Trojan-gen {other} removal sufficient?

Hi,

I’m a new user to Avast and downloaded it because my machine has been experiencing many lockups lately. I also have a reccuring problem with my Yahoo (and other) search engines being hijacked. The first page of results is obviously not the true results, and points to address http://61.131.54.618.cc/search.php.

I have tried Spybot and Ad-aware to repair this, but it still persists. When I ran Avast it found 2 files noted as Win32 trojan-gen {other}. I followed the recomendation and placed the files in the Chest. Is this all that needs to be done? Should there be some method of “cleaning” the virus, like any registry effects, etc?

I am on a Win 98SE OS.

Any advice would be greatly appreciated.

Thanks

Since your system was already infected prior to installing avast, there may be other malware on your system.

I would recommend a visit to Eddy’s Website click the “HiJackThis Section” and also the “Malware removal instructions and applications” section, and follow the directions there and get back to us if you need more help…

Hijackthis should help remove these browser hijacks.

Thanks David,

I’ll try this out. Can you please confirm that just moving the files to the Chest is enough ? No cleaning ? I tried the stand alone cleaner and locked up twice while scanning shared memory.

Under normal circumstances moving the file to the chest is enough, in the chest, it can’t be activated.

However if this has been on your system for some time there may be registry entries, these entries on there own can’t do anything if the file they call/use has been moved to the chest. So moving to the chest is effective, it should be used to give you time to investigate and if moving to file to the chest has no harmful effect (valid file recognised incorrectly) after a period of time you can also delete it from the chest.

Me I would want to get rid of the registry entries as well, which is why I suggested using hijackthis.

Hi guys,

Here is the result from HiJackThis. I used both Ad-aware and spybot and rebooted before running it. Please let me know what else I can do.

Thanks…

Logfile of HijackThis v1.99.1
Scan saved at 11:18:06 AM, on 2/18/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\PROGRAM FILES\DANTZ\RETROSPECT\LAUNCHER.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\SYSTEM\PTUDFAPP.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\KODAK\KODAK_DR\KODAKCCS.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\E_S5I2A1.EXE
C:\PROGRAM FILES\NETZERO\EXEC.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\REALITY FUSION\REALITY FUSION GAMECAM SE\PROGRAM\RFTRAY.EXE
C:\PROGRAM FILES\SCANSOFT\PAPERPORT\CONFIG\EREG\REMIND32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PC REPAIRS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\PROGRAM FILES\NZSEARCH\SEARCHENH1.DLL
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_3.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\SYSTEM\DSMANA~1.DLL
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_3.DLL
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
O4 - HKLM..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM..\Run: [SystemTray] SysTray.Exe
O4 - HKLM..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM..\Run: [AtiQiPcl] AtiQiPcl.exe
O4 - HKLM..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM..\Run: [Microsoft WebServer] C:\Program Files\WebSvr\System\svctrl /init
O4 - HKLM..\Run: [LoadQM] loadqm.exe
O4 - HKLM..\Run: [MoneyStartUp10.0] “C:\Program Files\Microsoft Money\System\Activation.exe”
O4 - HKLM..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM..\Run: [QuickTime Task] “C:\WINDOWS\SYSTEM\QTTASK.EXE” -atboottime
O4 - HKLM..\Run: [KodakCCS] C:\Program Files\Common Files\KODAK\KODAK_DR\KodakCCS.exe --pdr: “C:\Program Files\Common Files\KODAK\KODAK_DR\dcmnter.pdr”
O4 - HKLM..\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot
O4 - HKLM..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\SYSTEM\E_S5I2A1.EXE /P26 “EPSON Stylus CX4600 Series” /O7 “EPUSB1:” /M “Stylus CX4600”
O4 - HKLM..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM..\RunServices: [Retrospect Launcher] C:\PROGRAM FILES\DANTZ\RETROSPECT\LAUNCHER.EXE
O4 - HKLM..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU..\Run: [NetZero_uoltray] C:\PROGRAM FILES\NETZERO\EXEC.EXE regrun
O4 - HKCU..\Run: [spc_w] “C:\Program Files\NZSearch\nzspc.exe” -w
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Reality Fusion GameCam SE.lnk = C:\Program Files\Reality Fusion\Reality Fusion GameCam SE\Program\RFTray.exe
O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\ScanSoft\PaperPort\Config\Ereg\REMIND32.EXE
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: Epson all-in-one Registration.lnk = D:\EREG\EpsonReg.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O16 - DPF: {42442236-3673-4054-89C0-A7408BC51EFC} (SDLNSrvr.clsNotes) - https://mylearning.accenture.com/codebase/SDLNSrvr.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/24251b9124a35afc3706/netzip/RdxIE601.cab

Results from Eddy’s analyzer:


THESE ITEMS ARE EITHER HARMFULL OR A SECURITY RISK
WE STRONGLY RECOMMEND TO FIX THEM :

search bar = http://my.netzero.net/s/search?r=minisearch
r1 - hklm\software\microsoft\internet explorer\main
r1 - hklm\software\microsoft\internet explorer\main
r0 - hklm\software\microsoft\internet explorer\search
r1 - hkcu\software\microsoft\internet explorer\searchurl
(default) = http://my.netzero.net/s/search?r=minisearch
r1 - hkcu\software\microsoft\windows\currentversion\internet settings
proxyoverride = localhost
r3 - urlsearchhook: urlsearchhook class - {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - c:\program files\nzsearch\searchenh1.dll
o4 - hklm..\run: [systemtray] systray.exe
o4 - hkcu..\run: [netzero_uoltray] c:\program files\netzero\exec.exe regrun
o16 - dpf: {42442236-3673-4054-89c0-a7408bc51efc} (sdlnsrvr.clsnotes) - https://mylearning.accenture.com/codebase/sdlnsrvr.cab
o16 - dpf: {56336bcb-3d8a-11d6-a00b-0050da18de71} (rdxie class) - http://software-dl.real.com/24251b9124a35afc3706/netzip/rdxie601.cab


HARMFULL ITEMS IN THE DOCUMENTS AND SETTINGS FOLDER(S) :

Nothing found.


THE FOLLOWING ITEMS ARE NOT NEEDED TO LOAD
AT BOOTTIME FOR THE SYSTEM TO WORK PROPERLY :

o4 - hklm..\run: [loadqm] loadqm.exe
o4 - hklm..\run: [tkbellexe] “c:\program files\common files\real\update_ob\realsched.exe” -osboot

EDIT: Aslo remove these:

O2 - BHO: Explorer Class - {962F12AE-2773-4BEB-99EA-B5C3AB9A6606} - C:\WINDOWS\SYSTEM\DSMANA~1.DLL

Also using taskmanager (alt + ctrl + del) kill this proccess, (E_S5I2A1.EXE)

then delete this file,

C:\WINDOWS\SYSTEM[b]E_S5I2A1.EXE
[/b]
After this reboot, update your windows fully (www.windowsupdate.com), then redo and repost another hijackthis log.

–lee

Thanks for the examination. Being somewhat of a novice, I am a bit nervous about removing things without knowing what they are. Should I back any of this up in a directory before trying to remove them ?

For example, isn’t systray.exe part of windows ?? Is c:\program files\netzero\exec.exe regrun part of my netzero or just some phony file stuck in there?

Sorry for my ignorance…

Thanks

isn't systray.exe part of windows ??

Ahh your using windows 98, erm, best ignore that bit until eddy replys (the writter of the hijackthis log analyzer i used).

c:\program files\netzero\exec.exe regrun part of my netzero or just some phony file stuck in there?

Hmm, i have never heard of/used netzero myself, but if you feel it is legitimate, then leave it on there :slight_smile: :wink:

But the rest should be fine to remove/delete.

Hijackthis automaticly makes a backup of what you fix with it, but if you feel you want to make a backup of the file i suggested to delete then do so :wink: (its your system not mine remember :))

BTW, the ‘E_S5I2A1.EXE’ file is just a malware BHO/toolbar, but as i said, if you want to make a backup, then do so

–lee

systray.exe is indeed part of Windows.
On a 98(se) system the file should be in x:%systemroot%\system\

My HJT log analyzer doesn’t say to remove or fix it.
It say to fix: o4 - hklm..\run: [systemtray] systray.exe (which is a registry key)

I personally have checked ALL entries in the databases for the HJT log analyzer,
but I am a human just like you (hwoever reads this) and ofcourse I could have made a mistake.

Sofar however, noone reported any problems after fixing that registry key.
But as I said, it can be a mistake from me.
So if some who has 98(se) on his/her system and read this, please check the registry for this key (or use HijackThis to do so) and let me know if you have this key there or not.

OK,

Thanks Eddy and Lee16…thanks for the education. I’ll start removing stuff bit by bit and try to understand more of what I’m doing with this

I’ve jsut checked my old (but clean) w98SE box and do have the following registry entry…
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
name:SystemTray
value:“SysTray.Exe”

FWIW :slight_smile:

Hi again,

I removed all recommended items. I’m posting the new HijackThis log below.

By the way, I see the note from garyb about systray.exe. Should I reinstall this, and can it be done with the backup in HijackThis?

Logfile of HijackThis v1.99.1
Scan saved at 9:37:59 PM, on 2/18/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ATI2EVXX.EXE
C:\PROGRAM FILES\DANTZ\RETROSPECT\LAUNCHER.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\SYSTEM\PTUDFAPP.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\ATIPTAXX.EXE
C:\PROGRAM FILES\CREATIVE\SBLIVE\AUDIOHQ\AHQTB.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\COMMON FILES\KODAK\KODAK_DR\KODAKCCS.EXE
C:\PROGRAM FILES\NZSEARCH\NZSPC.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\PROGRAM FILES\REALITY FUSION\REALITY FUSION GAMECAM SE\PROGRAM\RFTRAY.EXE
C:\PROGRAM FILES\SCANSOFT\PAPERPORT\CONFIG\EREG\REMIND32.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PC REPAIRS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_3.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_3.DLL
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\PROGRAM FILES\NETZERO\TOOLBAR.DLL
O4 - HKLM..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM..\Run: [AtiQiPcl] AtiQiPcl.exe
O4 - HKLM..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
O4 - HKLM..\Run: [Microsoft WebServer] C:\Program Files\WebSvr\System\svctrl /init
O4 - HKLM..\Run: [MoneyStartUp10.0] “C:\Program Files\Microsoft Money\System\Activation.exe”
O4 - HKLM..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM..\Run: [QuickTime Task] “C:\WINDOWS\SYSTEM\QTTASK.EXE” -atboottime
O4 - HKLM..\Run: [KodakCCS] C:\Program Files\Common Files\KODAK\KODAK_DR\KodakCCS.exe --pdr: “C:\Program Files\Common Files\KODAK\KODAK_DR\dcmnter.pdr”
O4 - HKLM..\Run: [EPSON Stylus CX4600 Series] C:\WINDOWS\SYSTEM\E_S5I2A1.EXE /P26 “EPSON Stylus CX4600 Series” /O7 “EPUSB1:” /M “Stylus CX4600”
O4 - HKLM..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..\RunServices: [ATIPOLAB] ati2evxx.exe
O4 - HKLM..\RunServices: [Retrospect Launcher] C:\PROGRAM FILES\DANTZ\RETROSPECT\LAUNCHER.EXE
O4 - HKLM..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O4 - HKCU..\Run: [spc_w] “C:\Program Files\NZSearch\nzspc.exe” -w
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: Reality Fusion GameCam SE.lnk = C:\Program Files\Reality Fusion\Reality Fusion GameCam SE\Program\RFTray.exe
O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\ScanSoft\PaperPort\Config\Ereg\REMIND32.EXE
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: Epson all-in-one Registration.lnk = D:\EREG\EpsonReg.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra ‘Tools’ menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll

@Eddy,

I have checked my old Win98 downstairs, it seems ‘o4 - hklm..\run: [systemtray] systray.exe’ is a legitimate start up item, from what i can find out about it, it shows dates and time etc (i think its the taskbar).


@ratdog
,

So looks like you are going to need to bring ‘o4 - hklm..\run: [systemtray] systray.exe’, luckily this is easily done, to do it:

Open hijackthis > click ‘view list of back ups’, check/select ‘o4 - hklm..\run: [systemtray] systray.exe’ from the list and press restore, it will then be back in its place.

OK, about your log, its clean IMHO :wink:

However i can’t see any active firewall on your system, do you use a hardware one?, if not Zonealarm and kerio are some good firewall suggestions.

See here if you want to know what a computer firewall is: http://www.answers.com/firewall&r=67 (technology part).

Also your windows is out of date, please visit www.windowsupdate.com and get all security patches etc.

–lee

Hi lee16,

You guys were right on the mark with your help…and I sincerely appreciate it. The replacement search page from the hijacker is gone and things look back to normal.

No, I don’t have a firewall…but I will look into getting one. And I started looking into the Windows update but wasn’t sure if I was looking in the right place. I don’t want to apply a patch that wasn’t meant for Win98 SE, particularly if there isn’t any real support for it anymore.

In any case, thanks again for all your help…and I’ve learned a few things as well.

ratdog

You better get a good firewall.
Unfortunatly it is something you need nowadays for security reasons. :-X

Best is a router with hardware firewall, but if you can afford it (+/- 35 euro) there are some good software firewalls and several are even freeware.

I don't want to apply a patch that wasn't meant for Win98 SE

If you go to windows update with Win98 SE, it will only give you the Win98 SE patches, thats the way it was designed.

–lee