HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:33 AM, on 6/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dlbccoms.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\My Essentials\USB ME1001-USB\Wireless Utility\O-Maxwcui.exe
C:\WINDOWS\SYSTEM32\sistray.exe
C:\Program Files\Sprint music manager\MEMonitor.exe
C:\Documents and Settings\Kathy McDonald\Start Menu\Programs\Startup\userinit.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.dell4me.com/myway
O2 - BHO: (no name) - {5104FAD1-347A-4CBC-9D64-BCD52C8CC457} - C:\WINDOWS\system32\awtrPfcA.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: {977e31d4-196a-e76a-a804-2fc5b3f18cee} - {eec81f3b-5cf2-408a-a67e-a6914d13e779} - C:\WINDOWS\system32\ixacvmgx.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [44a46a1c] rundll32.exe "C:\WINDOWS\system32\mmmbmspn.dll",b
O4 - HKLM\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKLM\..\Run: [BM47975980] Rundll32.exe "C:\WINDOWS\system32\kaypbhce.dll",s
O4 - HKCU\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [winlogon] C:\Documents and Settings\LocalService\svchost.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [[system]] C:\WINDOWS\system32\drivers\services.exe (User 'Default user')
O4 - Startup: MEMonitor.lnk = C:\Program Files\Sprint music manager\MEMonitor.exe
O4 - Startup: userinit.exe
O4 - Global Startup: My Essentials Wireless USB Utility.lnk = C:\Program Files\My Essentials\USB ME1001-USB\Wireless Utility\O-Maxwcui.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\SYSTEM32\sistray.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) -
https://husqvarnaviking.webex.com/client/T23L/event/ieatgpc.cab
O20 - Winlogon Notify: usbmon - C:\WINDOWS\system32\usbmons.dll
O22 - SharedTaskScheduler: jhsf8d984jief8dsfus98jkefn - {C5AF49A2-94F3-42BD-F434-2604812C897D} - (no file)
O23 - Service: dlbc_device - - C:\WINDOWS\system32\dlbccoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O24 - Desktop Component 0: (no name) -
http://blstj.msn.com/br/voodoo/js/6/core.js
--
End of file - 5862 bytes
ComboFix Report:
ComboFix 08-06-20.4 - Kathy McDonald 2008-06-25 10:29:43.1 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.98 [GMT -6:00]
Running from: C:\Documents and Settings\Kathy McDonald\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM47975980.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\SYSTEM32\AcfPrtwa.ini
C:\WINDOWS\SYSTEM32\AcfPrtwa.ini2
C:\WINDOWS\system32\advpac.dll
C:\WINDOWS\system32\bmf.cs
C:\WINDOWS\system32\ccs.so
C:\WINDOWS\system32\ddcDtTnL.dll
C:\WINDOWS\system32\drivers\services.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\SYSTEM32\FLlUuBeg.ini2
C:\WINDOWS\system32\ho.ln
C:\WINDOWS\system32\ko.o
C:\WINDOWS\system32\mn.n
C:\WINDOWS\system32\npsmbmmm.ini
C:\WINDOWS\system32\nvrsma.dll
.
((((((((((((((((((((((((( Files Created from 2008-05-25 to 2008-06-25 )))))))))))))))))))))))))))))))
.
2008-06-24 16:54 . 2008-06-21 14:29 13,824 --a------ C:\Documents and Settings\Kathy McDonald\svchost.exe
2008-06-24 11:53 . 2008-06-24 12:02 1,584,898,827 --a------ C:\Documents and Settings\Kathy McDonald\My Documents.zip
2008-06-22 19:07 . 2008-06-22 19:07 86,528 --a------ C:\WINDOWS\SYSTEM32\mmmbmspn.dll
2008-06-22 19:04 . 2008-06-22 19:04 101,888 --a------ C:\WINDOWS\SYSTEM32\ixacvmgx.dll
2008-06-22 19:02 . 2008-06-22 19:02 95,232 --a------ C:\WINDOWS\SYSTEM32\kaypbhce.dll
2008-06-22 14:08 . 2008-06-21 14:29 13,824 --a------ C:\userinit.exe
2008-06-21 20:59 . 2008-06-22 19:13 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-21 20:59 . 2008-06-22 20:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-21 16:16 . 2008-06-21 16:16 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-21 16:16 . 2008-06-21 16:16 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-21 14:31 . 2008-06-22 13:35 13,824 --a------ C:\WINDOWS\SYSTEM32\idef.dll
2008-06-21 14:30 . 2008-06-21 14:30 0 --a------ C:\1151625907
2008-06-21 14:29 . 2008-06-21 14:29 66,048 --a------ C:\mxuxc.exe
2008-06-21 14:29 . 2008-06-25 10:38 62,384 --a------ C:\WINDOWS\SYSTEM32\pqasghjd.sys
2008-06-21 14:29 . 2008-06-21 14:29 13,824 --a------ C:\vwhfxvxv.exe
2008-06-21 14:29 . 2008-06-21 17:07 10,000 --a------ C:\WINDOWS\SYSTEM32\jfiehayd.dll
2008-06-21 14:29 . 2008-06-21 18:14 7,680 --a------ C:\kbvxxo.exe
2008-06-21 14:28 . 2008-06-21 17:07 41,984 --a------ C:\WINDOWS\mrofinu1535.exe
2008-06-10 19:09 . 2008-06-13 07:10 272,128 --------- C:\WINDOWS\SYSTEM32\DLLCACHE\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-22 20:05 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-08 23:22 --------- d-----w C:\Documents and Settings\Kathy McDonald\Application Data\MSN6
2008-05-21 01:47 --------- d-----w C:\Documents and Settings\Kathy McDonald\Application Data\Uniblue
2008-05-21 01:42 --------- d-----w C:\Program Files\AIM Toolbar
2008-05-21 01:40 --------- d-----w C:\Program Files\Viewpoint
2008-05-21 01:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-21 01:33 --------- d-----w C:\Program Files\Trend Micro
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-03 16:49 --------- d-----w C:\Program Files\Project64 1.6
.
C:\WINDOWS\system32\user32.dll ... is infected !! (additional data below)
577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
560,128 2004-06-17 17:58:35 C:\WINDOWS\$NtServicePackUninstall$\user32.dll
528,896 2002-11-01 22:26:46 C:\WINDOWS\$NtUninstallKB840987$\user32.dll
577,024 2004-08-04 07:56:46 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
577,024 2004-08-04 07:56:46 C:\WINDOWS\ServicePackFiles\i386\user32.dll
577,536 2008-06-21 20:29:49 C:\WINDOWS\SYSTEM32\user32.DLL
577,536 2008-06-21 20:29:49 C:\WINDOWS\SYSTEM32\DLLCACHE\user32.dll
------- Sigcheck -------
2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2004-06-17 11:58 560128 31fb2d788a9aa618452c02e8375b6dcd C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2002-11-01 16:26 528896 68e1f4ef02df52ca9c5e157045d23582 C:\WINDOWS\$NtUninstallKB840987$\user32.dll
2004-08-04 01:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2004-08-04 01:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\ServicePackFiles\i386\user32.dll
2008-06-21 14:29 577536 2384d63d6a86a75eb55d1a87f60e86c6 C:\WINDOWS\SYSTEM32\user32.DLL
2008-06-21 14:29 577536 2384d63d6a86a75eb55d1a87f60e86c6 C:\WINDOWS\SYSTEM32\DLLCACHE\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5104FAD1-347A-4CBC-9D64-BCD52C8CC457}]
C:\WINDOWS\system32\awtrPfcA.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{eec81f3b-5cf2-408a-a67e-a6914d13e779}]
2008-06-22 19:04 101888 --a------ C:\WINDOWS\system32\ixacvmgx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"[system]"="C:\WINDOWS\system32\drivers\services.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"winlogon"="C:\Documents and Settings\Kathy McDonald\svchost.exe" [2008-06-21 14:29 13824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"44a46a1c"="C:\WINDOWS\system32\mmmbmspn.dll" [2008-06-22 19:07 86528]
"[system]"="C:\WINDOWS\system32\drivers\services.exe" [ ]
"BM47975980"="C:\WINDOWS\system32\kaypbhce.dll" [2008-06-22 19:02 95232]
"winlogon"="C:\Documents and Settings\Kathy McDonald\svchost.exe" [2008-06-21 14:29 13824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"[system]"="C:\WINDOWS\system32\drivers\services.exe" [ ]
"winlogon"="C:\Documents and Settings\LocalService\svchost.exe" [ ]
C:\Documents and Settings\Kathy McDonald\Start Menu\Programs\Startup\
MEMonitor.lnk - C:\Program Files\Sprint music manager\MEMonitor.exe [2007-11-25 19:48:20 983040]
userinit.exe [2008-06-21 14:29:59 13824]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
My Essentials Wireless USB Utility.lnk - C:\Program Files\My Essentials\USB ME1001-USB\Wireless Utility\O-Maxwcui.exe [2006-09-11 20:02:00 1568768]
Utility Tray.lnk - C:\WINDOWS\SYSTEM32\sistray.exe [2004-07-14 09:15:04 335872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\usbmon]
C:\WINDOWS\system32\usbmons.dll 2008-05-21 21:49 0 C:\WINDOWS\SYSTEM32\usbmons.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^$McRebootA5E6DEAA56$.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\$McRebootA5E6DEAA56$.lnk
backup=C:\WINDOWS\pss\$McRebootA5E6DEAA56$.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2004-04-11 10:43 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2004-04-19 13:45 53248 c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
--a------ 2004-04-19 13:45 131072 C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2004-07-14 09:19 77824 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2004-07-14 09:19 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-11-10 12:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a------ 2003-08-19 00:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\WINDOWS\\SYSTEM32\\dlbccoms.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Documents and Settings\\Kathy McDonald\\My Documents\\Matt\\Games\\Nintendo\\nestc042\\NESTCL95.EXE"=
"C:\\Documents and Settings\\Kathy McDonald\\My Documents\\Matt\\Games\\Nintendo\\Nestopia137bin\\nestopia.exe"=
"C:\\Documents and Settings\\Kathy McDonald\\My Documents\\Matt\\Games\\gameboy\\VisualBoyAdvance\\VisualBoyAdvance [linker].exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27886:TCP"= 27886:TCP:Nestopia
"27886:UDP"= 27886:UDP:Nestopia
R2 dlbc_device;dlbc_device;C:\WINDOWS\system32\dlbccoms.exe [2007-02-07 16:26]
S3 OMAWGU(Belkin Corporation);My Essential G USB Adapter(Belkin Corporation);C:\WINDOWS\system32\DRIVERS\OMAWGU.sys [2006-08-04 01:55]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-25 10:36:40
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\rundll32.exe
C:\WINDOWS\SYSTEM32\rundll32.exe
C:\Documents and Settings\Kathy McDonald\Start Menu\Programs\Startup\userinit.exe
.
**************************************************************************
.
Completion time: 2008-06-25 10:45:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-25 16:45:00
Pre-Run: 27,598,761,984 bytes free
Post-Run: 27,409,592,320 bytes free
172 --- E O F --- 2008-06-20 15:31:37
Thanks!