]
S4 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-4 98304]
S4 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\adobe\photoshop elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-4 118784]
=============== Created Last 30 ================
2009-06-10 00:41 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-06-10 00:41 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-06-10 00:41 1,985,024 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-06-10 00:41 11,064,832 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-06-07 21:10 –d—– C:\PerfLogs
2009-06-06 23:30 –d—– c:\windows\system32\custom matrices
2009-06-06 23:29 –d—– c:\windows\system32\QuickTime
2009-06-06 23:29 –d—– c:\windows\system32\C2MP
2009-06-05 04:35 –d—– c:\program files\ScreenPrint32 v3
2009-06-03 14:17 –d—– c:\program files\iPod
2009-06-03 14:16 –d—– c:\program files\iTunes
2009-05-28 10:51 3,554,816 a——- c:\windows\system32\ffdshow.ax
2009-05-28 10:41 4,472,538 a——- c:\windows\system32\libavcodec.dll
2009-05-27 19:56 –d—– c:\docume~1\michelle\applic~1\Flickr
2009-05-27 19:55 –d—– c:\program files\Flickr Uploadr
2009-05-26 17:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a——- c:\windows\system32\QuickTime.qts
2009-05-25 18:39 –d—– c:\documents and settings\michelle\.housecall6.6
2009-05-25 10:38 830,004 a——- c:\windows\system32\ff_x264.dll
2009-05-22 04:19 –d—– c:\docume~1\michelle\applic~1\MilkShape 3D 1.x.x
2009-05-21 07:27 210,944 a——- c:\windows\system32\Msvcrt10.dll
2009-05-21 07:27 152,848 a——- c:\windows\system32\Comdlg32.ocx
2009-05-21 07:27 –d—– c:\program files\Plugin Commander Light
2009-05-21 03:00 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2
==================== Find3M ====================
2009-06-05 04:35 73,216 a——- c:\windows\ST6UNST.EXE
2009-06-05 04:35 249,856 ——– c:\windows\Setup1.exe
2009-05-18 02:24 83,968 a——- c:\windows\system32\ac3config.exe
2009-05-17 17:37 557,469 a——- c:\windows\system32\libmplayer.dll
2009-05-17 05:28 410,984 a——- c:\windows\system32\deploytk.dll
2009-05-12 23:15 915,456 a——- c:\windows\system32\wininet.dll
2009-05-07 09:32 345,600 a——- c:\windows\system32\localspl.dll
2009-05-01 09:25 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-05-01 09:25 325,896 a——- c:\windows\system32\drivers\avgldx86.sys
2009-05-01 09:25 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-04-24 02:11 46,713,993 a——- c:\windows\system32\xa38872295.exe
2009-04-24 02:11 46,713,993 a——- c:\windows\system32\xa38863412.exe
2009-04-21 10:38 328,334 a——- c:\windows\system32\ff_kernelDeint.dll
2009-04-21 10:08 425,040 a——- c:\windows\system32\TomsMoComp_ff.dll
2009-04-21 09:54 146,098 a——- c:\windows\system32\libmpeg2_ff.dll
2009-04-21 09:52 828,029 a——- c:\windows\system32\xvidcore.dll
2009-04-17 06:26 1,847,168 a——- c:\windows\system32\win32k.sys
2009-04-15 08:51 585,216 a——- c:\windows\system32\rpcrt4.dll
2009-04-02 08:23 98,304 a——- c:\windows\system32\ff_wmv9.dll
2009-04-02 08:21 84,480 a——- c:\windows\system32\ff_vfw.dll
2008-02-19 02:02 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat
2007-03-21 13:31 272,109 a——- c:\program files\hdd_thermometer_v1.3.exe
2007-01-21 13:10 8 —shr– c:\windows\system32\A6EF669AEE.sys
============= FINISH: 17:33:28.44 ===============