This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

please help!

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 1:56:52 PM, on 5/9/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WIN2000\System32\smss.exe
C:\WIN2000\system32\winlogon.exe
C:\WIN2000\system32\services.exe
C:\WIN2000\system32\lsass.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\LEXBCES.EXE
C:\WIN2000\system32\spoolsv.exe
C:\WIN2000\system32\LEXPPS.EXE
C:\WIN2000\System32\msdtc.exe
C:\Program Files\AVIRA Server\avguard.exe
C:\WIN2000\system32\crypserv.exe
C:\WIN2000\System32\svchost.exe
C:\WIN2000\System32\llssrv.exe
d:\programs\macopener\FORMATM.EXE
C:\WIN2000\System32\nvsvc32.exe
C:\WIN2000\system32\regsvc.exe
C:\WIN2000\system32\MSTask.exe
C:\WIN2000\system32\stisvc.exe
C:\WIN2000\System32\Tablet.exe
C:\WIN2000\system32\ZoneLabs\vsmon.exe
C:\WIN2000\System32\WBEM\WinMgmt.exe
C:\WIN2000\System32\mspmspsv.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\Dfssvc.exe
C:\WIN2000\system32\rundll32.exe
C:\WIN2000\Explorer.EXE
C:\WIN2000\system32\ZoneLabs\minilog.exe
C:\WIN2000\System32\svchost.exe
D:\programs\quicktime\qttask.exe
D:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\win2000\system32\waxcuozz.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\win2000\system32\packager.exe
D:\programs\WinZip\WZQKPICK.EXE
D:\programs\ZoneAlarm\zonealarm.exe
D:\Program Files\KeirNet\K9\K9.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Qualcomm\Eudora\Eudora.exe
D:\Program Files\hijackthis\HijackThis.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WIN2000\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [waxcuozz] c:\win2000\system32\waxcuozz.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [{D32470A1-B10C-4059-BA53-CF0486F68EBC}] RunDll32.exe C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\4.0.1.9-EasyShrx.Dll,_UninstallPlatform@16 C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup
O4 - Startup: Launch K9.lnk = D:\Program Files\KeirNet\K9\K9.exe
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: Anti-Virus&Trojan.lnk.disabled
O4 - Global Startup: eFax.com Tray Menu.lnk.disabled
O4 - Global Startup: Iomega Icons.lnk.disabled
O4 - Global Startup: Iomega Startup.lnk.disabled
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Live Menu.lnk.disabled
O4 - Global Startup: MacName.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk = D:\programs\microsoft\Office\OSA9.EXE
O4 - Global Startup: Refresh.lnk.disabled
O4 - Global Startup: WinZip Quick Pick.lnk = D:\programs\WinZip\WZQKPICK.EXE
O4 - Global Startup: zonealarm.lnk = D:\programs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\programs\AOL\AIM\aim.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_4us.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl Class) - http://picturecenter.kodak.com/activex/Lig…loadControl.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/…bio4_0_2_10.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FC} (PCUploader Class) - http://costco.internetimagingnetwork.com/a…x/PCAXSetup.cab?
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{44FD3C0B-E18A-45B4-AEE6-7AA5424C2B24}: NameServer = 68.62.160.6,192.168.0.1,192.168.0.1
O20 - Winlogon Notify: Run - C:\WIN2000\system32\l2l60c3sef.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVIRA Downloader (AVIRADownloader) - AVIRA GmbH - C:\Program Files\AVIRA Server\dwldsvc.exe
O23 - Service: AVIRA Service (AVIRAService) - AVIRA GmbH - C:\Program Files\AVIRA Server\avguard.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WIN2000\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WIN2000\System32\dmadmin.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WIN2000\system32\LEXBCES.EXE
O23 - Service: MacFormatService - DataViz Inc. - d:\programs\macopener\FORMATM.EXE
O23 - Service: TrueVector Basic Logging Client (minilog) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\minilog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WIN2000\System32\nvsvc32.exe
O23 - Service: ptssvc - Unknown owner - D:\Program Files\Kodak EasyShare\Kodak EasyShare software\bin\ptssvc.exe (file missing)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WIN2000\System32\Tablet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\vsmon.exe
O23 - Service: ZipToA - Unknown owner - C:\Program Files\Iomega\ToolsNT\ZipToA.exe (file missing)
——————————————————-

i'm running windows 2000 server and i cannot find any anti-virus software to run on the computer - can you PLEASE recommend something. anything free? or trial software?

i have a lot of popups and cpu is 50%-100% most of the time. spybot says i have backweb but i cannot get rid of it.

any help is appreciated. THANK! :)
its been over 5 days…any help will be appreciated.

thanks!

link to my post:
http://forums.tomcoyote.org/index.php?showtopic=36994


new log today: [my problems are worse now]

Logfile of HijackThis v1.99.1
Scan saved at 8:45:57 AM, on 5/16/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WIN2000\System32\smss.exe
C:\WIN2000\system32\winlogon.exe
C:\WIN2000\system32\services.exe
C:\WIN2000\system32\lsass.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\LEXBCES.EXE
C:\WIN2000\system32\spoolsv.exe
C:\WIN2000\system32\LEXPPS.EXE
C:\WIN2000\System32\msdtc.exe
C:\WIN2000\system32\crypserv.exe
C:\WIN2000\System32\svchost.exe
C:\WIN2000\system32\drivers\KodakCCS.exe
C:\WIN2000\System32\llssrv.exe
d:\programs\macopener\FORMATM.EXE
C:\WIN2000\System32\nvsvc32.exe
C:\WIN2000\system32\regsvc.exe
C:\WIN2000\system32\ZoneLabs\vsmon.exe
C:\WIN2000\System32\WBEM\WinMgmt.exe
C:\WIN2000\System32\mspmspsv.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\Dfssvc.exe
C:\WIN2000\system32\ZoneLabs\minilog.exe
C:\WIN2000\system32\rundll32.exe
C:\WIN2000\System32\svchost.exe
D:\programs\quicktime\qttask.exe
D:\Program Files\Winamp\winampa.exe
D:\TrojanHunter 4.2\THGuard.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\programs\WinZip\WZQKPICK.EXE
D:\programs\ZoneAlarm\zonealarm.exe
D:\Program Files\KeirNet\K9\K9.exe
C:\WIN2000\explorer.exe
C:\WIN2000\system32\rundll32.exe
D:\programs\LiveJournal\Semagic04\Semagic\LiveJournalU.exe
C:\WIN2000\explorer.exe
D:\Program Files\adobe\Photoshop CS\pscs.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~e5d141.tmp
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~e5d141.tmp
D:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WIN2000\mm15201518.Stub.exe
C:\WIN2000\explorer.exe
D:\Program Files\Qualcomm\Eudora\Eudora.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WIN2000\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [THGuard] "D:\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [waxcuozz] c:\win2000\system32\waxcuozz.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Launch K9.lnk = D:\Program Files\KeirNet\K9\K9.exe
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: Anti-Virus&Trojan.lnk.disabled
O4 - Global Startup: eFax.com Tray Menu.lnk.disabled
O4 - Global Startup: Iomega Icons.lnk.disabled
O4 - Global Startup: Iomega Startup.lnk.disabled
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Live Menu.lnk.disabled
O4 - Global Startup: MacName.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk = D:\programs\microsoft\Office\OSA9.EXE
O4 - Global Startup: Refresh.lnk.disabled
O4 - Global Startup: WinZip Quick Pick.lnk = D:\programs\WinZip\WZQKPICK.EXE
O4 - Global Startup: zonealarm.lnk = D:\programs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\programs\AOL\AIM\aim.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_4us.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl Class) - http://picturecenter.kodak.com/activex/Lig…loadControl.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FC} (PCUploader Class) - http://costco.internetimagingnetwork.com/a…x/PCAXSetup.cab?
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{44FD3C0B-E18A-45B4-AEE6-7AA5424C2B24}: NameServer = 68.62.160.6,192.168.0.1,192.168.0.1
O20 - Winlogon Notify: Installer - C:\WIN2000\system32\kwdfr.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WIN2000\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WIN2000\System32\dmadmin.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WIN2000\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WIN2000\system32\LEXBCES.EXE
O23 - Service: MacFormatService - DataViz Inc. - d:\programs\macopener\FORMATM.EXE
O23 - Service: TrueVector Basic Logging Client (minilog) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\minilog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WIN2000\System32\nvsvc32.exe
O23 - Service: ptssvc - Unknown owner - D:\Program Files\Kodak EasyShare\Kodak EasyShare software\bin\ptssvc.exe (file missing)
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WIN2000\System32\Tablet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\vsmon.exe
O23 - Service: ZipToA - Unknown owner - C:\Program Files\Iomega\ToolsNT\ZipToA.exe (file missing)
Hello dd19825, Welcome to the forum.

This is what I suggest you do.

Download CWShredder from my signature below. Unzip it on the desktop.
Open CWShredder and with ALL other windows closed, click fix.


Go here and run at least one of the online scans, allow them to delete whatever they find:

TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan
Note any thing that can't be fixed
Reboot when done.

Next:

Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.3 and Ad-aware SE Build 1.05 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

First in the main window look in the bottom right corner and click on Check for updates now then click Connect and download the latest reference files.

From main window :Click Start then under Select a scan Mode check Perform full system scan.
Next deselect Search for negligible risk entries.
Now to scan just click the Next button.

When the scan is finished mark everything for removal and get rid of it.(Right-click the window and choose select all from the drop down menu and click Next)

Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
thanks so much. i'm scanning now do all of these work for windows 2000 server? thats what i've had a problem with before. can you recommend any anti-virus software for this operating system. thank you!
ok… i ran cwshredder - it found VX2.Look2Me and REMOVED it. then i ran panda scan: it found 71 infected files that couldn't be cleaned and only one that was disinfected. heres the log: Adware:Adware/SaveNow No disinfected C:\WIN2000\system32\ap2nqrd4.dat Adware:Adware/Gator No disinfected C:\WIN2000\FT*_GEPFAH.EXE Adware:Adware/nCase No disinfected C:\Temp\FLEOK Spyware:Spyware/Dyfuca No disinfected C:\WIN2000\optimize.exe Adware:Adware/SAHAgent No disinfected C:\WIN2000\unstall.exe Adware:Adware/BookedSpace No disinfected C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\bs*.tmpbsx32 Spyware:Spyware/Bridge No disinfected Windows Registry Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\guard.tmp Spyware:Spyware/Media-motor No disinfected Windows Registry Adware:Adware/WUpd No disinfected C:\WIN2000\Downloaded Program Files\ActiveX.inf Adware:Adware/ExactSearch No disinfected Windows Registry Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\DrTemp\ceres.cab[ceres.dll] Adware:Adware/Transponder No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\DrTemp\ceres.cab[spike.exe] Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\DrTemp\ceres.dll Spyware:Spyware/BetterInet No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\DrTemp\ceres.dll.tcf Spyware:Spyware/Media-motor No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\ICD6.tmp\m67m.inf Spyware:Spyware/Media-motor No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\ICD6.tmp\m67m.ocx Adware:Adware/Look2Me No disinfected C:\Documents and Settings\Administrator\Local Settings\Temp\upd203.exe Spyware:Spyware/ClientMan No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq44.tmp Spyware:Spyware/ClientMan No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq45.tmp Spyware:Spyware/ClientMan No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq46.tmp Spyware:Spyware/BetterInet No disinfected C:\WIN2000\Buddy.exe Spyware:Spyware/BetterInet No disinfected C:\WIN2000\ceres.dll.tcf Adware:Adware/WUpd No disinfected C:\WIN2000\Downloaded Program Files\ActiveX.inf Spyware:Spyware/Media-motor No disinfected C:\WIN2000\Downloaded Program Files\m67m.inf Spyware:Spyware/Media-motor No disinfected C:\WIN2000\Downloaded Program Files\m67m.ocx Spyware:Spyware/Media-motor No disinfected C:\WIN2000\Downloaded Program Files\mm63.INF Spyware:Spyware/ISTbar No disinfected C:\WIN2000\Downloaded Program Files\QDow_AS2.dll.tcf Adware:Adware/Gator No disinfected C:\WIN2000\FT2_0_0_629_GEPFAH.EXE Spyware:Spyware/Dyfuca No disinfected C:\WIN2000\optimize.exe Adware:Adware/Look2Me No disinfected C:\WIN2000\system\UpdInst.exe Adware:Adware/WUpd No disinfected C:\WIN2000\system32\a95kfrhe.ini Adware:Adware/SaveNow No disinfected C:\WIN2000\system32\ap2nqrd4.dat Adware:Adware/WUpd No disinfected C:\WIN2000\system32\ap9h4qmo.ini Adware:Adware/SaveNow No disinfected C:\WIN2000\system32\baur5s9q.dat Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\dnjo0113e.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\en80l1lm1.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\f00o0ad3ed0.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\feamebuf.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\g0lm0a31ed.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\gp66l3js1.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\guard.tmp Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\ihetcfg.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\lvj0091me.dll Spyware:Spyware/ClientMan No disinfected C:\WIN2000\system32\msdhmd.dll Spyware:Spyware/Omi No disinfected C:\WIN2000\system32\msfdje.gif Spyware:Spyware/ClientMan No disinfected C:\WIN2000\system32\msglji.gif Spyware:Spyware/ClientMan No disinfected C:\WIN2000\system32\msiaih.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\nersptb.dll Adware:Adware/Look2Me No disinfected C:\WIN2000\system32\onesvr.dll Adware:Adware/SaveNow No disinfected C:\WIN2000\system32\q10pvbrv.dat Adware:Adware/WUpd No disinfected C:\WIN2000\system32\q17i9a4j.ini Adware:Adware/SAHAgent No disinfected C:\WIN2000\system32\ritsacnk.dat Adware:Adware/Twain-Tech No disinfected C:\WIN2000\system32\waxcuozz.exe.tcf Adware:Adware/Twain-Tech No disinfected C:\WIN2000\system32\waxcuozz.exe2882.tcf Adware:Adware/Twain-Tech No disinfected C:\WIN2000\system32\waxcuozz.exe5338.tcf Spyware:Spyware/Media-motor No disinfected C:\WIN2000\unstall.exe Spyware:Spyware/ClientMan No disinfected D:\Program Files\hijackthis\backups\backup-20040825-060854-551.dll Spyware:Spyware/ClientMan No disinfected D:\Program Files\hijackthis\backups\backup-20040825-061217-487.dll Adware:Adware/BrilliantDigitalNo disinfected D:\programs\KaZaA\bdcore.dll Adware:Adware/Look2Me No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\8Y71Z2RA\upd203[1].exe Spyware:Spyware/Media-motor No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\CONFMYAJ\joysaver[1].cab[m67m.inf] Spyware:Spyware/Media-motor No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\CONFMYAJ\joysaver[1].cab[m67m.ocx] Adware:Adware/DelFinMedia No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\FGCMSHW5\mm15201518.Stub[1].exe Adware:Adware/Twain-Tech No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\K9JE2BIC\polall2c[1].exe Spyware:Spyware/Dyfuca No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\K9KW1VV4\optimize[1].exe Spyware:Spyware/Media-motor No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\R71Y2MVF\unstall[1].exe Virus:Trj/Downloader.MO Disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\R71Y2MVF\webplugin[1].cab.tcf Spyware:Spyware/BetterInet No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\U5HAVE9O\ceres[1].cab[ceres.dll] Adware:Adware/Transponder No disinfected D:\temp\Temporary Internet Files\Temporary Internet Files\Content.IE5\U5HAVE9O\ceres[1].cab[spike.exe] ————————– then i ran spybot. it found several files and removed them. one that couldn't be removed - backweb. HKEY_USERS\.DEFAULT\Software\Backweb
one more thing… my computer is running very slow - i've rebooted several times since the scans. i ran trendmicro too and it only found 7 - same which is listed on the panda scan. my cpu usually runs at 100%. and it takes a while for the curser to be able to click on a link and to open up.
heres the new hijackthis log:



Logfile of HijackThis v1.99.1
Scan saved at 11:03:23 PM, on 5/17/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WIN2000\System32\smss.exe
C:\WIN2000\system32\winlogon.exe
C:\WIN2000\system32\services.exe
C:\WIN2000\system32\lsass.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\LEXBCES.EXE
C:\WIN2000\system32\spoolsv.exe
C:\WIN2000\system32\LEXPPS.EXE
C:\WIN2000\System32\msdtc.exe
C:\WIN2000\system32\crypserv.exe
C:\WIN2000\System32\svchost.exe
C:\WIN2000\System32\llssrv.exe
d:\programs\macopener\FORMATM.EXE
C:\WIN2000\System32\nvsvc32.exe
C:\WIN2000\system32\regsvc.exe
C:\WIN2000\system32\MSTask.exe
C:\WIN2000\system32\stisvc.exe
C:\WIN2000\System32\Tablet.exe
C:\WIN2000\system32\ZoneLabs\vsmon.exe
C:\WIN2000\System32\WBEM\WinMgmt.exe
C:\WIN2000\System32\mspmspsv.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\Dfssvc.exe
C:\WIN2000\system32\ZoneLabs\minilog.exe
C:\WIN2000\System32\svchost.exe
C:\WIN2000\Explorer.EXE
D:\programs\quicktime\qttask.exe
D:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\TrojanHunter 4.2\THGuard.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Spyware Doctor\swdoctor.exe
D:\programs\WinZip\WZQKPICK.EXE
D:\programs\ZoneAlarm\zonealarm.exe
D:\Program Files\KeirNet\K9\K9.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\programs\LiveJournal\Semagic04\Semagic\LiveJournalU.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\Bazooka Scanner\spywarescanner.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WIN2000\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [THGuard] "D:\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [waxcuozz] c:\win2000\system32\waxcuozz.exe
O4 - HKLM\..\Run: [Vrxcode] D:\Program Files\VrxcodeX\Vrxcode.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Launch K9.lnk = D:\Program Files\KeirNet\K9\K9.exe
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: Anti-Virus&Trojan.lnk.disabled
O4 - Global Startup: eFax.com Tray Menu.lnk.disabled
O4 - Global Startup: Iomega Icons.lnk.disabled
O4 - Global Startup: Iomega Startup.lnk.disabled
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Live Menu.lnk.disabled
O4 - Global Startup: MacName.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk = D:\programs\microsoft\Office\OSA9.EXE
O4 - Global Startup: Refresh.lnk.disabled
O4 - Global Startup: WinZip Quick Pick.lnk = D:\programs\WinZip\WZQKPICK.EXE
O4 - Global Startup: zonealarm.lnk = D:\programs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\programs\AOL\AIM\aim.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_4us.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl Class) - http://picturecenter.kodak.com/activex/Lig…loadControl.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FC} (PCUploader Class) - http://costco.internetimagingnetwork.com/a…x/PCAXSetup.cab?
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{44FD3C0B-E18A-45B4-AEE6-7AA5424C2B24}: NameServer = 68.62.160.6,192.168.0.1,192.168.0.1
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WIN2000\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WIN2000\System32\dmadmin.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WIN2000\system32\LEXBCES.EXE
O23 - Service: MacFormatService - DataViz Inc. - d:\programs\macopener\FORMATM.EXE
O23 - Service: TrueVector Basic Logging Client (minilog) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\minilog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WIN2000\System32\nvsvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WIN2000\System32\Tablet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\vsmon.exe
O23 - Service: ZipToA - Unknown owner - C:\Program Files\Iomega\ToolsNT\ZipToA.exe (file missing)
1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
5) Restart your computer.

After reboot:

Download L2mfix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!
i got a popup message that said: C:\WIN2000\SYSTEM32\CMD.EXE C:\WIN2000\SYSTEM32\AUTOEXE.NT. The system file is not suitable for running MS-DOS and Microsoft Windows Applications. Please close or ignore. i "ignored" and it saved this log. [am i missing a file?\ L2MFIX find log 1.03 These are the registry keys present ********************************************************************************** Winlogon/notify: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify] ********************************************************************************** useragent: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform] "{8A22B975-8498-C726-3C42-D5119B7C4251}"="" ********************************************************************************** Shell Extension key: Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved] "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension" "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player" "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip" "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip" "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip" "{E0D79307-84BE-11CE-9641-444553540000}"="WinZip" "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache" "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link" "{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension" "{5E44E225-A408-11CF-B581-008029601108}"="Adaptec Directcd Shell Extension" ********************************************************************************** HKEY ROOT CLASSIDS: ********************************************************************************** Files Found are not all bad files: ********************************************************************************** Directory Listing of system files: Volume in drive C has no label. Volume Serial Number is 20D9-BCFF Directory of C:\WIN2000\System32 05/16/2005 03:06p 236,060 g0lm0a31ed.dll 05/15/2005 01:38a 233,165 feamebuf.dll 05/15/2005 01:09a 233,165 nersptb.dll 05/15/2005 12:51a 234,186 lvj0091me.dll 05/12/2005 01:17p dllcache 05/11/2005 07:13p 235,038 onesvr.dll 05/11/2005 06:12p 235,946 ihetcfg.dll 05/06/2005 09:13p 234,110 dnjo0113e.dll 05/03/2005 12:16p 233,758 gp66l3js1.dll 8 File(s) 1,875,428 bytes 1 Dir(s) 416,961,536 bytes free
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
C:\WINNT\System32\Autoexec.nt The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose 'Close' to terminate the application.

Resolution Steps: Apparently this error message, or a similar one mentioning config.nt, can occur when one of the following files is missing or corrupt:

Autoexec.nt
Config.nt
Command.com
The error can occur when installing or uninstalling a program.

In case Autoexec.nt is missing from the C:\WINNT\System32 directory. Looking in the C:\WINNT\Repair directory. Windows automatically makes a backup copy of Autoexec.nt, so just copy Autoexec.nt into C:\WINNT\System32 and the problem should be fixed.
L2Mfix 1.03

Running From:
C:\Documents and Settings\Administrator\Desktop\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY –C——- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Administrator\Desktop\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Administrator\Desktop\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 544 'explorer.exe'
Killing PID 544 'explorer.exe'
Error 0x5 : Access is denied.


Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Error, Cannot find a process with an image name of rundll32.exe

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\WIN2000\system32\dnjo0113e.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\en80l1lm1.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\f00o0ad3ed0.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\feamebuf.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\g0lm0a31ed.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\gp66l3js1.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\ihetcfg.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\lvj0091me.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\nersptb.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\onesvr.dll
1 file(s) copied.
Backing Up: C:\WIN2000\system32\guard.tmp
1 file(s) copied.
deleting: C:\WIN2000\system32\dnjo0113e.dll
Successfully Deleted: C:\WIN2000\system32\dnjo0113e.dll
deleting: C:\WIN2000\system32\en80l1lm1.dll
Successfully Deleted: C:\WIN2000\system32\en80l1lm1.dll
deleting: C:\WIN2000\system32\f00o0ad3ed0.dll
Successfully Deleted: C:\WIN2000\system32\f00o0ad3ed0.dll
deleting: C:\WIN2000\system32\feamebuf.dll
Successfully Deleted: C:\WIN2000\system32\feamebuf.dll
deleting: C:\WIN2000\system32\g0lm0a31ed.dll
Successfully Deleted: C:\WIN2000\system32\g0lm0a31ed.dll
deleting: C:\WIN2000\system32\gp66l3js1.dll
Successfully Deleted: C:\WIN2000\system32\gp66l3js1.dll
deleting: C:\WIN2000\system32\ihetcfg.dll
Successfully Deleted: C:\WIN2000\system32\ihetcfg.dll
deleting: C:\WIN2000\system32\lvj0091me.dll
Successfully Deleted: C:\WIN2000\system32\lvj0091me.dll
deleting: C:\WIN2000\system32\nersptb.dll
Successfully Deleted: C:\WIN2000\system32\nersptb.dll
deleting: C:\WIN2000\system32\onesvr.dll
Successfully Deleted: C:\WIN2000\system32\onesvr.dll
deleting: C:\WIN2000\system32\guard.tmp
Successfully Deleted: C:\WIN2000\system32\guard.tmp

Desktop.ini sucessfully removed


Zipping up files for submission:
adding: dnjo0113e.dll (152 bytes security) (deflated 5%)
adding: en80l1lm1.dll (152 bytes security) (deflated 5%)
adding: f00o0ad3ed0.dll (152 bytes security) (deflated 6%)
adding: feamebuf.dll (152 bytes security) (deflated 4%)
adding: g0lm0a31ed.dll (152 bytes security) (deflated 5%)
adding: gp66l3js1.dll (152 bytes security) (deflated 5%)
adding: ihetcfg.dll (152 bytes security) (deflated 6%)
adding: lvj0091me.dll (152 bytes security) (deflated 5%)
adding: nersptb.dll (152 bytes security) (deflated 4%)
adding: onesvr.dll (152 bytes security) (deflated 5%)
adding: guard.tmp (152 bytes security) (deflated 5%)
adding: clear.reg (152 bytes security) (deflated 2%)
adding: echo.reg (152 bytes security) (deflated 10%)
adding: desktop.ini (152 bytes security) (stored 0%)
adding: direct.txt (152 bytes security) (stored 0%)
adding: lo2.txt (152 bytes security) (deflated 80%)
adding: readme.txt (152 bytes security) (deflated 49%)
adding: report.txt (152 bytes security) (deflated 62%)
adding: test.txt (152 bytes security) (deflated 72%)
adding: test2.txt (152 bytes security) (stored 0%)
adding: test3.txt (152 bytes security) (stored 0%)
adding: test5.txt (152 bytes security) (stored 0%)
adding: xfind.txt (152 bytes security) (deflated 66%)
adding: backregs/shell.reg (152 bytes security) (deflated 64%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Read BUILTIN\Power Users
(ID-IO) ALLOW Read BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators … successful

deleting local copy: dnjo0113e.dll
deleting local copy: en80l1lm1.dll
deleting local copy: f00o0ad3ed0.dll
deleting local copy: feamebuf.dll
deleting local copy: g0lm0a31ed.dll
deleting local copy: gp66l3js1.dll
deleting local copy: ihetcfg.dll
deleting local copy: lvj0091me.dll
deleting local copy: nersptb.dll
deleting local copy: onesvr.dll
deleting local copy: guard.tmp

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]


The following are the files found:
****************************************************************************
C:\WIN2000\system32\dnjo0113e.dll
C:\WIN2000\system32\en80l1lm1.dll
C:\WIN2000\system32\f00o0ad3ed0.dll
C:\WIN2000\system32\feamebuf.dll
C:\WIN2000\system32\g0lm0a31ed.dll
C:\WIN2000\system32\gp66l3js1.dll
C:\WIN2000\system32\ihetcfg.dll
C:\WIN2000\system32\lvj0091me.dll
C:\WIN2000\system32\nersptb.dll
C:\WIN2000\system32\onesvr.dll
C:\WIN2000\system32\guard.tmp

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
****************************************************************************






——————————–

Logfile of HijackThis v1.99.1
Scan saved at 11:08:41 PM, on 5/18/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WIN2000\System32\smss.exe
C:\WIN2000\system32\winlogon.exe
C:\WIN2000\system32\services.exe
C:\WIN2000\system32\lsass.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\LEXBCES.EXE
C:\WIN2000\system32\spoolsv.exe
C:\WIN2000\system32\LEXPPS.EXE
C:\WIN2000\System32\msdtc.exe
C:\WIN2000\system32\crypserv.exe
C:\WIN2000\System32\svchost.exe
C:\WIN2000\System32\llssrv.exe
d:\programs\macopener\FORMATM.EXE
C:\WIN2000\System32\nvsvc32.exe
C:\WIN2000\system32\regsvc.exe
C:\WIN2000\system32\MSTask.exe
C:\WIN2000\system32\stisvc.exe
C:\WIN2000\System32\Tablet.exe
C:\WIN2000\system32\ZoneLabs\vsmon.exe
C:\WIN2000\System32\WBEM\WinMgmt.exe
C:\WIN2000\System32\mspmspsv.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\Dfssvc.exe
C:\WIN2000\system32\ZoneLabs\minilog.exe
C:\WIN2000\System32\svchost.exe
D:\programs\quicktime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\TrojanHunter 4.2\THGuard.exe
D:\Program Files\Winamp\winampa.exe
D:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Spyware Doctor\swdoctor.exe
C:\WIN2000\explorer.exe
C:\WIN2000\system32\NOTEPAD.EXE
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WIN2000\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\quicktime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [THGuard] "D:\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [waxcuozz] c:\win2000\system32\waxcuozz.exe
O4 - HKLM\..\Run: [Vrxcode] D:\Program Files\VrxcodeX\Vrxcode.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] D:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Launch K9.lnk = D:\Program Files\KeirNet\K9\K9.exe
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: Anti-Virus&Trojan.lnk.disabled
O4 - Global Startup: eFax.com Tray Menu.lnk.disabled
O4 - Global Startup: Iomega Icons.lnk.disabled
O4 - Global Startup: Iomega Startup.lnk.disabled
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Live Menu.lnk.disabled
O4 - Global Startup: MacName.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk = D:\programs\microsoft\Office\OSA9.EXE
O4 - Global Startup: Refresh.lnk.disabled
O4 - Global Startup: WinZip Quick Pick.lnk = D:\programs\WinZip\WZQKPICK.EXE
O4 - Global Startup: zonealarm.lnk = D:\programs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\programs\AOL\AIM\aim.exe
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha…t/c381/chat.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab
O16 - DPF: YExplorer1_8US.CAB - http://photos.groups.yahoo.com/ocx/us/yexplorer1_8us.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_4us.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} (LightSurfUploadCtl Class) - http://picturecenter.kodak.com/activex/Lig…loadControl.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) -
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FC} (PCUploader Class) -
O16 - DPF: {F229AB32-7BF9-4225-B78F-B4680AE6FC23} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{44FD3C0B-E18A-45B4-AEE6-7AA5424C2B24}: NameServer = 68.62.160.6,192.168.0.1,192.168.0.1
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WIN2000\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WIN2000\System32\dmadmin.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WIN2000\system32\LEXBCES.EXE
O23 - Service: MacFormatService - DataViz Inc. - d:\programs\macopener\FORMATM.EXE
O23 - Service: TrueVector Basic Logging Client (minilog) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\minilog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WIN2000\System32\nvsvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WIN2000\System32\Tablet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\vsmon.exe
O23 - Service: ZipToA - Unknown owner - C:\Program Files\Iomega\ToolsNT\ZipToA.exe (file missing)
I suggest you do this:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

O4 - HKLM\..\Run: [QuickTime Task] "D:\programs\quicktime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [waxcuozz] c:\win2000\system32\waxcuozz.exe

O4 - HKLM\..\Run: [Vrxcode] D:\Program Files\VrxcodeX\Vrxcode.exe

ALL 016's. They'll come back if needed,


Close ALL windows and browsers except HijackThis and click "Fix checked"



Restart in Safe Mode:
Restart your computer.

Restart your computer in Safe Mode

Press the F8 key, when you see the Starting Windows bar at the bottom of the screen.

Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.


To configure Windows to show all files

Do the following:

On the Windows desktop, double-click the My Computer icon.
On the Tools menu, click Folder Options.
On the View tab, uncheck Hide file extensions for known file types.

Do the following:

Uncheck Hide protected operating system files. Then, under the "Hidden files" folder, click Show hidden files and folders.
If you see a warning message, click Yes.
Click Apply.
Click OK.



Delete these Folders, unless you know what they are.
D:\Program Files\VrxcodeX



Delete these files if listed:
c:\win2000\system32\waxcuozz.exe



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment. .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI