I am using Win 2000.
I am not able to run regedit (it close short after start).
Also I am not able to use paste (many times).
Also my AntiVir do not start at startup.
I found many entrys in hosts that disables many anti visur sites and so on.
After reading many docs and posts I concentrated of searching for libsysmgr and syslog32 in my registry and after restarting in safe mode I found this in reg file.
I removed all this entry and searched (also system and hidden files) for libsysmgr.exe and syslog32.exe but I DO NOT FOUND any in my file sysrtem.
The last was supprice for me.
After it I restarted in normal mode, but I was not able to run regedit again.
the last step was to download HijackThis .
It also stops to work very short after starting, but I was able (very quick) to save my log file.
I send this output:
Logfile of HijackThis v1.97.7
Scan saved at 8:39:41 AM, on 12/6/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
I:\WINNT\System32\smss.exe
I:\WINNT\system32\winlogon.exe
I:\WINNT\system32\services.exe
I:\WINNT\system32\lsass.exe
I:\WINNT\system32\svchost.exe
I:\WINNT\System32\WBEM\WinMgmt.exe
I:\WINNT\Explorer.EXE
I:\down\vir\HijackThis.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - I:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ATIPTA] I:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Microsoft Office.lnk = I:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://download.macr...ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9EE41BCA-A707-47B1-8C7A-B83FB7D20313}: NameServer = 192.168.1.1
Pls. help me to resolve this problem.