Hi to all. Can somebody please help me with my PC? After starting windows the internet connection dialog appears automatically (I have to close it twice). I suspect there are sypware or something like that :-(
Here is the log:

Logfile of HijackThis v1.98.2
Scan saved at 8.54.33, on 03/04/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\FMCTRL.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAMMI\SGRUNT\IE4321.EXE
C:\WINDOWS\SHCH.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\CLFMON.EXE
C:\PROGRAMMI\MESSENGER\MSMSGS.EXE
C:\PROGRAMMI\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\EXIF LAUNCHER\QUICKDCF.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\DOWNLOADS\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,Default_Search_URL = http://www.searchnow.ws/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F1 - win.ini: run=hpfsched
O1 - Hosts: auto.search.msn.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmi\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ATIGART] c:\ati\gart\atigart.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
O4 - HKLM\..\Run: [Q3dctlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Sexy_it] C:\Program Files\GMSoft\Dialers\Sexy_it\Sexy_it.exe /dontdial
O4 - HKLM\..\Run: [Olympic] c:\programmi\sgrunt\IE4321.exe
O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\shch.exe /i
O4 - HKLM\..\Run: [clfmon] C:\WINDOWS\clfmon.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKCU\..\Run: [MSMSGS] C:\Programmi\Messenger\msmsgs.exe /background
O4 - HKCU\..\Run: [5-11-1-56] c:\windows\5-11-1-56.exe -m
O4 - Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O4 - Startup: Avvio Office.lnk = C:\Programmi\Microsoft Office\Office\OSA.EXE
O4 - Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\MSMSGS.EXE
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=
O14 - IERESET.INF: START_PAGE_URL=
O15 - Trusted Zone: www.yeak.net
O15 - Trusted Zone: www.sgrunt.biz
O15 - Trusted Zone: www.master69.biz
O16 - DPF: {91413D86-9F27-402C-B5E3-DEBDD122C339} -
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/gampr-it/itp/games26.cab

Dani AI

Generated

The HijackThis log shows a classic mixture of browser tampering, extra autorun entries and what looks like dialer/adware activity on a Windows 98 SE machine. Immediate priorities are to stop any outbound connections and preserve recoverable data: disconnect the network/phone line, make a full copy of personal files, and create a disk image or file-level backup before changing the system.

Recommended cleanup workflow (safe, staged):

  • Work from a clean environment (Safe Mode or, for best assurance, remove the drive and scan it from another clean PC or a rescue boot disk). This prevents active malware from blocking removal.
  • Run a full antivirus scan (updated signatures) first, then run an anti-spyware scanner. Use two different engines if possible—they catch different things.
  • Produce a fresh HijackThis log and keep an untouched copy. Use the tool’s fixes sparingly: fix only clearly malicious, well-documented entries. When in doubt, save the log for expert review.
  • Check the Hosts file and Internet Explorer security/trusted-site lists (use the GUI where possible) for unfamiliar entries and remove them rather than editing deep registry keys unless comfortable with registry repair.
  • Remove unknown programs through Add/Remove Programs or by deleting their files from Safe Mode. If an executable is locked, rename it and schedule removal on next boot.

Recovery and hardening:

  • Clear temporary files, reset the browser home/search settings, and remove unknown Browser Helper Objects with care.
  • Back up the registry before manual edits (export All). This is a critical safety step as noted earlier by .
  • Do not follow “reinstaller” links or unfamiliar uninstall pages (a point raised by ); some pages only redeploy the unwanted software.
  • After cleanup, change online passwords and monitor financial accounts. If the system remains unstable or heavily compromised, a clean OS reinstall (or upgrading to a supported OS) is the most reliable way to restore trust in the machine.

This thread’s next useful item is a fresh, current HijackThis log and a short note of which scanners ran and their results; that will allow focused, item-by-item cleanup guidance.

Recommended Answers

All 3 Replies

Go to Windows Update and get the Critical Updates for your system

Get the latest version of HijackThis here:

Close all browser widows, scan with hijackthis, and post a new log please

when the boxes popup there is an email address in one of them
email them and they will send you to an uninstall page
everything is in itallian so you have to use a bit of guess work but if you get stuck email me at and i will be happy to help you.
once you have entered the information it will take you to another page with reinstaller or something on it do not click on this link because it will reinstall
the programme.

after you have done this restart your computer.
the problem shouldnt come again however there is still links on you computer that you need to get rid of to insure this.

1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
2. In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>Windows>
CurrentVersion>Internet Settings>ZoneMap\Domains
3. Still in the left panel, locate and delete the following key:
master69.biz
4. In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>Windows>
CurrentVersion>Internet Settings>ZoneMap>Domains
5. Still in the left panel, locate and delete the following:

6. In the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>Windows>
CurrentVersion>Internet Settings>ZoneMap>Domains
7. Still in the left panel, locate and delete the following:
yeak.net

1. Still in the Registry Editor, in the left panel, double-click the following:
HKEY_CURRENT_USER>Software>Microsoft>Internet Explorer>Main
2. In the right panel, right-click the entry and choose Modify:
Start Page = "www.master69.biz?654"
modify to
Start Page = “about:blank"
3. Close Registry Editor.


please email me at to let me no how you got on and if there is anything else i can help with i would love to hear that it worked for
you as it is a disgusting thing to have on your computer.

good luck
Daniel

I can't say whether the above instructions will work or not, but if you intend to try it, you should make a backup before you edit the registry. Go to Start, Run, type in regedit, and the Registry Editor will open. At the top of the Registry Editor window, click on File, and then Export. In the Export range panel, click All, give the file a name, then Save your registry as a backup to a location where you will be able to locate it easily if necessary.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.