This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log help

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I followed all the steps you're supposed to b4 posting a log. A few things came up tho, there is one thing Spytbot SnD couldnt remove called "Command Service". It says cannot remove and it will try to remove on the next restart but even after a restart it cannot remove it. Also Ewido reports that i have "Downloader.Qoologic.bj" which i have removed multiple times but still keeps popping up. When i start up regularly Ewido will pop up with the warning then when i remove it my comp basically locks up and i cant do anything. So right now im on Safe mode with networking. Anyway heres my log

Logfile of HijackThis v1.99.1
Scan saved at 6:25:27 AM, on 9/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\nst00a\Desktop\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.142.202.179:80
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\vrnkr.exe
F2 - REG:system.ini: UserInit=userinit.exe,gntodal.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll (file missing)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [faaxrs] C:\WINDOWS\system32\fivgst.exe reg_run
O4 - HKLM\..\Run: [lejodltA] C:\WINDOWS\lejodltA.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServicesOnce: [Geto] C:\GetoMan\Client\Verman.exe
O4 - HKLM\..\RunServicesOnce: [Geto Plus] C:\GetoMan\Client\VerMan.exe
O4 - HKCU\..\Run: [bwhat] C:\WINDOWS\system32\fivgst.exe reg_run
O4 - HKCU\..\Run: [UpData] C:\WINDOWS\system32\svch0st.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158228711437
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0C2C3E9-D0CA-487F-9E31-EBA0F4A13095}: NameServer = 206.13.29.12,206.13.30.12
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Geto Agent Service (GetoAgent) - Unknown owner - C:\WINDOWS\system32\AgentSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
I Reran all spybot/adaware/ediwo just to be sure. The only thing that keeps coming up thats out of the ordinary is the "command Service" that Spybot cannot remove. Anyway heres the log

Logfile of HijackThis v1.99.1
Scan saved at 1:45:09 PM, on 9/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\AgentSvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\Agent\agent40.bin
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\svch0st.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\nst00a\Desktop\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.142.202.179:80
F2 - REG:system.ini: UserInit=userinit.exe,gntodal.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll (file missing)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [faaxrs] C:\WINDOWS\system32\fivgst.exe reg_run
O4 - HKLM\..\Run: [lejodltA] C:\WINDOWS\lejodltA.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServicesOnce: [Geto] C:\GetoMan\Client\Verman.exe
O4 - HKLM\..\RunServicesOnce: [Geto Plus] C:\GetoMan\Client\VerMan.exe
O4 - HKCU\..\Run: [bwhat] C:\WINDOWS\system32\fivgst.exe reg_run
O4 - HKCU\..\Run: [UpData] C:\WINDOWS\system32\svch0st.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158228711437
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0C2C3E9-D0CA-487F-9E31-EBA0F4A13095}: NameServer = 206.13.29.12,206.13.30.12
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Geto Agent Service (GetoAgent) - Unknown owner - C:\WINDOWS\system32\AgentSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hello Leeter :D

You have a few issues going on that we need to fix. You may want to print this out since we will be offline for part of the fix.



Download and install the 30 day trial of Ewido Anti Spyware to your desktop.
  • Once you have downloaded Ewido Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close Ewido Anti-Spyware <– Do not run the scan yet.




Open HJT Scan Only, close your browser and all open windows, check these entries and click on Fix Checked


F2 - REG:system.ini: UserInit=userinit.exe,gntodal.exe

O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll (file missing)

O4 - HKCU\..\Run: [UpData] C:\WINDOWS\system32\svch0st.exe

O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll








Please download VirtumondoBegone to your desktop.
  • Reboot your computer into Safemode
  • Go to START/ SHUT OF YOUR COMPUTER/ RESTART
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
  • Then press the ENTER KEY ON YOUR KEYBOARD
  • Doubleclick on VirtumundoBeGone.exe and follow the instructions.
  • Do not worry if you see a BLUE SCREEN "Fatal Error" Message, it is normal and expected.
  • When it has finished, reboot and post the log that is created on your desktop called VBG.TXT in your next reply.




  • Launch Ewido-Anti-Spyware by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • Ewido will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close Ewido



Reboot normally





Download Pocket Killbox to your desktop, unzip it to a folder that you can find

C:\WINDOWS\system32\svch0st.exe
C:\WINDOWS\system32\xeymi.dll


Highlight all the files with the complete path in the quote and press Ctrl C on your keyboard.
  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure ALL Files is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes



Run this system cleaner

Please download ATF Cleaner by Atribune. Thank You Atribune :thumbup:
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

Post the log from Vundobegone, the Ewido Report and a new HJT log please.

Ken :D
Thank you for the help Ken, here are the logs [09/22/2006, 0:56:08] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\nst00a\Desktop\VirtumundoBeGone.exe" ) [09/22/2006, 0:56:16] - Detected System Information: [09/22/2006, 0:56:16] - Windows Version: 5.1.2600, Service Pack 2 [09/22/2006, 0:56:16] - Current Username: nst00a (Admin) [09/22/2006, 0:56:16] - Windows is in SAFE mode with Networking. [09/22/2006, 0:56:16] - Searching for Browser Helper Objects: [09/22/2006, 0:56:16] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper) [09/22/2006, 0:56:16] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} () [09/22/2006, 0:56:16] - WARNING: BHO has no default name. Checking for Winlogon reference. [09/22/2006, 0:56:16] - Checking for HKLM\…\Winlogon\Notify\SDHelper [09/22/2006, 0:56:16] - Key not found: HKLM\…\Winlogon\Notify\SDHelper, continuing. [09/22/2006, 0:56:16] - BHO 3: {A5366673-E8CA-11D3-9CD9-0090271D075B} (IeCatch2 Class) [09/22/2006, 0:56:16] - Finished Searching Browser Helper Objects [09/22/2006, 0:56:16] - Finishing up… [09/22/2006, 0:56:16] - Nothing found! Exiting…
——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 2:40:18 AM 9/15/2006 + Scan result: C:\WINDOWS\system32\nodeipproc.dll -> Adware.BHO : No action taken. C:\Documents and Settings\nst00a\Local Settings\Temp\mmxsnet.exe -> Adware.MediaMotor : No action taken. C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : No action taken. H:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : No action taken. C:\WINDOWS\system32\bez6n4r21.exe -> Adware.SearchAssistant : No action taken. C:\WINDOWS\system32\cvn0.exe -> Adware.SearchAssistant : No action taken. C:\WINDOWS\system32\ghynf.exe -> Adware.SearchAssistant : No action taken. C:\WINDOWS\system32bez6n4r21.exe -> Adware.SearchAssistant : No action taken. C:\WINDOWS\system32ghynf.exe -> Adware.SearchAssistant : No action taken. C:\Documents and Settings\nst00a\Local Settings\Temp\temp.frB802 -> Adware.Suggestor : No action taken. C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : No action taken. C:\WINDOWS\system32\n9nyb.exe -> Adware.Suggestor : No action taken. C:\WINDOWS\system32\wfxqhv.exe -> Adware.Suggestor : No action taken. C:\WINDOWS\system32\xeymi.dll -> Adware.Suggestor : No action taken. C:\WINDOWS\system32\zqskw.exe -> Adware.Suggestor : No action taken. C:\fym9bvo.exe -> Downloader.Agent.ala : No action taken. C:\Documents and Settings\nst00a\Local Settings\Temp\!update.exe -> Downloader.PurityScan.cu : No action taken. C:\WINDOWS\ΑрpPatch\rundll.exe -> Downloader.PurityScan.cu : No action taken. C:\WINDOWS\system32\lglke.dat -> Downloader.Qoologic.bj : No action taken. [864] C:\WINDOWS\system32\lpvhjdw.dll -> Downloader.Qoologic.bj : No action taken. C:\WINDOWS\win3208400-1996661.exe -> Downloader.VB.aga : No action taken. C:\visfx500new.exe -> Dropper.Agent.aie : No action taken. C:\Program Files\Internet Explorer\kyzezezov.html -> Hijacker.Small.jf : No action taken. C:\Program Files\Windows Media Player\howyw.html -> Hijacker.Small.jf : No action taken. C:\Documents and Settings\nst00a\Local Settings\Temp\drsmartload180a.exe -> Hijacker.VB.fg : No action taken. C:\Documents and Settings\nst00a\Local Settings\Temp\pre.exe -> Hijacker.VB.lb : No action taken. C:\dfndrfg_7.exe -> Hijacker.VB.ly : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@2o7[1].txt -> TrackingCookie.2o7 : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@cartoonnetwork.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@admarketplace[1].txt -> TrackingCookie.Admarketplace : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@admarketplace[2].txt -> TrackingCookie.Admarketplace : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][2].txt -> TrackingCookie.Adrevolver : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@advertising[1].txt -> TrackingCookie.Advertising : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@burstnet[1].txt -> TrackingCookie.Burstnet : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@com[1].txt -> TrackingCookie.Com : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@com[2].txt -> TrackingCookie.Com : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : No action taken. C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Goclick : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@oewabox[1].txt -> TrackingCookie.Oewabox : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Planetactive : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Popularix : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Realcastmedia : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@edge.ru4[1].txt -> TrackingCookie.Ru4 : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][1].txt -> TrackingCookie.Searchingbooth : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][2].txt -> TrackingCookie.Starware : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][1].txt -> TrackingCookie.Starware : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\nst00a\Cookies\nst00a@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed]-banners[1].txt -> TrackingCookie.Top-banners : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@login.tracking101[2].txt -> TrackingCookie.Tracking101 : No action taken. C:\Documents and Settings\nst00a\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : No action taken. H:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : No action taken. H:\Documents and Settings\Administrator\Cookies\administrator@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken. C:\WINDOWS\SYSC00.exe -> Trojan.VB.tg : No action taken. C:\WINDOWS\uni_eh.exe -> Trojan.VB.tg : No action taken. C:\WINDOWS\unin101.exe -> Trojan.VB.tg : No action taken. ::Report end
Logfile of HijackThis v1.99.1
Scan saved at 2:17:52 AM, on 9/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\AgentSvc.exe
C:\WINDOWS\system32\Agent\agent40.bin
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\nst00a\Desktop\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.142.202.179:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [faaxrs] C:\WINDOWS\system32\fivgst.exe reg_run
O4 - HKLM\..\Run: [lejodltA] C:\WINDOWS\lejodltA.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServicesOnce: [Geto] C:\GetoMan\Client\Verman.exe
O4 - HKLM\..\RunServicesOnce: [Geto Plus] C:\GetoMan\Client\VerMan.exe
O4 - HKCU\..\Run: [bwhat] C:\WINDOWS\system32\fivgst.exe reg_run
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158228711437
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0C2C3E9-D0CA-487F-9E31-EBA0F4A13095}: NameServer = 206.13.29.12,206.13.30.12
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Geto Agent Service (GetoAgent) - Unknown owner - C:\WINDOWS\system32\AgentSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
leeter :D

Your log is looking better but you did not follow my instructions when running Ewido. You have a lot of bad entries that were not removed. I would like you to run it again in Safemode to remove all that bad stuff then post a new Ewido log.

This is what you missed , running it the way you did was like not running it at all.
Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this



You can fix these with HJT, just clutter.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=





Brazil - Comite Gestor Da Internet No Brasil <– Is this your ISP ????


Ken
Ok i ran ewido again, i double checked all the settings to make sure they were as you said. I think the problem was that i didnt run it in safe mode. Also thats not my ISP i think i used a proxy a while back for some reason and i dont remember how to remove it, if its even necessary to remove it. Anyway heres my Ewido and HJT log. Oh one thing after i finished scanning with Ewido i clicked the "reports tab" and the "save reports as" was grayed out, so i went back to the "scanner tab" click on "Save report" then back to the "reports tab" and click on the report that had the date and time i finished scanning the "save report as". I hope thats the report i should be posting ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 6:51:22 AM 9/22/2006 + Scan result: C:\Documents and Settings\nst00a\Cookies\nst00a@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). C:\Documents and Settings\nst00a\Cookies\nst00a@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). C:\Documents and Settings\nst00a\Cookies\nst00a@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). C:\Documents and Settings\nst00a\Cookies\nst00a@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). C:\Documents and Settings\nst00a\Cookies\nst00a@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). C:\Documents and Settings\nst00a\Cookies\nst00a@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). ::Report end
Logfile of HijackThis v1.99.1
Scan saved at 6:55:53 AM, on 9/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\AgentSvc.exe
C:\WINDOWS\system32\Agent\agent40.bin
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\nst00a\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.142.202.179:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [faaxrs] C:\WINDOWS\system32\fivgst.exe reg_run
O4 - HKLM\..\Run: [lejodltA] C:\WINDOWS\lejodltA.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServicesOnce: [Geto] C:\GetoMan\Client\Verman.exe
O4 - HKLM\..\RunServicesOnce: [Geto Plus] C:\GetoMan\Client\VerMan.exe
O4 - HKCU\..\Run: [bwhat] C:\WINDOWS\system32\fivgst.exe reg_run
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158228711437
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0C2C3E9-D0CA-487F-9E31-EBA0F4A13095}: NameServer = 206.13.29.12,206.13.30.12
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Geto Agent Service (GetoAgent) - Unknown owner - C:\WINDOWS\system32\AgentSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
leeter :D

You log is very confusing. :unsure: Are you in Brazil? There are a lot of entries on your log pointing to Brazil.

GetoMan <– Is this a program that you use??


If you no longer use a proxy server, than remove this entry, you can always restore if need be by opening HJT > View the List of Backups and restore whatever you want.

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 200.142.202.179:80




Please download ComboFix by sUBs from either of these two locations

BleepingComputerComboFix
TechSupportForumComboFix
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply along with a new HJT log please.
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
No I'm not from brazil, I'm from California. Also i dont know what geto man is and im not sure how i got it on my computer. Here are the logs. nst00a - 06-09-22 11:19:16.76 Service Pack 2 ComboFix 06.09.23 - Running from: "C:\Documents and Settings\nst00a\Desktop" Command switches used :: ((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log ))))))))))))))))))))))))))))))))))))))))))))))))))) No infected Qoologic files found. Reg entries were fixed (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\kybrdfg_7.exe C:\warebundlenewer.exe C:\WINDOWS\system32\icon_mediamotor.exe C:\WINDOWS\system32\ts_mediamotor.exe C:\WINDOWS\media_motor_bundle.exe C:\WINDOWS\pf78.exe C:\WINDOWS\system32n9nyb.exe C:\Program Files\Common Files\{88FD5D68-0897-1033-1007-050318050001} ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Folders Quarantined: C:\QooBox\Purity\WINDOWS\PPATCH~1 C:\QooBox\Purity\WINDOWS\PPATCH~1\PPATCH~1 ((((((((((((((((((((((((((((((( Files Created from 2006-08-22 to 2006-09-22 )))))))))))))))))))))))))))))))))) 2006-09-14 03:16 22,752 –a—— C:\WINDOWS\system32\spupdsvc.exe 2006-09-14 03:12 18,200 –a—— C:\WINDOWS\system32\wups2.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-09-22 11:19 ——– d——– C:\Program Files\Common Files 2006-09-22 06:54 ——– d——– C:\Program Files\ewido anti-spyware 4.0 2006-09-20 23:42 ——– d——– C:\Program Files\FlashGet 2006-09-18 10:51 ——– d——– C:\Documents and Settings\nst00a\Application Data\AdobeUM 2006-09-18 10:50 ——– d——– C:\Program Files\Common Files\Adobe 2006-09-18 10:50 ——– d——– C:\Documents and Settings\nst00a\Application Data\Adobe 2006-09-18 10:49 875 –a—— C:\Documents and Settings\nst00a\Application Data\AdobeDLM.log 2006-09-18 10:49 0 –a—— C:\Documents and Settings\nst00a\Application Data\dm.ini 2006-09-18 10:49 ——– d——– C:\Program Files\Adobe 2006-09-15 05:38 421 –a—— C:\WINDOWS\eddnj.dll 2006-09-14 21:06 ——– d——– C:\Program Files\MSN Gaming Zone 2006-09-14 21:06 ——– d——– C:\Program Files\Common Files\kziu 2006-09-11 00:47 ——– d—s—- C:\Documents and Settings\nst00a\Application Data\Microsoft 2006-08-22 16:04 ——– d——– C:\Program Files\World of Warcraft 2006-07-28 07:47 176128 –a—— C:\WINDOWS\system32\tnupjebj.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "nwiz"="nwiz.exe /install" "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033 -noicon" "zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay" "lejodltA"="C:\\WINDOWS\\lejodltA.exe" "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservicesonce] "Geto"="C:\\GetoMan\\Client\\Verman.exe" "Geto Plus"="C:\\GetoMan\\Client\\VerMan.exe" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000005 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,e6,00,00,00,00,00,00,00,9a,03,00,00,42,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\ 00,00,04,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{5EA30390-CD35-11D5-B03F-0000E87525D0}"="ACT AgentMonitor" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=hex:91,00,00,00 "NoDriveAutoRun"=hex:00,00,00,00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GM-2003 Agent.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\GM-2003 Agent.lnk" "backup"="C:\\WINDOWS\\pss\\GM-2003 Agent.lnkCommon Startup" "location"="Common Startup" "command"="C:\\WINDOWS\\system32\\Agent\\VerMan.exe " "item"="GM-2003 Agent" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\services] "GetoAgent"=dword:00000002 HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll Completion time: Fri 09/22/2006 11:20:38.45 ComboFix.txt
Logfile of HijackThis v1.99.1
Scan saved at 11:23:03 AM, on 9/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\AgentSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\Agent\agent40.bin
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\nst00a\Desktop\hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [lejodltA] C:\WINDOWS\lejodltA.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServicesOnce: [Geto] C:\GetoMan\Client\Verman.exe
O4 - HKLM\..\RunServicesOnce: [Geto Plus] C:\GetoMan\Client\VerMan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158228711437
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0C2C3E9-D0CA-487F-9E31-EBA0F4A13095}: NameServer = 206.13.29.12,206.13.30.12
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Geto Agent Service (GetoAgent) - Unknown owner - C:\WINDOWS\system32\AgentSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
leeter :D

Sorry for the confusion, that entry for your proxy server that we removed was pointing to Brazil, if you look at the entry in your 017 on HJT, thats pointing to SBC internet services, so your ok in this department.

Geto Agent Service <– Related to Citrix Installation Manager Service :thumbup:


We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.




Your log is looking better, :thumbup: there is just one entry that I cant find any info on. What I would like you to do is to upload it to this site, it only takes a few min, it will give you a report on that file, post the report in your next reply. Use the browse feature and browse to C:\WINDOWS\lejodltA.exe Then click on Submit.


Ken :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI