Hello, AVG pops up now and then saying "Virus detected, GPSRESL.exe, trojan Dialer.18.c". I have also lost the "appearance tab" from the display properties on the desktop. Also IE links to explicit websites occasionally for no reason. I've run the AVG scan a few times but it doesn't detect anything. I tried the trendmicro housecall virus scan and that said I had TSPY_ALEMOD.A in wininet.dll. I've replaced wininet.dll now but havn't re-scanned yet. Here's the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 12:27:18 PM, on 7/8/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld
R3 - URLSearchHook: (no name) - {F5546F68-94AA-B470-61FD-B81EB24C4D0C} - AliceSD.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\SYSTEM\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\SYSTEM\intel32.exe
O4 - HKLM\..\Run: [avpmondll] SAPSTR.exe
O4 - HKLM\..\Run: [ActionScr] scanSYS.exe
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\SYSTEM\hookdump.exe
O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [abrek] ABCXYZ.exe
O4 - HKCU\..\Run: [systemdll] ExchangeMaster.exe
O4 - HKCU\..\Run: [MSTCPDLL] dePloy.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {99F9EF50-DEA2-4042-AF00-B1750610EA0F} (NetManage IE Frame) - https://www.ecom.honda-eu.com/w2hlegacy/express/hostexpress.cab
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = ,

Any help would be much apprieciated, :cheesy:

Dani AI

Generated

A short expert summary and practical checklist that complements the thread: the behavior you described (intermittent redirection to porn/poker sites, loss of the Display “Appearance” tab, inconsistent AV detection) fits a classic browser/DNS hijack combined with persistent autorun components. correctly focused on autostart/run entries and registry artifacts; the HijackThis O17 "NameServer" lines are the clearest sign that DNS settings were being forced to rogue servers (that explains the random redirects). (bleepingcomputer.com)

Quick, safe triage (Win98-specific notes first)

  • Immediately isolate the machine (unplug network or modem).
  • Backup personal files to external media, then scan those backups on a known-clean computer before restoring anything.
  • Look for a hosts file in C:\WINDOWS\HOSTS on Win98 (WinXP+ use the system32\drivers\etc path). Edit only after backing it up. (en.wikipedia.org)
  • Back up the registry with Windows 98’s Registry Checker (ScanReg/ScanRegW) before any manual edits; use it to restore if needed. Example commands:
    scanregw.exe        # run GUI to create a registry backup
    scanreg.exe /restore  # restore a backup from DOS prompt

    (See Microsoft guidance on using ScanReg.) (support.microsoft.com)

What to fix and how

  • Remove any suspicious O4/O17/O1 entries (use HijackThis to identify, but back up before fixing). Check the MSTCP NameServer registry location (the HijackThis O17 line shows where the bogus DNS is stored) and clear or restore to your ISP’s DNS or set DNS to obtain automatically. (bleepingcomputer.com)
  • Do not download random copies of wininet.dll from unknown sites. Restore system DLLs from the original Windows 98 install media or use the OS’s file-recovery tools (SFC/installation CABs) so you don’t introduce corrupted or mismatched DLLs. (lifewire.com)
  • Missing Control Panel tabs (Appearance) are commonly caused by removed/altered CPLs or shell extensions; restore the CPL from the install media or run ScanReg/SFC to recover the original file.

When to accept reinstallation
If multiple persistence mechanisms are present (many Run/RunServices entries, replaced system DLLs, DNS hijack that keeps returning), a full wipe and reinstall from trusted media is reasonable and often the fastest way to guarantee a clean system — but only after backing up and validating data. ’s final decision to reformat is a standard, defensible resolution for a heavily compromised Win98 machine. (askleo.com)

Quick checklist to keep: isolate → backup → offline/boot‑media scans → registry & hosts check (backup first) → repair from original media → reformat only if persistent.

Recommended Answers

All 7 Replies

WareOut.exe is a worm. IT IS NOT A SPYWARE REMOVER!

Kill the process called WareOut.exe

Delete folder:

c:\Program Files\WareOut

also delete these files in windows directory:

wosys.dll
wosysdll.dll
wotmp.tmp
wotmp11.tmp

Now open up your registry editor and search and remove these registry entries:

Wareout
___
_ctcp
10010
321102
34763
ABCXYZ
abrek
ActionScr
AliceSD
atl_helper.dll
ATLIEHELPER
avpmondll
backd
backorif
barint
bhoserv
bingo9
bnui
Bogobot
borlandg
BoundRec
br0ken
Brong32
browebar
clamav
cmon14
cnftips
control64
corrida
CToolBar
DCC_send
defect08
dePloy
Dest068
dialer423
driver32
DTOURS
ERTYDF
EXE2EXE
forces_elite
ftbar
gabber
hyandex
iesetupdll
init32
InpriseMon
install2
JAguAr
jopplerg
Kargo
keybdll
killall
LOPTCON
MONITER
MON76234
MNTP
msag
ms-its
MsNetHelper
MSTCPDLL
new32
newbreed
nmdllw
NopeZ
NukeSpan
ParisM
panel_its
PasswdMon
pizda
powerdll
prcmon
PrcIdle
prgsys0984
Preliminary
qwe
RtlFindVal
load32
SAPSTR
sbin
scanSYS
Serviceprocess
SetupExeDll
Shaitan1678
slamm
sound64
ssweeper
StartCpl
startman
StatusCheck
stuffmon
SYSTRAV
sysconf16
sysmon12
syspanel
SysSupport
systemdll
TemplateDongle
Testimonials
teqq32
TForm1
TorontoMail
Trayz
TRPT
trycrt
typeconf
uio
uint32
UserSP1
utsgmon
vxdman
zxc
AppMasterCenter
WhatsNewBot
wormexe
WTFCTF
XTermInit
xwiz
xxtoolbar
zantu


Post a new version of HijackThis

Thanks for the help, here's the latest log:

Logfile of HijackThis v1.99.1
Scan saved at 8:59:16 PM, on 7/8/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\SYSTEM\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\SYSTEM\intel32.exe
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {99F9EF50-DEA2-4042-AF00-B1750610EA0F} (NetManage IE Frame) - https://www.ecom.honda-eu.com/w2hlegacy/express/hostexpress.cab
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = ,

I suggest that you clean out your prefetch.

Also search for the file called abcxyz.exe and delete if you find it (although it is supposed to be gone already).

Search for files and registry keys like CoolSeach, and CoolWebSearch (just to make sure). Tell me if you find any.

Open up your Internet Explorer, goto Internet Options->programs->Manage Addons.

Make sure you dont have anything weird there (like CoolSearch).

Also I suggest getting CleanUp from:

http://cleanup.stevengould.org

and run it. It will clear temporary folders, and other places where the nasties like to keep copies of themselves.

Do you still get the problem?

I forgot one thing.

Could you also post the contents of your hosts file located in

c:\WINDOWS\system32\drivers\etc

thanks.

Hello, I'm running Win98 SE so I don't think I have Prefetch. I couldn't find abcxyz.exe anywhere. Also couldn't find any registry entries for Coolsearch etc. I downloaded and ran cleanup. I also have run cwshredder, which didn't find anything. I ran adaware and I've just run Spybot-S&D which found 3 problems: CWS.WinSecurityCenter, AV-Gold and CallingHome.biz. I had Spybot fix them all. However the browser is still accessing poker/viagra/explicit sites. I'd say about one in every 15 links I click, the browser will go to one of these sites instead of the selected site. Also, the appearance tab from the desktop display properties window is still missing. I couldn't find the hosts file you asked for in c:\WINDOWS\system32\drivers\etc

Here's the latest log:
Logfile of HijackThis v1.99.1
Scan saved at 3:09:15 PM, on 7/9/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Openworld
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - (no file)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\SYSTEM\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {99F9EF50-DEA2-4042-AF00-B1750610EA0F} (NetManage IE Frame) - https://www.ecom.honda-eu.com/w2hlegacy/express/hostexpress.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = ,

Hey,

Sorry for not getting back to you for a long time. I went on vacation for a week after the last post. I did not know that you were runing win98, and assumed some things...sorry.

The following entry:

HKLM\System\CCS\Services\VxD\MSTCP: NameServer =
,

indicates a possible DNS hijack i believe. Update your defenitions and run the antivirus again. I will look more into your problem. I also suggest you get pctools spyware doctor (run an update before you do a thorough system scan) and tell me what it finds. It's just that its late and I just got back.

I will get back to you.

Hi, thanks for the reply. I decided to format the disk and re-install win98, that seems to have solved the problem! Thanks very much for your help.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.