This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unable to Log into web applications

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

This is my daughters computer. It will not allow her to log into web applications, such as email, MySpace. You can enter your log in information but when you click enter nothing happens. I have run ATF Cleaner and SpyBoy S & D.

Here is her log file:

Logfile of HijackThis v1.99.1
Scan saved at 8:56:01 PM, on 2/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\CSSSWD.exe
C:\WINDOWS\SSLS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\AOL\1190564291\ee\AOLSoftware.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\SSCRG.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://register.freeze.com/ping/?shortname…mp;browsers=4,2
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1190564291\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'smdnn05.dll' missing
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp3.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: Sndonad - {F3589BE7-7D71-4C79-9F19-32D239BAB9C4} - C:\WINDOWS\system32\ocxanpac.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Monitoring Service (ChatRecMonSvc) - Solid Oak Software, Inc. - C:\WINDOWS\CSSSWD.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: SS Logging Service (SSLOGSVC) - Solid Oak Software, Inc. - C:\WINDOWS\SSLS.exe

Thank you for your help in advance.
Harry
Hello

CLICK THIS TO LINK TO BE SURE YOU CAN VIEW HIDDEN FILES

Please go here:
The Spy Killer Forum
  • Click on "New Topic"
  • Put your name, e-mail address, and this as the title: "C:\WINDOWS\system32\ocxanpac.dll"
  • Put a link to this topic in the description box.
  • Then next to the file box, at the bottom, click the browse button, then navigate to this file:


    • C:\WINDOWS\system32\ocxanpac.dll

  • Click Open.
  • Click Post.
Thank you!



Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.



Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Hello Rorschach112, Thanks for your reply. I have run into a few problems from the very beginning. While trying to post on the Spy Killer Forum ( I couldn't from the infected computer). So I copied it ( ocxanpac.dll ) to a zip drip and added it to my post that way using a different computer. Hopefully that will be ok. Next when I downloaded the DSS and saved it to my desktop, closed all other programs and and proceeded to run the program. Part way through it said I didn't appear to have Hijack This downloaded to the infected computer, so I selected "No" to allow me to browse to the program. It still said that the file I pointed it to wasn't what it had expected. So I selected "Yes" to allow it to download Hijack This, but it couldn't so I choose "Cancel" . Then DSS returned this error message "dss.exe encountered a problem and needs to close, sorry for the inconvenience. Then the program terminates. At this point I wasn't sure if I should run the Kaspersky WebScanner prior to checking back with you and updating you on my lack of progress. Thanks, Harry
Do this

Download WinPFind35U.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind35u on your desktop.
  • Open the WinPFind35u folder and double-click on WinPFind35U.exe to start the program.
  • Under Additional Scans check the boxes beside Reg - Disabled MS Config Items, Reg - File Additional Folder Scans and File - Purity Scan.
  • Under Drivers change it to Non-Microsoft.
  • Under Rootkit Search change that to Yes.
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.

Make sure you attach the report in your reply.
Here is the WinPFind35.txt log

WinPFind35 logfile created on: 2/20/2008 1:10:36 PM
WinPFind35U Version Beta52	 Folder = C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Desktop\WinPFind35u
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
1.99 Gb Total Physical Memory | 1.55 Gb Available Physical Memory | 77.82% Memory free
2.58 Gb Paging File | 2.27 Gb Available in Paging File | 87.99% Paging File free
Paging file location(s): c:\pagefile.sys 756 1512;
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.18 Gb Total Space | 9.99 Gb Free Space | 30.11% Space Free | Partition Type: NTFS
Drive D: | 4.07 Gb Total Space | 0.83 Gb Free Space | 20.42% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-C8BH3JAGLT
Current User Name: Courtney
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user

[Processes - Non-Microsoft Only]
aawservice.exe -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/4/2008 1:27:08 PM | Attr =	]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 12:28:18 PM | Attr =	]
guard.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 7:31:10 AM | Attr =	]
cssswd.exe -> %SystemRoot%\CSSSWD.exe -> Solid Oak Software, Inc. [Ver = 1.7.8.13 | Size = 452392 bytes | Modified Date = 2/2/2008 3:16:38 PM | Attr =	]
ssls.exe -> %SystemRoot%\SSLS.exe -> Solid Oak Software, Inc. [Ver = 1.7.9.28 | Size = 837216 bytes | Modified Date = 2/2/2008 3:16:24 PM | Attr =	]
jusched.exe -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:35 AM | Attr =	]
hpsysdrv.exe -> %SystemRoot%\system\hpsysdrv.exe -> Hewlett-Packard Company [Ver = 1, 7, 0, 0 | Size = 52736 bytes | Modified Date = 5/7/1998 7:04:38 PM | Attr =	]
igfxtray.exe -> %SystemRoot%\system32\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.3762 | Size = 155648 bytes | Modified Date = 2/10/2004 8:55:32 PM | Attr =	]
hkcmd.exe -> %SystemRoot%\system32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.3762 | Size = 118784 bytes | Modified Date = 2/10/2004 8:51:30 PM | Attr =	]
vttimer.exe -> %SystemRoot%\system32\VTTimer.exe -> S3 Graphics, Inc. [Ver = 1.100.2004.0115 | Size = 49152 bytes | Modified Date = 1/16/2004 6:33:44 AM | Attr =	]
alcxmntr.exe -> %SystemRoot%\ALCXMNTR.EXE -> Realtek Semiconductor Corp. [Ver = 1.2 | Size = 50176 bytes | Modified Date = 4/3/2003 11:35:38 PM | Attr =	]
agrsmmsg.exe -> %SystemRoot%\AGRSMMSG.exe -> Agere Systems [Ver = 2.1.41.10 2.1.41.10 06/29/2004 09:06:35 | Size = 88363 bytes | Modified Date = 6/29/2004 11:06:38 AM | Attr =	]
ps2.exe -> %SystemRoot%\system32\ps2.EXE -> Hewlett-Packard Company [Ver = 1.0.2.2.911 | Size = 98304 bytes | Modified Date = 9/12/2003 10:13:20 PM | Attr =	]
brmfcwnd.exe -> %ProgramFiles%\Brother\Brmfcmon\BrMfcWnd.exe ->  [Ver = 2, 0, 0, 10 | Size = 622592 bytes | Modified Date = 3/28/2006 2:48:54 PM | Attr = R  ]
aolsoftware.exe -> %CommonProgramFiles%\AOL\1190564291\ee\aolsoftware.exe -> America Online, Inc. [Ver = 1.5.6.1 | Size = 50736 bytes | Modified Date = 9/25/2006 7:52:48 PM | Attr =	]
nmctxth.exe -> %CommonProgramFiles%\Pure Networks Shared\Platform\nmctxth.exe -> Pure Networks, Inc. [Ver = 4.5.7274.0 | Size = 451896 bytes | Modified Date = 10/1/2007 8:08:18 PM | Attr =	]
nmapp.exe -> %ProgramFiles%\Pure Networks\Network Magic\nmapp.exe -> Pure Networks, Inc. [Ver = 4.5.7228.0 | Size = 451896 bytes | Modified Date = 10/29/2007 10:04:44 PM | Attr =	]
qttask.exe -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.4 | Size = 385024 bytes | Modified Date = 1/10/2008 3:27:36 PM | Attr =	]
brccmctl.exe -> %ProgramFiles%\Brother\ControlCenter3\BrccMCtl.exe -> Brother Industries, Ltd. [Ver = 3, 0, 83, 83 | Size = 339968 bytes | Modified Date = 4/24/2006 6:23:42 PM | Attr =	]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 267048 bytes | Modified Date = 1/15/2008 3:22:56 AM | Attr =	]
avgas.exe -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 4:25:42 AM | Attr =	]
nmsrvc.exe -> %CommonProgramFiles%\Pure Networks Shared\Platform\nmsrvc.exe -> Pure Networks, Inc. [Ver = 4.5.7274.0 | Size = 451896 bytes | Modified Date = 10/1/2007 8:08:18 PM | Attr =	]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 504104 bytes | Modified Date = 1/15/2008 3:22:44 AM | Attr =	]
sscrg.exe -> %SystemRoot%\SSCRG.exe -> Solid Oak Software, Inc. [Ver = 1.7.10.17 | Size = 760104 bytes | Modified Date = 2/1/2008 3:07:44 PM | Attr =	]
winpfind35u.exe -> %UserProfile%\Desktop\WinPFind35u\WinPFind35U.exe -> OldTimer Tools [Ver = 1.0.0.0 | Size = 309760 bytes | Modified Date = 2/16/2008 1:03:26 PM | Attr =	]

[Win32 Services - Non-Microsoft Only]
(aawservice) Ad-Aware 2007 Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Lavasoft\Ad-Aware 2007\aawservice.exe -> Lavasoft [Ver = 7,0,2,6 | Size = 587096 bytes | Modified Date = 1/4/2008 1:27:08 PM | Attr =	]
(AOL ACS) AOL Connectivity Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\AOL\acs\AOLacsd.exe -> AOL LLC [Ver = 4.6.1.2			   | Size = 46640 bytes | Modified Date = 10/23/2006 7:50:35 AM | Attr = R  ]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 12:28:18 PM | Attr =	]
(AVG Anti-Spyware Guard) AVG Anti-Spyware Guard [Win32_Own | Auto | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 22 | Size = 312880 bytes | Modified Date = 5/30/2007 7:31:10 AM | Attr =	]
(ChatRecMonSvc) Monitoring Service [Win32_Own | Auto | Running] -> %SystemRoot%\CSSSWD.exe -> Solid Oak Software, Inc. [Ver = 1.7.8.13 | Size = 452392 bytes | Modified Date = 2/2/2008 3:16:38 PM | Attr =	]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %SystemRoot%\system32\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 2/28/2006 7:00:00 AM | Attr =	]
(FLEXnet Licensing Service) FLEXnet Licensing Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -> Macrovision Europe Ltd. [Ver = 11.03.005 | Size = 654848 bytes | Modified Date = 1/1/2008 8:38:43 PM | Attr =	]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 504104 bytes | Modified Date = 1/15/2008 3:22:44 AM | Attr =	]
(nmraapache) Pure Networks Net2Go Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe -> Pure Networks, Inc. [Ver = 2.0.54 | Size = 12800 bytes | Modified Date = 10/29/2007 10:03:06 PM | Attr =	]
(nmservice) Pure Networks Platform Service [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Pure Networks Shared\Platform\nmsrvc.exe -> Pure Networks, Inc. [Ver = 4.5.7274.0 | Size = 451896 bytes | Modified Date = 10/1/2007 8:08:18 PM | Attr =	]
(SSLOGSVC) SS Logging Service [Win32_Own | Auto | Running] -> %SystemRoot%\SSLS.exe -> Solid Oak Software, Inc. [Ver = 1.7.9.28 | Size = 837216 bytes | Modified Date = 2/2/2008 3:16:24 PM | Attr =	]

[Driver Services - Non-Microsoft Only]
(Abiosdsk) Abiosdsk [Kernel | Disabled | Stopped] ->  -> File not found
(abp480n5) abp480n5 [Kernel | Disabled | Stopped] ->  -> File not found
(adpu160m) adpu160m [Kernel | Disabled | Stopped] ->  -> File not found
(AgereSoftModem) Agere Systems Soft Modem [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\AGRSM.sys -> Agere Systems [Ver = 2.1.41.10 2.1.41.10 06/29/2004 09:07:15 | Size = 1268204 bytes | Modified Date = 6/29/2004 11:07:18 AM | Attr =	]
(Aha154x) Aha154x [Kernel | Disabled | Stopped] ->  -> File not found
(aic78u2) aic78u2 [Kernel | Disabled | Stopped] ->  -> File not found
(aic78xx) aic78xx [Kernel | Disabled | Stopped] ->  -> File not found
(ALCXSENS) Service for WDM 3D Audio Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ALCXSENS.SYS -> Sensaura Ltd [Ver = 5.10.00.3511D | Size = 391424 bytes | Modified Date = 12/12/2003 9:54:14 AM | Attr =	]
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ALCXWDM.SYS -> Realtek Semiconductor Corp. [Ver = 5.10.5480 | Size = 611836 bytes | Modified Date = 2/14/2004 5:00:34 AM | Attr =	]
(AliIde) AliIde [Kernel | Disabled | Stopped] ->  -> File not found
(amsint) amsint [Kernel | Disabled | Stopped] ->  -> File not found
(asc) asc [Kernel | Disabled | Stopped] ->  -> File not found
(asc3350p) asc3350p [Kernel | Disabled | Stopped] ->  -> File not found
(asc3550) asc3550 [Kernel | Disabled | Stopped] ->  -> File not found
(Atdisk) Atdisk [Kernel | Disabled | Stopped] ->  -> File not found
(AVG Anti-Spyware Driver) AVG Anti-Spyware Driver [Kernel | System | Running] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\guard.sys ->  [Ver =  | Size = 11000 bytes | Modified Date = 5/30/2007 7:10:42 AM | Attr =	]
(AvgAsCln) AVG Anti-Spyware Clean Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Modified Date = 5/30/2007 7:10:42 AM | Attr =	]
(BrScnUsb) Brother USB Still Image driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\BrScnUsb.sys -> Brother Industries Ltd. [Ver = 1,0,2,1 | Size = 15295 bytes | Modified Date = 10/15/2004 11:50:20 AM | Attr =	]
(cd20xrnt) cd20xrnt [Kernel | Disabled | Stopped] ->  -> File not found
(Changer) Changer [Kernel | System | Stopped] ->  -> File not found
(CmdIde) CmdIde [Kernel | Disabled | Stopped] ->  -> File not found
(Cpqarray) Cpqarray [Kernel | Disabled | Stopped] ->  -> File not found
(dac960nt) dac960nt [Kernel | Disabled | Stopped] ->  -> File not found
(dmboot) dmboot [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmboot.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 799744 bytes | Modified Date = 2/28/2006 7:00:00 AM | Attr =	]
(dmio) dmio [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmio.sys -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 153344 bytes | Modified Date = 2/28/2006 7:00:00 AM | Attr =	]
(dmload) dmload [Kernel | Disabled | Stopped] -> %SystemRoot%\system32\drivers\dmload.sys -> Microsoft Corp., Veritas Software. [Ver = 2600.0.503.0 | Size = 5888 bytes | Modified Date = 2/28/2006 7:00:00 AM | Attr =	]
(dpti2o) dpti2o [Kernel | Disabled | Stopped] ->  -> File not found
(fasttx2k) fasttx2k [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\Fasttx2k.sys -> Promise Technology, Inc. [Ver =  1.00.0030.11 | Size = 142336 bytes | Modified Date = 12/2/2003 9:23:20 PM | Attr =	]
(GEARAspiWDM) GEAR CDRom Filter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> GEAR Software Inc. [Ver = 2.0.6.1 | Size = 15664 bytes | Modified Date = 9/19/2006 1:44:04 PM | Attr =	]
(hpn) hpn [Kernel | Disabled | Stopped] ->  -> File not found
(i2omgmt) i2omgmt [Kernel | System | Stopped] ->  -> File not found
(i2omp) i2omp [Kernel | Disabled | Stopped] ->  -> File not found
(ialm) ialm [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ialmnt5.sys -> Intel Corporation [Ver = 6.14.10.3762 | Size = 681469 bytes | Modified Date = 2/10/2004 9:17:06 PM | Attr =	]
(ini910u) ini910u [Kernel | Disabled | Stopped] ->  -> File not found
(lbrtfdc) lbrtfdc [Kernel | System | Stopped] ->  -> File not found
(mraid35x) mraid35x [Kernel | Disabled | Stopped] ->  -> File not found
(MRENDIS5) MRENDIS5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> %CommonProgramFiles%\Motive\MRENDIS5.sys -> Motive, Inc. [Ver = 503.1658.0 | Size = 18003 bytes | Modified Date = 11/22/2004 5:36:39 PM | Attr =	]
(PCIDump) PCIDump [Kernel | System | Stopped] ->  -> File not found
(PDCOMP) PDCOMP [Kernel | On_Demand | Stopped] ->  -> File not found
(PDFRAME) PDFRAME [Kernel | On_Demand | Stopped] ->  -> File not found
(PDRELI) PDRELI [Kernel | On_Demand | Stopped] ->  -> File not found
(PDRFRAME) PDRFRAME [Kernel | On_Demand | Stopped] ->  -> File not found
(perc2) perc2 [Kernel | Disabled | Stopped] ->  -> File not found
(perc2hib) perc2hib [Kernel | Disabled | Stopped] ->  -> File not found
(pnarp) Pure Networks Device Discovery Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\pnarp.sys -> Pure Networks, Inc. [Ver = 4.6.7236.0 | Size = 23864 bytes | Modified Date = 9/20/2007 10:16:06 AM | Attr =	]
(Ps2) Ps2 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\PS2.sys -> Hewlett-Packard Company [Ver = 1.0.2.0 | Size = 23808 bytes | Modified Date = 7/30/2002 12:43:50 AM | Attr =	]
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> Parallel Technologies, Inc. [Ver = 1.10 (XPClient.010817-1148) | Size = 17792 bytes | Modified Date = 2/28/2006 7:00:00 AM | Attr =	]
(purendis) Pure Networks Wireless Driver [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\purendis.sys -> Pure Networks, Inc. [Ver = 4.6.7236.0 | Size = 24888 bytes | Modified Date = 9/20/2007 10:16:06 AM | Attr =	]
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> Sonic Solutions [Ver = 3.00.56a | Size = 43528 bytes | Modified Date = 1/1/2008 8:24:23 PM | Attr =	]
(ql1080) ql1080 [Kernel | Disabled | Stopped] ->  -> File not found
(Ql10wnt) Ql10wnt [Kernel | Disabled | Stopped] ->  -> File not found
(ql12160) ql12160 [Kernel | Disabled | Stopped] ->  -> File not found
(ql1240) ql1240 [Kernel | Disabled | Stopped] ->  -> File not found
(ql1280) ql1280 [Kernel | Disabled | Stopped] ->  -> File not found
(RT2500USB) Wireless USB Card Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rt2500usb.sys -> Ralink Technology Inc. [Ver = 2.00.04.0000 | Size = 242432 bytes | Modified Date = 2/5/1784 7:28:16 PM | Attr = R  ]
(rtl8139) Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\R8139n51.sys -> Realtek Semiconductor Corporation		[Ver = 5.505.1004.2002 built by: WinDDK | Size = 46976 bytes | Modified Date = 10/4/2002 8:04:10 PM | Attr =	]
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\secdrv.sys -> Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K. [Ver = 4.03.086 | Size = 20480 bytes | Modified Date = 11/13/2007 5:25:53 AM | Attr =	]
(Simbad) Simbad [Kernel | Disabled | Stopped] ->  -> File not found
(SiS315) SiS315 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\sisgrp.sys -> Silicon Integrated Systems Corporation [Ver = 6.14.10.3560 | Size = 432000 bytes | Modified Date = 1/2/2004 10:20:40 PM | Attr =	]
(SISAGP) SiS AGP Filter [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\SISAGPX.SYS -> Silicon Integrated Systems Corporation [Ver = 7.2.0.1170 built by: WinDDK | Size = 36992 bytes | Modified Date = 7/18/2003 7:58:20 PM | Attr =	]
(SiSkp) SiSkp [Kernel | System | Running] -> %SystemRoot%\system32\drivers\srvkp.sys -> Silicon Integrated Systems Corporation [Ver = 6.14.10.3560 | Size = 11520 bytes | Modified Date = 1/2/2004 11:05:48 PM | Attr =	]
(Sparrow) Sparrow [Kernel | Disabled | Stopped] ->  -> File not found
(symc810) symc810 [Kernel | Disabled | Stopped] ->  -> File not found
(symc8xx) symc8xx [Kernel | Disabled | Stopped] ->  -> File not found
(sym_hi) sym_hi [Kernel | Disabled | Stopped] ->  -> File not found
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] ->  -> File not found
(TosIde) TosIde [Kernel | Disabled | Stopped] ->  -> File not found
(ultra) ultra [Kernel | Disabled | Stopped] ->  -> File not found
(USBAAPL) Apple Mobile USB Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\usbaapl.sys -> Apple, Inc. [Ver = 1, 25, 0, 0 | Size = 30464 bytes | Modified Date = 10/31/2007 2:09:14 PM | Attr =	]
(viaagp1) VIA AGP Filter [Kernel | Boot | Stopped] -> %SystemRoot%\System32\DRIVERS\viaagp1.sys -> File not found
(viagfx) viagfx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\vtmini.sys -> Copyright (C) VIA/S3 Graphics, Inc. [Ver = 6.14.10.0113-16.94.35.11 | Size = 134144 bytes | Modified Date = 2/4/2004 8:28:00 PM | Attr =	]
(wanatw) WAN Miniport (ATW) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\wanatw4.sys -> America Online, Inc. [Ver = 8.3.0.0 | Size = 33588 bytes | Modified Date = 1/10/2003 4:13:04 PM | Attr = R  ]
(WDICA) WDICA [Kernel | On_Demand | Stopped] ->  -> File not found

[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> 
!AVG Anti-Spyware -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\avgas.exe -> GRISOFT s.r.o. [Ver = 7, 5, 1, 43 | Size = 6731312 bytes | Modified Date = 6/11/2007 4:25:42 AM | Attr =	]
AGRSMMSG -> %SystemRoot%\AGRSMMSG.exe -> Agere Systems [Ver = 2.1.41.10 2.1.41.10 06/29/2004 09:06:35 | Size = 88363 bytes | Modified Date = 6/29/2004 11:06:38 AM | Attr =	]
AlcxMonitor -> %SystemRoot%\ALCXMNTR.EXE -> Realtek Semiconductor Corp. [Ver = 1.2 | Size = 50176 bytes | Modified Date = 4/3/2003 11:35:38 PM | Attr =	]
BrMfcWnd -> %ProgramFiles%\Brother\Brmfcmon\BrMfcWnd.exe ->  [Ver = 2, 0, 0, 10 | Size = 622592 bytes | Modified Date = 3/28/2006 2:48:54 PM | Attr = R  ]
ControlCenter3 -> %ProgramFiles%\Brother\ControlCenter3\BrCtrCen.exe -> Brother Industries, Ltd. [Ver = 3, 0, 8, 2 | Size = 61440 bytes | Modified Date = 4/10/2006 1:58:06 PM | Attr =	]
HostManager -> %CommonProgramFiles%\AOL\1190564291\ee\aolsoftware.exe -> America Online, Inc. [Ver = 1.5.6.1 | Size = 50736 bytes | Modified Date = 9/25/2006 7:52:48 PM | Attr =	]
HotKeysCmds -> %SystemRoot%\system32\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.3762 | Size = 118784 bytes | Modified Date = 2/10/2004 8:51:30 PM | Attr =	]
hpsysdrv -> %SystemRoot%\system\hpsysdrv.exe -> Hewlett-Packard Company [Ver = 1, 7, 0, 0 | Size = 52736 bytes | Modified Date = 5/7/1998 7:04:38 PM | Attr =	]
IgfxTray -> %SystemRoot%\system32\igfxtray.exe -> Intel Corporation [Ver = 3.0.0.3762 | Size = 155648 bytes | Modified Date = 2/10/2004 8:55:32 PM | Attr =	]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.6.0.29 | Size = 267048 bytes | Modified Date = 1/15/2008 3:22:56 AM | Attr =	]
nmapp -> %ProgramFiles%\Pure Networks\Network Magic\nmapp.exe -> Pure Networks, Inc. [Ver = 4.5.7228.0 | Size = 451896 bytes | Modified Date = 10/29/2007 10:04:44 PM | Attr =	]
nmctxth -> %CommonProgramFiles%\Pure Networks Shared\Platform\nmctxth.exe -> Pure Networks, Inc. [Ver = 4.5.7274.0 | Size = 451896 bytes | Modified Date = 10/1/2007 8:08:18 PM | Attr =	]
PS2 -> %SystemRoot%\system32\ps2.EXE -> Hewlett-Packard Company [Ver = 1.0.2.2.911 | Size = 98304 bytes | Modified Date = 9/12/2003 10:13:20 PM | Attr =	]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.4 | Size = 385024 bytes | Modified Date = 1/10/2008 3:27:36 PM | Attr =	]
Recguard -> %SystemRoot%\SMINST\Recguard.exe ->  [Ver = 5, 0, 44, 2 | Size = 233472 bytes | Modified Date = 4/13/2004 11:43:46 PM | Attr =	]
SetDefPrt -> %ProgramFiles%\Brother\Brmfl06a\BrStDvPt.exe -> Brother Industories, Ltd. [Ver = 1, 0, 1, 2 | Size = 49152 bytes | Modified Date = 1/26/2005 5:02:22 PM | Attr =	]
SunJavaUpdateSched -> %ProgramFiles%\Java\jre1.6.0_03\bin\jusched.exe -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:35 AM | Attr =	]
VTTimer -> %SystemRoot%\system32\VTTimer.exe -> S3 Graphics, Inc. [Ver = 1.100.2004.0115 | Size = 49152 bytes | Modified Date = 1/16/2004 6:33:44 AM | Attr =	]
< OptionalComponents [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> 
IMAIL-> Installed = 1 -> 
MAPI-> Installed = 1 -> 
MSFS-> Installed = 1 -> 
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup -> 
%AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk -> %ProgramFiles%\Adobe\Acrobat 7.0\Reader\reader_sl.exe -> Adobe Systems Incorporated [Ver = 7.0.0.0 | Size = 29696 bytes | Modified Date = 12/14/2004 4:44:06 AM | Attr =	]
< Courtney.YOUR-C8BH3JAGLT.000 Startup Folder > -> C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Start Menu\Programs\Startup -> 
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad -> 
{F3589BE7-7D71-4C79-9F19-32D239BAB9C4} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\ocxanpac.dll [Sndonad] -> File not found
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> 
{57B86673-276A-48B2-BAE7-C6DBB3020EB8} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [AVG Anti-Spyware 7.5] -> GRISOFT s.r.o. [Ver = 7, 5, 1, 36 | Size = 79408 bytes | Modified Date = 5/30/2007 7:29:58 AM | Attr =	]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> 
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> 
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> 
igfxcui -> %SystemRoot%\system32\igfxsrvc.dll -> Intel Corporation [Ver = 3.0.0.3762 | Size = 339968 bytes | Modified Date = 2/10/2004 8:51:10 PM | Attr =	]
< CurrentVersion Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext ->  -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> 
< CurrentVersion Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place0 -> ::{C55C499D-3518-44a1-998E-796AC5FC989D} -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place1 -> 8 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place2 -> 0 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place3 -> 5 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ComDlg32\PlacesBar\\Place4 -> 17 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools -> 0 -> 
< HOSTS File > (224459 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts -> 
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> 
HKEY_LOCAL_MACHINE\: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\Local Page -> %SystemRoot%\system32\blank.htm -> 
HKEY_LOCAL_MACHINE\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_LOCAL_MACHINE\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home -> 
HKEY_LOCAL_MACHINE\: Search\\CustomizeSearch -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm -> 
HKEY_LOCAL_MACHINE\: Search\\SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> 
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> -> 
HKEY_CURRENT_USER\: Main\\Local Page -> C:\WINDOWS\system32\blank.htm -> 
HKEY_CURRENT_USER\: Main\\Search Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> 
HKEY_CURRENT_USER\: Main\\Start Page -> http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> 
HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
HKEY_CURRENT_USER\: ProxyEnable -> 0 -> 
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4192 domain(s) found. -> 
33 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> 
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4191 domain(s) found. -> 
32 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> 
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. -> 
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> 
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [AcroIEHlprObj Class] -> Adobe Systems Incorporated [Ver = 7.0.0.2004121400 | Size = 63136 bytes | Modified Date = 12/14/2004 1:56:50 AM | Attr =	]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 1:11:33 AM | Attr =	]
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> 
{32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> 
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> 
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:34 AM | Attr =	]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} [HKEY_CURRENT_USER] -> %ProgramFiles%\Java\jre1.6.0_03\bin\ssv.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 501136 bytes | Modified Date = 9/25/2007 1:11:33 AM | Attr =	]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ -> 
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Java\jre1.6.0_03\bin\npjpi160_03.dll [Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.30.5 | Size = 132496 bytes | Modified Date = 9/25/2007 1:11:34 AM | Attr =	]
CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKEY_LOCAL_MACHINE] ->  [Reg Error: Key does not exist or could not be opened.] -> File not found
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ -> 
PluginsPageFriendlyName -> Microsoft ActiveX Gallery -> 
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s -> 
< User Agent Post Platform [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> 
SV1 ->  -> 
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> 
{1D7EED67-F7CB-4151-A015-D650BE13CF09} ->	(Wireless USB Card) -> 
{2AE17E0D-BF0F-4552-93F2-6744E19553B9} ->	(1394 Net Adapter) -> 
{2CB98DF8-52B6-436F-80BE-ED3F7ABDD49B} ->	(Wireless USB Card) -> 
{4FE123BA-5B5C-4D0B-97D9-67AC1ECCBCDD} ->	(Realtek RTL8139/810x Family Fast Ethernet NIC) -> 
{55A43072-E2C6-4F85-93B7-F9998DEB2D46} ->	(Wireless USB Card) -> 
{6464958E-C2A9-486C-AF6E-14B9021C39C6} ->	(Wireless USB Card) -> 
{7A50092C-2C78-403F-93D6-5D01F137E1A6} ->	(Wireless USB Card) -> 
{802F1BD8-13D8-4B76-B8F2-DD06EFF18212} ->	(Wireless USB Card) -> 
{E4CD246A-72FD-4FBC-9239-66866A0AB671} ->	(Wireless USB Card) -> 
< Winsock2 Catalogs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\ -> 
Protocol_Catalog9\Catalog_Entries\000000000001 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000002 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000003 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000004 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000005 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000006 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000007 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000008 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000009 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000010 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000011 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000012 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000013 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000014 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000015 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000016 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000017 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000018 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000019 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000020 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000021 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000022 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000023 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000024 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000025 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000026 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000027 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000028 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000029 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000030 -> ssmdnn05.dll -> File not found
Protocol_Catalog9\Catalog_Entries\000000000031 -> ssmdnn05.dll -> File not found
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> 
ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found
msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value  does not exist or could not be read.] -> File not found
pure-go:{4746C79A-2042-4332-8650-48966E44ABA8} [HKEY_LOCAL_MACHINE] -> %CommonProgramFiles%\Pure Networks Shared\Platform\puresp3.dll[CPureGoProtoInfo Object] -> Pure Networks, Inc. [Ver = 4.5.7324.0 | Size = 140600 bytes | Modified Date = 11/20/2007 2:18:32 PM | Attr =	]
vnd.ms.radio:{3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\msdxm.ocx[AsyncPProt Class] ->  [Ver =  | Size = 844314 bytes | Modified Date = 2/28/2006 7:00:00 AM | Attr =	]
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> 
{33564D57-0000-0010-8000-00AA00389B71}[HKEY_LOCAL_MACHINE] -> http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB[Reg Error: Key does not exist or could not be opened.] -> 
{8AD9C840-044E-11D1-B3E9-00805F499D93}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> 
{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab[Java Plug-in 1.4.2_03] -> 
{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab[Java Plug-in 1.6.0_02] -> 
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}[HKEY_LOCAL_MACHINE] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab[Java Plug-in 1.6.0_03] -> 
{D27CDB6E-AE6D-11CF-96B8-444553540000}[HKEY_LOCAL_MACHINE] -> http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[Shockwave Flash Object] -> 


[Registry - Additional Scans - Non-Microsoft Only]


[Files/Folders - Created Within 30 days]
Deckard -> %SystemDrive%\Deckard ->  [Folder | Created Date = 2/19/2008 10:29:06 PM | Attr =	]
AvgAsCln.sys -> %SystemRoot%\System32\drivers\AvgAsCln.sys -> GRISOFT, s.r.o. [Ver = 1.0.0.14 | Size = 10872 bytes | Modified Date = 5/30/2007 7:10:42 AM | Attr =	]
mp4afpac.dll -> %SystemRoot%\System32\mp4afpac.dll ->  [Ver =  | Size = 326656 bytes | Modified Date = 2/1/2008 2:44:49 PM | Attr =	]
ERDNT -> %SystemRoot%\ERDNT ->  [Folder | Created Date = 2/19/2008 10:29:53 PM | Attr =	]
13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
SSDGT.exe -> %SystemRoot%\SSDGT.exe -> Solid Oak Software, Inc. [Ver = 1.7.6.11 | Size = 716336 bytes | Modified Date = 2/19/2008 10:09:07 PM | Attr =	]
unins000.dat -> %SystemRoot%\unins000.dat ->  [Ver =  | Size = 3455 bytes | Modified Date = 2/11/2008 12:34:05 PM | Attr =	]
unins000.exe -> %SystemRoot%\unins000.exe ->  [Ver = 51.49.0.0 | Size = 691545 bytes | Modified Date = 2/11/2008 12:31:53 PM | Attr =	]
?ymbols -> %SystemRoot%\ѕymbols ->  [Folder | Modified Date = 7/13/2007 10:04:51 PM | Attr =	]
[Files Created - Additional Folder Scans - Non-Microsoft Only]
Lavasoft -> %AllUsersProfile%\Application Data\Lavasoft ->  [Folder | Created Date = 2/1/2008 6:08:44 PM | Attr =	]
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes ->  [Folder | Created Date = 2/14/2008 5:42:36 AM | Attr =	]
{8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7} -> %AllUsersProfile%\Application Data\{8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7} ->  [Folder | Created Date = 2/1/2008 3:07:11 PM | Attr =	]
AOL -> %AppData%\AOL ->  [Folder | Created Date = 2/11/2008 10:41:29 AM | Attr =	]
AVG7 -> %AppData%\AVG7 ->  [Folder | Created Date = 2/5/2008 8:47:00 PM | Attr =	]
Malwarebytes -> %AppData%\Malwarebytes ->  [Folder | Created Date = 2/14/2008 5:42:43 AM | Attr =	]
PC-FAX TX -> %AppData%\PC-FAX TX ->  [Folder | Created Date = 2/11/2008 11:26:43 AM | Attr =	]
Uniblue -> %AppData%\Uniblue ->  [Folder | Created Date = 2/11/2008 11:56:46 AM | Attr =	]
ApplicationHistory -> %UserProfile%\Local Settings\Application Data\ApplicationHistory ->  [Folder | Created Date = 2/1/2008 7:46:14 PM | Attr =	]
Seven Zip -> %UserProfile%\Local Settings\Application Data\Seven Zip ->  [Folder | Created Date = 2/1/2008 3:05:15 PM | Attr =	]
My eBooks -> %UserProfile%\My Documents\My eBooks ->  [Folder | Created Date = 1/27/2008 4:37:58 PM | Attr =	]
My Received Files -> %UserProfile%\My Documents\My Received Files ->  [Folder | Created Date = 1/26/2008 9:00:02 PM | Attr =	]
Prom Dress.jpg -> %UserProfile%\My Documents\Prom Dress.jpg ->  [Ver =  | Size = 29776 bytes | Modified Date = 2/10/2008 10:22:37 PM | Attr =	]
Tenis.html -> %UserProfile%\My Documents\Tenis.html ->  [Ver =  | Size = 14667 bytes | Modified Date = 1/23/2008 6:55:52 PM | Attr =	]
AVG Anti-Spyware.lnk -> %AllUsersProfile%\Desktop\AVG Anti-Spyware.lnk ->  [Ver =  | Size = 857 bytes | Modified Date = 2/14/2008 5:12:17 AM | Attr =	]
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk ->  [Ver =  | Size = 704 bytes | Modified Date = 2/14/2008 5:42:36 AM | Attr =	]
RegistryBooster 2.lnk -> %AllUsersProfile%\Desktop\RegistryBooster 2.lnk ->  [Ver =  | Size = 802 bytes | Modified Date = 2/11/2008 11:56:40 AM | Attr =	]
ATF-Cleaner.exe -> %UserProfile%\Desktop\ATF-Cleaner.exe -> Atribune.org [Ver = 3.00.0002 | Size = 50688 bytes | Modified Date = 2/11/2008 11:44:31 AM | Attr =	]
dss.exe -> %UserProfile%\Desktop\dss.exe ->  [Ver = 3, 2, 8, 1 | Size = 686630 bytes | Modified Date = 2/19/2008 10:28:34 PM | Attr =	]
Hijackthis.lnk -> %UserProfile%\Desktop\Hijackthis.lnk ->  [Ver =  | Size = 658 bytes | Modified Date = 2/13/2008 8:55:41 PM | Attr =	]
Log Files -> %UserProfile%\Desktop\Log Files ->  [Folder | Created Date = 2/14/2008 5:57:55 AM | Attr =	]
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> Malwarebytes												 [Ver = 1.0.0.0			  | Size = 1304224 bytes | Modified Date = 2/14/2008 5:41:49 AM | Attr =	]
Software -> %UserProfile%\Desktop\Software ->  [Folder | Created Date = 2/1/2008 5:59:52 PM | Attr =	]
Tenis.html -> %UserProfile%\Desktop\Tenis.html ->  [Ver =  | Size = 14667 bytes | Modified Date = 1/23/2008 6:56:16 PM | Attr =	]
WinPFind35u -> %UserProfile%\Desktop\WinPFind35u ->  [Folder | Created Date = 2/20/2008 12:52:10 PM | Attr =	]
WinPFind35u.exe -> %UserProfile%\Desktop\WinPFind35u.exe ->  [Ver =  | Size = 480802 bytes | Modified Date = 2/20/2008 12:51:37 PM | Attr =	]
Adobe Reader Speed Launch.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk ->  [Ver =  | Size = 1765 bytes | Modified Date = 1/29/2008 8:47:59 PM | Attr =	]
Wise Installation Wizard -> %CommonProgramFiles%\Wise Installation Wizard ->  [Folder | Created Date = 2/1/2008 6:07:48 PM | Attr =	]

[Files/Folders - Modified Within 30 days]
Config.Msi -> %SystemDrive%\Config.Msi ->  [Folder | Modified Date = 2/3/2008 5:24:13 AM | Attr =  HS]
Deckard -> %SystemDrive%\Deckard ->  [Folder | Modified Date = 2/19/2008 10:29:06 PM | Attr =	]
Program Files -> %ProgramFiles% ->  [Folder | Modified Date = 2/14/2008 5:42:36 AM | Attr =	]
WINDOWS -> %SystemRoot% ->  [Folder | Modified Date = 2/19/2008 10:29:53 PM | Attr =	]
etc -> %SystemRoot%\System32\drivers\etc ->  [Folder | Modified Date = 2/11/2008 12:43:15 PM | Attr =	]
hosts -> %SystemRoot%\System32\drivers\etc\hosts ->  [Ver =  | Size = 224459 bytes | Modified Date = 2/11/2008 12:43:15 PM | Attr = R  ]
hosts.20080204-181418.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080204-181418.backup ->  [Ver =  | Size = 224101 bytes | Modified Date = 2/1/2008 3:37:40 PM | Attr = R  ]
hosts.20080211-124009.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080211-124009.backup ->  [Ver =  | Size = 224101 bytes | Modified Date = 2/4/2008 6:14:18 PM | Attr = R  ]
hosts.20080211-124240.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080211-124240.backup ->  [Ver =  | Size = 224459 bytes | Modified Date = 2/11/2008 12:40:09 PM | Attr = R  ]
hosts.20080211-124315.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080211-124315.backup ->  [Ver =  | Size = 224459 bytes | Modified Date = 2/11/2008 12:42:40 PM | Attr = R  ]
CatRoot -> %SystemRoot%\System32\CatRoot ->  [Folder | Modified Date = 2/1/2008 7:46:10 PM | Attr =	]
3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> 
CatRoot2 -> %SystemRoot%\System32\CatRoot2 ->  [Folder | Modified Date = 2/20/2008 12:34:41 PM | Attr =	]
dllcache -> %SystemRoot%\System32\dllcache ->  [Folder | Modified Date = 2/14/2008 7:40:59 AM | Attr = RHS]
docarav -> %SystemRoot%\System32\docarav ->  [Folder | Modified Date = 2/20/2008 12:40:37 PM | Attr =	]
drivers -> %SystemRoot%\System32\drivers ->  [Folder | Modified Date = 2/14/2008 7:41:00 AM | Attr =	]
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT ->  [Ver =  | Size = 148400 bytes | Modified Date = 2/11/2008 12:05:13 PM | Attr =	]
inetsrv -> %SystemRoot%\System32\inetsrv ->  [Folder | Modified Date = 2/14/2008 7:40:59 AM | Attr =	]
logs -> %SystemRoot%\System32\logs ->  [Folder | Modified Date = 2/20/2008 12:37:13 PM | Attr =	]
mp4afpac.dll -> %SystemRoot%\System32\mp4afpac.dll ->  [Ver =  | Size = 326656 bytes | Modified Date = 2/1/2008 2:44:49 PM | Attr =	]
perfc009.dat -> %SystemRoot%\System32\perfc009.dat ->  [Ver =  | Size = 53436 bytes | Modified Date = 2/1/2008 7:51:50 PM | Attr =	]
perfh009.dat -> %SystemRoot%\System32\perfh009.dat ->  [Ver =  | Size = 381692 bytes | Modified Date = 2/1/2008 7:51:50 PM | Attr =	]
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI ->  [Ver =  | Size = 430014 bytes | Modified Date = 2/1/2008 7:51:50 PM | Attr =	]
smdnn05.dll -> %SystemRoot%\System32\smdnn05.dll -> Solid Oak Software, Inc. [Ver = 1, 7, 11, 1 | Size = 204800 bytes | Modified Date = 2/1/2008 3:07:32 PM | Attr =	]
wpa.dbl -> %SystemRoot%\System32\wpa.dbl ->  [Ver =  | Size = 12620 bytes | Modified Date = 2/19/2008 9:52:13 PM | Attr =	]
$hf_mig$ -> %SystemRoot%\$hf_mig$ ->  [Folder | Modified Date = 2/13/2008 7:47:20 PM | Attr =  H ]
13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> 
bootstat.dat -> %SystemRoot%\bootstat.dat ->  [Ver =  | Size = 2048 bytes | Modified Date = 2/20/2008 12:36:49 PM | Attr =   S]
Brpfx04a.ini -> %SystemRoot%\Brpfx04a.ini ->  [Ver =  | Size = 801 bytes | Modified Date = 2/11/2008 11:26:59 AM | Attr =	]
CSSSUpd.exe -> %SystemRoot%\CSSSUpd.exe -> Solid Oak Software, Inc. [Ver = 1.7.9.26 | Size = 289576 bytes | Modified Date = 2/1/2008 3:07:34 PM | Attr =	]
CSSSWD.exe -> %SystemRoot%\CSSSWD.exe -> Solid Oak Software, Inc. [Ver = 1.7.8.13 | Size = 452392 bytes | Modified Date = 2/2/2008 3:16:38 PM | Attr =	]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files ->  [Folder | Modified Date = 2/19/2008 10:32:35 PM | Attr =   S]
ERDNT -> %SystemRoot%\ERDNT ->  [Folder | Modified Date = 2/19/2008 10:29:53 PM | Attr =	]
Help -> %SystemRoot%\Help ->  [Folder | Modified Date = 2/1/2008 6:54:52 PM | Attr =	]
imsins.BAK -> %SystemRoot%\imsins.BAK ->  [Ver =  | Size = 1374 bytes | Modified Date = 2/14/2008 4:14:37 AM | Attr =	]
inf -> %SystemRoot%\inf ->  [Folder | Modified Date = 2/14/2008 4:14:48 AM | Attr =  H ]
Installer -> %SystemRoot%\Installer ->  [Folder | Modified Date = 2/3/2008 5:07:47 AM | Attr =  HS]
lfi.lmdi -> %SystemRoot%\lfi.lmdi ->  [Ver =  | Size = 11147 bytes | Modified Date = 2/20/2008 1:10:33 PM | Attr =	]
Media -> %SystemRoot%\Media ->  [Folder | Modified Date = 2/14/2008 7:40:59 AM | Attr =	]
mozver.dat -> %SystemRoot%\mozver.dat ->  [Ver =  | Size = 2122 bytes | Modified Date = 2/1/2008 2:52:41 PM | Attr =	]
Prefetch -> %SystemRoot%\Prefetch ->  [Folder | Modified Date = 2/20/2008 12:54:38 PM | Attr =	]
QTFont.qfn -> %SystemRoot%\QTFont.qfn ->  [Ver =  | Size = 54156 bytes | Modified Date = 2/20/2008 12:37:38 PM | Attr =  H ]
Registration -> %SystemRoot%\Registration ->  [Folder | Modified Date = 2/1/2008 7:51:12 PM | Attr =	]
security -> %SystemRoot%\security ->  [Folder | Modified Date = 2/20/2008 12:36:01 PM | Attr =	]
SSCRG.exe -> %SystemRoot%\SSCRG.exe -> Solid Oak Software, Inc. [Ver = 1.7.10.17 | Size = 760104 bytes | Modified Date = 2/1/2008 3:07:44 PM | Attr =	]
SSDGT.exe -> %SystemRoot%\SSDGT.exe -> Solid Oak Software, Inc. [Ver = 1.7.6.11 | Size = 716336 bytes | Modified Date = 2/19/2008 10:09:07 PM | Attr =	]
SSLS.exe -> %SystemRoot%\SSLS.exe -> Solid Oak Software, Inc. [Ver = 1.7.9.28 | Size = 837216 bytes | Modified Date = 2/2/2008 3:16:24 PM | Attr =	]
system -> %SystemRoot%\system ->  [Folder | Modified Date = 2/14/2008 5:19:07 AM | Attr =	]
system32 -> %SystemRoot%\system32 ->  [Folder | Modified Date = 2/14/2008 7:41:00 AM | Attr =	]
Temp -> %SystemRoot%\Temp ->  [Folder | Modified Date = 2/20/2008 1:10:35 PM | Attr =	]
unins000.dat -> %SystemRoot%\unins000.dat ->  [Ver =  | Size = 3455 bytes | Modified Date = 2/11/2008 12:34:05 PM | Attr =	]
unins000.exe -> %SystemRoot%\unins000.exe ->  [Ver = 51.49.0.0 | Size = 691545 bytes | Modified Date = 2/11/2008 12:31:53 PM | Attr =	]
?ymbols -> %SystemRoot%\ѕymbols ->  [Folder | Modified Date = 7/13/2007 10:04:51 PM | Attr =	]
SA.DAT -> %SystemRoot%\tasks\SA.DAT ->  [Ver =  | Size = 6 bytes | Modified Date = 2/20/2008 12:36:55 PM | Attr =  H ]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat ->  [Ver =  | Size = 5482 bytes | Modified Date = 2/20/2008 12:38:53 PM | Attr =	]
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat ->  [Ver =  | Size = 5482 bytes | Modified Date = 2/20/2008 12:38:53 PM | Attr =	]
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat ->  [Ver =  | Size = 11082 bytes | Modified Date = 9/30/2007 12:05:21 PM | Attr =	]
data.data -> C:\Documents and Settings\All Users\Application Data\Microsoft\Plus! Digital Media Edition\data\data.dat ->  [Ver =  | Size = 2408 bytes | Modified Date = 10/11/2007 4:18:13 PM | Attr =	]
wkcalcat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wkcalcat.dat ->  [Ver =  | Size = 16384 bytes | Modified Date = 9/3/2007 9:28:06 AM | Attr =	]
wklntnts.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wklntnts.dat ->  [Ver =  | Size = 525384 bytes | Modified Date = 9/30/2007 11:51:56 AM | Attr =	]
wklntsk.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wklntsk.dat ->  [Ver =  | Size = 525384 bytes | Modified Date = 9/30/2007 11:51:56 AM | Attr =	]
md5deep.exe -> C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Local Settings\Temp\~bojyxeq.tmp\md5deep.exe ->  [Ver =  | Size = 21504 bytes | Modified Date = 7/29/2007 9:23:07 PM | Attr =	]
sed.exe -> C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Local Settings\Temp\~bojyxeq.tmp\sed.exe ->  [Ver =  | Size = 37376 bytes | Modified Date = 7/29/2007 9:23:07 PM | Attr =	]
swreg.exe -> C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Local Settings\Temp\~bojyxeq.tmp\swreg.exe -> SteelWerX [Ver = 2.0.2.0 | Size = 119296 bytes | Modified Date = 7/29/2007 9:23:07 PM | Attr =	]
ojdgehxkH3JAGLT.dll -> C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Local Settings\Temp\ojdgehxkH3JAGLT.dll ->  [Ver =  | Size = 53248 bytes | Modified Date = 2/20/2008 12:56:55 PM | Attr =	]
1 C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Local Settings\Temp\*.tmp -> 
dss.dll -> C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT.000\Local Settings\Temp\~bojyxeq.tmp\dss.dll ->  [Ver =  | Size = 37888 bytes | Modified Date = 10/14/2007 1:42:28 AM | Attr =	]
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
397204398DF71B8D -> %AllUsersProfile%\Application Data\397204398DF71B8D ->  [Folder | Modified Date = 2/20/2008 1:10:38 PM | Attr =	]
Adobe -> %AllUsersProfile%\Application Data\Adobe ->  [Folder | Modified Date = 2/1/2008 7:44:31 AM | Attr =	]
Avg7 -> %AllUsersProfile%\Application Data\Avg7 ->  [Folder | Modified Date = 2/14/2008 5:18:51 AM | Attr =	]
Grisoft -> %AllUsersProfile%\Application Data\Grisoft ->  [Folder | Modified Date = 2/5/2008 8:46:17 PM | Attr =	]
Lavasoft -> %AllUsersProfile%\Application Data\Lavasoft ->  [Folder | Modified Date = 2/1/2008 6:09:35 PM | Attr =	]
Malwarebytes -> %AllUsersProfile%\Application Data\Malwarebytes ->  [Folder | Modified Date = 2/14/2008 5:42:36 AM | Attr =	]
Microsoft -> %AllUsersProfile%\Application Data\Microsoft ->  [Folder | Modified Date = 2/14/2008 7:41:00 AM | Attr =   S]
Spybot - Search & Destroy -> %AllUsersProfile%\Application Data\Spybot - Search & Destroy ->  [Folder | Modified Date = 2/14/2008 4:59:54 AM | Attr =	]
{8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7} -> %AllUsersProfile%\Application Data\{8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7} ->  [Folder | Modified Date = 2/1/2008 3:07:11 PM | Attr =	]
Adobe -> %AppData%\Adobe ->  [Folder | Modified Date = 2/1/2008 7:44:36 AM | Attr =	]
AdobeUM -> %AppData%\AdobeUM ->  [Folder | Modified Date = 1/29/2008 8:48:33 PM | Attr =	]
AOL -> %AppData%\AOL ->  [Folder | Modified Date = 2/11/2008 10:41:29 AM | Attr =	]
AVG7 -> %AppData%\AVG7 ->  [Folder | Modified Date = 2/5/2008 8:47:00 PM | Attr =	]
LimeWire -> %AppData%\LimeWire ->  [Folder | Modified Date = 2/5/2008 9:45:12 PM | Attr =	]
Malwarebytes -> %AppData%\Malwarebytes ->  [Folder | Modified Date = 2/14/2008 5:42:43 AM | Attr =	]
Microsoft -> %AppData%\Microsoft ->  [Folder | Modified Date = 2/14/2008 7:41:00 AM | Attr =   S]
PC-FAX TX -> %AppData%\PC-FAX TX ->  [Folder | Modified Date = 2/11/2008 11:26:43 AM | Attr =	]
Uniblue -> %AppData%\Uniblue ->  [Folder | Modified Date = 2/11/2008 11:56:46 AM | Attr =	]
ApplicationHistory -> %UserProfile%\Local Settings\Application Data\ApplicationHistory ->  [Folder | Modified Date = 2/1/2008 7:57:26 PM | Attr =	]
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini ->  [Ver =  | Size = 18432 bytes | Modified Date = 1/31/2008 9:01:53 PM | Attr =	]
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT ->  [Ver =  | Size = 30848 bytes | Modified Date = 2/14/2008 4:35:00 AM | Attr =	]
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db ->  [Ver =  | Size = 1930896 bytes | Modified Date = 2/20/2008 12:35:55 PM | Attr =  H ]
Microsoft -> %UserProfile%\Local Settings\Application Data\Microsoft ->  [Folder | Modified Date = 2/14/2008 5:19:10 AM | Attr =	]
Seven Zip -> %UserProfile%\Local Settings\Application Data\Seven Zip ->  [Folder | Modified Date = 2/1/2008 3:05:15 PM | Attr =	]
Courtney Birkins.doc -> %UserProfile%\My Documents\Courtney Birkins.doc ->  [Ver =  | Size = 648704 bytes | Modified Date = 1/21/2008 8:53:10 PM | Attr =	]
My eBooks -> %UserProfile%\My Documents\My eBooks ->  [Folder | Modified Date = 1/27/2008 4:37:58 PM | Attr =	]
My Music -> %UserProfile%\My Documents\My Music ->  [Folder | Modified Date = 1/31/2008 7:06:04 PM | Attr = R  ]
My Pictures -> %UserProfile%\My Documents\My Pictures ->  [Folder | Modified Date = 2/7/2008 1:36:48 PM | Attr = R  ]
My Received Files -> %UserProfile%\My Documents\My Received Files ->  [Folder | Modified Date = 1/26/2008 9:00:02 PM | Attr =	]
MySpaceIM Pics -> %UserProfile%\My Documents\MySpaceIM Pics ->  [Folder | Modified Date = 2/1/2008 3:25:58 PM | Attr =	]
Prom Dress.jpg -> %UserProfile%\My Documents\Prom Dress.jpg ->  [Ver =  | Size = 29776 bytes | Modified Date = 2/10/2008 10:22:37 PM | Attr =	]
Tenis.html -> %UserProfile%\My Documents\Tenis.html ->  [Ver =  | Size = 14667 bytes | Modified Date = 1/23/2008 6:55:52 PM | Attr =	]
AVG Anti-Spyware.lnk -> %AllUsersProfile%\Desktop\AVG Anti-Spyware.lnk ->  [Ver =  | Size = 857 bytes | Modified Date = 2/14/2008 5:12:17 AM | Attr =	]
iTunes.lnk -> %AllUsersProfile%\Desktop\iTunes.lnk ->  [Ver =  | Size = 2137 bytes | Modified Date = 2/1/2008 7:18:03 PM | Attr =	]
Malwarebytes' Anti-Malware.lnk -> %AllUsersProfile%\Desktop\Malwarebytes' Anti-Malware.lnk ->  [Ver =  | Size = 704 bytes | Modified Date = 2/14/2008 5:42:36 AM | Attr =	]
RegistryBooster 2.lnk -> %AllUsersProfile%\Desktop\RegistryBooster 2.lnk ->  [Ver =  | Size = 802 bytes | Modified Date = 2/11/2008 11:56:40 AM | Attr =	]
ATF-Cleaner.exe -> %UserProfile%\Desktop\ATF-Cleaner.exe -> Atribune.org [Ver = 3.00.0002 | Size = 50688 bytes | Modified Date = 2/11/2008 11:44:31 AM | Attr =	]
dss.exe -> %UserProfile%\Desktop\dss.exe ->  [Ver = 3, 2, 8, 1 | Size = 686630 bytes | Modified Date = 2/19/2008 10:28:34 PM | Attr =	]
Hijackthis.lnk -> %UserProfile%\Desktop\Hijackthis.lnk ->  [Ver =  | Size = 658 bytes | Modified Date = 2/13/2008 8:55:41 PM | Attr =	]
Log Files -> %UserProfile%\Desktop\Log Files ->  [Folder | Modified Date = 2/14/2008 7:42:27 AM | Attr =	]
mbam-setup.exe -> %UserProfile%\Desktop\mbam-setup.exe -> Malwarebytes												 [Ver = 1.0.0.0			  | Size = 1304224 bytes | Modified Date = 2/14/2008 5:41:49 AM | Attr =	]
Software -> %UserProfile%\Desktop\Software ->  [Folder | Modified Date = 2/14/2008 4:58:36 AM | Attr =	]
Tenis.html -> %UserProfile%\Desktop\Tenis.html ->  [Ver =  | Size = 14667 bytes | Modified Date = 1/23/2008 6:56:16 PM | Attr =	]
WinPFind35u -> %UserProfile%\Desktop\WinPFind35u ->  [Folder | Modified Date = 2/20/2008 1:09:48 PM | Attr =	]
WinPFind35u.exe -> %UserProfile%\Desktop\WinPFind35u.exe ->  [Ver =  | Size = 480802 bytes | Modified Date = 2/20/2008 12:51:37 PM | Attr =	]
Adobe Reader Speed Launch.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk ->  [Ver =  | Size = 1765 bytes | Modified Date = 1/29/2008 8:47:59 PM | Attr =	]
Wise Installation Wizard -> %CommonProgramFiles%\Wise Installation Wizard ->  [Folder | Modified Date = 2/1/2008 6:07:48 PM | Attr =	]

[File - Purity Scan: Additional Folder Scans - Non-Microsoft Only]
C:\WINDOWS\?ymbols\ -> C:\WINDOWS\ѕymbols ->  [Folder | Modified Date = 7/13/2007 10:04:51 PM | Attr =	]

[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden processes …
scanning hidden services & system hive …
scanning hidden registry entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
< Document and Settings folder & sub folders >
scanning hidden files …

< End of report >
Hello

Start WinPFind35U. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Processes - Non-Microsoft Only]
YY -> alcxmntr.exe -> %SystemRoot%\ALCXMNTR.EXE
[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> AlcxMonitor -> %SystemRoot%\ALCXMNTR.EXE
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YY -> {F3589BE7-7D71-4C79-9F19-32D239BAB9C4} [HKEY_LOCAL_MACHINE] -> %SystemRoot%\system32\ocxanpac.dll [Sndonad]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar]
< Internet Explorer Bars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
YN -> {32683183-48a0-441b-a342-7c2a440a9478} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened. [Yahoo! Toolbar]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKEY_LOCAL_MACHINE] -> [Reg Error: Key does not exist or could not be opened.]
< Protocol Handlers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\
YN -> ipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.]
YN -> msdaipp: [HKEY_LOCAL_MACHINE] -> Reg Error: Key does not exist or could not be opened.[Reg Error: Value does not exist or could not be read.]
[Files/Folders - Created Within 30 days]
YY -> mp4afpac.dll -> %SystemRoot%\System32\mp4afpac.dll
YY -> 13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
YY -> ?ymbols -> %SystemRoot%\ѕymbols
[Files Created - Additional Folder Scans - Non-Microsoft Only]
YY -> {8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7} -> %AllUsersProfile%\Application Data\{8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7}
[Files/Folders - Modified Within 30 days]
YY -> 3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
YY -> 13 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
YY -> ?ymbols -> %SystemRoot%\ѕymbols
[Files Modified - Additional Folder Scans - Non-Microsoft Only]
YY -> {8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7} -> %AllUsersProfile%\Application Data\{8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7}
[File - Purity Scan: Additional Folder Scans - Non-Microsoft Only]
YY -> C:\WINDOWS\?ymbols\ -> C:\WINDOWS\ѕymbols
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.


Then try run DSS and post that log

If it fails then post a new HijackThis log
WinPFind35 Log: Explorer killed successfully [Processes - Non-Microsoft Only] Process alcxmntr.exe killed successfully. C:\WINDOWS\ALCXMNTR.EXE moved successfully. [Registry - Non-Microsoft Only] Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AlcxMonitor deleted successfully. File C:\WINDOWS\ALCXMNTR.EXE not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\Sndonad deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3589BE7-7D71-4C79-9F19-32D239BAB9C4}\ deleted successfully. LoadLibrary failed for C:\WINDOWS\system32\ocxanpac.dll C:\WINDOWS\system32\ocxanpac.dll NOT unregistered. File move failed. C:\WINDOWS\system32\ocxanpac.dll scheduled to be moved on reboot. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32683183-48a0-441b-a342-7c2a440a9478}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ipp\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msdaipp\ deleted successfully. [Files/Folders - Created Within 30 days] LoadLibrary failed for C:\WINDOWS\System32\mp4afpac.dll C:\WINDOWS\System32\mp4afpac.dll NOT unregistered. C:\WINDOWS\System32\mp4afpac.dll moved successfully. C:\WINDOWS\ѕymbols folder moved successfully. [Files Created - Additional Folder Scans - Non-Microsoft Only] C:\Documents and Settings\All Users\Application Data\{8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7} folder moved successfully. [Files/Folders - Modified Within 30 days] File C:\WINDOWS\ѕymbols not found! [Files Modified - Additional Folder Scans - Non-Microsoft Only] File C:\Documents and Settings\All Users\Application Data\{8F53C81F-AC9B-4DBD-8DC0-5C2A8A1EEEE7} not found! [File - Purity Scan: Additional Folder Scans - Non-Microsoft Only] File C:\WINDOWS\ѕymbols not found! [Empty Temp Folders] User temp folders emptied. SystemRoot temp folder emptied. IE temp folders emptied RecycleBin -> emptied. Explorer started successfully < End of fix log > WinPFind35U Version Beta52 fix logfile created on 02202008_133947 Running DSS Now
Same issues with DSS, here is the new HijiackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 1:47:53 PM, on 2/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Common Files\AOL\1190564291\ee\AOLSoftware.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\CSSSWD.exe
C:\WINDOWS\SSLS.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SSCRG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://register.freeze.com/ping/?shortname…mp;browsers=4,2
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1190564291\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'smdnn05.dll' missing
O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp3.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Monitoring Service (ChatRecMonSvc) - Solid Oak Software, Inc. - C:\WINDOWS\CSSSWD.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: SS Logging Service (SSLOGSVC) - Solid Oak Software, Inc. - C:\WINDOWS\SSLS.exe
Hello

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Also tell me how your PC is running
The computer will still not allow me to log into a web application. After running the Malwarebytes system did not ask for a reboot. Here is the Malwarebytes' Anti-Malware Log: Malwarebytes' Anti-Malware 1.04 Database version: 383 Scan type: Quick Scan Objects scanned: 27510 Time elapsed: 5 minute(s), 48 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 6 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\Common Files\PrivacyProtector Free (Rogue.Privacy.Protector) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\SalesMonitor (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\SalesMonitor\Data (Rogue.Multiple) -> Quarantined and deleted successfully. C:\Program Files\Common Files\WinAntiSpyware 2007 (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully. C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT\Application Data\PrivacyProtector Free (Rogue.PrivacyProtector) -> Quarantined and deleted successfully. C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT\Application Data\PrivacyProtector Free\Logs (Rogue.PrivacyProtector) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT\Local Settings\Temp\GLC1F5.tmp (Malware.Trace) -> Quarantined and deleted successfully. C:\Program Files\Common Files\WinAntiSpyware 2007\err.log (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully. C:\Documents and Settings\Courtney.YOUR-C8BH3JAGLT\Application Data\PrivacyProtector Free\Logs\update.log (Rogue.PrivacyProtector) -> Quarantined and deleted successfully. C:\WINDOWS\tcb.pmw (Malware.Trace) -> Quarantined and deleted successfully.
Doesn't seem to be malware related

Try this

Download the HostsXpert 3.7 - Hosts File Manager.
  • Unzip HostsXpert 3.7 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert 3.7 - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper right corner (If available).
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.


Let me know if that works
You would be better off posting in another part of the forum as this doesn't seem to be malware related.

Your logs are clean, we need to do a few things

You can delete the tools that we used

Your using an old version of Adobe Acrobat Reader, this can leave your pc open to vulnerabilities, you can update it here :
http://www.adobe.com/products/acrobat/readstep2.html



You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here



Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI