Author Topic: Another day, another person infected with Win32:BHO-KD  (Read 13761 times)

0 Members and 3 Guests are viewing this topic.

SilentAngel

  • Guest
Another day, another person infected with Win32:BHO-KD
« on: January 03, 2008, 12:30:39 PM »
Except the infected file is different from everyone elses. :(
I can't delete the file in question, it gets detected by Avast, but can't delete, can't move to chest, can't move, or anything - access denied. The only thing I can do is ignore it. The file in question is datacle.dll
I'm not very tech savvy but I want to get rid of this thing. Thanks for any help in advance.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Another day, another person infected with Win32:BHO-KD
« Reply #1 on: January 03, 2008, 12:32:04 PM »
Are you using Windows XP?
Can you schedule a boot-time scanning?

Click on the Menu button.
Choose Schedule Boot Time Scan.
Doing so displays a dialog allowing you to schedule virus scanning.
Check Archives, if you want scan all the archives.
Specify whether all the disks or just a specific folder should be scanned.
Select Advanced options for scheduling details.
Select how to automatically process infected files.
Choose how to automatically process infected system files.
Click the Schedule button to confirm the settings.

If infected files are found, it's safer to send them to Chest instead of deleting them.
This way you can further analysis them.
The best things in life are free.

SilentAngel

  • Guest
Re: Another day, another person infected with Win32:BHO-KD
« Reply #2 on: January 03, 2008, 12:41:55 PM »
Just tried that, and I got 'access denied' again - I cannot move it, delete it or anything - forced to 'ignore' it.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Another day, another person infected with Win32:BHO-KD
« Reply #3 on: January 03, 2008, 12:46:24 PM »
Can you say what is the infected file name, where was it found (C:\windows\system32\infected-file-name.xxx)?
What avast! version and virus database are you using? (see About dialog of avast!)
The best things in life are free.

SilentAngel

  • Guest
Re: Another day, another person infected with Win32:BHO-KD
« Reply #4 on: January 03, 2008, 12:52:35 PM »
C:\windows\system32\datacle.dll is the infected file.

My Avast version is 4.7 Home Edition, database file version 080103-0 (January 3 '08)

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Another day, another person infected with Win32:BHO-KD
« Reply #5 on: January 03, 2008, 12:57:13 PM »
So, you're saying that in boot time scanning the file is not allowed to be accessed?

I suggest:

1. Disable System Restore and reenable it after step 2.
2. Test your machine with anti-rootkit applications. I suggest AVG or Trend Micro RootkitBuster.

Please, post the results.
The best things in life are free.

SilentAngel

  • Guest
Re: Another day, another person infected with Win32:BHO-KD
« Reply #6 on: January 03, 2008, 12:59:59 PM »
I can scan the file, and it shows up that its infected - but when I try to move it to the chest, or move it, or delete it, it says 'access denied'.

I'll try your next suggestion.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Another day, another person infected with Win32:BHO-KD
« Reply #7 on: January 03, 2008, 01:04:30 PM »
I can scan the file
I'm not saying scanning just this file, but I'm talking about boot time scanning? Did you schedule it and run?
The best things in life are free.

SilentAngel

  • Guest
Re: Another day, another person infected with Win32:BHO-KD
« Reply #8 on: January 03, 2008, 01:28:37 PM »
Yep I did perform a boot time scan - and I was still unable to move or otherwise do anything with the infected file when it was detected. My apologies for being unclear - it's kind of late here. :-[

I performed the anti-rootkit scan with AVG and it detected no rootkits installed.

Edit: Its almost midnight here, so I'm off to sleep. I'll check this thread when I wake up, thanks again for your help in advance. :)
« Last Edit: January 03, 2008, 01:40:02 PM by SilentAngel »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Another day, another person infected with Win32:BHO-KD
« Reply #9 on: January 03, 2008, 01:54:55 PM »
Why avast can't have full access at boot time? This is my doubt... hope they can help us.
The best things in life are free.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11652
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Another day, another person infected with Win32:BHO-KD
« Reply #10 on: January 03, 2008, 03:08:29 PM »
When trying the Delete button, did you check the "If necessary, delete the file during next boot" box?
That should work...

Thanks
If at first you don't succeed, then skydiving's not for you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Another day, another person infected with Win32:BHO-KD
« Reply #11 on: January 03, 2008, 05:50:10 PM »
Why avast can't have full access at boot time? This is my doubt... hope they can help us.
Vlk, and so? ???
The best things in life are free.

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11652
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: Another day, another person infected with Win32:BHO-KD
« Reply #12 on: January 03, 2008, 08:16:25 PM »
SilentAngel , You can also attach the boot time scan log file, C:\Program Files\ALWIL Software\Avast4\Data\Log\aswBoot.log ;)
If at first you don't succeed, then skydiving's not for you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Another day, another person infected with Win32:BHO-KD
« Reply #13 on: January 03, 2008, 08:39:30 PM »
Why avast can't have full access at boot time? This is my doubt... hope they can help us.
Vlk, and so? ???
I'm talking to myself...
The best things in life are free.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Another day, another person infected with Win32:BHO-KD
« Reply #14 on: January 03, 2008, 08:41:54 PM »
Why avast can't have full access at boot time? This is my doubt... hope they can help us.
I'm talking to myself...

Would seem so....