Introducing Divinty Death with Malware

  • Divinty Death
  • Born
  • Born
  • Divinty Death
  • Posts: 1

Post 3+ Months Ago

Heres my logfile please help


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:33:36 p.m., on 23/04/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2

(6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Irene\My

Documents\bin\jqs.exe
C:\Program Files\Common Files\Microsoft

Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement

Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\HP Software

Update\HPWuSchd.exe
C:\PROGRA~1\MYWEBS~1

\bar\1.bin\mwsoemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WinDir\svchost.exe
C:\WINDOWS\system32\WinDir\svchost.exe
C:\WINDOWS\system32\WinDir\svchost.exe
C:\WINDOWS\system32\WinDir\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\plugin-

container.exe
C:\Documents and Settings\James_shizzle\My

Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Start Page = Ask

Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet

Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Window Title = Packard Bell
R3 - URLSearchHook: UrlSearchHook Class -

{00000000-6E41-4FD3-8538-502F5495E5FC} -

C:\Program Files\Ask.c0m\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-

072E-44cf-8957-5838F569A31D} - C:\Program

Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO -

{00A6FAF1-072E-44cf-8957-5838F569A31D} -

C:\Program

Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-

C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 5.0

\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961

-B6BB-170DE4475CCA} - C:\Program

Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-

9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {62649F82-DA45-4665-

AB6F-4A88A8DF0FCC} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff

-A14F-B9E3AAC4465B} - C:\Program

Files\Microsoft\Search Enhancement Pack\Search

Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper -

{9030D464-4C02-4ABF-8ECC-5164760863C6} -

C:\Program Files\Common Files\Microsoft

Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-

2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program

Files\Skype\Toolbars\Internet

Explorer\skypeieplugin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-

4066-A1AD-4243D8127440} - C:\Program

Files\Ask.c0m\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper -

{DBC80044-A445-435b-BC74-9C25C1C588A9} -

C:\Documents and Settings\Irene\My

Documents\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper -

{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} -

C:\Program Files\Windows

Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-

17CE-4C07-BC86-EABFE594F69C} -

C:\Documents and Settings\Irene\My

Documents\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar -

{21FA44EF-376D-4D53-9B0F-8A89D3229068} -

C:\Program Files\Windows

Live\Toolbar\wltcore.dll
O3 - Toolbar: LimeWire Toolbar - {D4027C7F-

154A-4066-A1AD-4243D8127440} - C:\Program

Files\Ask.c0m\GenericAskToolbar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program

Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe" -

atboottime
O4 - HKLM\..\Run: [HP Software Update]

"C:\Program Files\HP\HP Software

Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HKLM]

c:\directory\CyberGate\install\server.exe
O4 - HKLM\..\Run: [My Web Search Bar]

rundll32 C:\PROGRA~1\MYWEBS~1

\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin]

C:\PROGRA~1\MYWEBS~1

\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Adobe Drivers]

C:\Documents and Settings\Casper

Blomgren\Application

Data\Microsoft\Local\UAC.exe
O4 - HKLM\..\Run: [WinDir]

C:\WINDOWS\system32\WinDir\svchost.exe
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SPMTray] C:\Program

Files\SpeedingUpMyPC\SPMTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program

Files\Windows Live\Messenger\msnmsgr.exe"

/background
O4 - HKCU\..\Run: [HKCU]

C:\WINDOWS\system32\install\server.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program

Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Config]

C:\Documents and Settings\James_shizzle\Local

Settings\Temp\msconfig.exe
O4 - HKCU\..\Run: [Adobe Drivers]

C:\Documents and Settings\Casper

Blomgren\Application

Data\Microsoft\Local\UAC.exe
O4 - HKCU\..\Run: [WinDir]

C:\WINDOWS\system32\WinDir\svchost.exe
O4 - HKLM\..\Policies\Explorer\Run: [Policies]

C:\WINDOWS\system32\WinDir\svchost.exe
O4 - HKCU\..\Policies\Explorer\Run: [Policies]

C:\WINDOWS\system32\WinDir\svchost.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE]

C:\WINDOWS\System32\CTFMON.EXE (User

'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE]

C:\WINDOWS\System32\CTFMON.EXE (User

'Default user')
O8 - Extra context menu item: &Search -

http://edits.mywebsearch.c0m/toolbaredits/menu

search.jhtml?

s=100000343&p=ZKxdm603YYNZ&si=&a=aR38

nmJFaBjkL.CrutEhTg&n=2010112314
O9 - Extra button: Blog This - {219C3416-8CB2-

491a-A3C7-D9FCDDC9D600} - C:\Program

Files\Windows

Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in

Windows Live Writer - {219C3416-8CB2-491a-

A3C7-D9FCDDC9D600} - C:\Program

Files\Windows

Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype add-on for Internet

Explorer - {898EA8C8-E7FF-479B-8935-

AEC46303B9E5} - C:\Program

Files\Skype\Toolbars\Internet

Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for

Internet Explorer - {898EA8C8-E7FF-479B-8935

-AEC46303B9E5} - C:\Program

Files\Skype\Toolbars\Internet

Explorer\skypeieplugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-

11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger

- {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .kar: C:\Program Files\Internet

Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mid: C:\Program Files\Internet

Explorer\PLUGINS\npqtplugin2.dll
O18 - Protocol: skype-ie-addon-data - {91774881-

D725-4E58-B298-07617B9B86A8} - C:\Program

Files\Skype\Toolbars\Internet

Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-

4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1

\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32

\cru629.dat
O20 - Winlogon Notify: urqPfGYR - urqPfGYR.dll

(file missing)
O22 - SharedTaskScheduler: Browseui preloader -

{438755C2-A8BA-11D1-B96B-00A0C90312E1} -

C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component

Categories cache daemon - {8C7461EF-2B13-11d2

-BE35-3078302C2030} -

C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: edfjgj - {441EF6D9-

C6A2-419f-9A71-977E2004EE14} - (no file)
O23 - Service: Java Quick Starter

(JavaQuickStarterService) - Sun Microsystems,

Inc. - C:\Documents and Settings\Irene\My

Documents\bin\jqs.exe
O23 - Service: My Web Search Service

(MyWebSearchService) - MyWebSearch.c0m -

C:\PROGRA~1\MYWEBS~1

\bar\1.bin\mwssvc.exe
O23 - Service: SmartLinkService (SLService) - -

C:\WINDOWS\SYSTEM32\slserv.exe

--
End of file - 7989 bytes
  • Anonymous
  • Bot
  • No Avatar
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post 3+ Months Ago

  • Don2007
  • Web Master
  • Web Master
  • Don2007
  • Posts: 4924
  • Loc: NY

Post 3+ Months Ago

C:\WINDOWS\system32\WinDir\svchost.exe
C:\WINDOWS\system32\WinDir\svchost.exe
C:\WINDOWS\system32\WinDir\svchost.exe
C:\WINDOWS\system32\WinDir\svchost.exe

I never saw \WinDir. svchost.exe should be in the system32 directory. I also never saw a \bin directory under the %users% directory.

Secondly, you installed Limewire which can give you all kinds of problems. I would uninstall Limewire & all toolbars.

Post Information

  • Total Posts in this topic: 2 posts
  • Users browsing this forum: No registered users and 44 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 1998-2014. Ozzu® is a registered trademark of Unmelted, LLC.