
http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\'

\' /> OK, Itried to do what you asked. It is funny that you told me about running the second.bat for l2mfix if the first didn't work. The first bat file has always run before, except this time. In fact, I tried to run both twice in succession and got lockups as a result.
Here are the latest files:
Logfile of HijackThis v1.99.1
Scan saved at 6:43:06 AM, on 11/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\America Online 9.0a\aoltray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\maria garcia\Desktop\HijackThis.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\system32\spool\drivers\w32x86\epsonstylus_photo_r2c5c0\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O5 "LPT1:" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=laptop
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
********
10:05 PM: | Start of Session, Tuesday, November 08, 2005 |
10:05 PM: Spy Sweeper started
10:05 PM: Sweep initiated using definitions version 569
10:05 PM: Starting Memory Sweep
10:05 PM: Found Adware: icannnews
10:05 PM: Detected running threat: C:\WINDOWS\system32\dn8001lme.dll (ID = 83)
10:06 PM: Detected running threat: C:\WINDOWS\system32\nntapi32.dll (ID = 83)
10:07 PM: Memory Sweep Complete, Elapsed Time: 00:01:52
10:07 PM: Starting Registry Sweep
10:07 PM: Registry Sweep Complete, Elapsed Time:00:00:11
10:07 PM: Starting Cookie Sweep
10:07 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
10:07 PM: Starting File Sweep
10:15 PM: Found Adware: directrevenue-abetterinternet
10:15 PM: 20051107083713515.zip (ID = 186349)
10:15 PM: 20051106212457578.zip (ID = 186349)
10:15 PM: 20051107171004.zip (ID = 186349)
10:15 PM: 20051107105056843.zip (ID = 186349)
10:15 PM: File Sweep Complete, Elapsed Time: 00:08:07
10:15 PM: Full Sweep has completed. Elapsed time 00:10:16
10:15 PM: Traces Found: 6
10:17 PM: Removal process initiated
10:17 PM: Quarantining All Traces: directrevenue-abetterinternet
10:17 PM: Quarantining All Traces: icannnews
10:17 PM: icannnews is in use. It will be removed on reboot.
10:17 PM: C:\WINDOWS\system32\dn8001lme.dll is in use. It will be removed on reboot.
10:17 PM: C:\WINDOWS\system32\nntapi32.dll is in use. It will be removed on reboot.
10:17 PM: Warning: Launched explorer.exe
10:17 PM: Warning: Quarantine process could not restart Explorer.
10:17 PM: Removal process completed. Elapsed time 00:00:21
********
8:51 AM: |··· Start of Session, Tuesday, November 08, 2005 ···|
8:51 AM: Spy Sweeper started
8:51 AM: Sweep initiated using definitions version 569
8:51 AM: Starting Memory Sweep
8:51 AM: Warning: Failed to check file "C:\WINDOWS\system32\jt4o07h3e.dll". Cannot open file "C:\WINDOWS\system32\jt4o07h3e.dll". The process cannot access the file because it is being used by another process
8:52 AM: Warning: Failed to check file "C:\WINDOWS\system32\rdnd.dll". Cannot open file "C:\WINDOWS\system32\rdnd.dll". The process cannot access the file because it is being used by another process
8:52 AM: Warning: Failed to check file "C:\WINDOWS\system32\rdnd.dll". Cannot open file "C:\WINDOWS\system32\rdnd.dll". The process cannot access the file because it is being used by another process
8:52 AM: Memory Sweep Complete, Elapsed Time: 00:01:06
8:52 AM: Starting Registry Sweep
8:52 AM: Registry Sweep Complete, Elapsed Time:00:00:06
8:52 AM: Starting Cookie Sweep
8:52 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
8:52 AM: Starting File Sweep
8:53 AM: Warning: Failed to read file "c:\windows\system32\en0ol1d31.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
8:53 AM: Warning: Failed to read file "c:\windows\system32\rdnd.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
8:54 AM: Warning: Failed to read file "c:\windows\system32\jt4o07h3e.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
8:54 AM: File Sweep Complete, Elapsed Time: 00:02:03
8:54 AM: Full Sweep has completed. Elapsed time 00:03:19
8:54 AM: Traces Found: 0
9:56 PM: Your definitions are up to date.
10:01 PM: Updating spyware definitions
10:01 PM: Your definitions are up to date.
10:05 PM: | End of Session, Tuesday, November 08, 2005 |
********
12:04 AM: |··· Start of Session, Tuesday, November 08, 2005 ···|
12:04 AM: Spy Sweeper started
12:04 AM: Sweep initiated using definitions version 569
12:04 AM: Found Adware: look2me
12:04 AM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\shell extensions\ || dllname (ID = 129986)
12:04 AM: ir6ql5j51.dll (ID = 129986)
12:04 AM: Starting Memory Sweep
12:04 AM: Warning: Failed to check file "C:\WINDOWS\system32\ir6ql5j51.dll". Cannot open file "C:\WINDOWS\system32\ir6ql5j51.dll". The process cannot access the file because it is being used by another process
12:05 AM: Warning: Failed to check file "C:\WINDOWS\system32\kedsl.dll". Cannot open file "C:\WINDOWS\system32\kedsl.dll". The process cannot access the file because it is being used by another process
12:05 AM: Memory Sweep Complete, Elapsed Time: 00:01:06
12:05 AM: Starting Registry Sweep
12:05 AM: Registry Sweep Complete, Elapsed Time:00:00:06
12:05 AM: Starting Cookie Sweep
12:05 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
12:05 AM: Starting File Sweep
12:05 AM: Warning: Failed to read file "c:\windows\system32\ir6ql5j51.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:06 AM: Warning: Failed to read file "c:\windows\system32\i8jq0i15e8.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:06 AM: Warning: Failed to read file "c:\windows\system32\kedsl.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs39822.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs39828.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs3982b.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs3982c.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs3982d.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs39840.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs39847.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs39848.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: Warning: Failed to read file "c:\windows\temp\cs3984e.tmp". System Error. Code: 32.
The process cannot access the file because it is being used by another process
12:07 AM: File Sweep Complete, Elapsed Time: 00:01:54
12:07 AM: Full Sweep has completed. Elapsed time 00:03:10
12:07 AM: Traces Found: 2
12:11 AM: Removal process initiated
12:11 AM: Quarantining All Traces: look2me
12:11 AM: An error occurred during quarantine:
12:11 AM: Cannot open file "C:\WINDOWS\system32\ir6ql5j51.dll". The process cannot access the file because it is being used by another process
12:11 AM: Removal process completed. Elapsed time 00:00:02
12:11 AM: Deletion from quarantine initiated
12:11 AM: Processing: exact cashback/bargain buddy
12:11 AM: Processing: dealhelper
12:11 AM: Processing: elitebar
12:11 AM: Processing: look2me
12:11 AM: Processing: personal money tree
12:11 AM: Deletion from quarantine completed. Elapsed time 00:00:00
8:51 AM: Program Version 4.0.3 (Build 363) Using Spyware Definitions 569
8:51 AM: |··· End of Session, Tuesday, November 08, 2005 ···|
********
8:43 PM: |··· Start of Session, Monday, November 07, 2005 ···|
8:43 PM: Spy Sweeper started
8:43 PM: Sweep initiated using definitions version 569
8:43 PM: Starting Memory Sweep
8:43 PM: Warning: Failed to check file "C:\WINDOWS\system32\h0n0la5m1d.dll". Cannot open file "C:\WINDOWS\system32\h0n0la5m1d.dll". The process cannot access the file because it is being used by another process
8:44 PM: Warning: Failed to check file "C:\WINDOWS\system32\nrtshell.dll". Cannot open file "C:\WINDOWS\system32\nrtshell.dll". The process cannot access the file because it is being used by another process
8:44 PM: Warning: Failed to check file "C:\WINDOWS\system32\nrtshell.dll". Cannot open file "C:\WINDOWS\system32\nrtshell.dll". The process cannot access the file because it is being used by another process
8:44 PM: Memory Sweep Complete, Elapsed Time: 00:01:08
8:44 PM: Starting Registry Sweep
8:44 PM: Registry Sweep Complete, Elapsed Time:00:00:06
8:44 PM: Starting Cookie Sweep
8:44 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
8:44 PM: Starting File Sweep
8:44 PM: Found Adware: elitebar
8:44 PM: 5701862_1924_3236_5680_63.41.tmp1 (ID = 137430)
8:44 PM: Found Adware: exact cashback/bargain buddy
8:44 PM: package_marketing30[1].exe (ID = 93621)
8:44 PM: Found Adware: look2me
8:44 PM: appwrap[1].exe (ID = 65739)
8:44 PM: 131826_1596_3608_1396_63.41.tmp1 (ID = 137430)
8:45 PM: 131862_668_3048_3324_63.41.tmp1 (ID = 137430)
8:45 PM: 918368_5260_3152_4424_63.41.tmp1 (ID = 137430)
8:45 PM: 131886_2024_2996_3220_63.41.tmp1 (ID = 137430)
8:45 PM: 459332_180_3220_5236_63.41.tmp1 (ID = 137430)
8:45 PM: 197838_3964_2284_4316_63.41.tmp1 (ID = 137430)
8:45 PM: 6816142_4456_3764_168_63.41.tmp1 (ID = 137430)
8:45 PM: Warning: Failed to read file "c:\windows\system32\nrtshell.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
8:45 PM: Warning: Failed to read file "c:\windows\system32\fpn2035oe.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
8:45 PM: 66550_3560_2092_1580_63.41.tmp1 (ID = 137430)
8:45 PM: 131718_3896_3000_972_63.41.tmp1 (ID = 137430)
8:45 PM: 262964_3964_2284_5132_63.41.tmp1 (ID = 137430)
8:45 PM: 524704_5208_2920_4188_63.41.tmp1 (ID = 137430)
8:45 PM: 2753328_5260_3152_176_63.41.tmp1 (ID = 137430)
8:45 PM: 2556146_3040_2408_3136_63.41.tmp1 (ID = 137430)
8:45 PM: 787640_5556_3612_4152_63.41.tmp1 (ID = 137430)
8:45 PM: 393702_2876_2828_3124_63.41.tmp1 (ID = 137430)
8:46 PM: 1180636_592_3384_5684_63.41.tmp1 (ID = 137430)
8:46 PM: 1180722_592_3384_4672_63.41.tmp1 (ID = 137430)
8:46 PM: 26214812_1544_2504_7060_63.41.tmp1 (ID = 137430)
8:46 PM: 984202_2192_3116_5636_63.41.tmp1 (ID = 137430)
8:46 PM: 132994_4492_1924_3320_63.41.tmp1 (ID = 137430)
8:46 PM: 1640082_5896_3232_6080_63.41.tmp1 (ID = 137430)
8:46 PM: 263076_5208_2920_5256_63.41.tmp1 (ID = 137430)
8:46 PM: 263104_3560_2092_2628_63.41.tmp1 (ID = 137430)
8:46 PM: Found Adware: personal money tree
8:46 PM: b7e5d.tmp (ID = 147038)
8:46 PM: Warning: Failed to read file "c:\windows\system32\h0n0la5m1d.dll". System Error. Code: 32.
The process cannot access the file because it is being used by another process
8:46 PM: nls[1].cfg (ID = 114713)
8:46 PM: Found Adware: dealhelper
8:46 PM: newuhbavhtime.xml (ID = 163168)
8:46 PM: File Sweep Complete, Elapsed Time: 00:02:04
8:46 PM: Full Sweep has completed. Elapsed time 00:03:22
8:46 PM: Traces Found: 29
8:52 PM: Removal process initiated
8:52 PM: Quarantining All Traces: elitebar
8:52 PM: Quarantining All Traces: exact cashback/bargain buddy
8:52 PM: Quarantining All Traces: look2me
8:52 PM: Quarantining All Traces: personal money tree
8:52 PM: Quarantining All Traces: dealhelper
8:52 PM: Removal process completed. Elapsed time 00:00:09
12:04 AM: Program Version 4.0.3 (Build 363) Using Spyware Definitions 569
12:04 AM: |··· End of Session, Tuesday, November 08, 2005 ···|
********
8:37 PM: |··· Start of Session, Monday, November 07, 2005 ···|
8:37 PM: Spy Sweeper started
8:37 PM: Sweep initiated using definitions version 492
8:37 PM: Starting Memory Sweep
8:37 PM: Warning: Failed to check file "C:\WINDOWS\system32\hr8s05l7e.dll". Cannot open file "C:\WINDOWS\system32\hr8s05l7e.dll". The process cannot access the file because it is being used by another process
8:37 PM: Sweep Canceled
8:37 PM: Memory Sweep Complete, Elapsed Time: 00:00:12
8:37 PM: Traces Found: 0
8:40 PM: Updating spyware definitions
8:41 PM: Your spyware definitions have been updated.
8:43 PM: Program Version 4.0.3 (Build 363) Using Spyware Definitions 569
8:43 PM: |··· End of Session, Monday, November 07, 2005 ···|
********
5:12 PM: |··· Start of Session, Monday, November 07, 2005 ···|
5:12 PM: Spy Sweeper started
5:12 PM: Sweep initiated using definitions version 492
5:12 PM: Starting Memory Sweep
5:12 PM: Warning: Failed to check file "C:\WINDOWS\system32\k2800clmefqa0.dll". Cannot open file "C:\WINDOWS\system32\k2800clmefqa0.dll". The process cannot access the file because it is being used by another process
5:13 PM: Memory Sweep Complete, Elapsed Time: 00:00:36
5:13 PM: Starting Registry Sweep
5:13 PM: Registry Sweep Complete, Elapsed Time:00:00:05
5:13 PM: Starting Cookie Sweep
5:13 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
5:13 PM: Starting File Sweep
5:15 PM: File Sweep Complete, Elapsed Time: 00:01:54
5:15 PM: Full Sweep has completed. Elapsed time 00:02:40
5:15 PM: Traces Found: 0
8:37 PM: Program Version 4.0.3 (Build 363) Using Spyware Definitions 492
8:37 PM: |··· End of Session, Monday, November 07, 2005 ···|
********
10:51 AM: |··· Start of Session, Monday, November 07, 2005 ···|
10:51 AM: Spy Sweeper started
10:51 AM: Sweep initiated using definitions version 492
10:51 AM: Starting Memory Sweep
10:51 AM: Warning: Failed to check file "C:\WINDOWS\system32\l2r0lc9m1f.dll". Cannot open file "C:\WINDOWS\system32\l2r0lc9m1f.dll". The process cannot access the file because it is being used by another process
10:52 AM: Memory Sweep Complete, Elapsed Time: 00:00:36
10:52 AM: Starting Registry Sweep
10:52 AM: Found Adware: clearsearch
10:52 AM: HKU\S-1-5-21-849630295-849363746-335434035-1006\software\microsoft\internet explorer\new windows\allow\ || 69.28.210.175 (ID = 651415)
10:52 AM: Found Adware: searchtoolbar
10:52 AM: HKU\S-1-5-21-849630295-849363746-335434035-1006\software\{12ee7a5e-0674-42f9-a76b-000000004d00}\ (3 subtraces) (ID = 686768)
10:52 AM: Registry Sweep Complete, Elapsed Time:00:00:06
10:52 AM: Starting Cookie Sweep
10:52 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
10:52 AM: Starting File Sweep
10:54 AM: File Sweep Complete, Elapsed Time: 00:01:55
10:54 AM: Full Sweep has completed. Elapsed time 00:02:41
10:54 AM: Traces Found: 5
2:03 PM: Removal process initiated
2:03 PM: Quarantining All Traces: clearsearch
2:03 PM: Quarantining All Traces: searchtoolbar
2:03 PM: Removal process completed. Elapsed time 00:00:01
2:03 PM: Deletion from quarantine initiated
2:03 PM: Processing: clearsearch
2:03 PM: Processing: searchtoolbar
2:03 PM: Deletion from quarantine completed. Elapsed time 00:00:00
5:12 PM: Program Version 4.0.3 (Build 363) Using Spyware Definitions 492
5:12 PM: |··· End of Session, Monday, November 07, 2005 ···|
********
10:51 AM: |··· Start of Session, Monday, November 07, 2005 ···|
10:51 AM: Spy Sweeper started
10:51 AM: Program Version 4.0.3 (Build 363) Using Spyware Definitions 492
10:51 AM: |··· End of Session, Monday, November 07, 2005 ···|