This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Hijacked, Popups Too Many

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

MyIE browser goes to about blank and I get popups for spyware removal. I hve run several spyware removal programs (s&d, adaware 6.0) but no good. I have started using firefox as my main browser, but this has not fixed the root problem. Thanks for your help.
Please post a hijackthis log. When you download it from the site below please make sure that you extract it to its own folder C:/HJT for example. Then close all browser windows and click on scan. Then save log and post a copy here by clicking on "add reply" at the bottom right.

You need an updated version of Hijackthis which you can get from HERE.
Logfile of HijackThis v1.98.2
Scan saved at 5:13:13 PM, on 8/26/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
D:\PROGRAM\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
D:\PROGRAM\MOUSE32A.EXE
D:\PROGRAM\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
D:\BACKUPS\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\TEMP\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\WINDOWS\TEMP\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F1 - win.ini: run=C:\WINDOWS\SYSTEM\cmmpu.exe
O2 - BHO: (no name) - {004A5840-FF59-11d2-B50D-0090271D3FD4} - (no file)
O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\WINDOWS\SPEECH\DRAGON\WEB_IE.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: (no name) - {EE8A6522-C7CD-11D8-924E-8EE8A7F53EED} - C:\WINDOWS\SYSTEM\LENIID.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [LWBMOUSE] D:\Program\MOUSE32A.EXE
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [SpyKiller] D:\Program\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [Spyware Begone] D:\PROGRAM\FREESCAN.EXE -FastScan
O4 - Global Startup: ZoneAlarm.lnk = D:\Program\Zone Labs\ZoneAlarm\zonealarm.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRAM\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRAM\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O13 - WWW. Prefix: http://
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe
O18 - Filter: text/html - {6E316C2A-D4ED-11D8-924E-A019FEE2C1EE} - C:\WINDOWS\SYSTEM\LENIID.DLL
O18 - Filter: text/plain - {6E316C2A-D4ED-11D8-924E-A019FEE2C1EE} - C:\WINDOWS\SYSTEM\LENIID.DLL
Step # 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeeks.com/download4086.html

REBOOT

Step #2

Please download and run Spybot & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

REBOOT

Step # 3

Please do an online scan,

Trend Micro http://housecall.trendmicro.com/housecall/start_corp.asp

Make sure that you choose "fix" or "clean".

Reboot and post a new HiJackThis log. [
Hi, Good news and bad. CWShredder found nothing. Spybot found and fixed DSO Esploit. I was not able to run ADAwareSE. When I ran it, it gave an illegal operation message. I deleted the install and the program folder then rebooted. After that I downloaded again and installed a second time and got the same exception. Housecall was also a failure. I clicked the link and was prompted to get a plugin. I did so and was redirected to a page not found. I closed all windows and started over at the post page several times and was not able to get to the scan. I don't think a new hjt log will be helpful now so I will wait for further instructions. Thanks for your patience. The exception failure was eedfadeH in module at 0000.00000000 all registers listed had a 000 value and at the end it said stack dump
I saw on the housecall page that I needed to be using IE or Netscape. I closed Firefox and opened IE. The page said my security did not allow running active X and would not display properly. I went through the procedure to allow active X several times and each time when I went backto the housecall page I got the same "your security does not allow running active X." I apologize for all the simple, "newbie type" hurdles. Any other suggestions? Thanks again. I am seriously considering replacing my present C drive with a new larger drive and running Linux and Firefox only. Yes, I know that is drastic, but I am frustrated with all that has happened.
Could you please scan again with HJT and POST a new log file to see what was able to be removed so that we can pursue further fixes thanks
Logfile of HijackThis v1.98.2
Scan saved at 4:11:41 PM, on 8/27/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
D:\PROGRAM\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
D:\PROGRAM\MOUSE32A.EXE
D:\PROGRAM\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
D:\BACKUPS\HIJACKTHIS\HIJACKTHIS.EXE

F1 - win.ini: run=C:\WINDOWS\SYSTEM\cmmpu.exe
O2 - BHO: (no name) - {004A5840-FF59-11d2-B50D-0090271D3FD4} - (no file)
O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\WINDOWS\SPEECH\DRAGON\WEB_IE.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [LWBMOUSE] D:\Program\MOUSE32A.EXE
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [SpyKiller] D:\Program\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\Run: [Spyware Begone] D:\PROGRAM\FREESCAN.EXE -FastScan
O4 - Global Startup: ZoneAlarm.lnk = D:\Program\Zone Labs\ZoneAlarm\zonealarm.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRAM\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRAM\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O13 - WWW. Prefix: http://
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe
It appears that the fixes you have done, were successful for some of the malware. The malware is preventing you from using Ad-AwareSE. To continue with the fix please do the following in order:

Step #1

We need to make sure all hidden files are showing so please:
* Open My Computer.
* Select the View menu and click Folder Options.
* Select the View Tab.
* In the Hidden files section select Show all files.
* Click OK.


Step #2

You have two programs on your computer which are known adware. Please see the following web page for information about SpyKiller and Spyware Begone:
Bad Spyware Programs The following website can give you a list of recommended programs to replace the ones we are going to remove:
Safe Programs

Please go to Start > Settings > Control Panel > Add Remove Programs and uninstall both SpyKiller and Spyware Begone.


Step #3

The malware that you have contains a hidden dll file which continually reinstalls the malware each time you reboot. We must find it and then kill it so that we can then kill the rest of the spyware and have the fix successful. Please follow the instructions in order:

There is a small program which we use to find out if there is a hidden file and if so, where it is. Once we have exposed the hidden file then we can start to fix your problem.

1.Download StartDreck. Unzip to a folder of its own and open the program:

Click 'Config'
Click 'Unmark All'

2. Please put a check mark beside the following boxes only:
Under Registry -> Run Keys
Under System/drivers -> Running processes

3. Click 'Ok'.

4. Click 'Save' and select the location to save the log file (if you do not choose, the log will be saved in the folder that the application is in).

5. Open the log where you saved it and select all, then copy the paste the log into this thread using 'Add Reply'.


You will then be given instructions on how to fix the rest of your computer.

Good Luck!
I had previously made hidden files viewable, but checked again. When I went to add/remove programs neither spykiller or Begone were there to select. I searched both C and D using *spy* as my search parameter. All I found was SpywareBegone.ini in D. I also followed the thread listed in the hjt log and still found nothing. D/program/ spykiller and D/program/ freescan.exe and determined neither was there. I ran hjt again to make sure that both entries still came up in the scan, and they did. So, neither spykiller or Begone have had anything done to them. I then followed step #3 and this is the result. I thank you for your continued help and patience. I deleted my name on the "Logged in as Unknown at" line.. Thanks again…………. StartDreck (build 2.1.7 public stable) - 2004-08-27 @ 23:46:49 (GMT -07:00) Platform: Windows 98 SE (Win 4.10.2222 A) Internet Explorer: 6.0.2800.1106 Logged in as Unknown at ********** »Registry »Run Keys »Current User »Run *SpyKiller=D:\Program\SpyKiller\spykiller.exe /startup *Spyware Begone=D:\PROGRAM\FREESCAN.EXE -FastScan »RunOnce »Default User »Run *SpyKiller=D:\Program\SpyKiller\spykiller.exe /startup *Spyware Begone=D:\PROGRAM\FREESCAN.EXE -FastScan »RunOnce »Local Machine »Run *SystemTray=SysTray.Exe *NAV Agent=D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE *Symantec NetDriver Monitor=C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE *ScanRegistry=C:\WINDOWS\scanregw.exe /autorun *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE *TkBellExe=C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot *mdac_runonce=C:\WINDOWS\SYSTEM\runonce.exe *Norton Auto-Protect=D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE /LOADQUIET *LWBMOUSE=D:\Program\MOUSE32A.EXE +OptionalComponents +IMAIL *Installed=1 +MAPI *NoChange=1 *Installed=1 +MAPI *NoChange=1 *Installed=1 »RunOnce »RunServices *SymTray - Norton SystemWorks=C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks" *TrueVector=C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service *ScriptBlocking="C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *SchedulingAgent=mstask.exe »RunServicesOnce »RunOnceEx »RunServicesOnceEx »Files »System/Drivers »Running Processes +FFEF95AB=C:\WINDOWS\SYSTEM\KERNEL32.DLL +FFFFE23F=C:\WINDOWS\SYSTEM\MSGSRV32.EXE +FFFFD54F=C:\WINDOWS\SYSTEM\MPREXE.EXE +FFFFCA8B=C:\WINDOWS\SYSTEM\mmtask.tsk +FFFE356B=C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE +FFFE7AAB=C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE +FFFE8647=C:\WINDOWS\SYSTEM\MSTASK.EXE +FFFD3A13=C:\WINDOWS\EXPLORER.EXE +FFFDD7DB=C:\WINDOWS\SYSTEM\SYSTRAY.EXE +FFFDE14B=D:\PROGRAM\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE +FFFC9457=C:\WINDOWS\SYSTEM\STIMON.EXE +FFFCDAFF=C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE +FFFC8933=D:\PROGRAM\MOUSE32A.EXE +FFFB0CA7=D:\PROGRAM\ZONE LABS\ZONEALARM\ZONEALARM.EXE +FFFA250B=C:\WINDOWS\SYSTEM\WMIEXE.EXE +FFF9AC33=C:\WINDOWS\SYSTEM\DDHELP.EXE +FFF954F7=C:\WINDOWS\SYSTEM\PSTORES.EXE +FFF6CE33=C:\WINDOWS\SYSTEM\SPOOL32.EXE +FFF85CE3=D:\PROGRAM\FIREFOX.EXE +FFF8BD87=C:\PROGRAM FILES\WINZIP\WINZIP32.EXE +FFF8BFB3=C:\WINDOWS\TEMP\STARTDRECK.EXE »Application specific
There is no hidden file showing in that log. Are there other users on this computer? There would be a list of different users in:
C:\Windows\Profiles\ name of user.

There may be one named 'All users' or 'default user'. Please log in to the other accounts one at a time and scan with HijackThis in each account, then POST each log here indicating where it came from so you know where to find what the log indicates.
Your two drives, is one drive partitioned with files on one side and your OS on the other? or are you running two OS's on separate hard drives?

This may be why you are not finding Spyware Begone and Spykiller. This log file does indicate that there is another account which may be 'default user'. To log in to that account in 98SE let Windows boot up to the log in screen and press ESC when it asks for your password. Windows should then load the default user account.

Please post the separate HJT logs here

Good Luck!
Sorry to be such an incompetent boob. There haven't been other users on this comp. I looked in C/windows and found no folder for users. I searched C and D for *user* and got 253 hits. I looked at each one and opened several to see if that was what I was looking for. I didn't find what you have described. A long time ago, I remember seeing an opton that said "log off" with my name on my start menu and I did something that prevented it from reappearing. I don't remember what. As for my drives, originally I purchased a computer that ran 95 with a small single drive. As I progressed thru other machines I upgraded to SE2 and moved that drive as C into each machine with D being my main storage drive. So I have 1 OS and 2 drives. I don't get a password prompt when I boot. Any suggestions on how to get what we need??????????? Thanks again
Sorry for the delay but I had some computer problems last night which prevented me from logging on.

Step#1

Please go to Start > Find and enter C:\Windows\Profiles\ into the box and search for the folders. If you find this folder, please open it and determine what users are listed. Then log into each account and do a HJT log from each user.


Step#2

Next I am going to have you use HJT to remove some entries and see if that solves your problems. Could you also describe what problems you are having now?

1. Scan again with HijackThis (ALL WINDOWS CLOSED EXCEPT HJT)

2. Put a check mark beside each of the following entries in the HJT window


O2 - BHO: (no name) - {004A5840-FF59-11d2-B50D-0090271D3FD4} - (no file)

O4 - HKCU\..\Run: [SpyKiller] D:\Program\SpyKiller\spykiller.exe /startup

O4 - HKCU\..\Run: [Spyware Begone] D:\PROGRAM\FREESCAN.EXE -FastScan

O13 - WWW. Prefix: http://

3. Click 'fix checked'

4. REBOOT to finish removing the entries into SAFE MODE by tapping F8 repeatedly while booting up

5. DELETE the following files:

D:\Program\SpyKiller\spykiller.exe

D:\PROGRAM\FREESCAN.EXE

6. DELETE the following folder:

D:\Program\SpyKiller\ <— this should be a folder named Program Files but doesn't appear to be. Would you please double check to see what the folder Program contains as it may be bad too. Please report back with your findings after deleting SpyKiller

D:\PROGRAM\ <— possible deletion if it is a stand alone folder without other programs in it.


7. REBOOT into normal mode



Step#3

Please go to Start>Programs>Accessories>System Tools > diskclean and run it to remove all temp, temporary internet and recycle bin files


Step#4

Now please run StartDreck again and post the log file


Step#5

Attempt to scan again with Ad-Aware SE and fix anything it finds if successful


Step#6

1. please SCAN again with HJT

2. POST a new log file here in this thread using 'Add Reply' to see if there is anything left to clean.


Good Luck!
Hi again, I'm still not able to find C/windows/profile. I removed the items specified with HJT. The pops-ups have stopped and I can now set my homepage and it stays. When I boot I sometimes have to make 3 to 5 tries at it, but I attribute that to Windoze. When I booted to safe it continually froze when I attempted any operation except mouse movement and after about 6 reboots I let it go to normal mode. I still can not find any files associated with spykiller or Begone except D/program/…..Begone.ini I was not able to locate either of the .exe programs so I am not able to delete them. D/program is my main program file on D. I have right at 1 gig of programs there. I found and deleted about half a meg when I ran diskclean. Here is Startdreck log StartDreck (build 2.1.7 public stable) - 2004-08-29 @ 17:52:15 (GMT -07:00) Platform: Windows 98 SE (Win 4.10.2222 A) Internet Explorer: 6.0.2800.1106 Logged in as Unknown at ************** »Registry »Run Keys »Current User »Run »RunOnce »Default User »Run »RunOnce »Local Machine »Run *SystemTray=SysTray.Exe *NAV Agent=D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE *Symantec NetDriver Monitor=C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE *ScanRegistry=C:\WINDOWS\scanregw.exe /autorun *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE *TkBellExe=C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot *mdac_runonce=C:\WINDOWS\SYSTEM\runonce.exe *Norton Auto-Protect=D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE /LOADQUIET *LWBMOUSE=D:\Program\MOUSE32A.EXE +OptionalComponents +IMAIL *Installed=1 +MAPI *NoChange=1 *Installed=1 +MAPI *NoChange=1 *Installed=1 »RunOnce »RunServices *SymTray - Norton SystemWorks=C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks" *TrueVector=C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service *ScriptBlocking="C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *SchedulingAgent=mstask.exe »RunServicesOnce »RunOnceEx »RunServicesOnceEx »Files »System/Drivers »Running Processes +FFEF996F=C:\WINDOWS\SYSTEM\KERNEL32.DLL +FFFFEEFB=C:\WINDOWS\SYSTEM\MSGSRV32.EXE +FFFFD98B=C:\WINDOWS\SYSTEM\MPREXE.EXE +FFFFC64F=C:\WINDOWS\SYSTEM\mmtask.tsk +FFFE39AF=C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE +FFFE7763=C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE +FFFE8BB7=C:\WINDOWS\SYSTEM\MSTASK.EXE +FFFD1743=C:\WINDOWS\EXPLORER.EXE +FFFDF46F=C:\WINDOWS\SYSTEM\SYSTRAY.EXE +FFFC207B=D:\PROGRAM\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE +FFFCA563=C:\WINDOWS\SYSTEM\STIMON.EXE +FFFCD1F3=C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE +FFFEE873=D:\PROGRAM\MOUSE32A.EXE +FFFB1D5F=D:\PROGRAM\ZONE LABS\ZONEALARM\ZONEALARM.EXE +FFFA1FDF=C:\WINDOWS\SYSTEM\WMIEXE.EXE +FFFD5A13=C:\WINDOWS\SYSTEM\PSTORES.EXE +FFF9DF7F=C:\WINDOWS\SYSTEM\SPOOL32.EXE +FFFBFDA3=D:\BACKUPS\HIJACKTHIS\STARTDRECK\STARTDRECK.EXE »Application specific I will post the HJT in the next lposting because I have to close this to run HJT and I dont want to lose the above info. Thanks so much.
Here is my latest HJt log. Thank you for all your help.


Logfile of HijackThis v1.98.2
Scan saved at 9:20:14 PM, on 8/29/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SYMTRAY.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
D:\PROGRAM\NORTON SYSTEMWORKS\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
D:\PROGRAM\MOUSE32A.EXE
D:\PROGRAM\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
D:\BACKUPS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.foxnews.com/
F1 - win.ini: run=C:\WINDOWS\SYSTEM\cmmpu.exe
O2 - BHO: DgnWebIE - {2843DAC1-05EF-11D2-95BA-0060083493D6} - C:\WINDOWS\SPEECH\DRAGON\WEB_IE.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NAV Agent] D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMANTEC\LIVEUP~1\SNDMON.EXE
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [mdac_runonce] C:\WINDOWS\SYSTEM\runonce.exe
O4 - HKLM\..\Run: [Norton Auto-Protect] D:\PROGRAM\NORTON~1\NORTON~3\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [LWBMOUSE] D:\Program\MOUSE32A.EXE
O4 - HKLM\..\RunServices: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Global Startup: ZoneAlarm.lnk = D:\Program\Zone Labs\ZoneAlarm\zonealarm.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRAM\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRAM\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI