I followed the directions you gave me on a previous thread, this is the scan after the CWS and Critical Updates. Sorry for not posting my own thread right away. Please Help. Thank You.


Logfile of HijackThis v1.97.7
Scan saved at 1:24:30 PM, on 5/16/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\ISS\BLACKICE\BLACKD.EXE
C:\PROGRAM FILES\ISS\BLACKICE\RAPAPP.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\ISS\BLACKICE\BLACKICE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\HIJACKTHIS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\TWAINTEC.DLL
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\RunServices: [LoadBlackD] "C:\PROGRAM FILES\ISS\BLACKICE\BLACKD.EXE"
O4 - HKLM\..\RunServices: [RapApp] C:\PROGRAM FILES\ISS\BLACKICE\RAPAPP.EXE
O4 - Startup: BlackICE PC Protection.lnk = C:\Program Files\ISS\BlackICE\blackice.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: Yahoo! Blackjack -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} (CInstall Class) -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
O16 - DPF: Yahoo! Pool 2 -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: Yahoo! Literati -
O16 - DPF: Toki Toki Boom -
O16 - DPF: Yahoo! Go -
O16 - DPF: Yahoo! Bingo -
O16 - DPF: Yahoo! Go Fish -
O16 - DPF: Tornado 21 -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

Dani AI

Generated

The HijackThis log posted by shows some suspicious items; was right to advise unzipping HijackThis into a permanent folder and to remove the unidentified Browser Helper Objects plus the outdated ActiveX/DPF entry. That is the correct first move, but follow a safe workflow so removal does not leave the system unstable or unrecoverable.

Before changing anything: make a registry backup and a file backup (if possible, a full disk image). On Windows 98 use the built-in registry backup utility (run it before edits) and let HijackThis create its own backups by running it from a permanent folder. Close all browsers and temporarily disable any third-party firewall/IDS so removals can complete. Copy any DLLs you expect to delete into a dated backup folder so they can be restored quickly.

After fixing the reported entries, reboot and re-run HijackThis to confirm they did not reappear. Search the drive for the DLL names reported in the log (do not delete without having the backups). Inspect autostart locations (Startup folder and the registry Run keys and any scheduled tasks) for items that might re-add the BHOs. If stability problems occur, restore via HijackThis’ backup or use the registry restore function you created earlier.

Because Windows 98 is long out of support, use multiple up-to-date scanners where possible. If modern AV/anti-malware no longer runs on that OS, make a disk image and scan it from a current, patched system or boot a trusted rescue environment to run offline scans. Finally, consider moving to a supported operating system: legacy platforms remain highly vulnerable and make long-term protection difficult.

Unzip HJT into it's own permanent folder before doing anything in order for it to create backups. (Not a temporary folder or the desktop & not directly on your hard drive). Close all (browser) windows & rescan with hijackthis. When the scan is finished place a check in the box to the left of the following entries & click 'fix checked' :

O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\TWAINTEC.DLL
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll

O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540002} (CInstall Class) -

Thats all. :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.