This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log help

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I cannot seem to find the file you are referring to and i unchecked hide file extensions for known file types, hide protected operating system files (recommended) and i even made it show hidden files incase that was the problem but i still cant find it.
OK,

If you need to restore anything we remove with HJT, just open HJT > View the List of Backups and select the one you want to restore.

Almost 100% of the time when I cant find info about a file, its bad.

Remove this entry with HJT,

O4 - HKLM\..\Run: [lejodltA] C:\WINDOWS\lejodltA.exe

Reboot and run the free online scan from Panda, it wont clean anything but will give us a nice report. Post the report into your next reply.

Panda ActiveScan <<
The rest of your log looks good :thumbup:

Ken :D
heres the report. Note H:\ is a my old harddrive that i only use to keep movie files on and other things i didnt wanna lose/save when i got a new harddrive. Incident Status Location Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\nst00a\Cookies\[removed][1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\nst00a\Cookies\nst00a@advertising[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\nst00a\Cookies\[removed][1].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\nst00a\Cookies\nst00a@atdmt[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\nst00a\Cookies\nst00a@belnk[1].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\nst00a\Cookies\nst00a@casalemedia[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\nst00a\Cookies\[removed][2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\nst00a\Cookies\nst00a@doubleclick[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\nst00a\Cookies\nst00a@fastclick[2].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\nst00a\Cookies\[removed][1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\nst00a\Cookies\nst00a@questionmarket[2].txt Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\nst00a\Cookies\[removed][2].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\nst00a\Cookies\nst00a@zedo[1].txt Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\nst00a\Desktop\VirtumundoBeGone.exe[²ƒÇ] Adware:Adware/CommAd Not disinfected C:\WINDOWS\bnN0MDA\vBhXgGE.vbs Adware:adware/dollarrevenue Not disinfected C:\WINDOWS\keyboard1.dat Potentially unwanted tool:Application/Restart Not disinfected C:\WINDOWS\system32\Tools\Restart.exe Spyware:Cookie/Hbmediapro Not disinfected H:\Documents and Settings\Administrator\Cookies\[removed][2].txt Spyware:Cookie/Belnk Not disinfected H:\Documents and Settings\Administrator\Cookies\[removed][2].txt Spyware:Cookie/Atwola Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@atwola[1].txt Spyware:Cookie/Azjmp Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@azjmp[1].txt Spyware:Cookie/Belnk Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@belnk[1].txt Spyware:Cookie/Ccbill Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@ccbill[1].txt Spyware:Cookie/Cgi-bin Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@cgi-bin[1].txt Spyware:Cookie/Belnk Not disinfected H:\Documents and Settings\Administrator\Cookies\[removed][1].txt Spyware:Cookie/Entrepreneur Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@entrepreneur[1].txt Spyware:Cookie/Rn11 Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@rn11[2].txt Spyware:Cookie/Searchportal Not disinfected H:\Documents and Settings\Administrator\Cookies\[removed][1].txt Spyware:Cookie/Tucows Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@tucows[1].txt Spyware:Cookie/Xiti Not disinfected H:\Documents and Settings\Administrator\Cookies\administrator@xiti[1].txt
We installed Killbox , run it the same way except be sure to change it to ALL FILES,

C:\WINDOWS\bnN0MDA\vBhXgGE.vbs
C:\WINDOWS\keyboard1.dat
C:\WINDOWS\system32\Tools\Restart.exe


Highlight all the files with the complete path in the quote and press Ctrl C on your keyboard.
  • Open Pocket Killbox
  • Go to File > Paste from clipboard
  • Set it to Delete on Reboot
  • Tick the box that says End Explorer shell while killing file
  • If its not greyed out..Click the radio button that say Unregister .dll before deleting.
  • Make sure ALL Files is selected
  • Click on the Red circle with the white X
  • It will ask you to confirm the deletion…Say yes
  • It will ask you to reboot, say yes


This may do it, post one last HJT log and lets make sure.

Ken :D
Im wondering can i start installing some of the programs "securing your PC after a attack" thread.

heres the log and thx again for all your help

Logfile of HijackThis v1.99.1
Scan saved at 4:20:56 PM, on 9/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\AgentSvc.exe
C:\WINDOWS\system32\Agent\agent40.bin
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\nst00a\Desktop\hijackthis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 -noicon
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServicesOnce: [Geto] C:\GetoMan\Client\Verman.exe
O4 - HKLM\..\RunServicesOnce: [Geto Plus] C:\GetoMan\Client\VerMan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158228711437
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0C2C3E9-D0CA-487F-9E31-EBA0F4A13095}: NameServer = 206.13.29.12,206.13.30.12
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Geto Agent Service (GetoAgent) - Unknown owner - C:\WINDOWS\system32\AgentSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
leeter,

Log looks fine :thumbup:


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.

TonyKlein CastleCops
Grinler BleepingComputer
Geeks To Go


Glad things are well, thanks for stopping by Tom Coyote.

Ken :D
Not a problem, it was my pleasure to help you :thumbup:

Here is my own list for you to ponder.



Here are some free programs and tips for keeping your system up to date, and to help keep all the riff raff out of your system.

Be sure to follow the instructions for System Restore because everything we removed is backed up in that program and if you ever use it to revert your system to an earlier date, you can reinfect your self all over again.


Download and Install CCleaner

* Click on Run Cleaner
* Run the Issues Scan < When it asks you to backup the Registry..Say Yes Tutorial for CCleaner


Now that your clean, we need to erase all possible older infected files that may still be lurking on your system.

* Clean out your Temp Files
* This procedure should be run from Safemode for better results.


Boot into Safemode

* Go to Start> Shut off your Computer> Restart
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the Up and Down Arrow Keys to scroll up to Safemode
* Then press the Enter Key on your Keyboard




* Go to My Computer/ C: Drive/ Documents and Settings/ Every User on this Computer Local Settings and delete all the contents of the Temp Folder and the Temporary Internet Files Folder <–Just the contents, not the folder itself.

* Go to My Computer/ C:/ Windows/ Temp and delete all the contents of the Temp Folder <– But not the temp folder itself.

* Go to My Computer/ C:/ Windows/ Prefetch and remove all the contents of the Prefetch Folder. <–But not the Prefetch folder itself.



Reboot your system normally


Close any instance of Internet Explorer and Windows Explorer.
  • Go to Start> Control Panel> Internet Options . You shoud be on the General Tab
  • Delete Cookies
  • Delete Files > and offline content as well

Now Empty your Recycle Bin


System Restore makes regular backups of all your settings, if you ever had to use this program to restore your
system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Reboot your System

Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
  • Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
    You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this


Make sure that your ANTI-VIRUS SOFTWARE is up to date and run a full scan at least once aweek.

Here are Free Anti-Virus Programs if you need one. Just install one because with AV software…MORE IS NOT BETTER.
* AVG Free Edition
* AntVir Personal Edition


* Spybot Search and Destroy 1.4
Check for Updates/ Immunize and run a Full System Scan on a regular basis.

* Ad-Aware SE Personal 1.06
Check for Updates and run a Full System Scan on a regular basis.

* Spyware Blaster It will prevent most spyware from ever being installed.

* Spyware Guard It offers realtime protection from spyware installation attempts.

* Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.

* IE- Spyad IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.

* Firefox Browser It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.

* Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.

* Windows Updates Go to Start> Control Panel> Security Center> Windows Updates and check the radio button that says " Notify me but don't automatically download and install them "

* Go to Start> All Programs> Assessories > System Tools> Disk Defragmenter. This is the Windows Disk Defragger, run this maybe once or twice a month to keep your system running good. The first time you run it, it may take awhile.



Ken :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI