This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

I ended up doing a format.. No need for further assistance..

4 min read

This thread's last reply is from January 10, 2009, 6:23 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I also cant get updates or certain downloads..Ps I already uninstalled bitlord and limewire..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:26:26 PM, on 1/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://windowsupdate.microsoft.com/
O1 - Hosts: 61.157.217.210 http://www.yahoo.com
O1 - Hosts: 61.157.217.210 http://www.google.com
O1 - Hosts: 61.157.217.210 http://www.google.co.uk
O1 - Hosts: 61.157.217.210 http://www.myspace.com
O1 - Hosts: 61.157.217.210 http://www.youtube.com
O1 - Hosts: 61.157.217.210 http://www.facebook.com
O1 - Hosts: 61.157.217.210 http://www.antispy.com
O1 - Hosts: 61.157.217.210 http://www.yahoo.com
O1 - Hosts: 61.157.217.210 http://www.yahoo.co.uk
O1 - Hosts: 61.157.217.210 http://www.antispyware.com
O1 - Hosts: 61.157.217.210 antispyware.com
O1 - Hosts: 61.157.217.210 antispy.com
O1 - Hosts: 61.157.217.210 http://www.msn.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.gg.com
O1 - Hosts: 123.251.143.110 http://www.ghfhj.com
O1 - Hosts: 123.251.143.110 http://www.cvnbcvnb.com
O1 - Hosts: 123.251.143.110 http://www.1.com
O1 - Hosts: 123.251.143.110 http://www.3.com
O1 - Hosts: 123.251.143.110 http://www.asdf4asdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfawsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfatsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfadsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfafsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfagsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasgdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdhfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfjd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfkd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfld.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdf,d.com
O1 - Hosts: 123.251.143.110 http://www.asxdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdzfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdcfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfvasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfabsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasndfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdmfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.11asdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.as222dfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfa33sdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasd44fd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasdfd5.com
O1 - Hosts: 123.251.143.110 http://www.as66dfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdf77asdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdf8asdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdf9asdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdf0asdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdf-asdfd.com
O1 - Hosts: 123.251.143.110 http://www.aqqsdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.aswwdfasdfd.com
O1 - Hosts: 123.16.197.121 http://www.asdhhfasdfdyy.com
O1 - Hosts: 61.157.217.210 http://www.live.com
O1 - Hosts: 123.251.143.110 http://www.asdwwwfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfeasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfrrasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfttasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfyyasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfuuuasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfaiisdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfaoosdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfappsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfasssdfd.com
O1 - Hosts: 123.251.143.110 http://www.aswwdfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdeefasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfffasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfavvvsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asnnndfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdmmmfasdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdfaffsdfd.com
O1 - Hosts: 123.251.143.110 http://www.asdhhfasdfd.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228618811843
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1228670324816&h=93929ffde59b4f2de07499600d7ed243/&filename=jinstall-6u11-windows-i586-jc.cab
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

--
End of file - 8284 bytes
This topic is now closed. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.