This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Analyze Hijackthis Logfile

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is the new logfile from version 1.99.1:


Logfile of HijackThis v1.99.1
Scan saved at 7:29:43 PM, on 3/16/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\OPERA\OPERA.EXE
C:\PROGRAM FILES\ENZIP\ENZIP.EXE
C:\WINDOWS\TEMP\_ENZTMP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.superwebsearch.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Opera
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {D5C778F1-CF13-4E70-ADF0-45A953E7CB8B} - (no file)
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O8 - Extra context menu item: Download with &FD - fdiectx.htm
O8 - Extra context menu item: Download &All by FD - fdiectx2.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/284f32af774994172001/…ip/RdxIE601.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotion…ctor/WebSWK.cab
Hello sunsession, Welcome to TomCoyote forum. If you still want help then please follow these directions. Check Zone Alarm to see if it needs an update.

1) HJT is running from a Temp folder and must have a permanent folder to store backups for safety: C:\WINDOWS\TEMP\_ENZTMP\HIJACKTHIS.EXE Return to where the HJT.exe is, and point to a blank spot and RIGHT click then then make a NEW FOLDER, call it HJT. Move the HJT.exe into that folder. It will then look like this: C:\Windows\HJT\HJT.exe. Here is aditional information if you need it: http://russelltexas.com/malware/faqhijackthis.htm It may not be safe to proceed without doing this. Once this is done, you may delete all files in the Temp folder (NOT THE FOLDER) just the files.

2) Download CWShredder from the following link. Save it to your Desktop, then open it and update first, then click on FIX not scan. Allow it to remove anything it locates and let me know what it found in the next post.

3) Scan with HJT and put a check in front of each of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.superwebsearch.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - {D5C778F1-CF13-4E70-ADF0-45A953E7CB8B} - (no file)
O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/284f32af774994172001/…ip/RdxIE601.cab
Netster

Close all programs but HJT and all browser windows then click on "Fix Checked"

We need to clean, try this free utility to do this: http://www.ccleaner.com/

Empty the recycle bin and restart the computer. Stay in this thread and post a new log, include the information I asked for and any comments you have.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Thank you for your reply. There is no sign of HJT.exe anywhere in my Windows Temp folder. A search for the file turned up nothing. I should mention that I have it as a ZIP icon on my desktop. I used the "Find" feature from the start button and could not locate the file, either .exe or .zip. How do I get the program into that safe permanent folder before proceding with your instructions? BTW, I am using the Opera browser, although IE6 is installed, if that makes any difference. Ken
OK Ken, follow these instructions. Delete the file on the desktop then search once more to make sure you have no instance of HJT.exe on your computer, make sure you are searching the whole computer.
Once you are assured there is no version, zipped or otherwise that can confuse matters, and I should point out I left you a link above that will explain this same thing, then I want you to go to the first level of your C drive. Once there, point your mouse to a blank spot and RIGHT click the mouse then make a NEW FOLDER. Name this folder HJT. The folder will look like this C:\HJT\ and it will be empty. Now go here: http://www.malwareremoval.com/downloads.html Scoll down a little until you see this: 2. Also available as a exe download from HijackThis Then click on HijackThis. When asked what to do choose Save this file now, when you have to choose where to save it, in the Save in box at the top, locate the folder you created by browsing to it and make sure C:\HJT\ is in that Save in box, then click ok. You will then have this: C:\HJT\HijackThis.exe and all will be well for saving backups and logs. Once you reach this point, then continue with the balance of the directions.
I hope this helps
pskelley
OK, I followed all instructions. When I did the first HJT scan you asked for, only 3 of the items you said to check for deletion appeared on the scan. I only checked these items that corresponded EXACTLY to what you indicated. Also, the CW Shredder report indicated "Cool Web Search was not found on this system." Here is the very latest HJT log:


Logfile of HijackThis v1.99.1
Scan saved at 11:27:48 AM, on 3/20/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\WINDOWS\SYSTEM\FPDISP4A.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Opera
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [FinePrint Dispatcher v4] C:\WINDOWS\SYSTEM\fpdisp4a.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O8 - Extra context menu item: Download with &FD - fdiectx.htm
O8 - Extra context menu item: Download &All by FD - fdiectx2.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotion…ctor/WebSWK.cab
OK Ken, To keep you informed, this line: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank is being pick up as CWS by my scan. It very well might be seeing the words about:blank and misreading them, I am pointed to this information: http://www.doxdesk.com/parasite/CoolWebSearch.html and to be sure, I will always request a CWShredder scan to be sure the infection is not present, especially since CWS has the ability to morph. I would like you to look at this.
Go to Internet Explorer > Tools > Internet Options > under the General Tab please make sure your Home Page is set in the address line and you are not running either Default or Use Blank. Thanks.

Besides the above issue, which may not be an issue at all, your log appears clean of malware. I see you mention that some items were no longer there when you got to the removal instructions. I would be interested in what was gone if you can remember and what was left you had to remove with HJT. It is interesting in that the only thing you appear to have run prior to following those HJT instruction was CWShredder. If it did not find CWS then what removed the lines? Perhaps the Intermute tool does more than remove CWS? I wish to point out that this line in the first log:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.superwebsearch.com/ie/
Was also read as CWS by my scanner. I would appreciate any feedback you can give me as it may help with the CWS fix for some other member.

I will give you the All Clean message so you can start looking over the advice in an effort to keep you clean. I will leave this post open for several days in the event you wish to respond and if anything else rears an ugly head.
Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Good luck and safe surfing
Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you get help here consider a donation:
http://tomcoyote.com/donate.php
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
I redid the scan and sure enough, the line you mention, ending in "about:blank" was there. I must have missed it the first time, so I did delete it. I think the reason that the scan I did for you differed from the original scan I posted is because several days went by while I was waiting for a response from this board. I'm in one of my frenzied clean-up periods so I probably used some other utility that I read about which apparently removed some of the items on the original HJT log. I don't think it was any special properties of CWS. As you suggested, I went to IE tools,etc and changed the blank home page to a homepage URL. The R1 item, with "superwebsearch.com" was listed and deleted. After going through all of this, and thinking about ZoneAlarm, SpyBot, etc etc, it seems that no matter how much progress we make in what amounts to making the sum total of human knowledge available to everyone without having to leave the house, it all comes down to look at everything we have to do to protect ourselves from each other. Pretty sad…. One last question, how frequently should I run CWShredder and CCleaner? Thanks for your help. Ken
Ok Ken, Thanks for that information. I will mention this…the tool CWShredder was purchased by intermute from the creator who also created HJT. There is still an older version 1.59.1 that was not purchased that we still find works better for some versions of CWS. Sometimes I will run them both and sometimes in the safe mode. There are so many varieties of CWS. Many versions especially the A:B varities of which there are many do not even respond to CWShredder and other complex fixes are constantly being developed by folks I work with who have abilities far beyond mine. The link I am providing will take you to lots of information you just have to click around through the links at the site. I have both versions tucked away on my C drive and I keep the Intermute product updated. Certain infections actually block your ability to download the tools you need to fight them. I rarely run CWShredder, usually when I do it is just to refresh my memory when answering questions from infected members. So there is no schedule for running it, lets hope you never need it. You may delete it or you may do as I have, just update it now and then. I hope this answers that question.
http://www.spywareinfo.com/~merijn/downloads.html

Now for CCleaner, I must tell you that it is just one of great new tools available. http://www.igorshpak.net/ is another and until recently I myself had been using "cleanmgr" which is part of windows and an old freeware program which went to shareware called CleanDisk2002. At the suggestion of a associate I decided to try CCleaner after I did a good cleaning and thought the job was done. I was very impressed with the product and have been offering it as a suggested utility for the several weeks since. I suggest you do a little research here: http://www.ccleaner.com/ looking at FAQ's and Help for suggestions about how often to run the utility. My clean may not be the same as yours…lol.

I hope this information helps,
Phil Skelley
I think I have another problem. Based on what I read in someone else's post, I think I may have a fake "System Tray" entry checked on the Start Up page of my System Configuration Utility. It says "System Tray" and to the right, where a full file extension should be, it only says "Sys Tray.Exe" There is no other listing for System Tray on the Start Up page. Is this the real one? Thanks. Ken
Ken, Be careful when you look at other folks logs. You may be looking at another operating system entirely. Your entry for systray or systray.exe in your log: C:\WINDOWS\SYSTEM\SYSTRAY.EXE is in the proper position for Windows 98SE. http://www.liutilities.com/products/wintas…ibrary/systray/ and you have only the one entry in the log. If your computer is running well, then there will be enough problems in the future without looking for them. I will look at another log if you wish, but if your computer is running ok now, I would not be concerned with this.

pskelley
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI