This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Just-in-time debugger popup / MalwareBytes full scan crashes

8 min read

This thread's last reply is from July 5, 2010, 12:17 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hi -- I started getting the Just-in-time debuggng popups which I am pretty sure is not the genuine thing, it is malware. MalwareBytes full scan crashes after about 45 mins -- blue screen of death. Hijack This log file below. Any help will be much appreciated!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:30 AM, on 7/4/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\ibmpmsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\mfevtps.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\rpcnet.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\TPHDEXLG.exe
C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe
C:\WINNT\System32\SrvAny.exe
C:\WINNT\System32\SrvAny.exe
C:\WINNT\System32\SrvAny.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINNT\System32\SrvAny.exe
C:\WINNT\System32\SrvAny.exe
C:\WINNT\System32\SrvAny.exe
C:\WINNT\System32\SrvAny.exe
C:\WINNT\system32\CCM\CcmExec.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
C:\Program Files\McAfee\Host Intrusion Prevention\FireTray.exe
C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe
C:\Program Files\DeltaCrypt\DUSKWatch\DUSKWatch.exe
C:\Program Files\DeltaCrypt\DUSKWatch\DUSKWatch.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
C:\WINNT\system32\hkcmd.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINNT\system32\TpShocks.exe
C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\BainUtil\Shutdown\BainShutdown.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\Copernic Desktop Search 2 - Corporate Edition\DesktopSearchService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\BainApps\Bulletins\BainBulletins.exe
C:\WINNT\system32\wbem\wmiapsrv.exe
C:\WinNT\BainUtil\MapDrives.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bain.com/remotehome/default3.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ViewerHelper Class - {78104A01-8E71-4F30-9A36-3793799615B4} - C:\Program Files\Bain & Company, Inc\Rights Management Add-on\RMAFilt.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [TrackPointSrv] C:\Program Files\Lenovo\TrackPoint\tp4serv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [_MapDrives] Run.vbs /c:"C:\WinNT\BainUtil\MapDrives.exe" /d:90 /w:No
O4 - HKLM\..\Run: [_Communicator] Run.vbs /c:"C:\Program Files\Microsoft Office Communicator\Communicator.exe" /p:"/FromRunKey" /d:30 /w:No
O4 - HKLM\..\Run: [_Copernic] Run.vbs /c:"C:\Program Files\Copernic Desktop Search 2 - Corporate Edition\DesktopSearchService.exe" /p:"/Tray" /d:10 /w:No
O4 - HKLM\..\Run: [_BainBulletins] Run.vbs /c:"C:\Program Files\BainApps\Bulletins\BainBulletins.exe" /d:60 /w:No
O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a
O4 - HKLM\..\Run: [RDVCHG] "C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PrnStatusMX] C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Communicator] Services.exe (This is a placeholder to keep Communicator from repairing itself)
O4 - HKLM\..\Run: [Rjopigibavu] rundll32.exe "C:\WINNT\axuyeguwiviyi.dll",Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [BainShutdown] C:\WINNT\BainUtil\Shutdown\BainShutdown.exe SysTray
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [{251229BC-B803-5DD3-6337-C730609C27A6}] "C:\Users\29KSA\Application Data\Zuru\evdar.exe"
O4 - Global Startup: Symantec NetBackup Desktop Agent.lnk = C:\Program Files\Symantec\NetBackup DLO\DLO\DLOClientu.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: (no name) - {685ec120-f786-4498-a8f0-794d47916161} - C:\Program Files\Bain & Company, Inc\Rights Management Add-on\RMAFilt.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Bain & Company, Inc\Rights Management Add-on\RMARes.dll,-40971 - {685ec120-f786-4498-a8f0-794d47916161} - C:\Program Files\Bain & Company, Inc\Rights Management Add-on\RMAFilt.dll
O9 - Extra button: @C:\Program Files\Bain & Company, Inc\Rights Management Add-on\RMARes.dll,-205 - {aede78a6-42b6-4c3c-96eb-5ae6dbec4859} - C:\Program Files\Bain & Company, Inc\Rights Management Add-on\RMAFilt.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Bain & Company, Inc\Rights Management Add-on\RMARes.dll,-40970 - {aede78a6-42b6-4c3c-96eb-5ae6dbec4859} - C:\Program Files\Bain & Company, Inc\Rights Management Add-on\RMAFilt.dll
O9 - Extra button: (no name) - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINNT\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O14 - IERESET.INF: START_PAGE_URL=about:blank
O15 - Trusted Zone: *.alacra.com
O15 - Trusted Zone: http://*.alacra.com
O15 - Trusted Zone: *.bainsecure.com
O15 - Trusted Zone: http://*.bainsecure.com
O15 - Trusted Zone: *.bts.com
O15 - Trusted Zone: http://*.bts.com
O15 - Trusted Zone: *.ioma.com
O15 - Trusted Zone: http://*.ioma.com
O15 - Trusted Zone: *.rbb.com
O15 - Trusted Zone: http://*.rbb.com
O15 - Trusted Zone: *.reuters.com
O15 - Trusted Zone: http://*.reuters.com
O15 - Trusted Zone: *.sabrebts.com
O15 - Trusted Zone: http://*.sabrebts.com
O15 - Trusted Zone: *.thomsonib.com
O15 - Trusted Zone: http://*.thomsonib.com
O15 - Trusted Zone: *.webex.com
O15 - Trusted Zone: http://*.webex.com
O15 - Trusted Zone: *.alacra.com (HKLM)
O15 - Trusted Zone: http://*.alacra.com (HKLM)
O15 - Trusted Zone: *.bainsecure.com (HKLM)
O15 - Trusted Zone: http://*.bainsecure.com (HKLM)
O15 - Trusted Zone: *.bts.com (HKLM)
O15 - Trusted Zone: http://*.bts.com (HKLM)
O15 - Trusted Zone: *.ioma.com (HKLM)
O15 - Trusted Zone: http://*.ioma.com (HKLM)
O15 - Trusted Zone: *.lyrishq.net (HKLM)
O15 - Trusted Zone: http://*.lyrishq.net (HKLM)
O15 - Trusted Zone: *.rbb.com (HKLM)
O15 - Trusted Zone: http://*.rbb.com (HKLM)
O15 - Trusted Zone: *.reuters.com (HKLM)
O15 - Trusted Zone: http://*.reuters.com (HKLM)
O15 - Trusted Zone: *.sabrebts.com (HKLM)
O15 - Trusted Zone: http://*.sabrebts.com (HKLM)
O15 - Trusted Zone: *.thomsonib.com (HKLM)
O15 - Trusted Zone: http://*.thomsonib.com (HKLM)
O15 - Trusted Zone: *.up0.net (HKLM)
O15 - Trusted Zone: http://*.up0.net (HKLM)
O15 - Trusted Zone: *.webex.com (HKLM)
O15 - Trusted Zone: http://*.webex.com (HKLM)
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/60.10/uploader2.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
O16 - DPF: {62CEC9E0-3811-4C36-A94E-4F7565DCD23F} (DDSC Class) - http://corpmbbos1.bain.com/dashboard/msddsc.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = BAIN.COM
O17 - HKLM\Software\..\Telephony: DomainName = workstation.bain.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = BAIN.COM
O20 - Winlogon Notify: DWGina - C:\Program Files\DeltaCrypt\DUSKWatch\DUSKWatch.dll
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: McAfee Host Intrusion Prevention Service (enterceptAgent) - McAfee, Inc. - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HIPSCore Service (hips) - McAfee, Inc. - C:\Program Files\McAfee\Host Intrusion Prevention\HIPSCore\HIPSvc.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINNT\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Engine Service (McAfeeEngineService) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\WINNT\system32\mfevtps.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote Procedure Call (RPC) Net (rpcnet) - Absolute Software Corp. - C:\WINNT\system32\rpcnet.exe
O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - SmithMicro Inc. - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINNT\System32\TPHDEXLG.exe
O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
O23 - Service: Symantec NetBackup Desktop Agent Change Journal Reader (VRTSChangeJournalReader) - Symantec Corporation - C:\Program Files\Symantec\NetBackup DLO\DLO\DLOChangeLogSvcu.exe
O23 - Service: _McAfee-ShStatEXE - Unknown owner - C:\WINNT\System32\SrvAny.exe
O23 - Service: _McAfee-UpdaterUI - Unknown owner - C:\WINNT\System32\SrvAny.exe
O23 - Service: _Microsoft-IMEKRMIG6.1 - Unknown owner - C:\WINNT\System32\SrvAny.exe
O23 - Service: _Microsoft-IMJPMIG8.1 - Unknown owner - C:\WINNT\System32\SrvAny.exe
O23 - Service: _Microsoft-MSPY2002 - Unknown owner - C:\WINNT\System32\SrvAny.exe
O23 - Service: _Microsoft-PHIME2002A - Unknown owner - C:\WINNT\System32\SrvAny.exe
O23 - Service: _Microsoft-PHIME2002ASync - Unknown owner - C:\WINNT\System32\SrvAny.exe

--
End of file - 15943 bytes
It appears this computer is a business computer, or a computer that is used for business, and it is part of a domain as well. As such, it may very likely have been connected to the domain's network while infected, therefore, presenting a risk to other computers connected to that same network.

The online anti-malware community primarily serves home users and is therefore not ideally suited to deal with situations that are best handled by a company's own IT department. All companies have their own set of policies and procedures for handling situations like this, all of which are beyond our sphere of knowledge. Therefore, as this computer has been identified as infected, you are strongly advised to immediately seek the assistance of your company's IT department so they may implement their preferred method for handling this situation.

In addition, there are data protection laws in many countries. If the machine is suspected of being "owned" or taken over by an outside force, and it has sensitive data stored on it, that could well be a reportable incident under data protection laws. For instance, it is possible that a machine could have credit card data, or other equally sensitive data, for hundreds or even thousands of customers of a business that would now be compromised.

As this issue involves either a company owned machine or a machine that is used for business purposes, it falls outside the scope of this forum. Therefore, this topic is now closed.

You can help support this site from this link :
Donations For Malware Removal