Unsolved
This post is more than 5 years old
4 Posts
0
8480
February 24th, 2005 23:00
Hidden file - how to remove -- Windows 98 - HELP!
My parents have an antiquated system -- Windows 98. Not that I am tech saavy but they've had this system for over 6 years now.
There is something listed I cannot delete. It is causing all sorts of pop up windows and pop up error messages. It just started today. Here is what I see:
0 events found
No Events found!


ScreenGoddess
4 Posts
0
February 24th, 2005 23:00
jds54
2 Posts
0
February 25th, 2005 10:00
I also found this on my Inspiron 3700 running 98 last night.
I tried to delete using Lavasoft Reghance . Kept coming back.
If anyone has info on how to get this out please advise.
joe53
2 Intern
•
5.8K Posts
•
17.3K Points
0
February 25th, 2005 11:00
Try downloading the latest version of HijackThis (1.99.1) from here:
HijackThis 1.99.1
Run a scan- don't try to fix anything- and post back the logfile generated to this thread.
ScreenGoddess
4 Posts
0
February 25th, 2005 15:00
This is the outcome I received from HiJack This:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName=
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}-C:\PROGRAMFIELS\ADOBE\ACROBAT5.0\READER\ACTIVEX\ACROIEHELPER.OCX
02 - BHO: WaveHelper Class - {EA7F9A52-0A05-11D2-98C5-00104B7229C2}-C:\PROGRAM FILES\WAVETOP\BIN\WAVEIE.DLL
02 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094}-C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLST.DLL
02 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F}-C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
03 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467}-C:\WINDOWS\SYSTEM\MSDXM.OCX
03 - Toolbar: AOL Toolbar - {4982D0A-C53B-4615-B15B-B5B5E98D167C}-C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
04 - HKLM\..\Run: [ScanRegistry]c:\windows\scanregw.exe/autorun
04 - HKLM\..\Run: [SystemTray] SysTray.Exe
04 - HKLM\..\Run: [McAfeeWebScanX]C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCANN\WebScanX.Exe
04 - HKLM\..\Run: [TaskMonitor]c:\windows\taskmon.exe
04 - HKLM\..\Run: [Vshwin32EXE]C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
04 - HKLM\..\RunServices: [McAfeeWebScanX]C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\WebScanX.Exe/RUNSERVICES
04 - HKLM\..\RunServices: [AOL TopSpeedMonitor]C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon/exe
04 - HKLM\..\RunServices: [Vshwin32EXE]C:]PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
04 - HKCU\..\Run: [AOL Fast Start]"C:\PROGRAM FILES\AMERICA ONLINE 9.0\AOL.EXE" -b
04 - Startup: Office Startup.Ink = C:\Program Files\Microsoft Office\OSA.EXE
08 - Extra context menu item: E&xport to Microsoft Excel - res://c:\PROGRA~1\MICROS~7\OFFICE10\EXCEL.EXE/3000
08 - Extra context menu Item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML
09 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
09 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
09 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL
09 - Extra button: Dell Home - {43127860-257D-11D3-B73C-40564FC10000} - http://www.dell.com/(file missing) (HKCU)
012 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
012 - Plugin for .adp: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
014 - IERESET.INF: START_PAGE_URL=http://www.aol.com
016 - DPF: {DC765522-D5BE-49C9-AF5F-8C715A44BA28} - http://fdl.msn.com/public/investor/v9/ticker.cab
016 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe
016 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheck/qdiagcc.cab
016 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4363/mcfscan.cab
016 - DPF: {E504EE6E-47C6-11D5-B8A8-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
016 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
016 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
016 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
016 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
016 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
017 - HKLM\System\CCS\Services\VxD\MSTCP: Domain - aoldsl.net
******
Any assistance would be greatly appreciated!
Midnight Star
4.8K Posts
0
February 25th, 2005 16:00
Let's also run the following programs:
-
Download: "StartDreck", from here: http://www.niksoft.at/_data/startdreck.zip
Unzip to its own folder and start the program,
Press 'Config'
Press 'Unmark All'
Check the following boxes only:
Registry -> Run Keys
System/drivers> Running processes
Press 'Ok'
Press 'Save' and select the location to save the log file
(default is the same folder as the application)
Please post the log in this thread.
-
Here is some information about a program called dllcompare: http://forums.subratam.org/index.php?showtopic=1725
Please run it and post its log here too.
-
Mike.
ScreenGoddess
4 Posts
0
February 26th, 2005 01:00
I ran a scan on Hijack This and posted the logfile. Can you please review it and see what I need to have deleted and/or fixed. I am unable to download the zip file recommended by Midnight Star. My parents computer is old and only has Windows 98. Please advise!
jds54
2 Posts
0
February 26th, 2005 01:00
Webroot told me to run Spysweeper in safemode 3 times to get rid of it.
It apparently worked. My registry is clear of that pest.