This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Vers.1.98_beta3 -is This A Valid File?

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I received a zip file called HijackThis vers 1.98_beta3 :scratch: from someone at Merijn.org on 5/24/2004 in response to a question I had about CWShredder. I was asking someone at Merijn.org to help me with the problem I had experienced last May 17th which I posted (about blank malware) in this forum and received no reply. Question 1: is HJT vers1.98_beta3 a valid file? Question 2: Could someone please review the HJT logfile I posted last May 17 under "about blank malware?" I know you guys are busy and this is strictly voluntary. So, if no one can help me, please tell me how to uninstall both versions of HJT from my computer? Thanks much!

Question 1: is HJT vers1.98_beta3 a valid file?

The newest version that I know of is 1.97.7


Could someone please review the HJT logfile I posted last May 17 under



A lot could have happened sence then post another log . please follow the steps below.


Scanning in Spybot Search and Destroy:


1. Downloaded and Install Spybot S&D, accepting the Default Settings

2. In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.

3. Close ALL windows except Spybot S&D

4. Click the button to ‘Search for Updates’ and download and install the Updates.

5. Next click the button ‘Check for Problems’

6. When Spybot is complete, it will be showing ‘RED’ (RED) entries ‘BLACK’ entries and ‘GREEN’ (GREEN) entries in the window

7. Make certain there is a check mark beside all of the RED (RED) entries ONLY.

8. Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED (RED) entries.

9. REBOOT to complete the scan.


Scanning in Ad-Aware :

1. Download and Install Ad-Aware , keeping the default options. However you will need to change some of the settings before your first scan

2. Close ALL windows except Ad-Aware

3. Go to Start > Programs > Lavasoft and click on AdAware 6 to open the program

4. Look at the icons on the top right of the page and click on the ‘world’ and let AdAware update the spyware reference list

5. Once the update is finished click on the ‘Gear’ icon (second from the left) to access the preferences/settings window

1) In the ‘General’ window make sure the following are selected:

*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

2) Click on the ‘Scanning’ button on the left and select :

*Scan Within Archives
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file

3)Under ‘Click here to select drives + folders’, choose:

*All of your hard drives

4) Click on the ‘Advanced’ button on the left and select:

*Include additional process information
*Include additional file information
*Include environment information
*Include additional object details

5) Click the ‘Tweak’ button and select:

6)Under the ‘Scanning Engine’:

*Unload recognized processes during scanning
*Include basic Ad-aware settings in logfile
*Include additional Ad-aware settings in logfile

7)Under the ‘Cleaning Engine’:

*Let Windows remove files in use at next reboot


6. Click on ‘Proceed’ to save the settings.

7. Click ‘Start’

*on the next screen choose ‘Activate in-depth Scan’ at the bottom of the page
*then choose:'Use Custom Scanning Options'

8. Click ‘Next’ and AdAware will scan your hard drive(s) with the options you have selected and clean automatically. .

9. Save the log file when it asks and then click ‘finish’

10. REBOOT to complete the removal of what Ad-Aware found

Finally after running both Spybot SD and Ad-Aware

Let's have a look at a HijackThis Log.

Download HijackThis.zip
When downloading, choose "save to disk" and NOT open!


Now create a new folder for it, C:\Hijackthis, for example.
After you the file to C:\Hijack This, you'll end up with the file itself, which is Hijackthis.exe, and that's the one you'll need to doubleclick.'

When the program launches, hit the "Scan" button
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, and save the log anywhere you like.

Now if you doubleclick the log file, does it open in Notepad?

If so, go to Edit > Select all, then to Edit > copy.
Now you've copied the entire text to the Windows Clipboard (this happens behind your back.)

Next, go back to this forum thread, and click "Post Reply".
In an empty area click your RIGHT mouse button, and choose 'Paste' from the context menu.
And there's your Hijack This log. DO NOT Delete or modify anything yet,
as some of it is needed to keep your system in Good Shape.

The last time you post it was in a temporary folder,
Hijackthis cannot create backup files while it is being run from a
temporary folder.
Thanks much, little eagle. I do have Spybot S&D, Adaware, CWShredder, and Spywareblaster. I also have NIS. I check for updates to all the mentioned software daily. In addition I scan my computer before shutting it down.

Since the HJT file that I received from Merijn.org is not valid, would you kindly give me instructions to uninstall that version from my computer? Dummy me, I trusted the source and extracted the file. It now lives in my Program Files.

I am very grateful for your help.

I ran the HJT ver 1.97.7 and here's the log:

Logfile of HijackThis v1.97.7
Scan saved at 8:45:24 PM, on 6/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\EarthLink 5.0\ConMgr.exe
C:\Program Files\EarthLink 5.0\updatemgr.exe
C:\WINDOWS\DELLMMKB.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\mrtMngr.EXE
C:\Program Files\Netropa\OSD.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\EarthLink 5.0\FastLane\ARUpld32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis197.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.earthlink.net/partner/more/msie…ton/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.earthlink.net/partner/more/msie…ton/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.dellnet.com/
R3 - Default URLSearchHook is missing
O1 - Hosts: 172.16.120.12 amhphost # Informix
O1 - Hosts: 172.16.120.11 Arden999 Arduhost
O1 - Hosts: 172.16.120.14 VSEHost
O1 - Hosts: 172.16.120.15 amsrv01
O1 - Hosts: 172.16.140.11 gel9200
O1 - Hosts: 172.16.130.11 gel0999
O1 - Hosts: 172.16.120.17 AMSRV02
O1 - Hosts: 172.16.120.8 amsrv03
O1 - Hosts: 172.16.120.6 amsrv04
O1 - Hosts: 172.16.120.7 amsrv05
O1 - Hosts: 172.16.120.21 amsrv06
O1 - Hosts: 172.16.120.30 amsrv07
O1 - Hosts: 172.16.120.143 amsrv09
O1 - Hosts: 172.16.120.144 amsrv10
O1 - Hosts: 172.16.130.13 gmsrv01
O1 - Hosts: 172.16.130.15 gmsrv02
O1 - Hosts: 172.16.140.15 gmdc01
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [UpdateMgr.exe] "C:\Program Files\EarthLink 5.0\updatemgr.exe" /NOCM
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\PC Magazine Utilities\Spybot - Search & Destroy\SpybotSD.exe" /autoclose
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://c:\windows\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\windows\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\windows\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\windows\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…8009.7809027778
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{52309D55-0A3D-41FC-81F5-7AA726D548B8}: NameServer = 207.69.188.185 207.69.188.187
HijackThis 1.98 beta 3 is a valid file and has been in use for several months now as a beta version (it is very stable). HJT 1.98 is due out in the next couple of weeks as the replacement for 1.97.7 . The version you have is an improvement on 1.97.7 hope this helps!
Thanks so much, dgosling. You have no idea how relieved I am to hear this. By some chance, did you see anything in the HJT log that looks unusual that would cause adaware to find an about blank malware each time I go to tools/internet options/about blank? Also, when I try to set my start page to about blank, it changes to Earthlink's startpage. Yet, in the other sessions about blank remains as the start page. Hope you can help me.
I am not understanding you I don't think. Your browser start and search pages are set to Earthlink. Your local start page is set to blank. I assume you have set this yourself in Tools/Internet Options/Use Blank? I don't understand what you mean by AdAware telling you that you have the about:blank malware. These settings are two entirely different things. The first is one you set yourself, the second is a malware infection which I don't see any sign of in your log. Your log is clean. When does AdAware tell you this? AdAware does not run constantly so would not be showing you errors unless you were scanning with it. Perhaps you should post in the AdAware Support forum with an AdAware log and they will be able to help you there. Hope this helps
Thanks for looking at the HJT log. I'm glad to hear that it looks clean. You understood me correctly when I said that my startpage is set to Earthlink's startpage. Everytime I sign on, it comes up. Oftentimes I just prefer to use about blank, so I go to my internet options and change the settings to use about blank. Whenever I've changed my settings myself, prior to shut down, I run scans of Spybot, CWShredder and they both say that my system is clean. I scan with Adaware - bam - it finds 3 about blank malware. This is what is confusing me. I did go to Adaware's forum and apparently I'm not the only one experiencing this problem. Someone suggested excluding about blank - which is not a good suggestion, don't you think? Thanks for you help, dgosling.
This answer is pure speculation but I think AdAware is reacting to your start page having the word 'blank' in it. Often AV products and antispyware products will pick up the text in the name and respond to it. Usually there is a fix shortly afterwards which cures the problem. For instance in AdAware the next ref list will probably cure it. I will give you an example: I had an HJT log that showed a trojan in it a few months ago. I saved the notepad file with the name of the trojan (I don't remember which one it was) but eg: I named it Trojan Agobot.B. My antivirus software immediately came up with a warning and kept forcing me to delete the notepad file. The notepad file was not infected it just had the name of the trojan in it and that's what my AV reacted to. About:Blank will have other ways of AdAware recognizing it, but it may be reacting just to the text in your log file. Another thing that both Spybot and AdAware have a problem with - they react to each others backup files. So if you fixed something with Spybot, AdAware may be detecting what you fixed in the backups for Spybot. It is more common for Spybot to do this than AdAware, but I have seen them both react to the backups. In AdAware, Spybot will react to the quarantined files, in Spybot, AdAware will sometimes react to the backups. If you have no other signs of infection, I wouldn't worry about it. Hope this helps!
Thank you so much for your help, dgosling. I had the feeling that what you described is the case. I haven't had any more problems since I stopped changing my startpage awhile ago. Please keep up the good work. Users like myself really appreciate the help and assistance.
Your Welcome I'm glad we could help!

I am going to close the topic now. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI