This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Something is wrong

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I use win 98 and am having problems with pop-ups and certain web sites being blocked.

I have used ad-ware and it always finds 30 - 75 problems.

Something is just not right… my kid uses Instant Messenger and wife downloads stupid games and they leave me to fit the problems.

One tell tale problem I have is when I do a scan disk or a defragment it keeps on restarting and my disk space capacity reads "2{00 GB".

Thanks for the help in advance.

Here is my HJT log…

Logfile of HijackThis v1.99.0
Scan saved at 8:21:17 PM, on 9/6/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\AIM\AIM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/index.php
R3 - Default URLSearchHook is missing
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [OEMCLEANUP] C:\windows\OPTIONS\oemreset.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://ns-cncrooks2.wnyric.org/iNotes6.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…/bridge-c18.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/09c2a9f7dfbbd4…ip/RdxIE601.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
Hello BB and welcome to the forum. First your HJT is out of date. Use these instructions to update from within the program: Open HJT > Open the Misc Tools section > Scroll to Check for update online > Follow instructions. If you have a problem with that method, you can download from here: http://www.malwareremoval.com/downloads.html
Make sure your next log is posted with version 1.99.1. Now do this:

1) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp and please do not run it until I ask you to.

2) Download and run this uninstaller: http://www.purityscan.com/uninstall.html

2) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php
The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed.

3) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R3 - Default URLSearchHook is missing
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
see this: http://editor.actrix.co.nz/byarticle/spyw.htm
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
PurityScan/Clickspring adware
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…/bridge-c18.cab
Windows AdTools winad
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/09c2a9f7dfbbd4…ip/RdxIE601.cab
Netster
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab

Close all programs but HJT and all browser windows, then click on "Fix Checked"

4) SHOW HIDDEN FILES: Follow the instructions in the link to enable hidden files for your operating system.
You may wish to reverse this process if you have any concern about anyone getting into these hidden system files.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

c:\windows\scanregw.exe >>> file

5) (Optional, but not a bad idea to check for hidden trojans, if any are locate a2 will remove them free)
Let's check for trojans in case any are hiding, run this free online scan, scan the whole system. Let me know what it finds and the exact name and location of anything it locates but can't remove. You may be asked to install an ActiveX, please do so as this program is safe and it can not run without it.
http://www.windowsecurity.com/trojanscan/

6) Run CCleaner, when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do. Then restart the computer and post a new HJT log using version 1.99.1 in this same thread along with any feedback you have. Let me know how you are running now.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Hello PS

Followed your instructions as best I could.

Ran S&D and AW

I could not find

c:\windows\scanregw.exe >>> file

When I scanned for trojans it found a load of stuff. I could not get a log so copied what I thought was important. Amoung other things it found

Conflict.2\install007.exe
Qdow_as2.dll
Ssk.exe
NULL

Ran cc clraner then hjt…

Logfile of HijackThis v1.99.1
Scan saved at 10:23:06 PM, on 9/14/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/index.php
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Texasholdem Game1] C:\WINDOWS\Texasholdem Game1.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://ns-cncrooks2.wnyric.org/iNotes6.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab



Thanks for yor help!
Hello BB, I'm sorry :( I should have moved the HJT from your desktop. Since it is there I am concerned that logs and backups might get deleted by accident and we may need them. Open your C:\ then RIGHT click a blank spot and make a new folder called HJT. Move the HijackThis.exe from the Desktop to that new folder for safety. Thanks.

First I must point out that this item: O4 - HKLM\..\Run: [Texasholdem Game1] C:\WINDOWS\Texasholdem Game1.exe was not in the first log. If it was installed and just not running, I understand. If someone is downloading new stuff in the middle of our repair efforts, you must put a stop to that. Once I have you clean and give you some information to hopefully help you stay that way, then you can do what you wish…it is afterall your computer. I do want to add that downloading "Free" games without carefully checking first to find out if the download has a history of being bundled with spyware, etc., and without carefully reading the EULA agreement to find out what you are installing may be the fastest way to getting infected there is? Anytime you see "Free" be suspicious.

These items: O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
Were also not in the first log and as you can see, do not belong where they are. Do you know why they are there in this new log. Have you or anyone else made a change to cause this to happen?

When I scanned for trojans it found a load of stuff. I could not get a log so copied what I thought was important. Amoung other things it found

When this scan is complete, if it locates items to be removed, it then gives you the option to use the free version of a2 to remove the offending items, it does not remove the junk until you do this. If you stopped at the point where the junk was located, you need to run that scan again, when you get to the point where it shows stuff that needs to be removed, use the option to download and use a2 to remove them.
Please do this: Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list…" Button.
Save it to your desktop. Copy and paste the contents into your reply.

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Post the programs log and a new HJT log with your feedback/comments about the above information, let me know of any issues, symptoms or error messages (word for word) that you are now receiving.

Thanks…Phil

I will point out that you have enough posts to use personal messages for questions if you wish: http://forums.tomcoyote.org/index.php?showuser=3363
Hello Phil- thanks for your feed back. My orginal HJT log that you saw was made last week. Since then my wife decided to download that poker game. I have printed your last post an taped it on the computer screen… if she won't listen to me maybe she will listen to you.

Did the a-squared thing deleted all that trash.
Rebooted, no error messages.

Ran the "Open Uninstall Manager" below is the log.

3D Frog Frenzy
3dfx Tools and Voodoo3 Display Drivers
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Download Manager (Remove Only)
Adobe Type Manager
AIM Toolbar
AOL Instant Messenger
a-squared Free 1.6
Aureal A3D for Compaq
Built-In Technician
Bushnell ImageView
Carbon Copy 32
Card Games for Windows
CCleaner (remove only)
CeQuadrat just!burn
CeQuadrat PacketCD
Compaq Diagnostics for Windows
Compaq IE Custom
Compaq IE5 Customization
Compaq OOBE Online
Compaq Presario Screen Saver
Compaq WebISP
Compaq WebReg
Compaq Wizard Host Online
Compaq.NET Registration
Conexant HCF V.90/56K Modem
Cookie Washer (AOL)
CPQ Hardware Discovery
DirectX Media Runtime 5.1
Family Tree Maker 2005
Field & Stream® Trophy Bass 3D
Google Toolbar for Internet Explorer
HijackThis 1.99.1
HP DeskJet 830C Series (Remove only)
HP PhotoSmart C200 Photo Imaging Software
HP PhotoSmart Photo Printing Software
HP PrecisionScan LT
Indeo® software
Internet Explorer Q889293
ItalianNow!
Lernout & Hauspie TruVoice American English TTS Engine
Lernout & Hauspie TruVoice for Microsoft Agent
MapSource
MGI VideoWave II (Remove Only)
Microsoft Data Access Components KB870669
Microsoft Internet Explorer 6 SP1 and Internet Tools
Microsoft Money 99
Microsoft Office 2000 Disc 2
Microsoft Office 2000 Professional
Microsoft Outlook Express 6
Microsoft Press Interactive Training
Microsoft VGX Q833989
Microsoft Web Publishing Wizard 1.6
Microsoft Word 2000
Microsoft Works 4.5
MouseWare
Napster v2.0 Beta 5
Nero - Burning Rom (Web installer)
Network Play System (Patching)
Outlook Express Q837009
PhotoSuite 4 (Remove Only)
QuickTime
QuickTime for Windows (32-bit)
RealDownload
RealPlayer
RichFX Player
Running Microsoft Windows 98
Service Connection
Shockwave
Spybot - Search & Destroy 1.4
System Monitor for Windows 98/NT/XP/2000/2003
Terayon DOCSIS Modem
Texasholdem Game1
The Sims 2
The Sims 2 University
The Sims Makin' Magic
Ulead Photo Explorer 4.2
UnInstaller
Universal Media Player
Who Wants To Be A Millionaire Kids Edition
Windows 98 Q823559 Update
Windows 98 Q840315 Update
Windows 98 Q890175 Update
Windows Media Player 7.1
WinZip
ZoneAlarm

Fixed the
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone

problems with HJT

Below is the most newest log.

Logfile of HijackThis v1.99.1
Scan saved at 10:28:23 PM, on 9/15/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/index.php
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Texasholdem Game1] C:\WINDOWS\Texasholdem Game1.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://ns-cncrooks2.wnyric.org/iNotes6.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab

Overall things are working better… but I still have the problem with my disk space capacity still reads "2{00 GB".

What do you see??

Thants for all your help Phil.

BB
Hi BB, Before I look at your new information, we have to fix something, which is the reason for being careful with the backups. Here is what I want you to do:
Open HJT then click on the third button down "View the list of backups" I want you to put a check in the box of this line only:
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun Then click on the "Restore" button. Thanks. Now just to be sure I would like you to use any of these links:
http://virusscan.jotti.org/
http://www.kaspersky.com/scanforvirus
http://www.virustotal.com/flash/index_en.html
To check that file: c:\windows\scanregw.exe and post the results for me.

Feedback on your programs list: I like to start with the fact that this is a good time for you to review what is there. If you have programs that are no longer used, this would be a good time to uninstall them. Make sure not to uninstall anything Microsoft or involving your security. What else I see:
Adobe Acrobat 5.0: IF you use Adobe, it is outdated, version is up to 7.0

AIM Toolbar: you have Google which is the best, if you don't use aol toolbar you might want to uninstall it.

Compaq: I have an older Compaq as one of my backup computers. Some of the Compaq OEM programs no longer work. You will save some disk space if you ask Compaq\HP which ones you can remove. Optional, but they are space wasters, probably don't work and most likely are wasting your resrouces if they are running at startup. Your call.
Nothing else jumps out as malware but I do not know all of those programs.

Your HJT log is clean, here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Overall things are working better… but I still have the problem with my disk space capacity still reads "2{00 GB".

Not sure about this one, try this. I am looking at WinXp so the instructions might vary with Win98. Open MyComputer then right click on the C:\ and choose Properties. On the General Tab see what the Capacity is. I also suggest you click on Tools and as soon as possible check for errors and defrag. With Windows 98 you will benefit much by doing this in safe mode: http://www.bleepingcomputer.com/forums/tutorial61.html
Let me know what the capacity of the drive shows and post one more HJT log for me after you have completed all of these instructions.

Thanks…Phil
Hello Phil- The "O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun" was not listed on the HJT backup list. I did locate the scanregw.exe and checked it on www.kaspersky.com/scanforvirus It said the file was clean. Am working on he other instructions
Phil- I ran into some problems attempting to scan the drive.

1st I cleaned the C:/ by using the "clean disk" tool. Then I rebooted the compter… I got hung up on the reboot and would not get past the opening blue screen with an hour glass on the curser. Had to reboot in safe mode, scaned the disk with the "scandisk" tool. It found errors and fixed them. Rebooted it still hung up. Rebooted it one command at a time and that worked.


Zone alarm pops up and tell mev that WWW.LIENVANDEKELDER.BE.EXE wanted to connect tothe internet. I denyed it access.

I tried a "scan disk" and got a message that could'nt run because something else was running.

I googled "LIENVANDEKELDER.BE.EXE" and McAfee says its a worm-W32/Mytob.ca@MM "This detection is for a mass-mailing worm that combines W32/Mydoom@MM functionality with W32/Sdbot.worm functionality."

I ran HJT. Here is the log….
Logfile of HijackThis v1.99.1
Scan saved at 10:59:07 AM, on 9/17/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\WWW.LIENVANDEKELDER.BE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/index.php
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Texasholdem Game1] C:\WINDOWS\Texasholdem Game1.exe
O4 - HKLM\..\Run: [Lien Van de Kelder] www.lienvandekelder.be.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [Lien Van de Kelder] www.lienvandekelder.be.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://ns-cncrooks2.wnyric.org/iNotes6.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab

I will not go further until I here from you.

Thanks for all your help Phil.
http://www.bleepingcomputer.com/startups/L….exe-10573.html

http://vil.mcafeesecurity.com/vil/content/v_134038.htm
Please read this information especially from here down:
Mail Propagation
The virus arrives in an email message as follows:

This is a new infetion, someone opened an infected email. I can't let this go on forever, a cycle of you and me cleaning and someone coming along behind us to reinfect the computer. Here: Yesterday, 10:44 AM You had a clean HJT log, and now it is infected with Mytob. You must keep the computer offline except while you are working with me. Cut the cord if you have two. I will post what I hope will be removal instuctions for this worm in less than one hour. You get control of that computer or I am afraid we are both wasting our time and I personally do not have it to waste.


Download this free program: http://free.grisoft.com/freeweb.php Update it first then run it, allow it to remove anything it locates. Post a new HJT log at that point. I will review that log and give you additional instruction once it is posted.

Thanks…Phil :)
Phil- I too have better things to do espically on a Saturday. Thanks for your time!

Installed Avg- scanned and found 2 things
1. Trojan Horse Dropper.Small.6.BB - it fix the problem and placed it in the virus vault.

2. WWW.LIENVANDEKELDER.BE.EXE- it identifed it but did not remove it.

Here is the latest HJT Log…


Logfile of HijackThis v1.99.1
Scan saved at 12:23:10 PM, on 9/17/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/index.php
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Texasholdem Game1] C:\WINDOWS\Texasholdem Game1.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [Lien Van de Kelder] www.lienvandekelder.be.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://ns-cncrooks2.wnyric.org/iNotes6.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab

Thanks ! BB
OK BB, wish us luck. One problem is that most of the removal tools do not work on the old 98/ME operating systems, which limits what we can do. We will have a go at this manually and see what happens.
I do want to mention while I am thinking of it, and that is that all of your maintenance tools will run better in safe mode without a lot of programs running. If you need instruction let me know.

This item: C:\WINDOWS\SYSTEM\WWW.LIENVANDEKELDER.BE.EXE was showing in the running programs in the last log. It is not showing in this one. Open Task Manager and look for it and end process on it if there. End process on this item if you see it: C:\WINDOWS\Texasholdem Game1.exe

You may not see all of these but they were running in the log just before the last one, if there, we want to check them:

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O4 - HKLM\..\Run: [Texasholdem Game1] C:\WINDOWS\Texasholdem Game1.exe
O4 - HKLM\..\Run: [Lien Van de Kelder] www.lienvandekelder.be.exe
O4 - HKLM\..\RunServices: [Lien Van de Kelder] www.lienvandekelder.be.exe

Close all programs but HJT and all browser windows, then click on "Fix Checked"
SHOW HIDDEN FILES: Follow the instructions in the link to enable hidden files for your operating system.
You may wish to reverse this process if you have any concern about anyone getting into these hidden system files.
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

C:\WINDOWS\Texasholdem Game1.exe >>> file

C:\WINDOWS\SYSTEM\WWW.LIENVANDEKELDER.BE.EXE >>> file

Now we need to dump every Temp file and Temp Internet File you can find, use this information:
Review the information in the following two links, then rid yourself of all Temp, TIF and Prefetch files.
http://www.personal-computer-tutor.com/deletingtempfiles.htm
http://www.safecomputing.umn.edu/guides/tempdirectories.html
Do not concern yourself with Prefetch, not on your Operating System.

Now run these two free online scans, have them remove, delete or quarantine anything they locate. Note anything they can't, complete name and pathway.
http://housecall.trendmicro.com/housecall/start_corp.asp
http://www.pandasoftware.com/activescan/co…n_principal.htm

Post the logs from the scans and a new HJT log when you are finished.

Thanks, Phil
Phil-followed your instructions.

HJT, Delete files,delete tremp files, ran the online scans.


First Scan Log

Incident Status Location

Adware:adware/wintools No disinfected C:\WINDOWS\SYSTEM\TBPS.ini
Adware:adware/sahagent No disinfected C:\WINDOWS\SYSTEM\SHAgentNew.dlltmp
Spyware:spyware/whazit No disinfected C:\WINDOWS\SYSTEM\fiz1
Adware:Adware/Transponder No disinfected C:\WINDOWS\SYSTEM\c53bFs.dll
Adware:adware/ncase No disinfected C:\WINDOWS\SYSTEM\saieau.dat
Spyware:Spyware/ClientMan No disinfected C:\WINDOWS\SYSTEM\mshfan.dll
Spyware:Spyware/ClientMan No disinfected C:\WINDOWS\SYSTEM\msiaih.dll
Virus:Trj/Imk.A Disinfected C:\WINDOWS\SYSTEM\msnimk.gif
Spyware:Spyware/Omi No disinfected C:\WINDOWS\SYSTEM\msfdje.gif
Adware:adware/portalscan No disinfected C:\WINDOWS\SYSTEM\winupdt.bin
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\INF\BI6.INF
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\INF\BIF.INF
Adware:Adware/BTGrab No disinfected C:\WINDOWS\INF\BTGRAB.INF
Adware:adware/ieplugin No disinfected C:\WINDOWS\Desktop\Desktop Toolbar
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.bak
Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall4_80.exe
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050122-171320.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050120-184037.backup
Adware:Adware/StatBlaster No disinfected C:\WINDOWS\o.bat
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050124-200430.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050122-125528.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050124-200431.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050121-040219.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050124-210831.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050124-210838.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050121-060636.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050121-060710.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050122-071834.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050122-071835.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050122-125529.backup
Virus:Trj/Qhost.Y Disinfected C:\WINDOWS\hosts.20050126-192547.backup
Adware:Adware/StatBlaster No disinfected C:\o.bat
Spyware:Spyware/AdClicker No disinfected C:\web.exe

2nd Scan found and removed several more.

HJT Log
ogfile of HijackThis v1.99.1
Scan saved at 10:08:37 PM, on 9/17/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\STARTER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/index.php
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://ns-cncrooks2.wnyric.org/iNotes6.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab



Thanks! BB
:D BB, at this moment: Scan saved at 10:08:37 PM, on 9/17/05 the HJT log is clean :thumbup: Now you should return to the four links I gave you on Sept. 16, and read what the experts say about how to stay that way. Please understand there are no 100% guarantees. We can put the most sophisticated network of security in place there is and it will not help if users download malware or open email with viruses and trojans in them. A Google will provide loads of information, but unless the online habits of users changes, information will not help:
http://www.google.com/search?sourceid=navc…tay+safe+online

Now let's address the First Scan Log, Incident Status Location: I believe the items that the scanner, and if you did them in the order posted that would be Housecall? is locating bits and pieces of leftover files from your system. Run your CCleaner again, and see what it locates. Make sure your version is v1.23.160 as it was just updated. Under the Windows Tab, check all boxes in the first three catagories except Autocomplete Form History. Leave "Advanced" alone unless you are sure you know how to make those changes, I do not use it.
Under Applications, check all boxes. Run those two areas and remove anything located unless you see something you know is wrong. I never have. Now "Issues", when you run the regcleaner, if it locates items for removal, when you check and then try to remove them you will get a popup window prompting you to backup, always say yes to the backup. You can delete the backups after a week or so. Be sure to right click and delete, if you click to open it, it may be returned to your registry. I am hoping this will clean out some of the fragments shown in the scan. you need not be concerned with the ones the scan was able to: Disinfected The others are the ones we want gone, and I will say again I do not believe they are a problem, just leftover junk from old removals. The only way you will know if they are gone is to search for them item by item or run that same scan again. If you search, make sure you have hidden files enabled or you may never find them. I will take the time to show you these items.

C:\WINDOWS\SYSTEM\TBPS.ini
C:\WINDOWS\SYSTEM\SHAgentNew.dlltmp
C:\WINDOWS\SYSTEM\saieau.dat
C:\WINDOWS\SYSTEM\mshfan.dll
C:\WINDOWS\SYSTEM\msiaih.dll
C:\WINDOWS\SYSTEM\msfdje.gif
C:\WINDOWS\SYSTEM\winupdt.bin
C:\WINDOWS\INF\BI6.INF
C:\WINDOWS\INF\BTGRAB.INF
C:\WINDOWS\NDNuninstall4_80.exe
C:\WINDOWS\o.bat
C:\o.bat
C:\web.exe


**you could also use Killbox to remove these items. Killbox will place a folder on the desktop with deleted items in it called: C:\!Submit folder. You would want to delete that folder after a short period***

Link: http://forum.malwareremoval.com/viewtopic.php?t=320

If you want to remove them manually, you will probably have to be in safe mode:
http://www.bleepingcomputer.com/forums/tutorial61.html with hidden files and folder enabled:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Make sure your Recycle Bin (right click then Properties) DOES NOT have a check in the box "Do not move files to the Recycle Bin. Remove files immediately when deleted. Also make sure you are allow at least 5% for "Maximum size of Recycle Bin"

Now you can safely delete each item and it will be move to the Recycle Bin. After a grace period of say a week then empty the Recycle Bin.

I Can't think of anything else, your thread will stay open for a couple of days if you need it. Good luck to you sir at keeping your computer free of malware.

Safe surfing…Phil :wavey:


Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI