TheTerrorist_75 Posted March 27, 2006 Report Share Posted March 27, 2006 (edited) I have manually removed BDE, Ares, Kaaza and some other old P2P programs plus a few items identified as malware using Google. AdAware found 306 items including remnants of BDE, Lop and CoolWeb. This POS isn't on the Internet yet. There's about 2000 bad registry entries to deal with I have been cleaning the rgistry by hand along with jv16. It had every version of AOL fromn 5.0 to 9.0 plus AIM from AIM95. I deleted a lot of music and game downloads. I am going to transfer Avast over to it shortly. AOL and CallWave need to go along with Real Player. Here's what my log looks like so far. Logfile of HijackThis v1.99.1Scan saved at 9:30:01 PM, on 3/26/06Platform: Windows 98 Gold (Win9x 4.10.1998)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\SYSTEM\KERNEL32.DLLC:\WINDOWS\SYSTEM\MSGSRV32.EXEC:\WINDOWS\SYSTEM\MPREXE.EXEC:\WINDOWS\SYSTEM\SA3DSRV.EXEC:\WINDOWS\SYSTEM\DDHELP.EXEC:\WINDOWS\SYSTEM\mmtask.tskC:\WINDOWS\EXPLORER.EXEC:\WINDOWS\TASKMON.EXEC:\WINDOWS\SYSTEM\SYSTRAY.EXEC:\WINDOWS\SYSTEM\RNAAPP.EXEC:\WINDOWS\SYSTEM\TAPISRV.EXEC:\HJT\HIJACKTHIS.EXER1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America OnlineO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCXO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCXO4 - HKLM\..\Run: [scanRegistry] c:\windows\scanregw.exe /autorunO4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exeO4 - HKLM\..\Run: [systemTray] SysTray.ExeO4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\Run: [Essdc] essdc.exeO4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exeO4 - HKLM\..\Run: [CPQSTUTFIX] C:\Windows\stutfix.exeO4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrSchemeO4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exeO4 - HKLM\..\RunOnce: [instMsi1] rundll32.exe C:\WINDOWS\SYSTEM\advpack.dll,DelNodeRunDLL32 "C:\WINDOWS\Installer\InstMsi0"O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dllO14 - IERESET.INF: START_PAGE_URL=http://www.aol.comO16 - DPF: {45231111-1111-1111-1111-111111113458} - file://C:\WINDOWS\Tempor~1\Content.IE5\WWQGV3EE\epl169[1].cabO16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CABO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cab Edited March 27, 2006 by TheTerrorist_75 Link to post Share on other sites
Matt Posted March 27, 2006 Report Share Posted March 27, 2006 Not too much left on here.Scan with HJT and place a check next to the following items:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America OnlineO14 - IERESET.INF: START_PAGE_URL=http://www.aol.comO16 - DPF: {45231111-1111-1111-1111-111111113458} - file://C:\WINDOWS\Tempor~1\Content.IE5\WWQGV3EE\epl169[1].cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...tup1.0.0.15.cabThen, make sure all broswer windows and other applications are running, and click the Fix Checked button.If you are able to connect the PC to the internet, do the following:Please go HERE to run Panda's ActiveScanOnce you are on the Panda site click the Scan your PC buttonA new window will open...click the Check Now buttonEnter your CountryEnter your State/ProvinceEnter your e-mail address and click sendSelect either Home User or CompanyClick the big Scan Now buttonIf it wants to install an ActiveX component allow itIt will start downloading the files it requires for the scan (Note: It may take a couple of minutes)When download is complete, click on My Computer to start the scanWhen the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report and a new HJT log Link to post Share on other sites
TheTerrorist_75 Posted March 27, 2006 Author Report Share Posted March 27, 2006 (edited) I can't get Panda Active Scan to run. I tried HouseCall but it needs Java and Java 1.05_6 doesn't like Win98 Gold. I downloaded and burned Avast to a CD and loaded it. I was able to connect through dial-up and update it. It has found 3 trojans so far and is still running. I also tried to hook up one of my 98SE drives but Compaq must need certain files on the HDD. It would not recognize the new hard drive with 98SE. I think there is a file I need to download and install to the hard drive. 98 Gold isn't going to cut it. I'm still finding downloaded garbage spread throughout C:.I got rid of AOL through the registry and HJT. Real Player is gone. Most of the major malware is history. There were 8 dialers. I ran jv16 RegCleaner, CCleaner and am now running Registry Healer. There was over 3000 instances of crap in the registry. 15 hours in hades so far. After this scan I am installing Java 1_4_2_11 so I can use HouseCall then I will install SpyBot and see if there are any dregs.I couldn't believe it when I saw the previous owners tax returns in a folder. How could anybody be that stupid to store private data on a PC that wasn't protected. Edited March 27, 2006 by TheTerrorist_75 Link to post Share on other sites
Matt Posted March 27, 2006 Report Share Posted March 27, 2006 If all you can get is Avast to run, post the log it generates. (I'm not sure if it gives you the ability to save a log, but if it does, please post that).Good LuckMatt Link to post Share on other sites
TheTerrorist_75 Posted March 27, 2006 Author Report Share Posted March 27, 2006 (edited) I'll check for logs after Registry Healer finishes. Between that, CCleaner and RegClean there was over 3000 items to be addressed. I am still finding garbage throughout the folders/files. SpyBot found nothing. I also ran C.W.Shredder and it found nothing. I still can't get Panda or HouseCall scans to run. I found updates for 98 FE/Gold and will apply them once I get the registry straightened out. My eyes are bugging out using a 14" monitor that will onlly only operate at 60Hz. This PC isn't very fast. 350MHz Celeron with 128MB RAM. Tweak time.Avast log.3/27/06 7:31:07 AM Default 4294469309 Sign of "Win32:Small-LJ [Trj]" has been found in "c:\WINDOWS\SYSTEM32\sysinit32m.exe\[uPX]" file. 3/27/06 7:33:18 AM Default 4294469309 Sign of "Win32:Dialer-336 [Trj]" has been found in "c:\WINDOWS\internt.exe" file. 3/27/06 7:33:36 AM Default 4294469309 Sign of "Win32:Small-LJ [Trj]" has been found in "c:\WINDOWS\msxmidi.exe\[uPX]" file. AdAware log.ArchiveData(auto-quarantine- 2006-03-26 19-30-24.bckp)Referencefile : SE1R47 24.05.2005======================================================MRU LIST»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[0]=MRU RegReference : .DEFAULT\software\microsoft\clipart gallery\2.0\mrudescriptionobj[1]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication nameobj[2]=MRU RegReference : software\microsoft\direct3d\mostrecentapplication nameobj[3]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication nameobj[4]=MRU RegReference : .DEFAULT\software\microsoft\internet explorer download directoryobj[5]=MRU RegReference : .DEFAULT\software\microsoft\internet explorer\main save directoryobj[6]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\player\recenturllistobj[7]=MRU RegReference : .DEFAULT\software\microsoft\mediaplayer\radio\mrulistobj[8]=MRU RegReference : .DEFAULT\software\microsoft\outlook express\recent stationery listobj[9]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\applets\paint\recent file listobj[10]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\applets\wordpad\recent file listobj[11]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\doc find spec mruobj[12]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\findcomputermruobj[13]=MRU RegReference : .DEFAULT\software\microsoft\windows\currentversion\explorer\runmruBRILLIANTDIGITAL»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[14]=Regkey : clsid\{51958169-d5e3-11d1-aa42-0000e842e40a}obj[15]=Regkey : interface\{67925164-c4b6-11d2-b9c6-0000e84f59a6}obj[16]=Regkey : s3d_auto_fileobj[23]=Regkey : .DEFAULT\software\brilliant digital entertainmentobj[299]=Regkey : .s3dCOMETSYSTEMS»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[17]=Regkey : clsid\{6f2d6a5e-e3e7-4f18-887c-c777650def57}obj[18]=Regkey : clsid\{7f0f5da7-84cb-11d4-8137-00500487b1c5}obj[19]=Regkey : clsid\{827a2ece-d76f-4bcc-82ed-d6a287c11211}obj[20]=Regkey : clsid\{a335d52f-d489-472d-9eaa-d72a40aaf7ca}obj[21]=Regkey : clsid\{c38fc998-3b1b-4f59-a710-5a6c9cf8bd92}obj[38]=RegValue : .DEFAULT\software\microsoft\internet explorer\toolbar\Webbrowser "{fe6bc4ef-5676-484b-88ae-883323913256}"LOP»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[22]=Regkey : protocols\handler\aybobj[300]=Regkey : software\microsoft\downloadmanagerobj[301]=RegValue : software\microsoft\internet explorer\toolbar\shellbrowser "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"ALEXA»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[24]=Regkey : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}obj[25]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "MenuStatusBar"obj[26]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "Script"obj[27]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "clsid"obj[28]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "Icon"obj[29]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "HotIcon"obj[30]=RegValue : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} "ButtonText"obj[31]=RegValue : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"COOLWEBSEARCH»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[32]=RegValue : .DEFAULT\software\microsoft\internet explorer\main "HOMEOldSP"obj[302]=RegValue : software\microsoft\internet explorer\main "Enable Browser Extensions"obj[303]=RegValue : software\microsoft\internet explorer\main "Use Custom Search URL"obj[304]=RegValue : software\microsoft\internet explorer\main "Search Bar"obj[305]=File : C:\WINDOWS\wplog.txtWINDOWS»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[33]=RegData : software\microsoft\windows nt\currentversion\winlogon "Shell"POSSIBLE BROWSER HIJACK ATTEMPT»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[34]=RegData : .DEFAULT\Software\Microsoft\Internet Explorer "SearchURL"EGROUP DIALER»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[35]=Regkey : software\microsoft\windows\currentversion\wintrust\trust providers\software publishing\trust database\0obj[36]=RegValue : software\microsoft\windows\currentversion\wintrust\trust providers\software publishing\trust database\0 "bhhphijojgfcdocagmhjgjbhmieinfap fkjonmkpfpdedpniogpgdebnflofpdcj"obj[37]=RegValue : software\microsoft\windows\currentversion\wintrust\trust providers\software publishing\trust database\0 "ppcimdnnnjbeahepfabjipfginloedkg fhikaj"TRACKING COOKIE»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»obj[39]=IECache Entry : C:\WINDOWS\Cookies\default@doubleclick(1).txtobj[40]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[2].txtobj[41]=IECache Entry : C:\WINDOWS\Cookies\default@flycast(1).txtobj[42]=IECache Entry : C:\WINDOWS\Cookies\default@valueclick[1].txtobj[43]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[44]=IECache Entry : C:\WINDOWS\Cookies\default@mediaplex[2].txtobj[45]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[46]=IECache Entry : C:\WINDOWS\Cookies\default@realmedia[3].txtobj[47]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[1].txtobj[48]=IECache Entry : C:\WINDOWS\Cookies\default@targetnet[1].txtobj[49]=IECache Entry : C:\WINDOWS\Cookies\default@linksynergy[2].txtobj[50]=IECache Entry : C:\WINDOWS\Cookies\default@excite[2].txtobj[51]=IECache Entry : C:\WINDOWS\Cookies\default@bfast[1].txtobj[52]=IECache Entry : C:\WINDOWS\Cookies\default@hitbox[1].txtobj[53]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[54]=IECache Entry : C:\WINDOWS\Cookies\default@gator[1].txtobj[55]=IECache Entry : C:\WINDOWS\Cookies\default@x10[1].txtobj[56]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[57]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[58]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[4].txtobj[59]=IECache Entry : C:\WINDOWS\Cookies\default@flycast[1].txtobj[60]=IECache Entry : C:\WINDOWS\Cookies\default@x10[3].txtobj[61]=IECache Entry : C:\WINDOWS\Cookies\default@iwon[1].txtobj[62]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[63]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[18].txtobj[64]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[7].txtobj[65]=IECache Entry : C:\WINDOWS\Cookies\default@bfast[2].txtobj[66]=IECache Entry : C:\WINDOWS\Cookies\default@adbureau[1].txtobj[67]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[68]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[3].txtobj[69]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[4].txtobj[70]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[71]=IECache Entry : C:\WINDOWS\Cookies\default@hitbox[3].txtobj[72]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[73]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[74]=IECache Entry : C:\WINDOWS\Cookies\default@linksynergy[3].txtobj[75]=IECache Entry : C:\WINDOWS\Cookies\default@valueclick[3].txtobj[76]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[77]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[5].txtobj[78]=IECache Entry : C:\WINDOWS\Cookies\default@casalemedia[2].txtobj[79]=IECache Entry : C:\WINDOWS\Cookies\default@atdmt[2].txtobj[80]=IECache Entry : C:\WINDOWS\Cookies\default@sextracker[6].txtobj[81]=IECache Entry : C:\WINDOWS\Cookies\default@excite[3].txtobj[82]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[14].txtobj[83]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[1].txtobj[84]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[85]=IECache Entry : C:\WINDOWS\Cookies\default@hypercount[1].txtobj[86]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[87]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[88]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[9].txtobj[89]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[6].txtobj[90]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[91]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[92]=IECache Entry : C:\WINDOWS\Cookies\default@mediaplex[1].txtobj[93]=IECache Entry : C:\WINDOWS\Cookies\default@fastclick[1].txtobj[94]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[95]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[11].txtobj[96]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[8].txtobj[97]=IECache Entry : C:\WINDOWS\Cookies\default@mediaplex[4].txtobj[98]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[2].txtobj[99]=IECache Entry : C:\WINDOWS\Cookies\default@admonitor[1].txtobj[100]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[101]=IECache Entry : C:\WINDOWS\Cookies\default@bfast[3].txtobj[102]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[103]=IECache Entry : C:\WINDOWS\Cookies\default@hitbox[6].txtobj[104]=IECache Entry : C:\WINDOWS\Cookies\default@tripod[1].txtobj[105]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[106]=IECache Entry : C:\WINDOWS\Cookies\default@fastclick[2].txtobj[107]=IECache Entry : C:\WINDOWS\Cookies\default@x10[2].txtobj[108]=IECache Entry : C:\WINDOWS\Cookies\default@linksynergy[4].txtobj[109]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[110]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[111]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[112]=IECache Entry : C:\WINDOWS\Cookies\default@spinbox[1].txtobj[113]=IECache Entry : C:\WINDOWS\Cookies\default@hitbox[2].txtobj[114]=IECache Entry : C:\WINDOWS\Cookies\default@spinbox[3].txtobj[115]=IECache Entry : C:\WINDOWS\Cookies\default@bluestreak[1].txtobj[116]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[117]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[13].txtobj[118]=IECache Entry : C:\WINDOWS\Cookies\default@realmedia[1].txtobj[119]=IECache Entry : C:\WINDOWS\Cookies\default@7search[1].txtobj[120]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[15].txtobj[121]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[122]=IECache Entry : C:\WINDOWS\Cookies\default@valueclick[2].txtobj[123]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[124]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[125]=IECache Entry : C:\WINDOWS\Cookies\default@bfast[4].txtobj[126]=IECache Entry : C:\WINDOWS\Cookies\default@sexlist[2].txtobj[127]=IECache Entry : C:\WINDOWS\Cookies\default@linksynergy[1].txtobj[128]=IECache Entry : C:\WINDOWS\Cookies\default@sextracker[1].txtobj[129]=IECache Entry : C:\WINDOWS\Cookies\default@fastclick[4].txtobj[130]=IECache Entry : C:\WINDOWS\Cookies\default@clickagents[2].txtobj[131]=IECache Entry : C:\WINDOWS\Cookies\default@hitbox[4].txtobj[132]=IECache Entry : C:\WINDOWS\Cookies\default@paycounter[4].txtobj[133]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[19].txtobj[134]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[135]=IECache Entry : C:\WINDOWS\Cookies\default@trafficmp[3].txtobj[136]=IECache Entry : C:\WINDOWS\Cookies\default@hitbox[5].txtobj[137]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[16].txtobj[138]=IECache Entry : C:\WINDOWS\Cookies\[email protected][5].txtobj[139]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[140]=IECache Entry : C:\WINDOWS\Cookies\default@sextracker[4].txtobj[141]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[142]=IECache Entry : C:\WINDOWS\Cookies\default@admonitor[3].txtobj[143]=IECache Entry : C:\WINDOWS\Cookies\default@gator[2].txtobj[144]=IECache Entry : C:\WINDOWS\Cookies\default@x10[4].txtobj[145]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[146]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[147]=IECache Entry : C:\WINDOWS\Cookies\default@fastclick[7].txtobj[148]=IECache Entry : C:\WINDOWS\Cookies\default@questionmarket[1].txtobj[149]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[150]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[151]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[152]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[153]=IECache Entry : C:\WINDOWS\Cookies\default@tripod[2].txtobj[154]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[3].txtobj[155]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[156]=IECache Entry : C:\WINDOWS\Cookies\default@sexlist[1].txtobj[157]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[158]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[5].txtobj[159]=IECache Entry : C:\WINDOWS\Cookies\default@bluestreak[2].txtobj[160]=IECache Entry : C:\WINDOWS\Cookies\default@paycounter[1].txtobj[161]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[162]=IECache Entry : C:\WINDOWS\Cookies\default@sextracker[2].txtobj[163]=IECache Entry : C:\WINDOWS\Cookies\[email protected][4].txtobj[164]=IECache Entry : C:\WINDOWS\Cookies\default@sexlist[3].txtobj[165]=IECache Entry : C:\WINDOWS\Cookies\[email protected][4].txtobj[166]=IECache Entry : C:\WINDOWS\Cookies\default@trafficmp[1].txtobj[167]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[17].txtobj[168]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[169]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[170]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[171]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[172]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[173]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[174]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[20].txtobj[175]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[176]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[177]=IECache Entry : C:\WINDOWS\Cookies\[email protected][6].txtobj[178]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[179]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[180]=IECache Entry : C:\WINDOWS\Cookies\default@bluestreak[4].txtobj[181]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[182]=IECache Entry : C:\WINDOWS\Cookies\default@hotlog[1].txtobj[183]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[184]=IECache Entry : C:\WINDOWS\Cookies\default@dbbsrv[1].txtobj[185]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[186]=IECache Entry : C:\WINDOWS\Cookies\default@paycounter[3].txtobj[187]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[22].txtobj[188]=IECache Entry : C:\WINDOWS\Cookies\default@list[1].txtobj[189]=IECache Entry : C:\WINDOWS\Cookies\default@sexlist[5].txtobj[190]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[191]=IECache Entry : C:\WINDOWS\Cookies\[email protected][5].txtobj[192]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[193]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[194]=IECache Entry : C:\WINDOWS\Cookies\default@toteme[2].txtobj[195]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[196]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[21].txtobj[197]=IECache Entry : C:\WINDOWS\Cookies\default@paycounter[2].txtobj[198]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[199]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[200]=IECache Entry : C:\WINDOWS\Cookies\default@sextracker[5].txtobj[201]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[202]=IECache Entry : C:\WINDOWS\Cookies\default@fastclick[5].txtobj[203]=IECache Entry : C:\WINDOWS\Cookies\default@hitbox[8].txtobj[204]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[205]=IECache Entry : C:\WINDOWS\Cookies\[email protected][4].txtobj[206]=IECache Entry : C:\WINDOWS\Cookies\default@valueclick[4].txtobj[207]=IECache Entry : C:\WINDOWS\Cookies\default@gator[3].txtobj[208]=IECache Entry : C:\WINDOWS\Cookies\[email protected][5].txtobj[209]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[7].txtobj[210]=IECache Entry : C:\WINDOWS\Cookies\[email protected][5].txtobj[211]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[212]=IECache Entry : C:\WINDOWS\Cookies\default@doubleclick[2].txtobj[213]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[214]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[215]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[216]=IECache Entry : C:\WINDOWS\Cookies\default@xxxtoolbar[2].txtobj[217]=IECache Entry : C:\WINDOWS\Cookies\[email protected][7].txtobj[218]=IECache Entry : C:\WINDOWS\Cookies\default@offshoreclicks[2].txtobj[219]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[24].txtobj[220]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[221]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[222]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[23].txtobj[223]=IECache Entry : C:\WINDOWS\Cookies\default@mediaplex[3].txtobj[224]=IECache Entry : C:\WINDOWS\Cookies\default@real[2].txtobj[225]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[226]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[227]=IECache Entry : C:\WINDOWS\Cookies\default@toprefsys[1].txtobj[228]=IECache Entry : C:\WINDOWS\Cookies\default@xxxcounter[1].txtobj[229]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[230]=IECache Entry : C:\WINDOWS\Cookies\default@hitbox[7].txtobj[231]=IECache Entry : C:\WINDOWS\Cookies\[email protected][4].txtobj[232]=IECache Entry : C:\WINDOWS\Cookies\default@targetnet[3].txtobj[233]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[234]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[235]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[236]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[237]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[238]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[239]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[26].txtobj[240]=IECache Entry : C:\WINDOWS\Cookies\[email protected][7].txtobj[241]=IECache Entry : C:\WINDOWS\Cookies\default@tribalfusion[1].txtobj[242]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[243]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[244]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[8].txtobj[245]=IECache Entry : C:\WINDOWS\Cookies\default@euniverseads[2].txtobj[246]=IECache Entry : C:\WINDOWS\Cookies\[email protected][5].txtobj[247]=IECache Entry : C:\WINDOWS\Cookies\default@realmedia[2].txtobj[248]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[249]=IECache Entry : C:\WINDOWS\Cookies\default@zedo[1].txtobj[250]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[251]=IECache Entry : C:\WINDOWS\Cookies\default@cgi-bin[27].txtobj[252]=IECache Entry : C:\WINDOWS\Cookies\default@valueclick[5].txtobj[253]=IECache Entry : C:\WINDOWS\Cookies\default@adrevolver[2].txtobj[254]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[255]=IECache Entry : C:\WINDOWS\Cookies\default@0[1].txtobj[256]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[257]=IECache Entry : C:\WINDOWS\Cookies\default@specificclick[1].txtobj[258]=IECache Entry : C:\WINDOWS\Cookies\default@serving-sys[2].txtobj[259]=IECache Entry : C:\WINDOWS\Cookies\default@2o7[2].txtobj[260]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[261]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txtobj[262]=IECache Entry : C:\WINDOWS\Cookies\default@hypercount[2].txtobj[263]=IECache Entry : C:\WINDOWS\Cookies\default@qksrv[1].txtobj[264]=IECache Entry : C:\WINDOWS\Cookies\[email protected][4].txtobj[265]=IECache Entry : C:\WINDOWS\Cookies\default@2o7[1].txtobj[266]=IECache Entry : C:\WINDOWS\Cookies\[email protected][3].txtobj[267]=IECache Entry : C:\WINDOWS\Cookies\default@apmebf[2].txtobj[268]=IECache Entry : C:\WINDOWS\Cookies\default@fastclick[8].txtobj[269]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[6].txtobj[270]=IECache Entry : C:\WINDOWS\Cookies\default@maxserving[1].txtobj[271]=IECache Entry : C:\WINDOWS\Cookies\default@sextracker[3].txtobj[272]=IECache Entry : C:\WINDOWS\Cookies\default@xxxcounter[2].txtobj[273]=IECache Entry : C:\WINDOWS\Cookies\default@trafficmp[2].txtobj[274]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[275]=IECache Entry : C:\WINDOWS\Cookies\default@fastclick[6].txtobj[276]=IECache Entry : C:\WINDOWS\Cookies\[email protected][2].txtobj[277]=IECache Entry : C:\WINDOWS\Cookies\default@paycounter[6].txtobj[278]=IECache Entry : C:\WINDOWS\Cookies\default@tribalfusion[3].txtobj[279]=IECache Entry : C:\WINDOWS\Cookies\default@paycounter[5].txtobj[280]=IECache Entry : C:\WINDOWS\Cookies\[email protected][8].txtobj[281]=IECache Entry : C:\WINDOWS\Cookies\[email protected][4].txtobj[282]=IECache Entry : C:\WINDOWS\Cookies\default@fastclick[10].txtobj[283]=IECache Entry : C:\WINDOWS\Cookies\[email protected][5].txtobj[284]=IECache Entry : C:\WINDOWS\Cookies\default@sextracker[8].txtobj[285]=IECache Entry : C:\WINDOWS\Cookies\[email protected][4].txtobj[286]=IECache Entry : C:\WINDOWS\Cookies\default@xxxcounter[3].txtobj[287]=IECache Entry : C:\WINDOWS\Cookies\default@advertising[10].txtobj[288]=IECache Entry : C:\WINDOWS\Cookies\default@maxserving[3].txtobj[289]=IECache Entry : C:\WINDOWS\Cookies\[email protected][9].txtobj[290]=IECache Entry : C:\WINDOWS\Cookies\default@2o7[4].txtobj[291]=IECache Entry : C:\WINDOWS\Cookies\default@overture[2].txtobj[292]=IECache Entry : C:\WINDOWS\Cookies\default@trafficmp[5].txtobj[293]=IECache Entry : C:\WINDOWS\Cookies\default@adrevolver[1].txtobj[294]=IECache Entry : C:\WINDOWS\Cookies\default@tribalfusion[4].txtobj[295]=IECache Entry : C:\WINDOWS\Cookies\default@apmebf[1].txtobj[296]=IECache Entry : C:\WINDOWS\Cookies\default@qksrv[2].txtobj[297]=IECache Entry : C:\WINDOWS\Cookies\default@hypercount[3].txtobj[298]=IECache Entry : C:\WINDOWS\Cookies\[email protected][1].txt Edited March 27, 2006 by TheTerrorist_75 Link to post Share on other sites
Matt Posted March 28, 2006 Report Share Posted March 28, 2006 Wow, looks like AdAware found a lot. We're going to kill those three files found by avast just to be sure that infection is gone. From its showing, the PC is looking better.Please download the Killbox by Option^Explicit.Note: In the event you already have Killbox, this is a new version that I need you to download. Save it to your desktop. Please double-click Killbox.exe to run it. Select: Delete on Reboot then Click on the All Files button.[*]Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):c:\WINDOWS\internt.exec:\WINDOWS\SYSTEM32\sysinit32m.exec:\WINDOWS\msxmidi.exe[*] Return to Killbox, go to the File menu, and choose Paste from Clipboard.[*]Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).If your computer does not restart automatically, please restart it manually.If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.If you get the ability to run Panda ActiveScan, please do that, and post back its report. Link to post Share on other sites
TheTerrorist_75 Posted March 28, 2006 Author Report Share Posted March 28, 2006 (edited) I'll try that a little later. I am just finishing up the Windows updates. There wasn't one update installed on this POS. I would have put a Ehernet card in it and dug out my router, but it would have taken me longer to set it up than downloading the updates by dial-up. I hate Compaq/HP mini cases.Killbox found nothing. I'm still having problems getting any online scans to run. Somehting isn't working with the ActiveX or Java.I'm getting Kaspersky's online scan to load. I think the problem with Panda and HouseCall is due to their crappy designed webpages wanting to load tons of graphics. For dial-up users this is BS. Edited March 28, 2006 by TheTerrorist_75 Link to post Share on other sites
Matt Posted March 28, 2006 Report Share Posted March 28, 2006 Alright, if you can get KAV to run, that'd be great Link to post Share on other sites
TheTerrorist_75 Posted March 28, 2006 Author Report Share Posted March 28, 2006 KAV gave a clean bill of health. Another Avast scan found nothing. The computer is behaving nicely. No more flashing of the open windows and the buttons. I have Windows fully updated and now it's time to install and update Office. I installed SpywareBlaster, AdWare, SpyBot, Avast and IE-Spyad. This should keep her fairly safe. At least as safe as Win98 FE and dial-up can get without slowing it down. She doesn't surf the net much but constantly uses Office to do her school work. At least now she shouldn't be transferring infected files to the school's computers. Thanks. Link to post Share on other sites
Matt Posted March 28, 2006 Report Share Posted March 28, 2006 Glad to see you got everything under control! Link to post Share on other sites
Matt Posted March 28, 2006 Report Share Posted March 28, 2006 Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. Link to post Share on other sites
Recommended Posts