This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Having fun with bluescreen, ibm0001.exe and c:\secure32.html

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Excuse my ignorance, I am only a casual computer user. Been spending all day trying to undue the damage. Wasn't able to use IE for a while. I ran: Spybot & Ad-Aware which didn't do anything I later ran: SuperAdBlocker which allowed me access to my browser again. At that point, I downloaded HiJackThis and got a log which I will post from the infected computer momentarily. Any help is appreciated.
Logfile of HijackThis v1.99.1
Scan saved at 1:13:51 PM, on 4/29/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\COMPAQ\INTERNET\ISDBDC.EXE
C:\WINDOWS\CPQDIAG\CPQDFWAG.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\PROGRAM FILES\MOTIVE\MOTIVEASSISTANT\MOTMON.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\TPPALDR.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\PROGRAM FILES\LEXMARK X1100 SERIES\LXBKBMGR.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE
C:\WINDOWS\SYSTEM\FPDISP5A.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\PAYTIME.EXE
C:\PROGRAM FILES\LEXMARK X1100 SERIES\LXBKBMON.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SADBLOCK.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IMGICON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\PROGRAM FILES\LINKSYS\WIRELESS-B PCI ADAPTER\ODHOST.EXE
C:\PROGRAM FILES\LINKSYS\WIRELESS-B PCI ADAPTER\WMP11CFG.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirec…archbar&LC=0409
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 12.242.18.8
O1 - Hosts: 127.0.0.5 makethemcry.com
O1 - Hosts: 127.0.0.5 loudcash.com
O1 - Hosts: 127.0.0.5 iframestat.com
O1 - Hosts: 127.0.0.5 toolbarpartner.com
O1 - Hosts: 127.0.0.5 hqcash.com
O1 - Hosts: 127.0.0.5 verybigcash.com
O1 - Hosts: 127.0.0.5 makethemcry.com
O1 - Hosts: 127.0.0.5 moviepartnership.com
O1 - Hosts: 127.0.0.5 callmachine.com
O1 - Hosts: 127.0.0.5 regcash.com
O1 - Hosts: 127.0.0.5 toolbarpartner.com
O1 - Hosts: 127.0.0.5 klikrevenue.com
O1 - Hosts: 127.0.0.5 p2dll.com
O1 - Hosts: 127.0.0.5 t73.com
O1 - Hosts: 127.0.0.5 www.makethemcry.com
O1 - Hosts: 127.0.0.5 www.loudcash.com
O1 - Hosts: 127.0.0.5 www.iframestat.com
O1 - Hosts: 127.0.0.5 www.toolbarpartner.com
O1 - Hosts: 127.0.0.5 www.hqcash.com
O1 - Hosts: 127.0.0.5 www.verybigcash.com
O1 - Hosts: 127.0.0.5 www.makethemcry.com
O1 - Hosts: 127.0.0.5 www.moviepartnership.com
O1 - Hosts: 127.0.0.5 www.callmachine.com
O1 - Hosts: 127.0.0.5 www.regcash.com
O1 - Hosts: 127.0.0.5 www.toolbarpartner.com
O1 - Hosts: 127.0.0.5 www.klikrevenue.com
O1 - Hosts: 127.0.0.5 www.p2dll.com
O1 - Hosts: 127.0.0.5 www.t73.com
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} - (no file)
O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SABBHO.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SABTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
O4 - HKLM\..\Run: [AvconsoleEXE] C:\Program Files\Network Associates\McAfee VirusScan\avconsol.exe /minimize
O4 - HKLM\..\Run: [VsecomrEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSECOMR.EXE
O4 - HKLM\..\Run: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\Run: [VsStatEXE] C:\Program Files\Network Associates\McAfee VirusScan\VSSTAT.EXE /SHOWWARNING
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\MotiveAssistant\motmon.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.EXE -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\issch.exe" -start
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\SYSTEM\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [KodakCCS] C:\windows\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [SysTray] C:\PROGRAM FILES\PAYTIME.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [CPQInet Runtime Service] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\RunServices: [isdbdc] c:\compaq\internet\isdbdc.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CpqDfwAg.exe
O4 - HKLM\..\RunServices: [Vshwin32EXE] C:\PROGRAM FILES\NETWORK ASSOCIATES\MCAFEE VIRUSSCAN\VSHWIN32.EXE
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SuperAdBlocker] C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SADBLOCK.EXE
O4 - Startup: Iomega Watch.lnk = C:\Program Files\Iomega\Tools\IOWATCH.EXE
O4 - Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools\IMGSTART.EXE
O4 - Startup: Iomega Disk Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.EXE
O4 - Startup: Refresh.lnk = C:\Program Files\Iomega\Tools\REFRESH.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: FirstPlace Software Scheduler 2.lnk = C:\Program Files\Plus!\SYSAGENT.EXE
O4 - Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O4 - Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B PCI Adapter\Startup.exe
O8 - Extra context menu item: AltaVista Home - http://jump.altavista.com/avie5/home
O8 - Extra context menu item: AV Search This Term - http://jump.altavista.com/avie5/search
O8 - Extra context menu item: AV Translate this Web Page - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: AV Translate Selection - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: (no name) - {06FE5D00-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra 'Tools' menuitem: &AltaVista Home - {06FE5D00-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr…en/nsmp2inf.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: SABWinLogon - C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SABWINLO.DLL
Hello ZDallas, welcome to the TC.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.


Please download hoster from the link below.

http://www.funkytoad.com/download/hoster.zip

Unzip Hoster.zip
Open Hoster.exe.

Then click on "Restore Original Hosts"

Close program when complete.


Empty Recycle Bin

Reboot and "copy/paste" a new HJT log as well as the Results from Spy Sweeper file into this thread.

Also please describe how your computer behaves at the moment.
Thanks for your help.

I tried to use spy sweeper three times before I decided to try out a couple of other programs first - a trendmicro product and f-secure product (both free trials)

Came back to use spysweeper. Ran totally different this time…didn't pick up a trojan and as much adware and it took less than 30 minutes. Before it was taking between 3-10 hours.

My computer still booted up with the blue screen, the missing ibm0001.exe error message and the c:\secure32.html screen from IE.

spysweeper log and HJT log follows…

********
1:06 AM: | Start of Session, Thursday, May 04, 2006 |
1:06 AM: Spy Sweeper started
1:06 AM: Sweep initiated using definitions version 556
1:06 AM: Starting Memory Sweep
1:11 AM: Memory Sweep Complete, Elapsed Time: 00:05:20
1:11 AM: Starting Registry Sweep
1:12 AM: Found Adware: blazefind
1:12 AM: HKLM\software\microsoft\windows\currentversion\run\ || systray (ID = 104536)
1:17 AM: Found Adware: psguard
1:17 AM: HKCR\clsid\{357a87ed-3e5d-437d-b334-deb7eb4982a3}\ (1 subtraces) (ID = 487755)
1:17 AM: HKLM\software\classes\clsid\{357a87ed-3e5d-437d-b334-deb7eb4982a3}\ (1 subtraces) (ID = 488280)
1:18 AM: Registry Sweep Complete, Elapsed Time:00:07:11
1:18 AM: Starting Cookie Sweep
1:18 AM: Found Spy Cookie: 2o7.net cookie
1:18 AM: default@2o7[1].txt (ID = 1957)
1:18 AM: Cookie Sweep Complete, Elapsed Time: 00:00:02
1:18 AM: Starting File Sweep
1:18 AM: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbc2-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbc3-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbc4-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbc5-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbc6-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbc7-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbc8-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbc9-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbca-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbcb-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbcc-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbcd-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbce-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbcf-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd0-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd1-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd2-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd3-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd4-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd5-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd6-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd7-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd8-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbd9-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbda-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbdb-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbdc-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbdd-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbde-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbdf-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe0-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe1-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe2-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe3-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe4-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe5-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe6-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe7-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe8-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbe9-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbea-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbeb-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbec-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbed-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbee-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbef-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf0-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf1-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf2-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf3-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf4-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf5-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf6-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf7-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf8-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbf9-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbfa-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbfb-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbfc-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbfd-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbfe-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dbff-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc00-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc01-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc02-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc03-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc04-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc05-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc06-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc07-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc08-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc09-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc0a-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc0b-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc0c-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc0d-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc0e-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc0f-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc10-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc11-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc12-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc13-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc14-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc15-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc16-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc17-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc18-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc19-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc1a-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc1b-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc1c-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc1d-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc1e-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc1f-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc20-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc21-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc22-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc23-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc24-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc25-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc26-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc27-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc28-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:21 AM: Warning: Failed to open file "c:\windows\application data\webroot\spy sweeper\temp\sscsda72dc29-db09-11da-a1ed-001217c4af9e.tmp". The process cannot access the file because
it is being used by another process
1:23 AM: Found System Monitor: cybervizion keylogger
1:23 AM: _isreg32.dll (ID = 163284)
1:28 AM: Warning: Invalid file - not a PKZip file
1:32 AM: File Sweep Complete, Elapsed Time: 00:13:38
1:32 AM: Full Sweep has completed. Elapsed time 00:26:16
1:32 AM: Traces Found: 7
1:32 AM: Removal process initiated
1:33 AM: Quarantining All Traces: cybervizion keylogger
1:33 AM: Warning: Out of memory
1:33 AM: Failed to quarantine cybervizion keylogger
1:33 AM: Failed to quarantine _isreg32.dll
1:33 AM: Quarantining All Traces: blazefind
1:33 AM: Quarantining All Traces: psguard
1:33 AM: Warning: Out of memory
1:33 AM: Warning: Out of memory
1:33 AM: Failed to quarantine psguard
1:33 AM: Failed to quarantine clsid\{357a87ed-3e5d-437d-b334-deb7eb4982a3}\
1:33 AM: Failed to quarantine HKLM: software\classes\clsid\{357a87ed-3e5d-437d-b334-deb7eb4982a3}\
1:33 AM: Quarantining All Traces: 2o7.net cookie
1:33 AM: Warning: Out of memory
1:33 AM: Failed to quarantine 2o7.net cookie
1:33 AM: Failed to quarantine default@2o7[1].txt
1:33 AM: Removal process completed. Elapsed time 00:00:43
1:35 AM: | End of Session, Thursday, May 04, 2006 |
********
9:04 PM: | Start of Session, Wednesday, May 03, 2006 |
9:04 PM: Spy Sweeper started
9:04 PM: Sweep initiated using definitions version 556
9:04 PM: Starting Memory Sweep
********
9:02 PM: | Start of Session, Wednesday, May 03, 2006 |
9:02 PM: Spy Sweeper started
9:03 PM: Your definitions are up to date.
9:04 PM: | End of Session, Wednesday, May 03, 2006 |


Logfile of HijackThis v1.99.1
Scan saved at 1:54:24 AM, on 5/4/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\COMPAQ\INTERNET\ISDBDC.EXE
C:\WINDOWS\CPQDIAG\CPQDFWAG.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\PROGRAM FILES\MOTIVE\MOTIVEASSISTANT\MOTMON.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\TPPALDR.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\PROGRAM FILES\LEXMARK X1100 SERIES\LXBKBMGR.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE
C:\WINDOWS\SYSTEM\FPDISP5A.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\LEXMARK X1100 SERIES\LXBKBMON.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IMGICON.EXE
C:\PROGRAM FILES\KODAK\KODAK EASYSHARE SOFTWARE\BIN\EASYSHARE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\LINKSYS\WIRELESS-B PCI ADAPTER\ODHOST.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\PROGRAM FILES\LINKSYS\WIRELESS-B PCI ADAPTER\WMP11CFG.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 12.242.18.8
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\MotiveAssistant\motmon.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.EXE -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\issch.exe" -start
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\SYSTEM\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [KodakCCS] C:\windows\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [CPQInet Runtime Service] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\RunServices: [isdbdc] c:\compaq\internet\isdbdc.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CpqDfwAg.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Iomega Watch.lnk = C:\Program Files\Iomega\Tools\IOWATCH.EXE
O4 - Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools\IMGSTART.EXE
O4 - Startup: Iomega Disk Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.EXE
O4 - Startup: Refresh.lnk = C:\Program Files\Iomega\Tools\REFRESH.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: FirstPlace Software Scheduler 2.lnk = C:\Program Files\Plus!\SYSAGENT.EXE
O4 - Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O4 - Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B PCI Adapter\Startup.exe
O8 - Extra context menu item: AltaVista Home - http://jump.altavista.com/avie5/home
O8 - Extra context menu item: AV Search This Term - http://jump.altavista.com/avie5/search
O8 - Extra context menu item: AV Translate this Web Page - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: AV Translate Selection - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: (no name) - {06FE5D00-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra 'Tools' menuitem: &AltaVista Home - {06FE5D00-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr…en/nsmp2inf.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: SABWinLogon - C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SABWINLO.DLL (file missing)
I suggest you do this:

Please do not delete anything unless instructed to.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime


Close ALL windows and browsers except HijackThis and click "Fix checked"



1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files (If listed)
7. Click OK and windows will comply.

Restart your computer.

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Continued thanks,

Computer loads up much faster.
Still getting ibm00001.exe error
Wallpaper is till default 98 blue
homepage was set to about:blank

HJT logfile follows:

Logfile of HijackThis v1.99.1
Scan saved at 6:29:54 PM, on 5/4/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\COMPAQ\INTERNET\ISDBDC.EXE
C:\WINDOWS\CPQDIAG\CPQDFWAG.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\CPQS\BWTOOLS\SCCENTER.EXE
C:\PROGRAM FILES\MOTIVE\MOTIVEASSISTANT\MOTMON.EXE
C:\WINDOWS\TPPALDR.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\PROGRAM FILES\LEXMARK X1100 SERIES\LXBKBMGR.EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE
C:\WINDOWS\SYSTEM\FPDISP5A.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\LEXMARK X1100 SERIES\LXBKBMON.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IMGICON.EXE
C:\PROGRAM FILES\ARCSOFT\PHOTOIMPRESSION 5\PI MONITOR.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\KODAK\KODAK EASYSHARE SOFTWARE\BIN\EASYSHARE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\LINKSYS\WIRELESS-B PCI ADAPTER\ODHOST.EXE
C:\PROGRAM FILES\LINKSYS\WIRELESS-B PCI ADAPTER\WMP11CFG.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 12.242.18.8
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\MotiveAssistant\motmon.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.EXE -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\issch.exe" -start
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\SYSTEM\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [KodakCCS] C:\windows\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [CPQInet Runtime Service] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\RunServices: [isdbdc] c:\compaq\internet\isdbdc.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CpqDfwAg.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Iomega Watch.lnk = C:\Program Files\Iomega\Tools\IOWATCH.EXE
O4 - Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools\IMGSTART.EXE
O4 - Startup: Iomega Disk Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.EXE
O4 - Startup: Refresh.lnk = C:\Program Files\Iomega\Tools\REFRESH.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: FirstPlace Software Scheduler 2.lnk = C:\Program Files\Plus!\SYSAGENT.EXE
O4 - Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O4 - Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B PCI Adapter\Startup.exe
O8 - Extra context menu item: AltaVista Home - http://jump.altavista.com/avie5/home
O8 - Extra context menu item: AV Search This Term - http://jump.altavista.com/avie5/search
O8 - Extra context menu item: AV Translate this Web Page - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: AV Translate Selection - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: (no name) - {06FE5D00-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra 'Tools' menuitem: &AltaVista Home - {06FE5D00-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr…en/nsmp2inf.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: SABWinLogon - C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SABWINLO.DLL (file missing)
Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL




Click "Start"> "Run"> type in Regedit tap Enter Key

Make sure "My Computer" is highlighted

Click "Edit"> "Find"
Type in ibm00001.exe tap Enter Key.
Right Click on the file if found and select "Delete"

Tap the "F3" Key to find the next entry of the file. Continue using the "F3" Key until it's finished searching.

Close Regedit.


Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
I returned my wallpaper to normal and the bluescreen didn't come back on startup.
Could not find ibm0001.exe in the registry (which confirms the error message)

The steps you gave me for backing up my registry must be for a later version of windows.
I used hte HELp function to find out how to do it and when I applied the steps, it said that I had already backed it up for today.

HJT logfile follows…

Logfile of HijackThis v1.99.1
Scan saved at 7:33:14 PM, on 5/4/06
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\COMPAQ\INTERNET\ISDBDC.EXE
C:\WINDOWS\CPQDIAG\CPQDFWAG.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\PROGRAM FILES\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEADM.EXE
C:\PROGRAM FILES\MOTIVE\MOTIVEASSISTANT\MOTMON.EXE
C:\WINDOWS\TPPALDR.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\PROGRAM FILES\LEXMARK X1100 SERIES\LXBKBMGR.EXE
C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\ISSCH.EXE
C:\WINDOWS\SYSTEM\FPDISP5A.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\LEXMARK X1100 SERIES\LXBKBMON.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\REMINDER.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SADBLOCK.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\PROGRAM FILES\IOMEGA\TOOLS\IMGICON.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\KODAK\KODAK EASYSHARE SOFTWARE\BIN\EASYSHARE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\PROGRAM FILES\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\LINKSYS\WIRELESS-B PCI ADAPTER\ODHOST.EXE
C:\PROGRAM FILES\LINKSYS\WIRELESS-B PCI ADAPTER\WMP11CFG.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 12.242.18.8
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: SuperAdBlockerBHO Class - {00000000-6C30-11D8-9363-000AE6309654} - C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SABBHO.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Super Ad Blocker Toolbar - {B4B3001E-0F56-4E51-8250-BDE11547EC55} - C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SABTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [Service Connection] c:\cpqs\bwtools\sccenter.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\MotiveAssistant\motmon.exe
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.EXE -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRAM FILES\COMMON FILES\INSTALLSHIELD\UPDATESERVICE\issch.exe" -start
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\SYSTEM\fpdisp5a.exe" /source=HKLM
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [KodakCCS] C:\windows\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [CPQInet Runtime Service] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\RunServices: [isdbdc] c:\compaq\internet\isdbdc.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\WINDOWS\cpqdiag\CpqDfwAg.exe
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft Money\System\reminder.exe
O4 - HKCU\..\Run: [MsnMsgr] "c:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [SuperAdBlocker] C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SADBLOCK.EXE
O4 - Startup: Iomega Watch.lnk = C:\Program Files\Iomega\Tools\IOWATCH.EXE
O4 - Startup: Iomega Startup Options.lnk = C:\Program Files\Iomega\Tools\IMGSTART.EXE
O4 - Startup: Iomega Disk Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.EXE
O4 - Startup: Refresh.lnk = C:\Program Files\Iomega\Tools\REFRESH.EXE
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: FirstPlace Software Scheduler 2.lnk = C:\Program Files\Plus!\SYSAGENT.EXE
O4 - Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
O4 - Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B PCI Adapter\Startup.exe
O8 - Extra context menu item: AltaVista Home - http://jump.altavista.com/avie5/home
O8 - Extra context menu item: AV Search This Term - http://jump.altavista.com/avie5/search
O8 - Extra context menu item: AV Translate this Web Page - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: AV Translate Selection - http://jump.altavista.com/avie5/babelfish
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: (no name) - {06FE5D00-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra 'Tools' menuitem: &AltaVista Home - {06FE5D00-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/home (file missing)
O9 - Extra button: Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra 'Tools' menuitem: AV &Translate - {06FE5D05-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/babelfish (file missing)
O9 - Extra button: (no name) - {06FE5D02-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL - {06FE5D02-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/linksearch (file missing)
O9 - Extra button: (no name) - {06FE5D03-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host - {06FE5D03-8F11-11d2-804F-00105A133818} - http://jump.altavista.com/avie5/hostsearch (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {22D6F312-B0F6-11D0-94AB-0080C74C7E95} (Windows Media Player) - http://activex.microsoft.com/activex/contr…en/nsmp2inf.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17.hotmail.msn.com/resources/MsnPUpld.cab
O20 - Winlogon Notify: SABWinLogon - C:\PROGRAM FILES\SUPERADBLOCKER.COM\SUPER AD BLOCKER\SABWINLO.DLL
yes, ther error message says ibm00001.exe Cannot find the file ibm00001.exe' (or one of its components). Make sure the path and filename are correct and that all required libraries are available.
click Start> Run> type in Msconfig tap enter key. look in the Startup. If listed, uncheck it. After you uncheck it and rebooting, you'll be using Selective startup. When you might see the box popup that tells you that, just put a Check in the Box to not show that when you startup. That's how I run mine. If not there it could be in the System.ini file.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI