This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Help

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ad Aware no longer finds anything, however the explorer browser always comes up "this page can't be displayed". I am unable to access anything via the web. Logfile of HijackThis v1.98.2 Scan saved at 8:49:43 PM, on 9/23/04 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v5.00 (5.00.2614.3500) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\PROGRAM FILES\REALVNC\VNC4\WINVNC4.EXE C:\WINDOWS\EXPLORER.EXE C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\diurc.dll/sp.html#37794 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\diurc.dll/sp.html#37794 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\RunServices: [WinVNC4] "C:\PROGRAM FILES\REALVNC\VNC4\WINVNC4.EXE" -noconsole -service O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0 O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = DOMAIN O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 206.13.28.12,206.13.30.12
Thank you. I now can connect to the web through Firefox. Any suggestions on how to restore IE? CWShredder and Ad Aware can't find anything. Do I need to fix any of the items in the hijack log? It still says "the page cannot be displayed" when I try to use internet explorer.
Since my internet explorer is not working, Windows update won't work. I am running Win 98 and just installed Exporer 6 service pack 1 and one security update. IE is still not working. I'm not sure what to do from here. Here is my latest Hijack log. Logfile of HijackThis v1.98.2 Scan saved at 5:42:48 PM, on 9/26/04 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\PROGRAM FILES\REALVNC\VNC4\WINVNC4.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE C:\WINDOWS\SYSTEM\PSTORES.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\diurc.dll/sp.html#37794 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080 O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\RunServices: [WinVNC4] "C:\PROGRAM FILES\REALVNC\VNC4\WINVNC4.EXE" -noconsole -service O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SPYSWEEPER.EXE" /0 O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = DOMAIN O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 206.13.28.12,206.13.30.12 Any help would be greatly appreciated.
For the following program , I want to make sure it's valid. Right click on it and go to Properties. Then go to the Version tab to see what company name it's from: C:\PROGRAM FILES\REALVNC
It is RealVNC Ltd. It was installed by our network computer co. He accessed it to see if he could fix it. The original problem was the browser start page was always "about blank". It would change the browser page to a MSN search page. I have used several spyware programs. One is called Xoftspy. It finds "C.W.S.Systeminit" it says it removes it, but it doesn't. The log file says" CWS.Systeminit name: Software\Microsoft\Internet Explorer\Main\Use Search Asst:@:no type The other programs I have used are Ad Aware which doesn't find anything now. Spybot S&D which found one called Alexa, Spy Sweeper and CWSShredder says my system is clean. Any help would be greatly appreciated.
Glad we could help. :)

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.
IE worked a couple of times before it started malfuntioning again. When I establish a dial up connection first and then open IE, it can't find the wed address, tries to open autosearch.msn.com and then I get an error message saying that Internet Explorer could not open the search page. When I click ok, it says" Downloading from site: res://C:/WINDOWS/SYSTEM/SHDOCLC.DLL/dnserror.htm.

When I click on IE first, it opens the dialer prompt and will connect to my home page…Yahoo will open (it won't open gif files) but any subsequent web requests states "this page cannot be displayed".

All of the bookmarks refer to http://www.microsoft.com/isapi/redir.dll?…The only bookmarks are the links that are installed in IE6.

I have tried a couple of things: I re-installed IE6..it didn't help. I reverted back to a previous version of IE it didn't help. I have since re-installed IE6. I have run updated versions of Adaware and S&D. The only thing they find is a Alexa related issue.

CWShredder doesn't find anything. I can't tell if I'm still infected or if I possible deleted something through all of this mess. It all started with about:blank. Here is my latest Hijack log:

Logfile of HijackThis v1.98.2
Scan saved at 8:09:18 AM, on 11/7/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = DOMAIN
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 206.13.28.12,206.13.30.12
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = DOMAIN
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 206.13.28.12,206.13.30.12

Could it be a hidden file or do you think IE is corrupt?

I can't access windows update since IE won't work. I do have Firefox which works fine.

Thank you for any suggestions.
I downloaded service filter but when I went to run it a message came up stating it was for Windows 2000 and XP only. I am running Win98.
Please download from the following links:

StartDreck


Unzip and run StartDreck.exe
Hit: -config
hit: -Unmark all
Check these boxes only:
*Registry->run keys
*Registry->Browser helper objects
*System/drivers> Running processes
hit >ok.

Use the "save" tab, to save, name and post the log here in this thread
StartDreck (build 2.1.7 public stable) - 2004-11-08 @ 09:29:12 (GMT -08:00) Platform: Windows 98 SE (Win 4.10.2222 A) Internet Explorer: 6.0.2800.1106 »Registry »Run Keys »Current User »Run »RunOnce »Default User »Run »RunOnce »Local Machine »Run Here it is: »RunOnce »RunServices »RunServicesOnce »RunOnceEx »RunServicesOnceEx »Browser Helper Objects (LM) »Files »System/Drivers »Running Processes +FF0FF10F=C:\WINDOWS\SYSTEM\KERNEL32.DLL +FFFE32D3=C:\WINDOWS\SYSTEM\MSGSRV32.EXE +FFFE3F63=C:\WINDOWS\SYSTEM\MPREXE.EXE +FFFEB80F=C:\WINDOWS\SYSTEM\SPOOL32.EXE +FFFEA8DB=C:\WINDOWS\SYSTEM\mmtask.tsk +FFFE8A73=C:\WINDOWS\EXPLORER.EXE +FFFD3C8B=C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE +FFFC5073=C:\WINDOWS\SYSTEM\RNAAPP.EXE +FFFCB78B=C:\WINDOWS\SYSTEM\TAPISRV.EXE +FFFCF983=C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE +FFFB9D47=C:\WINDOWS\DESKTOP\STARTDRECK.EXE »Application specific

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI