Spyware / Malware / Virus Removal
Logfile for Adware/homepage hijacker
3 min read
Page 1 of 2
Next →
This thread's last reply is from September 9, 2005, 3:12 AM UTC . Advice, software, and links
below may be out of date — treat specific steps and download links with caution.
Looking for the outcome? ✨ Ask AI
Hi:
I have the "About:blank" home page hijacker on my computer along with hard to get rid of pop up ads. Could someone check out my HjT logfile below and advise?
- Oswald
Logfile of HijackThis v1.99.1
Scan saved at 12:53:27 PM, on 8/24/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ESET\NOD32KRN.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\ESET\NOD32KUI.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\MSOFFICE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {85980321-F485-11D9-A0B0-4445D30E090B} - C:\WINDOWS\SYSTEM\HEDF.DLL
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [NOD32kernel] "C:\Program Files\Eset\nod32krn.exe"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O18 - Filter: text/html - {85980320-F485-11D9-A0B0-4445BC42AC90} - C:\WINDOWS\SYSTEM\HEDF.DLL
O18 - Filter: text/plain - {85980320-F485-11D9-A0B0-4445BC42AC90} - C:\WINDOWS\SYSTEM\HEDF.DLL
Hi:
Here's a fresh HjT log:
Logfile of HijackThis v1.99.1
Scan saved at 4:10:26 PM, on 9/6/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ESET\NOD32KRN.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\ESET\NOD32KUI.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\MSOFFICE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {85980321-F485-11D9-A0B0-4445D30E090B} - C:\WINDOWS\SYSTEM\HEDF.DLL
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [NOD32kernel] "C:\Program Files\Eset\nod32krn.exe"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O18 - Filter: text/html - {85980320-F485-11D9-A0B0-4445BC42AC90} - C:\WINDOWS\SYSTEM\HEDF.DLL
O18 - Filter: text/plain - {85980320-F485-11D9-A0B0-4445BC42AC90} - C:\WINDOWS\SYSTEM\HEDF.DLL
Download CW-Shredder at the link below: (don't run it yet)
http://cwshredder.net/bin/CWShredder.exe
Download 'SpSeHjfix'. into a folder. (don't run it yet)
http://www.derbilk.de/SpSeHjfix109.zip
Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:
Temporary Files
Temporary Internet Files
Recycle Bin
Make sure you know how to boot into - SafeMode
Reboot into safe mode.
Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.
Now run the Shredder - Hit The FIX button!
Reboot and repeat the process above.
Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'
OK, got that done - here's the logs:
Logfile of HijackThis v1.99.1
Scan saved at 7:27:53 PM, on 9/6/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ESET\NOD32KRN.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\PROGRAM FILES\ESET\NOD32KUI.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\MSOFFICE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [NOD32kernel] "C:\Program Files\Eset\nod32krn.exe"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
(9/6/05 6:44:54 PM) SPSeHjFix started v1.09
(9/6/05 6:44:55 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 6:44:55 PM) Language: english
(9/6/05 6:45:03 PM) Disinfect started
(9/6/05 6:45:03 PM) Bad-Dll(IEP): (not found)
(9/6/05 6:45:03 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 6:45:03 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\HEDF.DLL
(9/6/05 6:45:03 PM) Searchassistant Uninstaller - Keys Deleted
(9/6/05 6:45:03 PM) UBF: 6
(9/6/05 6:45:03 PM) UBB: 2
(9/6/05 6:45:03 PM) FilterKey: HKCR\text/html (deleted)
(9/6/05 6:45:03 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(9/6/05 6:45:03 PM) FilterKey: HKCR\CLSID\{85980320-F485-11D9-A0B0-4445BC42AC90} (deleted)
(9/6/05 6:45:03 PM) FilterKey: HKCR\text/plain (deleted)
(9/6/05 6:45:03 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(9/6/05 6:45:03 PM) FilterKey: HKCR\CLSID\{85980320-F485-11D9-A0B0-4445BC42AC90} (error while deleting)
(9/6/05 6:45:03 PM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85980321-F485-11D9-A0B0-4445D30E090B} (deleted)
(9/6/05 6:45:03 PM) BHO-Key: HKCR\CLSID\{85980321-F485-11D9-A0B0-4445D30E090B} (deleted)
(9/6/05 6:45:03 PM) UBR: 12
(9/6/05 6:45:03 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(9/6/05 6:45:03 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(9/6/05 6:45:03 PM) Stealth-String not found:
(9/6/05 6:45:03 PM) File added to delete: c:\windows\system\hedf.dll
(9/6/05 6:45:03 PM) File added to delete: c:\windows\system\hedf.dll
(9/6/05 6:45:03 PM) File added to delete: c:\windows\temp\se.dll
(9/6/05 6:45:04 PM) Reboot
(9/6/05 6:48:04 PM) SPSeHjFix 2nd Step
(9/6/05 6:48:05 PM) RunServicesOnce-Key: (edited)
(9/6/05 6:48:20 PM) Cleaned
(9/6/05 7:01:38 PM) SPSeHjFix started v1.09
(9/6/05 7:01:38 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 7:01:38 PM) Language: english
(9/6/05 7:01:42 PM) Disinfect started
(9/6/05 7:01:42 PM) Bad-Dll(IEP): (not found)
(9/6/05 7:01:42 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 7:01:42 PM) UBF: 4
(9/6/05 7:01:42 PM) UBB: 1
(9/6/05 7:01:42 PM) UBR: 11
(9/6/05 7:01:42 PM) Bad IE-pages:
(9/6/05 7:01:42 PM) Stealth-String not found:
(9/6/05 7:01:42 PM) Not infected->END
(9/6/05 7:05:13 PM) SPSeHjFix started v1.09
(9/6/05 7:05:13 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 7:05:13 PM) Language: english
(9/6/05 7:05:21 PM) Disinfect started
(9/6/05 7:05:21 PM) Bad-Dll(IEP): (not found)
(9/6/05 7:05:21 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 7:05:21 PM) UBF: 4
(9/6/05 7:05:21 PM) UBB: 1
(9/6/05 7:05:21 PM) UBR: 11
(9/6/05 7:05:21 PM) Bad IE-pages:
(9/6/05 7:05:21 PM) Stealth-String not found:
(9/6/05 7:05:21 PM) Not infected->END
Please boot to safe moe again and run the tools 2 times and then post the logs.
I hope I did this right (I booted to safe mode twice, each time running both scans, and then I rebooted normally and got the log files).
Logfile of HijackThis v1.99.1
Scan saved at 9:46:09 PM, on 9/6/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [NOD32kernel] "C:\Program Files\Eset\nod32krn.exe"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
SPSsehjfix Log:
(9/6/05 6:44:54 PM) SPSeHjFix started v1.09
(9/6/05 6:44:55 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 6:44:55 PM) Language: english
(9/6/05 6:45:03 PM) Disinfect started
(9/6/05 6:45:03 PM) Bad-Dll(IEP): (not found)
(9/6/05 6:45:03 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 6:45:03 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\HEDF.DLL
(9/6/05 6:45:03 PM) Searchassistant Uninstaller - Keys Deleted
(9/6/05 6:45:03 PM) UBF: 6
(9/6/05 6:45:03 PM) UBB: 2
(9/6/05 6:45:03 PM) FilterKey: HKCR\text/html (deleted)
(9/6/05 6:45:03 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(9/6/05 6:45:03 PM) FilterKey: HKCR\CLSID\{85980320-F485-11D9-A0B0-4445BC42AC90} (deleted)
(9/6/05 6:45:03 PM) FilterKey: HKCR\text/plain (deleted)
(9/6/05 6:45:03 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(9/6/05 6:45:03 PM) FilterKey: HKCR\CLSID\{85980320-F485-11D9-A0B0-4445BC42AC90} (error while deleting)
(9/6/05 6:45:03 PM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85980321-F485-11D9-A0B0-4445D30E090B} (deleted)
(9/6/05 6:45:03 PM) BHO-Key: HKCR\CLSID\{85980321-F485-11D9-A0B0-4445D30E090B} (deleted)
(9/6/05 6:45:03 PM) UBR: 12
(9/6/05 6:45:03 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(9/6/05 6:45:03 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(9/6/05 6:45:03 PM) Stealth-String not found:
(9/6/05 6:45:03 PM) File added to delete: c:\windows\system\hedf.dll
(9/6/05 6:45:03 PM) File added to delete: c:\windows\system\hedf.dll
(9/6/05 6:45:03 PM) File added to delete: c:\windows\temp\se.dll
(9/6/05 6:45:04 PM) Reboot
(9/6/05 6:48:04 PM) SPSeHjFix 2nd Step
(9/6/05 6:48:05 PM) RunServicesOnce-Key: (edited)
(9/6/05 6:48:20 PM) Cleaned
(9/6/05 7:01:38 PM) SPSeHjFix started v1.09
(9/6/05 7:01:38 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 7:01:38 PM) Language: english
(9/6/05 7:01:42 PM) Disinfect started
(9/6/05 7:01:42 PM) Bad-Dll(IEP): (not found)
(9/6/05 7:01:42 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 7:01:42 PM) UBF: 4
(9/6/05 7:01:42 PM) UBB: 1
(9/6/05 7:01:42 PM) UBR: 11
(9/6/05 7:01:42 PM) Bad IE-pages:
(9/6/05 7:01:42 PM) Stealth-String not found:
(9/6/05 7:01:42 PM) Not infected->END
(9/6/05 7:05:13 PM) SPSeHjFix started v1.09
(9/6/05 7:05:13 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 7:05:13 PM) Language: english
(9/6/05 7:05:21 PM) Disinfect started
(9/6/05 7:05:21 PM) Bad-Dll(IEP): (not found)
(9/6/05 7:05:21 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 7:05:21 PM) UBF: 4
(9/6/05 7:05:21 PM) UBB: 1
(9/6/05 7:05:21 PM) UBR: 11
(9/6/05 7:05:21 PM) Bad IE-pages:
(9/6/05 7:05:21 PM) Stealth-String not found:
(9/6/05 7:05:21 PM) Not infected->END
(9/6/05 9:41:49 PM) SPSeHjFix started v1.09
(9/6/05 9:41:49 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 9:41:49 PM) Language: english
(9/6/05 9:41:57 PM) Disinfect started
(9/6/05 9:41:57 PM) Bad-Dll(IEP): (not found)
(9/6/05 9:41:58 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 9:41:58 PM) UBF: 4
(9/6/05 9:41:58 PM) UBB: 1
(9/6/05 9:41:58 PM) UBR: 11
(9/6/05 9:41:58 PM) Bad IE-pages:
(9/6/05 9:41:58 PM) Stealth-String not found:
(9/6/05 9:41:58 PM) Not infected->END
(9/6/05 9:49:49 PM) SPSeHjFix started v1.09
(9/6/05 9:49:50 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 9:49:50 PM) Language: english
(9/6/05 9:49:58 PM) Disinfect started
(9/6/05 9:49:58 PM) Bad-Dll(IEP): (not found)
(9/6/05 9:49:58 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 9:49:58 PM) UBF: 4
(9/6/05 9:49:58 PM) UBB: 1
(9/6/05 9:49:58 PM) UBR: 11
(9/6/05 9:49:58 PM) Bad IE-pages:
(9/6/05 9:49:58 PM) Stealth-String not found:
(9/6/05 9:49:58 PM) Not infected->END
(9/6/05 9:55:40 PM) SPSeHjFix started v1.09
(9/6/05 9:55:40 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 9:55:40 PM) Language: english
(9/6/05 9:55:50 PM) Disinfect started
(9/6/05 9:55:50 PM) Bad-Dll(IEP): (not found)
(9/6/05 9:55:50 PM) Bad-Dll(IEP) in BHO: (not found)
(9/6/05 9:55:50 PM) UBF: 4
(9/6/05 9:55:50 PM) UBB: 1
(9/6/05 9:55:50 PM) UBR: 11
(9/6/05 9:55:50 PM) Bad IE-pages:
(9/6/05 9:55:50 PM) Stealth-String not found:
(9/6/05 9:55:50 PM) Not infected->END
(9/6/05 10:03:54 PM) SPSeHjFix started v1.09
(9/6/05 10:03:54 PM) OS: Win98SE A (4.10.67766446)
(9/6/05 10:03:54 PM) Language: english
Scan with hijackthis and put a check beside these lines and choose FIX.
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/space.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
Then reboot and post a new log please.
OK, here's the new one:
Logfile of HijackThis v1.99.1
Scan saved at 10:54:27 PM, on 9/6/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ESET\NOD32KRN.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\PROGRAM FILES\ESET\NOD32KUI.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\MSOFFICE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [NOD32kernel] "C:\Program Files\Eset\nod32krn.exe"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
Looks ok, how is it running?
Siggyx,
My homepage is no longer being overwritten, the pop-ups are gone and java is working again. Everything seems fine. Thank you so much. You have really helped me out in a big way.
Thanks again,
– Ossie
Siggyx,
Just noticed this line in my last log file:
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
PS Gaurd was responsible for all this adware carp** on my computer and installed itself without permission. Should I delete of fix this line?
To ensure PSguard follow the steps in the link below (method #2) to remove it. Then post a new hijackthis log please.
http://www.bleepingcomputer.com/forums/How…aid-t17258.html
Siggyx,
I can't paste all those files (step 10) into killbox. All I get is the first one! Should I cram them all into the little window one directly after another?
- Oss
Yes do them one at a time. Choose delete on reboot after each.
ActiveScan took an eternity; it said it found two spyware items. Here's the new HjT log:
Logfile of HijackThis v1.99.1
Scan saved at 6:31:05 PM, on 9/7/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\ESET\NOD32KRN.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\PROGRAM FILES\ESET\NOD32KUI.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\MSOFFICE.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [NOD32kernel] "C:\Program Files\Eset\nod32krn.exe"
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
Scan with hijackthis and put a hecek beside this line and choose FIX
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Program Files\PSGuard\PSGuard.exe
Then reboot and a new log please.