it could not find nothing wrong. Here is my files.=
The blue Smitfraud Screen is still the Wallpaper.
Claude
(6/26/05 7:57:03 AM) SPSeHjFix started v1.09
(6/26/05 7:57:04 AM) OS: Win98SE A (4.10.67766446)
(6/26/05 7:57:04 AM) Language: english
(6/26/05 7:57:32 AM) Disinfect started
(6/26/05 7:57:32 AM) Bad-Dll(IEP): se.dll
(6/26/05 7:57:32 AM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\SYSTEM\KKOMODA.DLL
(6/26/05 7:57:32 AM) Searchassistant Uninstaller - Keys Deleted
(6/26/05 7:57:32 AM) UBF: 6
(6/26/05 7:57:32 AM) UBB: 0
(6/26/05 7:57:32 AM) FilterKey: HKCR\text/html (deleted)
(6/26/05 7:57:32 AM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(6/26/05 7:57:32 AM) FilterKey: HKCR\CLSID\{EFAA44E9-D9BD-11D9-9956-0004C405594A} (deleted)
(6/26/05 7:57:32 AM) FilterKey: HKCR\text/plain (deleted)
(6/26/05 7:57:32 AM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(6/26/05 7:57:32 AM) FilterKey: HKCR\CLSID\{EFAA44E9-D9BD-11D9-9956-0004C405594A} (error while deleting)
(6/26/05 7:57:32 AM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EFAA44EA-D9BD-11D9-9956-000434D7C73D} (deleted)
(6/26/05 7:57:32 AM) BHO-Key: HKCR\CLSID\{EFAA44EA-D9BD-11D9-9956-000434D7C73D} (deleted)
(6/26/05 7:57:32 AM) UBR: 13
(6/26/05 7:57:32 AM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall (deleted)
(6/26/05 7:57:32 AM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://C:\WINDOWS\TEMP\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://C:\WINDOWS\TEMP\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(6/26/05 7:57:32 AM) Stealth-String found: C:\WINDOWS\HLPBEWL.GIF
(6/26/05 7:57:32 AM) File added to delete: c:\windows\system\kkomoda.dll
(6/26/05 7:57:32 AM) File added to delete: c:\windows\system\kkomoda.dll
(6/26/05 7:57:32 AM) File added to delete: c:\windows\temp\se.dll
(6/26/05 7:57:32 AM) File added to delete: c:\windows\hlpbewl.gif
(6/26/05 7:57:32 AM) Reboot
(6/26/05 8:13:09 AM) SPSeHjFix 2nd Step
(6/26/05 8:13:10 AM) RunServicesOnce-Key: (edited)
(6/26/05 8:13:24 AM) Cleaned
Logfile of HijackThis v1.99.1
Scan saved at 8:24:14 AM, on 6/26/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\WINDOWS\SYSTEM\ATITASK.EXE
C:\PROGRAM FILES\EASY KEYBOARD\EASYKEY.EXE
C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE
C:\PROGRAM FILES\WINZIP\WZQKPICK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.e4me.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [Easykey] C:\Program Files\Easy Keyboard\Easykey.exe
O4 - HKLM\..\Run: [SBWatchDog.EXE] C:\WINDOWS\SYSTEM\SBUtils\SBWatchDog.EXE /l
O4 - HKLM\..\Run: [SoundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd
O4 - HKLM\..\Run: [THGuard] "C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE"
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] c:\windows\SYSTEM\mstask.exe
O4 - Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O14 - IERESET.INF: START_PAGE_URL=www.e4me.com
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab