This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

please help!

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

new log file:
Logfile of HijackThis v1.99.1
Scan saved at 3:47:15 PM, on 5/20/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WIN2000\System32\smss.exe
C:\WIN2000\system32\csrss.exe
C:\WIN2000\system32\winlogon.exe
C:\WIN2000\system32\services.exe
C:\WIN2000\system32\lsass.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\LEXBCES.EXE
C:\WIN2000\system32\spoolsv.exe
C:\WIN2000\system32\LEXPPS.EXE
C:\WIN2000\System32\msdtc.exe
C:\WIN2000\system32\crypserv.exe
C:\WIN2000\System32\svchost.exe
C:\WIN2000\System32\llssrv.exe
d:\programs\macopener\FORMATM.EXE
C:\WIN2000\System32\nvsvc32.exe
C:\WIN2000\system32\regsvc.exe
C:\WIN2000\system32\MSTask.exe
C:\WIN2000\system32\stisvc.exe
C:\WIN2000\System32\Tablet.exe
C:\WIN2000\system32\ZoneLabs\vsmon.exe
C:\WIN2000\System32\WBEM\WinMgmt.exe
C:\WIN2000\System32\mspmspsv.exe
C:\WIN2000\system32\svchost.exe
C:\WIN2000\system32\Dfssvc.exe
C:\WIN2000\system32\ZoneLabs\minilog.exe
C:\WIN2000\Explorer.EXE
C:\WIN2000\System32\svchost.exe
D:\Program Files\Winamp\winampa.exe
D:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
D:\programs\WinZip\WZQKPICK.EXE
D:\programs\ZoneAlarm\zonealarm.exe
D:\Program Files\KeirNet\K9\K9.exe
C:\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - D:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WIN2000\System32\msdxm.ocx
O4 - HKLM\..\Run: [THGuard] "D:\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] D:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "D:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Launch K9.lnk = D:\Program Files\KeirNet\K9\K9.exe
O4 - Global Startup: Adobe Gamma Loader.lnk.disabled
O4 - Global Startup: Anti-Virus&Trojan.lnk.disabled
O4 - Global Startup: eFax.com Tray Menu.lnk.disabled
O4 - Global Startup: Iomega Icons.lnk.disabled
O4 - Global Startup: Iomega Startup.lnk.disabled
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: Live Menu.lnk.disabled
O4 - Global Startup: MacName.lnk.disabled
O4 - Global Startup: Microsoft Office.lnk = D:\programs\microsoft\Office\OSA9.EXE
O4 - Global Startup: Refresh.lnk.disabled
O4 - Global Startup: WinZip Quick Pick.lnk = D:\programs\WinZip\WZQKPICK.EXE
O4 - Global Startup: zonealarm.lnk = D:\programs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - D:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\programs\AOL\AIM\aim.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{44FD3C0B-E18A-45B4-AEE6-7AA5424C2B24}: NameServer = 68.62.160.6,192.168.0.1,192.168.0.1
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WIN2000\SYSTEM32\crypserv.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WIN2000\System32\dmadmin.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WIN2000\system32\LEXBCES.EXE
O23 - Service: MacFormatService - DataViz Inc. - d:\programs\macopener\FORMATM.EXE
O23 - Service: TrueVector Basic Logging Client (minilog) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\minilog.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WIN2000\System32\nvsvc32.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WIN2000\System32\Tablet.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WIN2000\system32\ZoneLabs\vsmon.exe
O23 - Service: ZipToA - Unknown owner - C:\Program Files\Iomega\ToolsNT\ZipToA.exe (file missing)


there was nothing in my windows\temp foler
and on the c\docs\everyuser… is that supposed to be ALL users? theres nothing there either

there was nothing in my windows\temp foler
and on the c\docs\everyuser… is that supposed to be ALL users? theres nothing there either

Don't worry about it then :thumbup:


Good Job :thumbup:


Log looks good :D :thumbup: How is it running any issues?



1.Do one of the following:
In Windows 98/Me/2000, on the Windows desktop, double-click the My Computer icon.
In Windows XP, on the taskbar, click Start > My Computer.

2.Do one of the following:
In Windows 98, on the View menu, click Folder Options.
In Windows Me/2000/XP, on the Tools menu, click Folder Options.
On the View tab, check Hide file extensions for known file types.

3.Do one of the following:
In Windows 98, in the Advanced Settings box, under the "Hidden files" folder, unclick Show all files.
In Windows Me/2000/XP, check Hide protected operating system files. Then, under the "Hidden files" folder, unclick Show hidden files and folders.
If you see a warning message, click Yes.
Click Apply.
Click OK.



If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Great job :thumbup:

You're more then welcome.
Glad we were able to help :wavey:





If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI