I’m having a few different problems and was wondering if someone could take a look at the following and give me some suggestions.

I have Norton Anti Virus 2004 running, Spybot S&D, Spyware Blaster, Spyware Guard, Mozilla for the browser, and AOL 9.0 on a Windows 98SE system.

First of all , after reboot, the first time I open something like “My Computer”, “Control Panel”, or “Windows Explorer” I get a nagging error that “ Work Offline, no connection was found, click one of the following ,work offline or try again.”

Sometimes, I also get the blue screen of death when I try to reboot or shutdown.

I run Spybot and scan for files or problems , it finds four or five problems ,I select the fix it option. After deleting the problems I can close and reopen the Spybot ,do another scan and the same problems show up again. Why do these keep coming back and how do I keep them from coming back or does it even matter. Here is the problems, I also attached my HighJacker log below .


--- Search result list ---
Delfin Project: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Dpi

DSO Exploit: Data source object exploit (Registry change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

PeopleOnPage: Global settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Envolo

Unknown: IE Search bar (Registry change, nothing done)
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar=about:blank

Unknown: IE Search URL (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant=about:blank

Unknown: IE Search URL (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchAssistant=about:blank


--- Spybot - Search && Destroy version: 1.3 ---
2004-08-11 Includes\Cookies.sbi
2004-09-16 Includes\Dialer.sbi
2004-09-16 Includes\Hijackers.sbi
2004-09-16 Includes\Keyloggers.sbi
2004-09-16 Includes\Malware.sbi
2004-08-12 Includes\Revision.sbi
2004-09-16 Includes\Security.sbi
2004-09-16 Includes\Spybots.sbi
2004-05-12 Includes\LSP.sbi
2004-09-16 Includes\Trojans.sbi
2004-08-30 Includes\Tracks.uti


--- System information ---
Windows 98 (Build: 2222) A


--- Startup entries list ---
Located: HK_LM:Run, AutoLoadero0uf1IITLIPK
command: "C:\WINDOWS\SYSTEM\LAPFS400.EXE"

Located: HK_LM:Run, AutoUpdater
command: "c:\Program Files\AutoUpdate\AutoUpdate.exe"
file: c:\Program Files\AutoUpdate\AutoUpdate.exe
size: 225280
MD5: 0b491a091f3ca5a6ae78b106c16a8d31

Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 70816
MD5: 631bd98882f6fc3e1191c8c7ef942638

Located: HK_LM:Run, Dpi
command: C:\PROGRAM FILES\COMMON FILES\DPI\DPI.EXE
file: C:\PROGRAM FILES\COMMON FILES\DPI\DPI.EXE
size: 94208
MD5: 0782d3416735ca91c24837b80c4acf6c

Located: HK_LM:Run, HP Product Registration
command: C:\WINDOWS\HPOnLReg\Remind32.exe
file: C:\WINDOWS\HPOnLReg\Remind32.exe
size: 68096
MD5: e7d4c21e60ca622d7e0eadb0fb5dba55

Located: HK_LM:Run, InCD
command: C:\Program Files\ahead\InCD\InCD.exe
file: C:\Program Files\ahead\InCD\InCD.exe
size: 629760
MD5: c189a1c1fe3fedb40ca693d90152f125

Located: HK_LM:Run, LoadPowerProfile
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\Rundll32.exe
size: 24576
MD5: 3857d93aa630abbd63467db4aeffce2c

Located: HK_LM:Run, NaviSearch
command: C:\Program Files\NaviSearch\bin\nls.exe
file: C:\Program Files\NaviSearch\bin\nls.exe
size: 77824
MD5: 766df2c8c88f7c3e59012cf97dd8f39a

Located: HK_LM:Run, o75V36V
command: LAPFS400.EXE

Located: HK_LM:Run, Pcsv
command: C:\WINDOWS\system32\pcs\pcsvc.exe
file: C:\WINDOWS\system32\pcs\pcsvc.exe
size: 35840
MD5: f03db954d348fe4ab79df8db7a5218b9

Located: HK_LM:Run, QuickTime Task
command: "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
file: C:\WINDOWS\SYSTEM\QTTASK.EXE
size: 77824
MD5: c2a735b94ae4f4729ed152bff6a08e4d

Located: HK_LM:Run, RealTray
command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

Located: HK_LM:Run, ScanRegistry
command: C:\WINDOWS\scanregw.exe /autorun
file: C:\WINDOWS\scanregw.exe
size: 86016
MD5: f123231689e2ab2fa5c636b99314501f

Located: HK_LM:Run, SpybotSnD
command: "C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE" /autocheck /autofix
file: C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE
size: 3948032
MD5: 9d7660564cf9a8226dc8d44679f3a64b

Located: HK_LM:Run, Symantec Core LC
command: C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start

Located: HK_LM:Run, SystemTray
command: SysTray.Exe
file: C:\WINDOWS\SYSTEM\SysTray.Exe
size: 32768
MD5: 73681085dcd0997e531240100ca12b28

Located: HK_LM:Run, TaskMonitor
command: C:\WINDOWS\taskmon.exe
file: C:\WINDOWS\taskmon.exe
size: 28672
MD5: f795110611101279aa15997801abaca0

Located: HK_LM:Run, winmain
command: winmain.exe

Located: HK_LM:Run, WinTools
command: C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
file: C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
size: 455680
MD5: 449f885dc6f27345dd2d6d6822559a71

Located: HK_LM:RunServices, AolAcsDaemon1
command: "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
file: C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
size: 1434848
MD5: 52e82740fdf434a625fe0ac5e119a51f

Located: HK_LM:RunServices, ccEvtMgr
command: "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
size: 255136
MD5: 2a90a0a9e086d928c9f7ccacca87e6dc

Located: HK_LM:RunServices, ccSetMgr
command: "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
size: 234656
MD5: aa9904ce3ab832b160e592bf5588c0ea

Located: HK_LM:RunServices, LoadPowerProfile
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\Rundll32.exe
size: 24576
MD5: 3857d93aa630abbd63467db4aeffce2c

Located: HK_LM:RunServices, SchedulingAgent
command: mstask.exe
file: C:\WINDOWS\SYSTEM\mstask.exe
size: 118784
MD5: 6ebe6cad9397461161fa747336afcdfd

Located: HK_LM:RunServices, ScriptBlocking
command: "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
file: C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
size: 66784
MD5: 928627472adbd58bb72d5bb9cb1448f6

Located: HK_LM:RunServices, WinTools
command: C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
file: C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
size: 455680
MD5: 449f885dc6f27345dd2d6d6822559a71

Located: HK_CU:Run, Zwu9RWZ7Q
command: LIGSSPC.EXE
file: C:\WINDOWS\SYSTEM\LIGSSPC.EXE
size: 98304
MD5: d9dc2a1daa5f12bd8ffeace71548cab1

Located: Startup (user), America Online Tray Icon.lnk
command: C:\Program Files\America Online 9.0a\aoltray.exe
file: C:\Program Files\America Online 9.0a\aoltray.exe
size: 36954
MD5: 5f1272f5c6de24cea4f736859a9a55d1

Located: Startup (user), SpywareGuard.lnk
command: C:\Program Files\SpywareGuard\sgmain.exe
file: C:\Program Files\SpywareGuard\sgmain.exe
size: 360448
MD5: 61c028aba5e49573a6332f4a7c744e87

Located: Win.ini, Load
command: C:\OPLIMIT\OCRAWARE.EXE



--- Browser helper object list ---
{F4E04583-354E-4076-BE7D-ED6A80FD66DA} (ADP UrlCatcher Class)
BHO name:
CLSID name: ADP UrlCatcher Class
Path: C:\WINDOWS\SYSTEM\
Long name: msbe.dll
Short name: MSBE.DLL
Date (created): 8/12/04 4:06:50 PM
Date (last access): 9/16/04
Date (last write): 8/12/04 4:06:52 PM
Filesize: 53248
Attributes: archive
MD5: C0DF070EA8EE15C03552DE3E25756715
CRC32: 6F3450D7
Version: 0.2.0.0

{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} (NLS UrlCatcher Class)
BHO name:
CLSID name: NLS UrlCatcher Class
Path: C:\WINDOWS\SYSTEM\
Long name: nvms.dll
Short name: NVMS.DLL
Date (created): 8/12/04 4:05:58 PM
Date (last access): 9/16/04
Date (last write): 8/12/04 4:06:00 PM
Filesize: 73728
Attributes: archive
MD5: 02D5E94C3C02C86DFC00B5CA0D905731
CRC32: 206CA328
Version: 0.2.0.0

{CE188402-6EE7-4022-8868-AB25173A3E14} (CB UrlCatcher Class)
BHO name:
CLSID name: CB UrlCatcher Class
Path: C:\WINDOWS\SYSTEM\
Long name: mscb.dll
Short name: MSCB.DLL
Date (created): 8/12/04 4:06:08 PM
Date (last access): 9/16/04
Date (last write): 8/12/04 4:06:10 PM
Filesize: 90112
Attributes: archive
MD5: 179AD39708BC9DBBF232B0AFEB0B4FCF
CRC32: E8819FB6
Version: 0.2.0.0

{C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} (Band Class)
BHO name:
CLSID name: Band Class
Path: C:\PROGRAM FILES\SEP\
Long name: sep.dll
Short name: SEP.DLL
Date (created): 6/7/04 11:50:40 AM
Date (last access): 9/16/04
Date (last write): 6/7/04 11:50:42 AM
Filesize: 184320
Attributes: archive
MD5: 53962AD01ED1B98CA682D4338523DF28
CRC32: 2C34D161
Version: 0.1.0.0

{87766247-311C-43B4-8499-3D5FEC94A183} ()
BHO name:
CLSID name:
Path: C:\PROGRA~1\COMMON~1\WINTOOLS\
Long name: WToolsB.dll
Short name: WTOOLSB.DLL
Date (created): 9/1/04 3:03:58 PM
Date (last access): 9/16/04
Date (last write): 8/10/04 3:30:32 AM
Filesize: 189952
Attributes: readonly archive
MD5: 05A1E6F28C322E887B3A69A9F093D5D9
CRC32: 38D03863
Version: 0.1.0.0

{BDF3E430-B101-42AD-A544-FADC6B084872} (NAV Helper)
BHO name: NAV Helper
CLSID name: CNavExtBho Class
description: Norton Antivirus
classification: Legitimate
known filename: NavShExt.dll
info link: http://www.symantec.com/nav/nav_9xnt/
info source: TonyKlein
Path: C:\Program Files\Norton AntiVirus\
Long name: NAVShExt.dll
Short name: NAVSHEXT.DLL
Date (created): 3/17/04 11:23:48 AM
Date (last access): 9/16/04
Date (last write): 3/17/04 11:23:48 AM
Filesize: 103552
Attributes: archive
MD5: A11EB3F6C746FBFFDF9C587183FE7678
CRC32: E6026094
Version: 0.10.0.0

{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 5/12/04 1:03:00 AM
Date (last access): 9/16/04
Date (last write): 5/12/04 1:03:00 AM
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3

{4A368E80-174F-4872-96B5-0B27DDD11DB2} (SpywareGuard Download Protection)
BHO name: SpywareGuard Download Protection
CLSID name: SpywareGuardDLBLOCK.CBrowserHelper
description: SpywareGuard download protection
classification: Legitimate
known filename: dlprotect.dll
info link: http://www.wilderssecurity.net/spywareguard.html
info source: TonyKlein
Path: C:\PROGRAM FILES\SPYWAREGUARD\
Long name: dlprotect.dll
Short name: DLPROT~1.DLL
Date (created): 8/2/03 11:24:00 PM
Date (last access): 9/16/04
Date (last write): 8/2/03 11:24:02 PM
Filesize: 192512
Attributes: readonly archive
MD5: 964621E8B2415FEAA99026ED4F29D198
CRC32: DC8CF59D
Version: 0.2.0.2



--- ActiveX list ---
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla

DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla

Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla



--- Process list ---
Spybot - Search && Destroy process list report, 9/16/04 7:23:25 PM

PID: 4291790505 (2121221273) C:\WINDOWS\SYSTEM\KERNEL32.DLL
PID: 4294252745 (4294796941) C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE
PID: 4294368089 (4294436389) C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
PID: 4294402861 (4294796941) C:\PROGRAM FILES\AMERICA ONLINE 9.0A\AOLTRAY.EXE
PID: 4294436389 (4294796941) C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
PID: 4294508133 (4294848861) C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WSUP.EXE
PID: 4294516433 (4294796941) C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
PID: 4294537989 (4294796941) C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
PID: 4294541533 (4294796941) C:\PROGRAM FILES\COMMON FILES\DPI\DPI.EXE
PID: 4294550917 (4294796941) C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
PID: 4294551317 (4294796941) C:\WINDOWS\SYSTEM\LIGSSPC.EXE
PID: 4294600909 (4294652321) C:\OPLIMIT\OCRAWR32.EXE
PID: 4294603725 (4294796941) C:\WINDOWS\HPONLREG\REMIND32.EXE
PID: 4294621009 (4294796941) C:\WINDOWS\SYSTEM\QTTASK.EXE
PID: 4294652321 (4294796941) C:\OPLIMIT\OCRAWARE.EXE
PID: 4294676441 (4294796941) C:\WINDOWS\TASKMON.EXE
PID: 4294679013 (4294796941) C:\WINDOWS\SYSTEM\SYSTRAY.EXE
PID: 4294680261 (4294796941) C:\PROGRAM FILES\NAVISEARCH\BIN\NLS.EXE
PID: 4294751489 (4294679013) C:\WINDOWS\SYSTEM\WMIEXE.EXE
PID: 4294773141 (4294854545) C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
PID: 4294781737 (4294796941) C:\PROGRAM FILES\AUTOUPDATE\AUTOUPDATE.EXE
PID: 4294782145 (4294854545) C:\WINDOWS\SYSTEM\MSTASK.EXE
PID: 4294796941 (4294947073) C:\WINDOWS\EXPLORER.EXE
PID: 4294799745 (4294854545) C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
PID: 4294827337 (4294796941) C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
PID: 4294848861 (4294854545) C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WTOOLSA.EXE
PID: 4294850853 (4294854545) C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
PID: 4294854545 (4294947073) C:\WINDOWS\SYSTEM\MPREXE.EXE
PID: 4294860745 (4294947073) C:\WINDOWS\SYSTEM\mmtask.tsk
PID: 4294947073 (4291790505) C:\WINDOWS\SYSTEM\MSGSRV32.EXE


--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 9/16/04 7:23:25 PM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\SYSTEM\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
http://www.websearch.com/ie.aspx?tb_id=50171
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
about:blank
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
about:blank
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://home.microsoft.com/access/autosearch.asp?p=%s
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\SYSTEM\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
about:blank
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.aol.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir...ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\SearchAssistant
http://www.websearch.com/ie.aspx?tb_id=50171
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://www.websearch.com/ie.aspx?tb_id=50171


--- Winsock Layered Service Provider list ---
Protocol 0: MS.w95.spi.osp
GUID: {FF017DE1-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\mswsosp.dll
Description: Microsoft Windows 9x/ME name space provider
DB filename: %windir%\system\mswsosp.dll
DB protocol: MS.w95.spi.*

Protocol 1: MS.w95.spi.tcp
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*

Protocol 2: MS.w95.spi.udp
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*

Protocol 3: MS.w95.spi.raw
GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\msafd.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\msafd.dll
DB protocol: MS.w95.spi.*

Protocol 4: MS.w95.spi.rsvptcp
GUID: {ECBDCBA0-334A-11D0-BD88-0000C082E69A}
Filename: C:\WINDOWS\SYSTEM\rsvpsp.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\rsvoso.dll
DB protocol: MS.w95.spi.*

Protocol 5: MS.w95.spi.rsvpudp
GUID: {ECBDCBA0-334A-11D0-BD88-0000C082E69A}
Filename: C:\WINDOWS\SYSTEM\rsvpsp.dll
Description: Microsoft Windows 9x/ME network protocol
DB filename: %windir%\system\rsvoso.dll
DB protocol: MS.w95.spi.*

Namespace Provider 0: DNS Name Space Provider.
GUID: {FF017DE2-CAE9-11CF-8A99-00AA0062C609}
Filename: C:\WINDOWS\SYSTEM\rnr20.dll
Description: Microsoft Windows 9x/ME name space provider
DB filename: %windir%\system\rnr20.dll
DB protocol: DNS Name Space Provider.




Here is my HighJacker .log


Logfile of HijackThis v1.98.2
Scan saved at 6:35:54 PM, on 9/16/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WTOOLSA.EXE
C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\OPLIMIT\OCRAWARE.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\HPONLREG\REMIND32.EXE
C:\OPLIMIT\OCRAWR32.EXE
C:\PROGRAM FILES\AHEAD\INCD\INCD.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAM FILES\NAVISEARCH\BIN\NLS.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\AUTOUPDATE\AUTOUPDATE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\DPI\DPI.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\COMMON FILES\WINTOOLS\WSUP.EXE
C:\WINDOWS\SYSTEM\LIGSSPC.EXE
C:\PROGRAM FILES\AMERICA ONLINE 9.0A\AOLTRAY.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50171
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50171
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50171
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
F1 - win.ini: load=C:\OPLIMIT\OCRAWARE.EXE
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\SYSTEM\MSBE.DLL
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\SYSTEM\NVMS.DLL
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\SYSTEM\MSCB.DLL
O2 - BHO: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\PROGRAM FILES\SEP\SEP.DLL
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSB.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: Band Class - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - C:\PROGRAM FILES\SEP\SEP.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [HP Product Registration] C:\WINDOWS\HPOnLReg\Remind32.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [winmain] winmain.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AutoUpdater] "c:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Pcsv] C:\WINDOWS\system32\pcs\pcsvc.exe
O4 - HKLM\..\Run: [Dpi] C:\PROGRAM FILES\COMMON FILES\DPI\DPI.EXE
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SpybotSnD] "C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE" /autocheck /autofix
O4 - HKLM\..\Run: [AutoLoadero0uf1IITLIPK] "C:\WINDOWS\SYSTEM\LAPFS400.EXE"
O4 - HKLM\..\Run: [o75V36V] LAPFS400.EXE
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
O4 - HKLM\..\RunServices: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE
O4 - HKLM\..\RunServices: [AolAcsDaemon1] "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServicesOnce: [WinTools] C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLSA.EXE /boot
O4 - HKCU\..\Run: [Zwu9RWZ7Q] LIGSSPC.EXE
O4 - Startup: America Online Tray Icon.lnk = C:\Program Files\America Online 9.0a\aoltray.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\ms.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINDOWS\SYSTEM\ms.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com