This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cousins laptop browser hijack at startup

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my cousin's laptop runs Windows 98
When you start the computer, you get some error messages.
RUNDLL - error loading sre.dll system cannot find

Hbcl - performed illegal operation and will be shut down

Spoolsrv32 - performed illegal operation and will be shut down

Internet Explorer than opens and he also has a Vp Chat Browser that also opens.

This is all happening while Windows starts up

Thanks in advance!

Logfile of HijackThis v1.99.1
Scan saved at 8:57:09 PM, on 5/13/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\APOINT\APOINT.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\DSLAUNCH.EXE
C:\WINDOWS\SYSTEM\PELMICED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKSERV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\BATTERYSCOPE\BATMGR.EXE
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PCFMGR.EXE
C:\PALM\HOTSYNC.EXE
C:\PROGRAM FILES\SMC\SMC2532W-B 2.4GHZ HIGH POWER WLAN UTILITY\SMCUTIL.EXE
C:\WINDOWS\DESKTOP\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\WEBSHOTS.SCR
C:\PROGRAM FILES\APOINT\APWHEEL.EXE
C:\WINDOWS\SYSTEM\SVCHST.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HTJ\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://msn.dll/index
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://msn.dll/index
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.morrisonseahorses.org/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = res://msn.dll/index
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\PROGRAM FILES\IPSWITCH\WS_FTP HOME\WSBHO2K0.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5205CA83-C3D2-11D9-8876-08003EA0EA99} - C:\WINDOWS\SYSTEM\DDHB.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AlpsPoint] C:\Progra~1\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [YAMAHA DS-XG Launcher] c:\windows\dslaunch.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [hbcl] C:\WINDOWS\HBCL.EXE
O4 - HKLM\..\Run: [sre] rundll32.exe sre.dll,Register
O4 - HKLM\..\Run: [Startup] WinlogonStartup
O4 - HKLM\..\Run: [VPLACES.EXE] C:\PROGRAM FILES\VPLACES\VPLACES.EXE
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe
O4 - HKCU\..\Run: [WinHost] C:\WINDOWS\SYSTEM\SVCHST.EXE
O4 - Startup: BatteryScope.lnk = C:\Program Files\BatteryScope\Batmgr.exe
O4 - Startup: PowerPanel.lnk = C:\Program Files\PowerPanel\Program\PcfMgr.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Startup: MBLauncher.lnk = C:\Program Files\SONY\Digital Media Park\MBLauncher.exe
O4 - Startup: SMC2532W-B 2.4GHz High Power WLAN Utility.lnk = C:\Program Files\SMC\SMC2532W-B 2.4GHz High Power WLAN Utility\SMCUTIL.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\WINDOWS\Desktop\WinZip\WZQKPICK.EXE
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {B05D2900-BF29-11D9-8876-0800460222F0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {B05D2900-BF29-11D9-8876-0800460222F0} - (no file) (HKCU)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {F57D27AE-CE57-4BC8-B232-EA57747BE5B7} - ms-its:mhtml:file://C:\PATH.MHT!http://195.225.176.5//d//hvyzabl//pbojrwb//rdccbud//fdotjb//US//arct.chm::/painter.dll
O21 - SSODL: Sysctl Desktop Handler - {23456789-0000-0020-0900-00AAFF6D2EA4} - C:\WINDOWS\System32\NTOSV.DLL
Hello whyme. :wavey:

You have several items on your computer which are better removed with automated scanners.


Step 1
Download CWShredder.exe to your desktop from one of these places:

http://www.majorgeeks.com/download.php?det=3019
http://www.intermute.com/spysubtract/cwshr…r_download.html
http://cwshredder.net/bin/CWShredder.exe

Double click on CWShredder.exe to clean up clicking FIX to have it remove all it finds. Reboot when completed.


Step 2
Please download the trial version of Ewido security suite.

Scanning With Ewido:
  • Download and install Ewido security suite.
  • Launch Ewido, there should be an icon on your desktop double-click it.
    • The program will prompt you to update click the OK button
    • The program will now go to the main screen
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update
    • Click on Start
    • The update will start and a progress bar will show the updates being installed.
  • Once the updates are installed reboot the computer into Safe Mode:
    • Restart the computer.
    • As the computer restarts, press and hold down the F8 key until the Windows 98/ME startup menu appears.
    • Choose Safe mode from the startup menu, and then press Enter. Windows starts in Safe mode.
  • Launch Ewido again
    • Click on scanner
    • Make sure the following boxes are checked before scanning:
      • Binder
      • Crypter
      • Archives
  • Click on Start Scan
    • Let the program scan the machine
    • While the scan is in progress you will be prompted to clean files, click OK
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    • Click Save report
    • Save the report to your desktop
  • Reboot the computer.
Step 3
Please download and install Ad-Aware SE and Spybot S&D according to the following instructions. If you already have these programs, please make sure they are the latest version (Ad-Aware SE Personal 1.05, Spybot Search and Destroy 1.3), than run scans as described below.

Scanning With Spybot S&D;:
  • Downloaded and Install Spybot S&D; accepting the Default Settings.
  • In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.
  • Close ALL windows except Spybot S&D.
  • Click the button to ‘Search for Updates’ then download and install the Updates.
  • Next click the button ‘Check for Problems’
  • When Spybot is complete, it will be showing ‘RED’ entries bold 'Black' entries and ‘GREEN’ entries in the window.
  • Make certain there is a check mark beside all of the RED entries ONLY.
  • Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.
  • REBOOT to complete the scan and clear memory.
  • Do not enable Tea Timer until the log is clean as it will prevent the fix from working.
Scanning With Ad-Aware SE:
  • Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan.
  • Close ALL windows except Ad-Aware SE.
  • Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  • Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window.
    • In the ‘General’ window make sure the following are selected in green:
      • Automatically save log-file
      • Automatically quarantine objects prior to removal
      • Safe Mode (always request confirmation)
    • Under Definitions:
      • Prompt to udate outdated definitions - set the number of days
    • Click on the ‘Scanning’ button on the left and select in green :
      • Under Driver, Folders & Files:
        • Scan Within Archives
      • Under Select drives & folders to scan -
        • choose all hard drives
      • Under Memory & Registry: all green
      • Scan Active Processes
      • Scan Registry
      • Deep Scan Registry
      • Scan my IE favorites for banned URL’s
      • Scan my Hosts file
    • Click on the ‘Advanced’ button on the left and select in green:
      • Under Shell Integration:
        • Move deleted files to recycle bin
      • Under Logfile Detail Level: (all green)
        • include addtional object information
        • DESELECT - include negligible objects information
        • include environment information
      • Under Alternate Data Streams:
        • Don't log streams smaller than 0 bytes
        • Don't log ADS with the following names: CA_INOCULATEIT
    • Click the ‘Tweak’ button and select in green:
      • Under the ‘Scanning Engine’:
        • Unload recognized processes during scanning
        • Scan registry for all users instead of current user only
      • Under the ‘Cleaning Engine’:
        • Always try to unload modules before deletion
        • During removal, unload Explorer and IE if necessary
        • Let Windows remove files in use at next reboot
      • Under the Log Files:
        • Include basic Ad-aware SE settings in logfile
        • Include additional Ad-aware SE settings in logfile
        • Please do not check or make green: Include Module list in logfile
  • Click on ‘Proceed’ to save the settings.
  • Click ‘Start’
    • Choose:'Perform Full System Scan'
    • DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  • Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  • If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window.
  • Save the log file when it asks and then click ‘finish’.
  • REBOOT to complete the removal of what Ad-Aware SE found.
Step 4
Run at least two of the following online virus scans making sure to reboot after each one.
  • Allow them to fix anything they find.
  • You need to use Internet Explorer or Netscape browsers.
    Bitdefender
    Pandasoftware
    Trend Micro << Click Auto Clean
    Symantec Security Check << click scan for viruses
    RAV Online Virus Scanner << Enter your e-mail address and click on To continue without subscribing
    McAfee
  • Write down anything that can not be fixed. Include the file name and the path to the file.
Step 5
Prepare your reply
  • Scan with HijackThis and post the new log as a reply to this thread.
  • Post the Ewido report.
  • Post anything that can not be fixed by the online scans.
Ewido won't install…………says it needs Windows 2000 or higher installed on the computer. The laptop is running Windows 98.
My apologies for that. Skip that step and continue with the rest of the scans. Post a new HijackThis log when everything is completed.
Logfile of HijackThis v1.99.1
Scan saved at 6:36:39 PM, on 5/29/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\APOINT\APOINT.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\DSLAUNCH.EXE
C:\WINDOWS\SYSTEM\PELMICED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKSERV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\WINDOWS\HBCL.EXE
C:\WINDOWS\APPLICATION DATA\SASO.EXE
C:\PROGRAM FILES\BATTERYSCOPE\BATMGR.EXE
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PCFMGR.EXE
C:\PALM\HOTSYNC.EXE
C:\PROGRAM FILES\SMC\SMC2532W-B 2.4GHZ HIGH POWER WLAN UTILITY\SMCUTIL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\WEBSHOTS.SCR
C:\PROGRAM FILES\APOINT\APWHEEL.EXE
C:\HTJ\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://msn.dll/index
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://msn.dll/index
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clicksearchclick.com/index.php?aff=9
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = res://msn.dll/index
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\PROGRAM FILES\IPSWITCH\WS_FTP HOME\WSBHO2K0.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: BHOmodObj Class - {7F6828CA-9E42-462C-BC60-418C8144012C} - C:\WINDOWS\SYSTEM\BHOMOD.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AlpsPoint] C:\Progra~1\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [YAMAHA DS-XG Launcher] c:\windows\dslaunch.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [hbcl] C:\WINDOWS\HBCL.EXE
O4 - HKLM\..\Run: [sre] rundll32.exe sre.dll,Register
O4 - HKLM\..\Run: [Startup] WinlogonStartup
O4 - HKLM\..\Run: [VPLACES.EXE] C:\PROGRAM FILES\VPLACES\VPLACES.EXE
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [WinHost] C:\WINDOWS\SYSTEM\SVCHST.EXE
O4 - HKCU\..\Run: [Usaa] C:\WINDOWS\Application Data\saso.exe
O4 - Startup: BatteryScope.lnk = C:\Program Files\BatteryScope\Batmgr.exe
O4 - Startup: PowerPanel.lnk = C:\Program Files\PowerPanel\Program\PcfMgr.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Startup: MBLauncher.lnk = C:\Program Files\SONY\Digital Media Park\MBLauncher.exe
O4 - Startup: SMC2532W-B 2.4GHz High Power WLAN Utility.lnk = C:\Program Files\SMC\SMC2532W-B 2.4GHz High Power WLAN Utility\SMCUTIL.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Microsoft AntiSpyware helper - {B05D2900-BF29-11D9-8876-0800460222F0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {B05D2900-BF29-11D9-8876-0800460222F0} - (no file) (HKCU)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {F57D27AE-CE57-4BC8-B232-EA57747BE5B7} - ms-its:mhtml:file://C:\PATH.MHT!http://195.225.176.5//d//hvyzabl//pbojrwb//rdccbud//fdotjb//US//arct.chm::/painter.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O21 - SSODL: Sysctl Desktop Handler - {23456789-0000-0020-0900-00AAFF6D2EA4} - C:\WINDOWS\System32\NTOSV.DLL



Did 3 online scans


Pandasoftware
Incident Status Location

Adware:Adware/PurityScan No disinfected C:\WINDOWS\APPLICATION DATA\SASO.EXE
Possible Virus. No disinfected C:\WINDOWS\SYSTEM\SVCHST.EXE
Adware:Adware/TopSpyware No disinfected C:\WINDOWS\SYSTEM\SPOOLS~1.EXE
Possible Virus. No disinfected C:\WINDOWS\SYSTEM\SVCHST.EXE
Adware:Adware/PurityScan No disinfected C:\WINDOWS\APPLIC~1\SASO.EXE
Adware:Adware/PurityScan No disinfected C:\windows\TEMP\!update.exe
Adware:Adware/MediaTickets No disinfected Windows Registry
Adware:Adware/Tubby No disinfected C:\WINDOWS\SYSTEM\MTC.ini
Adware:Adware/CWS.Searchmeup No disinfected C:\WINDOWS\loadnew.exe
Adware:Adware/Index-se No disinfected Windows Registry
Adware:Adware/Dloader No disinfected C:\WINDOWS\SYSTEM\intronsad.exe
Adware:Adware/Tubby No disinfected C:\WINDOWS\SYSTEM\MTC.ini
Adware:Adware/SearchExe No disinfected C:\WINDOWS\SYSTEM\PMLHGG.DLL
Adware:Adware/SearchExe No disinfected C:\WINDOWS\SYSTEM\ambjgg.dll
Adware:Adware/TopSpyware No disinfected C:\WINDOWS\SYSTEM\spoolsrv32.exe
Adware:Adware/SearchExe No disinfected C:\WINDOWS\SYSTEM\winjv.dll
Adware:Adware/Trustbid No disinfected C:\WINDOWS\SYSTEM\intronsad.exe
Adware:Adware/BlueScreenWarningNo disinfected C:\WINDOWS\SYSTEM\intffdsronsad.exe
Adware:Adware/Trustbid No disinfected C:\WINDOWS\SYSTEM\win32.exe
Adware:Adware/Index-se No disinfected C:\WINDOWS\SYSTEM32\msn.dll
Adware:Adware/PurityScan No disinfected C:\WINDOWS\TEMP\!update.exe
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\TEMP\ICD1.tmp\MediaTicketsInstaller.ocx
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\TEMP\ICD1.tmp\MediaTicketsInstaller.INF
Adware:Adware/PurityScan No disinfected C:\WINDOWS\Application Data\saso.exe
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\Downloaded Program Files\eied.inf
Adware:Adware/CWS.Searchmeup No disinfected C:\WINDOWS\loadnew.exe
Adware:Adware/SearchExe No disinfected C:\WINDOWS\netob.dll
Adware:Adware/BlueScreenWarningNo disinfected C:\Program Files\Common Files\SYSTEM\Mapi\1033\95\6.dat
Adware:Adware/Trustbid No disinfected C:\Program Files\Common Files\SYSTEM\Mapi\1033\95\5.dat
Adware:Adware/BlueScreenWarningNo disinfected C:\Program Files\vplaces\6.dat


Symantec

c:\Program Files\Common Files\SYSTEM\Mapi\1033\95\5.dat is infected with Backdoor.Trojan
c:\WINDOWS\loadnew.exe is infected with Downloader.Trojan
c:\WINDOWS\SYSTEM\PMLHGG.DLL is infected with Trojan.StartPage
c:\WINDOWS\SYSTEM\ambjgg.dll is infected with Trojan.StartPage
c:\WINDOWS\SYSTEM\gmfk.dll is infected with Trojan.StartPage.M
c:\WINDOWS\SYSTEM\intronsad.exe is infected with Backdoor.Trojan
c:\WINDOWS\SYSTEM\win32.exe is infected with Backdoor.Trojan


Bitdefender

C:\WINDOWS\SYSTEM\BHOmod.dll
C:\WINDOWS\SYSTEM32\ntosv.dll


Thanks for all your help!

Eric
Please save these instructions to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you will not be able to access the Internet. You will need this to copy/paste file paths later in the fix.

Click on this link http://www.downloads.subratam.org/KillBox.zip to download Pocket Killbox by Option^Explicit. Extract it from the zip file to the desktop.ata has been Removed by External Process!" message then just restart manually.

Step 1
Reboot the computer into Safe Mode
  • Restart the computer.
  • As the computer restarts, press and hold down the F8 key until the Windows 98/ME startup menu appears.
  • Choose Safe mode from the startup menu, and then press Enter. Windows starts in Safe mode.

Step 2
Open HijackThis, run a scan, then check the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://msn.dll/index
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://msn.dll/index
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clicksearchclick.com/index.php?aff=9
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = res://msn.dll/index

O2 - BHO: BHOmodObj Class - {7F6828CA-9E42-462C-BC60-418C8144012C} - C:\WINDOWS\SYSTEM\BHOMOD.DLL

O4 - HKLM\..\Run: [hbcl] C:\WINDOWS\HBCL.EXE
O4 - HKLM\..\Run: [sre] rundll32.exe sre.dll,Register
O4 - HKLM\..\Run: [Startup] WinlogonStartup
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\RunServices: [Srv32 spool service] C:\WINDOWS\System\spoolsrv32.exe
O4 - HKCU\..\Run: [WinHost] C:\WINDOWS\SYSTEM\SVCHST.EXE
O4 - HKCU\..\Run: [Usaa] C:\WINDOWS\Application Data\saso.exe

O9 - Extra button: Microsoft AntiSpyware helper - {B05D2900-BF29-11D9-8876-0800460222F0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {B05D2900-BF29-11D9-8876-0800460222F0} - (no file) (HKCU)

O15 - Trusted Zone: *.windupdates.com (HKLM)

O16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {F57D27AE-CE57-4BC8-B232-EA57747BE5B7} - ms-its:mhtml:file://C:\PATH.MHT!http://195.225.176.5//d//hvyzabl//pbojrwb//rdccbud//fdotjb//US//arct.chm::/painter.dll

O21 - SSODL: Sysctl Desktop Handler - {23456789-0000-0020-0900-00AAFF6D2EA4} - C:\WINDOWS\System32\NTOSV.DLL


With all other programs and browsers closed, click fix checked.


Step 3
Please set your computer to show all files.
  • Double-click the My Computer icon on the Windows desktop.
  • Click Folder Options. Select the View Tab.
  • In the Advanced Settings box, under the "Hidden files" folder, click "Show all files".
  • On the View tab, uncheck the "Hide file extensions for known file types" option.
  • Click Yes to confirm. Click OK.
You will need to reverse this process when all steps are done.


Step 4
Double-click on Killbox.exe to run it. Click on Tools < Delete Temp Files.
When that finishes, copy and paste each of the following lines into the Full Path of File to Delete box in Killbox, and click the red button with the white X on it after each. Keep track of any files it tells you either could not be found or could not be deleted, as you'll need those later:

C:\WINDOWS\loadnew.exe
C:\WINDOWS\netob.dll
C:\WINDOWS\HBCL.EXE
C:\WINDOWS\System\spoolsrv32.exe
C:\WINDOWS\SYSTEM\MTC.ini
c:\WINDOWS\SYSTEM\gmfk.dll
C:\WINDOWS\SYSTEM\PMLHGG.DLL
C:\WINDOWS\SYSTEM\ambjgg.dll
C:\WINDOWS\SYSTEM\winjv.dll
C:\WINDOWS\SYSTEM\intronsad.exe
C:\WINDOWS\SYSTEM\intffdsronsad.exe
C:\WINDOWS\SYSTEM\win32.exe
C:\WINDOWS\SYSTEM\SVCHST.EXE
C:\WINDOWS\System32\NTOSV.DLL
C:\WINDOWS\SYSTEM32\msn.dll
C:\WINDOWS\Application Data\saso.exe
C:\WINDOWS\Downloaded Program Files\eied.inf
C:\Program Files\Common Files\SYSTEM\Mapi\1033\95\6.dat
C:\Program Files\Common Files\SYSTEM\Mapi\1033\95\5.dat
C:\Program Files\vplaces\6.dat


For the files that it either couldn't find or couldn't delete, in the killbox again this time, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.


Step 5
You'll need to search for these files with Explorer to delete. They may be in C:\WINDOWS\system32\ or C:\WINDOWS\
(Start > Search > All files and folders > More advanced options place a check in the first three boxes)

sre.dll
WinlogonStartup


If you have any problem deleting these files, reboot into Safe Mode and try again.


Step 6
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread.
Please let us know of any complications you had and how the computer is behaving.
In Step 2 I did not find
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clicksearchclick.com/index.php?aff=9
for Hijack this to fix.

In Step 5 I couldn't find
sre.dll
WinlogonStartup

Except for the VP Browser I am not getting any Error Messages when the computer starts up.
But the Explorer and VP Browser still open on start-up.


Logfile of HijackThis v1.99.1
Scan saved at 11:25:59 PM, on 5/29/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\APOINT\APOINT.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\DSLAUNCH.EXE
C:\WINDOWS\SYSTEM\PELMICED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKSERV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\BATTERYSCOPE\BATMGR.EXE
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PCFMGR.EXE
C:\PALM\HOTSYNC.EXE
C:\WINDOWS\WEBSHOTS.SCR
C:\PROGRAM FILES\SMC\SMC2532W-B 2.4GHZ HIGH POWER WLAN UTILITY\SMCUTIL.EXE
C:\PROGRAM FILES\APOINT\APWHEEL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HTJ\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://c:\windows\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\PROGRAM FILES\IPSWITCH\WS_FTP HOME\WSBHO2K0.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {F2C128C7-D070-11D9-8876-0800427C78FE} - C:\WINDOWS\SYSTEM\KLPBOAA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AlpsPoint] C:\Progra~1\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [YAMAHA DS-XG Launcher] c:\windows\dslaunch.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [VPLACES.EXE] C:\PROGRAM FILES\VPLACES\VPLACES.EXE
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - Startup: BatteryScope.lnk = C:\Program Files\BatteryScope\Batmgr.exe
O4 - Startup: PowerPanel.lnk = C:\Program Files\PowerPanel\Program\PcfMgr.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Startup: MBLauncher.lnk = C:\Program Files\SONY\Digital Media Park\MBLauncher.exe
O4 - Startup: SMC2532W-B 2.4GHz High Power WLAN Utility.lnk = C:\Program Files\SMC\SMC2532W-B 2.4GHz High Power WLAN Utility\SMCUTIL.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab
O18 - Filter: text/html - {F2C128C6-D070-11D9-8876-08002D30DD65} - C:\WINDOWS\SYSTEM\KLPBOAA.DLL
O18 - Filter: text/plain - {F2C128C6-D070-11D9-8876-08002D30DD65} - C:\WINDOWS\SYSTEM\KLPBOAA.DLL
:rant2: Now you have picked up a whole new infection. This is caused by a lack of an antivirus or firewall program.
I recommend downloading and installing the following free programs:
ZoneAlarm Firewall
AVG7 Antivirus.

Be sure to check for updates after installation.


You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.
  • Prepare CWShredder for use:
    • Download CWShredder.
    • Save CWShredder.exe to a convenient location.
    • Please do not do anything with it yet.
  • Prepare SpSeHjfix
    • Download SpSeHjfix from here.
    • Unzip the contents of SpSeHjfix109.zip.
    • Please do not do anything with it yet.
  • Clean out temporary files:
    • Start | Run | type cleanmgr | OK
    • Let it scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
    • Click "OK" to remove them.
    • Click "Yes" to confirm the deletion.

Reboot the computer into Safe Mode
  • Restart the computer.
  • As the computer restarts, press and hold down the F8 key until the Windows 98/ME startup menu appears.
  • Choose Safe mode from the startup menu, and then press Enter. Windows starts in Safe mode.
  • Disconnect from the Internet and Close ALL OPEN PROGRAMS.
    • Run 'SpSeHjfix'. and click on "Start Disinfection".
    • When it's finished it will reboot your machine to finish the cleaning process.
    • The tool creates a log of the fix which will appear in the folder.
  • Run CWShredder:
    • Double-click on CWShredder.exe.
    • Click "Fix ->" and click "OK" at the prompt.
    • CWShredder will scan and clean your system of CWS files.
    • Click "Next->" and then "Exit".
  • Reboot and repeat the process above.
  • Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix' as a reply to this thread.
<=><=><=><=><=><=><=><=><=><=><=><=><=><=><=><=><=><=><=><=><=>

Occasionally after running 'SpSeHjfix' you may have trouble getting Internet Explorer to open, if this is the case - just run the Internet Explorer repair tool or System File Checker.

To repair Internet Explorer on Windows 98:

Go to Start > Run > copy and paste this in > OK > and choose repair IE

rundll32 setupwbv.dll,IE6Maintenance

…or go to your control panels add/remove programs and double click on Microsoft Internet Explorer 6 and Internet Tools > choose Repair IE.

Additional Info
Installed Zone Alarm….will install AVG7 shortly.
Things seem to be running faster now, still have Explorer and VP browser opening on Startup though.

Logfile of HijackThis v1.99.1
Scan saved at 10:37:58 AM, on 5/30/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\APOINT\APOINT.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\DSLAUNCH.EXE
C:\WINDOWS\SYSTEM\PELMICED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKSERV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\BATTERYSCOPE\BATMGR.EXE
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PCFMGR.EXE
C:\PALM\HOTSYNC.EXE
C:\WINDOWS\WEBSHOTS.SCR
C:\PROGRAM FILES\APOINT\APWHEEL.EXE
C:\PROGRAM FILES\SMC\SMC2532W-B 2.4GHZ HIGH POWER WLAN UTILITY\SMCUTIL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HTJ\HIJACKTHIS.EXE

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\PROGRAM FILES\IPSWITCH\WS_FTP HOME\WSBHO2K0.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AlpsPoint] C:\Progra~1\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [YAMAHA DS-XG Launcher] c:\windows\dslaunch.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [VPLACES.EXE] C:\PROGRAM FILES\VPLACES\VPLACES.EXE
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: BatteryScope.lnk = C:\Program Files\BatteryScope\Batmgr.exe
O4 - Startup: PowerPanel.lnk = C:\Program Files\PowerPanel\Program\PcfMgr.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Startup: MBLauncher.lnk = C:\Program Files\SONY\Digital Media Park\MBLauncher.exe
O4 - Startup: SMC2532W-B 2.4GHz High Power WLAN Utility.lnk = C:\Program Files\SMC\SMC2532W-B 2.4GHz High Power WLAN Utility\SMCUTIL.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab





(5/30/05 10:14:46 AM) SPSeHjFix started v1.09
(5/30/05 10:14:46 AM) OS: Win98SE A (4.10.67766446)
(5/30/05 10:14:46 AM) Language: english
(5/30/05 10:14:55 AM) Disinfect started
(5/30/05 10:14:55 AM) Bad-Dll(IEP): se.dll
(5/30/05 10:14:55 AM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\KLPBOAA.DLL
(5/30/05 10:14:55 AM) Searchassistant Uninstaller - Keys Deleted
(5/30/05 10:14:55 AM) UBF: 6
(5/30/05 10:14:55 AM) UBB: 3
(5/30/05 10:14:55 AM) FilterKey: HKCR\text/html (deleted)
(5/30/05 10:14:55 AM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(5/30/05 10:14:55 AM) FilterKey: HKCR\CLSID\{F2C128C6-D070-11D9-8876-08002D30DD65} (deleted)
(5/30/05 10:14:55 AM) FilterKey: HKCR\text/plain (deleted)
(5/30/05 10:14:55 AM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(5/30/05 10:14:55 AM) FilterKey: HKCR\CLSID\{F2C128C6-D070-11D9-8876-08002D30DD65} (error while deleting)
(5/30/05 10:14:55 AM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F2C128C7-D070-11D9-8876-0800427C78FE} (deleted)
(5/30/05 10:14:55 AM) BHO-Key: HKCR\CLSID\{F2C128C7-D070-11D9-8876-0800427C78FE} (deleted)
(5/30/05 10:14:55 AM) UBR: 20
(5/30/05 10:14:55 AM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(5/30/05 10:14:55 AM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\TEMP\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\TEMP\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(5/30/05 10:14:55 AM) Stealth-String found: C:\WINDOWS\JAUTOERP.DAT
(5/30/05 10:14:55 AM) File added to delete: c:\windows\system\klpboaa.dll
(5/30/05 10:14:55 AM) File added to delete: c:\windows\system\klpboaa.dll
(5/30/05 10:14:55 AM) File added to delete: c:\windows\temp\se.dll
(5/30/05 10:14:55 AM) File added to delete: c:\windows\jautoerp.dat
(5/30/05 10:14:55 AM) Reboot
(5/30/05 10:18:47 AM) SPSeHjFix 2nd Step
(5/30/05 10:18:47 AM) RunServicesOnce-Key: (alex)
(5/30/05 10:19:00 AM) Cleaned


(5/30/05 10:19:10 AM) SPSeHjFix started v1.09
(5/30/05 10:19:10 AM) OS: Win98SE A (4.10.67766446)
(5/30/05 10:19:10 AM) Language: english
(5/30/05 10:19:12 AM) Disinfect started
(5/30/05 10:19:12 AM) Bad-Dll(IEP): (not found)
(5/30/05 10:19:12 AM) Bad-Dll(IEP) in BHO: (not found)
(5/30/05 10:19:12 AM) UBF: 4
(5/30/05 10:19:12 AM) UBB: 2
(5/30/05 10:19:12 AM) UBR: 20
(5/30/05 10:19:12 AM) Bad IE-pages:
(5/30/05 10:19:12 AM) Stealth-String found: C:\WINDOWS\JAUTOERP.DAT
(5/30/05 10:19:12 AM) File added to delete: c:\windows\jautoerp.dat
(5/30/05 10:19:12 AM) Reboot
(5/30/05 10:22:25 AM) SPSeHjFix 2nd Step
(5/30/05 10:22:26 AM) RunServicesOnce-Key: (edited)
(5/30/05 10:22:35 AM) Cleaned
The new infection is not entirely gone yet so we need you to run the previous fix again.

Clean out temporary files:
  • Start | Run | type cleanmgr | OK
  • Let it scan your system for files to remove.
  • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
  • Click "OK" to remove them.
  • Click "Yes" to confirm the deletion.

Reboot the computer into Safe Mode
  • Restart the computer.
  • As the computer restarts, press and hold down the F8 key until the Windows 98/ME startup menu appears.
  • Choose Safe mode from the startup menu, and then press Enter. Windows starts in Safe mode.
  • Disconnect from the Internet and Close ALL OPEN PROGRAMS.
    • Run 'SpSeHjfix'. and click on "Start Disinfection".
    • When it's finished it will reboot your machine to finish the cleaning process.
    • The tool creates a log of the fix which will appear in the folder.
  • Run CWShredder:
    • Double-click on CWShredder.exe.
    • Click "Fix ->" and click "OK" at the prompt.
    • CWShredder will scan and clean your system of CWS files.
    • Click "Next->" and then "Exit".
  • Repeat the process above until you get a log like this - 'not infected'

    3-26-05 18:08:05) SPSeHjFix started v1.1.0
    (3-26-05 18:08:05) OS: Win (4.10.2222)
    (3-26-05 18:08:05) Language: svenska
    (3-26-05 18:08:07) Disinfect started
    (3-26-05 18:08:07) Bad-Dll(IEP): (not found)  <——
    (3-26-05 18:08:07) Bad-Dll(IEP) in BHO: (not found) <——
    (3-26-05 18:08:07) UBF: 4
    (3-26-05 18:08:07) UBB: 2
    (3-26-05 18:08:07) UBR: 17
    (3-26-05 18:08:07) Bad IE-pages:
    (3-26-05 18:08:07) Stealth-String not found:  <——
    (3-26-05 18:08:07) Not infected->END  <——

  • Reboot and scan with HijackThis. Check the following:O4 - HKLM\..\Run: [VPLACES.EXE] C:\PROGRAM FILES\VPLACES\VPLACES.EXE
    O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    With all other programs and browsers closed, click fix checked.
  • Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix' as a reply to this thread.
No more browsers opening at start-up. :)


Logfile of HijackThis v1.99.1
Scan saved at 4:44:10 PM, on 5/30/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\APOINT\APOINT.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\DSLAUNCH.EXE
C:\WINDOWS\SYSTEM\PELMICED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\SONY\HOTKEY UTILITY\HKSERV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\BATTERYSCOPE\BATMGR.EXE
C:\PROGRAM FILES\POWERPANEL\PROGRAM\PCFMGR.EXE
C:\PALM\HOTSYNC.EXE
C:\WINDOWS\WEBSHOTS.SCR
C:\PROGRAM FILES\SMC\SMC2532W-B 2.4GHZ HIGH POWER WLAN UTILITY\SMCUTIL.EXE
C:\PROGRAM FILES\APOINT\APWHEEL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HTJ\HIJACKTHIS.EXE

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\PROGRAM FILES\IPSWITCH\WS_FTP HOME\WSBHO2K0.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AlpsPoint] C:\Progra~1\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [YAMAHA DS-XG Launcher] c:\windows\dslaunch.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] PELMICED.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: BatteryScope.lnk = C:\Program Files\BatteryScope\Batmgr.exe
O4 - Startup: PowerPanel.lnk = C:\Program Files\PowerPanel\Program\PcfMgr.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Startup: MBLauncher.lnk = C:\Program Files\SONY\Digital Media Park\MBLauncher.exe
O4 - Startup: SMC2532W-B 2.4GHz High Power WLAN Utility.lnk = C:\Program Files\SMC\SMC2532W-B 2.4GHz High Power WLAN Utility\SMCUTIL.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YPAGER.EXE
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedCon…bin/AvSniff.cab



(5/30/05 10:14:46 AM) SPSeHjFix started v1.09
(5/30/05 10:14:46 AM) OS: Win98SE A (4.10.67766446)
(5/30/05 10:14:46 AM) Language: english
(5/30/05 10:14:55 AM) Disinfect started
(5/30/05 10:14:55 AM) Bad-Dll(IEP): se.dll
(5/30/05 10:14:55 AM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\KLPBOAA.DLL
(5/30/05 10:14:55 AM) Searchassistant Uninstaller - Keys Deleted
(5/30/05 10:14:55 AM) UBF: 6
(5/30/05 10:14:55 AM) UBB: 3
(5/30/05 10:14:55 AM) FilterKey: HKCR\text/html (deleted)
(5/30/05 10:14:55 AM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(5/30/05 10:14:55 AM) FilterKey: HKCR\CLSID\{F2C128C6-D070-11D9-8876-08002D30DD65} (deleted)
(5/30/05 10:14:55 AM) FilterKey: HKCR\text/plain (deleted)
(5/30/05 10:14:55 AM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(5/30/05 10:14:55 AM) FilterKey: HKCR\CLSID\{F2C128C6-D070-11D9-8876-08002D30DD65} (error while deleting)
(5/30/05 10:14:55 AM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F2C128C7-D070-11D9-8876-0800427C78FE} (deleted)
(5/30/05 10:14:55 AM) BHO-Key: HKCR\CLSID\{F2C128C7-D070-11D9-8876-0800427C78FE} (deleted)
(5/30/05 10:14:55 AM) UBR: 20
(5/30/05 10:14:55 AM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(5/30/05 10:14:55 AM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\TEMP\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\TEMP\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(5/30/05 10:14:55 AM) Stealth-String found: C:\WINDOWS\JAUTOERP.DAT
(5/30/05 10:14:55 AM) File added to delete: c:\windows\system\klpboaa.dll
(5/30/05 10:14:55 AM) File added to delete: c:\windows\system\klpboaa.dll
(5/30/05 10:14:55 AM) File added to delete: c:\windows\temp\se.dll
(5/30/05 10:14:55 AM) File added to delete: c:\windows\jautoerp.dat
(5/30/05 10:14:55 AM) Reboot
(5/30/05 10:18:47 AM) SPSeHjFix 2nd Step
(5/30/05 10:18:47 AM) RunServicesOnce-Key: (alex)
(5/30/05 10:19:00 AM) Cleaned




(5/30/05 10:19:10 AM) SPSeHjFix started v1.09
(5/30/05 10:19:10 AM) OS: Win98SE A (4.10.67766446)
(5/30/05 10:19:10 AM) Language: english
(5/30/05 10:19:12 AM) Disinfect started
(5/30/05 10:19:12 AM) Bad-Dll(IEP): (not found)
(5/30/05 10:19:12 AM) Bad-Dll(IEP) in BHO: (not found)
(5/30/05 10:19:12 AM) UBF: 4
(5/30/05 10:19:12 AM) UBB: 2
(5/30/05 10:19:12 AM) UBR: 20
(5/30/05 10:19:12 AM) Bad IE-pages:
(5/30/05 10:19:12 AM) Stealth-String found: C:\WINDOWS\JAUTOERP.DAT
(5/30/05 10:19:12 AM) File added to delete: c:\windows\jautoerp.dat
(5/30/05 10:19:12 AM) Reboot
(5/30/05 10:22:25 AM) SPSeHjFix 2nd Step
(5/30/05 10:22:26 AM) RunServicesOnce-Key: (edited)
(5/30/05 10:22:35 AM) Cleaned


(5/30/05 3:35:24 PM) SPSeHjFix started v1.09
(5/30/05 3:35:24 PM) OS: Win98SE A (4.10.67766446)
(5/30/05 3:35:24 PM) Language: english
(5/30/05 3:35:33 PM) Disinfect started
(5/30/05 3:35:33 PM) Bad-Dll(IEP): (not found)
(5/30/05 3:35:33 PM) Bad-Dll(IEP) in BHO: (not found)
(5/30/05 3:35:33 PM) UBF: 4
(5/30/05 3:35:33 PM) UBB: 2
(5/30/05 3:35:33 PM) UBR: 19
(5/30/05 3:35:33 PM) Bad IE-pages:
(5/30/05 3:35:33 PM) Stealth-String not found:
(5/30/05 3:35:33 PM) Not infected->END


(5/30/05 3:36:07 PM) SPSeHjFix started v1.09
(5/30/05 3:36:07 PM) OS: Win98SE A (4.10.67766446)
(5/30/05 3:36:07 PM) Language: english
(5/30/05 3:36:14 PM) Disinfect started
(5/30/05 3:36:14 PM) Bad-Dll(IEP): (not found)
(5/30/05 3:36:14 PM) Bad-Dll(IEP) in BHO: (not found)
(5/30/05 3:36:14 PM) UBF: 4
(5/30/05 3:36:14 PM) UBB: 2
(5/30/05 3:36:14 PM) UBR: 19
(5/30/05 3:36:14 PM) Bad IE-pages:
(5/30/05 3:36:14 PM) Stealth-String not found:
(5/30/05 3:36:14 PM) Not infected->END


(5/30/05 3:40:33 PM) SPSeHjFix started v1.09
(5/30/05 3:40:33 PM) OS: Win98SE A (4.10.67766446)
(5/30/05 3:40:33 PM) Language: english
(5/30/05 3:40:36 PM) Disinfect started
(5/30/05 3:40:36 PM) Bad-Dll(IEP): (not found)
(5/30/05 3:40:36 PM) Bad-Dll(IEP) in BHO: (not found)
(5/30/05 3:40:36 PM) UBF: 4
(5/30/05 3:40:36 PM) UBB: 2
(5/30/05 3:40:36 PM) UBR: 19
(5/30/05 3:40:36 PM) Bad IE-pages:
(5/30/05 3:40:36 PM) Stealth-String not found:
(5/30/05 3:40:36 PM) Not infected->END
Just these two items left to fix now. The rest of the log appears clean. :)

Open HijackThis, run a scan, then check the following:

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


With all other programs and browsers closed, click fix checked.


I suggest that you get these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
SpywareGuard - Real-time protection from spyware installation attempts
ie-spyad - Puts over 8,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.
a² Free Trojan Remover

Update these regularly.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-virus updated.
As this topic has been resolved, the thread will be closed.

If you need this topic reopened, please request this by sending an email to us at the following link:
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI