ARTICLES

unknown HJT line

Patrick Bateman June 2, 2004 at 15:58:57 Pacific
Windows 95, Pentium MMX

Anybody know what this is? Should I delete it? I have the CoolWebSearch trojan--ran CWShredder and SpyBot and it didn't fix it.

O4 - HKLM\..\Run: [jopa] C:\WINDOWS\SYSTEM\SYSSTARTUP.exe

and

O4 - HKCU\..\Run: [jopa] C:\WINDOWS\SYSTEM\SYSSTARTUP.exe

Thanks.




Google Ads

#1
+1
Derek June 2, 2004 at 17:28:28 Pacific

Did a quick Google on sysstartup.exe

Take a look at this link, seems to have fixed it:
CLICK HERE

Derek.W



#2
+1
Derek June 2, 2004 at 17:30:51 Pacific

... should have said, look at discoqail's second post.

Derek.W



#3
+1
Patrick Bateman June 3, 2004 at 14:25:17 Pacific

Thanks but it didn't work. I ran HJT again and deleted a line from registry ending in YER6032.DLL and its corresponding files from my system folder, then deleted 3 backups it made to my start menu. That didn't work either.

Here are a couple of lines from HJT that I don't know what they are. Could they have something to do with it?

O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\MSOPT.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX



#4
+1
Derek June 3, 2004 at 15:06:09 Pacific

I'll be honest, it's the blind leading the blind on this. Searching Google with the CLSID's (long numbers) revealed this:

Tick the first one for deletion, this one:
O2 - BHO: (no name) - {B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} - C:\WINDOWS\MSOPT.DLL

It's apparently some sort of nasty.

The second entry you gave appears valid (Radio Toolbar).

Take a trip around Google because it may be necessary to do more than tick the HiJack Log entry. Google will often give hits on the file names too.

If you can't sort it out post on the Security & Virus forum because they are the best folk to help you.

Hope this moves you forward a bit, best I can do.

Derek.W



#5
+1
Abnormal June 3, 2004 at 19:10:41 Pacific

Some more info, this clsid stays the same
A9A674BF-771F-42E5-A440-D20DDA85A862

related link to your problem
> http://www.wilderssecurity.com




Related Posts

#6
+1
Derek June 3, 2004 at 19:24:45 Pacific

Word of warning. Don't do the stupid thing that I did!

If you go to the the link in Abnormal's posting, don't click on the active link within the 2nd posting there (it's obviously to a dodgy site).

I should have known better, fortunately it was blocked in my "Restricted Sites" - yours may not be....

Derek.W



#7
+1
Derek June 3, 2004 at 19:29:21 Pacific

... sorry, rephrase that - not 2nd posting but any link in the Hijack Logs.

Derek.W



#8
+1
Allen Maples June 4, 2004 at 14:38:05 Pacific

Abnormal, what do you mean by the clsid stays the same?

I found the file sysstartup.exe in my system folder. Just to be sure, is he saying that I should delete it?



#9
+1
Abnormal June 4, 2004 at 17:00:28 Pacific

-drops sysstartup.exe in the system/system32 folder

-accompanied with a randomly named BHO dll but STATIC clsid! :
Always the same letters and numbers.
{A9A674BF-771F-42E5-A440-D20DDA85A862}

The (BHO) Browser helper object should
come with your problem.
Do you have that in your hijackthis log?

This is new, I only know what I can find
in a search.

Post your log, lets see what you have.



#10
+1
Allen Maples June 5, 2004 at 11:32:19 Pacific

I can't post the HFT log. Tried a few times and kept getting an illegal operation message. What's going on?



#11
+1
Abnormal June 5, 2004 at 22:26:50 Pacific

I do not know, see if you can get anything
from this.

Blind helping to a problem I have never
seen is not easy.

http://www.computing.net/security/wwwboard/forum/12126.html



#12
+1
Allen Maples June 6, 2004 at 17:07:04 Pacific

Thanks for the link. I tried running CWShredder and Window Washer in safe mode but the problem is still there. I fixed the start page hijack, the only problem now is that I'm still getting the CoolWebSearch page when I go to a particular website. Could it be the website that's the problem instead of my computer? It's a site for the Sims game.



#13
+1
Abnormal June 6, 2004 at 19:17:06 Pacific

"Could it be the website that's the problem instead of my computer?"

You need to update to prevent it.
http://www.microsoft.com/technet/security/bulletin/MS03-011.mspx

The Microsoft VM is a virtual machine for the Win32operating environment. The Microsoft VM is shipped in most versions of Windows and in most versions of Microsoft Internet Explorer. A new security vulnerability has been reported that affects the ByteCode Verifier component of the Microsoft VM.

It occurs because the ByteCode verifier does not correctly look for certain malicious code when a Java applet is being loaded. The attack vector for this new security issue would likely involve an attacker creating a malicious Java applet and inserting it into a Web page that would exploit this vulnerability when it was opened. An attacker could then host this malicious Web page on a Web site or could send it to a user in e-mail.

The present Microsoft VM has been updated to include a fix for this newly reported security vulnerability. This version of VM includes all previously released fixes to the VM.

To download the patch to update existing installations of the Microsoft VM, visit the Microsoft Windows Update Web site. Windows Update detects what version of Windows you are running and offers the appropriate patch. To locate the update, visit the "Critical Updates" section of the Microsoft Windows Update Web site:

http://windowsupdate.microsoft.com



#14
+1
Allen Maples June 7, 2004 at 13:28:34 Pacific

When I tried the second link, all I got was a blank page.



#15
+1
Derek June 7, 2004 at 17:07:04 Pacific

I understand MS have ceased support for W95.

I cannot be sure but perhaps that's the reason for the blank page. I downloaded mine (W98) from the corporate update page. I've just checked and they don't give the option of W95 OS.

This post is getting a bit ancient now. Maybe you would get more attention if you posted it again (on the S&V forum I would have thought). A few fresh ideas might help.

Derek.W



Google Ads
Start New Discussion Reply to Message Icon
« problems with the new har... Problems with Computer. V... »


This post is quite old and has been locked from receiving new replies. Please create a new posting instead.



Ask the Community!
Describe your Problem
Example: Hard Drive Not Detected on My PC


Google Ads



Results for: unknown HJT line

reg files www.computing.net/answers/windows-95/reg-files/151822.html

unknown Disk error - Win 95...help! www.computing.net/answers/windows-95/unknown-disk-error-win-95help/167307.html

unknown device at start up www.computing.net/answers/windows-95/unknown-device-at-start-up/83524.html