HijackDat v1.99.1
HijackDat v1.99.1 — a parody of HijackThis, the classic browser-hijacker log scanner.
From the desktop window
HijackDat v1.99.1 — by Merijn Bellekom
This program scans your Doors registry, startup entries, browser settings, and running services for known adware, spyware, and browser hijackers.
Click Scan to begin a full system scan.
CAUTION: Only fix items you are certain are threats. Fixing legitimate entries may render Doors unstable or prevent it from starting.
Ready
HijackDat v1.99.1 — HijackThis Parody Browser Hijacker Scanner
HijackDat is a parody of HijackThis — the beloved free Windows security tool created by Dutch programmer Merijn Bellekom, widely used from approximately 2003 to 2007. HijackThis scanned a Windows system for browser hijackers, adware, and spyware by inspecting registry keys, Browser Helper Objects (BHOs), startup entries, Winsock LSP providers, running NT services, and protocol handlers. It presented results as a log file of categorized entries — R0 and R1 for browser start and search page hijacks, O2 for Browser Helper Objects, O4 for startup registry entries, O10 for Winsock/LSP hijackers, O17 for DNS name server changes, O18 for protocol hijacks, and O23 for NT services — which users would copy and post on security forums like SpywareInfo, Bleeping Computer, or DSL Reports, where experts would advise which items to fix. HijackThis was later acquired by Trend Micro. Version 1.99.1 was one of the most widely distributed builds.
HijackDat simulates a period-accurate scan of Doors 98's parody C:\\ drive. The 7-second animated scan traverses C:\\Doors\\System\\ and C:\\Program Files\\ and reveals 18 log entries spanning all major HijackThis categories: R0 and R1 entries show the browser start page hijacked to muricaweb.net; R3 shows a missing URLSearchHook; O2 entries flag YourWay Search Assistant and NeatWebFind Toolbar as Browser Helper Objects; O4 entries show six programs autolaunching at startup — ChumChimp, Snoozer, BassJamb, MuricaOnline, and StarPointer; O10 flags a DoorSock hijack by WhileU (DoorSock being Doors 98's equivalent of Winsock, after the parody OS name); O17 shows a suspicious NameServer entry; O18 flags the muricaweb protocol handler; and O23 exposes three NT services — Download More RAM Helper, WhileU Scheduler, and StarPointer Cursor Driver.
Parody threat roster: ChumChimp (parody of BonziBuddy) is a purple gorilla desktop assistant that installs NeatWebFind toolbar and resets the homepage to muricaweb.net. Snoozer (parody of Kazaa) is a P2P file sharing client seeding 4 files to 1,337 peers with 2,847 shared files indexed. YourWay Search Assistant (parody of MyWay Search) hijacked the browser search bar across 847 browsing sessions. NeatWebFind Toolbar (parody of CoolWebSearch) is an aggressive browser hijacker with a DLL in C:\\Doors\\System\\. MuricaOnline (parody of AOL) autolaunches mol.exe at startup — dialing in at 56,000 baud with 9,847 hours remaining. BassJamb (parody of Winamp) is the era-standard MP3 player found in virtually every HijackThis log of the period. StarPointer (parody of Comet Cursor) replaces the cursor with a shooting star and registers both an autorun executable and a kernel driver starpnt.sys. WhileU (parody of WhenU SaveNow) hijacks the DoorSock LSP layer with whileu.dll and runs a background scheduler. Download More RAM Helper (dlmore.exe) is a parody of the classic internet joke — registering as a legitimate NT service that reports downloading 0 additional megabytes of RAM.
Fix Checked triggers 49 sequential confirmation dialog boxes that cannot be dismissed — you must click OK through all of them. They escalate from earnest system warnings through guilt-tripping ("ChumChimp will be very lonely"), existential observations ("Are you even still reading these?"), corporate defeat ("Fine.", "FINE.", "We just want you to know we are very disappointed."), and finally a last-gasp deal pitch from WhileU before bottoming out at "fine" and "Reboot required to complete removal." Clicking OK on the final dialog triggers a full-screen blue screen of death — Doors 98 fatal exception 0E at 0028:C0034B53 — that holds for five seconds before resetting to idle. Save Log downloads a correctly formatted hijackdat.log including running process list, all log entries, and a byte count footer. Analyze This attempts to contact merijn.org for online log analysis and cannot connect.
All parody paths referenced in the log are real entries in the Doors 98 command-line filesystem. C:\\Doors\\System\\ contains starpnt.exe, starpnt.sys, whileu.dll, dlmore.exe, nwfsrch.dll, and the core Doors system executables. C:\\Program Files\\ contains subdirectories for ChumChimp, Snoozer, MuricaOnline, BassJamb, WhileU, and YourWay — all navigable from the command line. Running chimpassist.exe, snoozer.exe, mol.exe, dlmore.exe, or starpnt.exe from the command line produces era-appropriate fake output.
A parody of HijackThis — the free Windows spyware and browser-hijacker scanner created by Dutch programmer Merijn Bellekom, widely used from 2003 to 2007. HijackThis scanned system registry keys, Browser Helper Objects (BHOs), startup entries, Winsock LSP providers, running services, and protocol hijacks, presenting results as a categorized log file (R0, O2, O4, O10, O17, O18, O23 entries) that users posted on security forums for expert analysis. HijackDat simulates a period-accurate scan of Doors 98's parody C:\ drive, surfacing era-authentic threats: ChumChimp desktop adware (parody of BonziBuddy), Snoozer P2P client (parody of Kazaa), YourWay Search Assistant BHO (parody of MyWay), NeatWebFind Toolbar BHO (parody of CoolWebSearch), MuricaOnline autostart (parody of AOL), BassJamb media player (parody of Winamp), StarPointer cursor spyware (parody of Comet Cursor), WhileU DoorSock hijack (parody of WhenU SaveNow via Doors 98's equivalent of Winsock LSP), and Download More RAM Helper fake NT service. The scan reveals 18 entries across R0, R1, R3, O2, O4, O10, O17, O18, and O23 categories. Fix Checked triggers 49 sequential confirmation dialogs escalating from earnest to guilt-tripping to unhinged to defeated, followed by a simulated blue screen of death. Save Log generates a downloadable hijackdat.log in authentic HijackThis format. Analyze This attempts to connect to merijn.org and fails. All parody paths exist in the Doors 98 command-line filesystem under C:\Program Files\ and C:\Doors\System\.
Animated 7-second progress scan of C:\Doors\System; 18 categorized log entries across R0, R1, R3, O2, O4, O10, O17, O18, O23; Select/deselect all with per-entry checkboxes; Fix Checked with 49 sequential escalating confirmation dialogs; Simulated BSOD on completion; Save Log downloads hijackdat.log in HijackThis format; Analyze This connects to merijn.org and fails
These are the fictional log entries and scripted messages used by the desktop parody.
Scan log
R0 - HKCU\Software\MuriCaSoft\InfoSurfer\Main,Start Page = http://www.muricaweb.net
R1 - HKCU\Software\MuriCaSoft\InfoSurfer\Main,Search Page = http://search.muricaweb.net
R3 - Default URLSearchHook is missing
O2 - BHO: YourWay Search Assistant - {3F0C-AFF1-1337-DEAD} - C:\PROGRA~1\YOURWAY\srchbar.dll
O2 - BHO: NeatWebFind Toolbar Helper - {4E2A-DEAD-BEEF-1234} - C:\Doors\System\nwfsrch.dll
O4 - HKLM\..\Run: [ChumChimp] C:\Program Files\ChumChimp\chimpassist.exe
O4 - HKLM\..\Run: [Snoozer] C:\Program Files\Snoozer\snoozer.exe -systray
O4 - HKLM\..\Run: [BassJamb] C:\Program Files\BassJamb\bjamb.exe
O4 - HKLM\..\Run: [MuricaOnline] C:\Program Files\MuricaOnline\mol.exe
O4 - HKLM\..\Run: [StarPointer] C:\Doors\System\starpnt.exe /startup
O4 - STARTUP: ChumChimp.lnk = C:\Program Files\ChumChimp\chimpassist.exe
O10 - DoorSock hijack by WhileU: C:\Doors\System\whileu.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{A7BE-9C2D}: NameServer = 69.42.0.1
O18 - Protocol: muricaweb - {1D2E-3F4A-5B6C-7D8E} - C:\PROGRA~1\MURICA~1\murica.dll
O23 - Service: Download More RAM Helper (dlmore) - Unknown owner - C:\Doors\System\dlmore.exe
O23 - Service: WhileU Scheduler (wusched) - Unknown owner - C:\Program Files\WhileU\wusched.exe
O23 - Service: StarPointer Cursor Driver (starpnt) - Unknown owner - C:\Doors\System\starpnt.sysScan messages
- Initializing HijackDat v1.99.1...
- Scanning C:\Doors\System...
- Checking Browser Helper Objects...
- Scanning HKLM\SOFTWARE...
- Analyzing running processes...
- Scanning C:\Doors\Temp...
- Checking startup entries...
- Scanning downloaded program files...
- Analyzing hosts file for modifications...
- Checking DoorSock providers...
- Scanning C:\Program Files...
- Cross-referencing threat signatures...
- Finalizing...
Confirmation dialogs
- Are you sure you want to fix the checked items?
- This action cannot be undone. Continue?
- Warning: Fixing these items may affect your internet experience. Proceed?
- Some of these programs may be required for normal system operation. Continue anyway?
- Removing these items will require a system restart. Proceed?
- ChumChimp will be removed. He will be very lonely. Continue?
- Snoozer currently has 14,000 songs queued. Proceed with removal?
- YourWay Search has learned your browsing preferences over 847 sessions. Delete this data?
- Are you really sure?
- This is your absolute last chance to cancel.
- Okay but like, are you SURE sure?
- Have you considered that muricaweb.net is actually a great homepage?
- StarPointer makes your cursor a shooting star. You want to delete a shooting star?
- BassJamb is currently playing 'All Star'. Stop playback to continue?
- WhileU Scheduler has a great deal queued for you in 3 minutes. Cancel that deal?
- Download More RAM Helper has freed 47MB of RAM since last Tuesday. Remove it?
- Are you even still reading these?
- NeatWebFind found 12 great deals on carpet cleaning near you. Dismiss these deals?
- WARNING: Removing these items may cause Doors to become more stable.
- That sounds bad actually. Reconsider?
- NOTICE: Your IP address has been logged.
- Just kidding. Or have we?
- Proceeding will void your warranty.
- You don't have a warranty.
- 25 of 50 confirmations complete. You're halfway there!
- Have you tried restarting instead?
- ChumChimp says: 'Please don't go.'
- Snoozer is currently seeding 4 files to 1,337 peers. Interrupt this?
- MuricaOnline has been your ISP for 9 years. Think of the memories.
- Your free trial of NeatWebFind expires in 0 days. Renew now?
- No? Okay.
- Fine.
- FINE.
- We just want you to know we are very disappointed.
- YourWay Search wanted to say goodbye.
- ChumChimp has left the building.
- We have informed muricaweb.net of your decision.
- They said 'whatever.'
- WhileU wanted to tell you about one last deal.
- A really good one.
- Like, genuinely outstanding.
- Fine, we will not tell you.
- You will regret this.
- We mean that sincerely.
- Okay we are almost done.
- Almost.
- ALMOST.
- fine
- Reboot required to complete removal. Click OK to reboot.