Hi Pancake
Combifix Log & Hi Jack this log enlcosed
since running combifix right mouse button has been restored but i now have 2 of each icon on my desktop any thoughts?
ComboFix 08-04-20.5 - Laura 2008-04-22 20:55:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.112 [GMT 1:00]
Running from: C:\Desktop\ComboFix.exe
Command switches used :: C:\Desktop\winxpsp1_en_pro_bf.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\desktop.html
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\install.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-22 to 2008-04-22 )))))))))))))))))))))))))))))))
.
2067-02-24 15:21 . 2003-02-05 04:02 79,947 --a------ C:\WINDOWS\fw20.vxd
2008-04-20 03:03 . 2008-04-20 03:03 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-19 21:59 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll
2008-04-19 21:59 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll.mui
2008-04-19 21:09 . 2008-04-19 21:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-04-19 19:31 . 2008-04-19 19:31 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\Grisoft
2008-04-19 19:16 . 2008-04-19 19:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-04-19 19:13 . 2004-04-02 20:23 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-04-19 19:13 . 2004-04-02 20:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-04-19 19:13 . 2008-04-19 19:13 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-19 19:13 . 2008-04-22 20:45 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-19 18:15 . 2008-04-19 18:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-19 17:08 . 2008-04-19 19:35 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-19 17:08 . 2008-04-19 17:08 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-19 17:08 . 2008-04-19 17:08 <DIR> d-------- C:\Documents and Settings\Laura\Application Data\SUPERAntiSpyware.com
2008-04-19 17:08 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2008-04-18 19:10 . 2008-04-19 13:28 8,627 --a------ C:\WINDOWS\SYSTEM32\PAV_FOG.OPC
2008-04-04 20:31 . 2008-04-04 20:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-04 20:18 . 2008-04-04 20:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Backup
2008-04-04 20:16 . 2007-04-24 16:43 1,990 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\net_m32.inf
2008-04-04 20:10 . 2008-04-04 20:10 61,440 --a------ C:\pav.tmp
2008-03-27 22:57 . 1997-09-18 07:12 9,488 --a------ C:\WINDOWS\SYSTEM32\sporder.dll
2008-03-27 22:45 . 2008-04-19 19:29 <DIR> d-------- C:\Program Files\Common Files\Panda Software
2008-03-27 22:41 . 2008-03-27 22:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-27 19:54 . 2002-08-29 04:40 20,480 --a------ C:\WINDOWS\SYSTEM32\hidserv.dll
2008-03-27 19:54 . 2002-08-29 04:40 20,480 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\hidserv.dll
2008-03-27 19:54 . 2001-08-17 14:48 13,952 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\kbdhid.sys
2008-03-27 19:54 . 2001-08-17 14:48 13,952 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\kbdhid.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-04-19 18:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-27 23:20 --------- d-----w C:\Program Files\Dell Fax Solutions
2008-03-27 23:20 --------- d-----w C:\Program Files\Dell AIO Printer 946
2008-03-27 21:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-27 19:01 --------- d-----w C:\Program Files\Yahoo!
2008-03-27 18:54 --------- d-----w C:\Program Files\Dl_cats
2002-04-16 09:27 5 --sha-w C:\WINDOWS\SYSTEM32\CdI5T.drv
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1EB014C4-4A82-7807-CE4A-BAADCF30D82A}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 03:41 13312]
"Url"="C:\WINDOWS\System32\Ftp.exe" [2002-08-29 03:41 40448]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-10-02 13:37 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-10-02 13:19 118784]
"DSL Connection Manager"="C:\Program Files\INTEL\DSLSetup\ProDsl.exe" [2002-05-10 20:30 65536]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"dlcimon.exe"="C:\Program Files\Dell AIO Printer 946\dlcimon.exe" [2006-12-08 06:16 435080]
"FaxCenterServer"="C:\Program Files\Dell Fax Solutions\fm3032.exe" [2006-12-08 06:19 312200]
"DLCICATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X 86\3\DLCItime.dll" [2006-10-20 23:01 73728]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 03:41 13312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2002-11-20 19:50 51200 C:\WINDOWS\SYSTEM32\narrator.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"Btn_Search"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\curr entversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R2 dlci_device;dlci_device;C:\WINDOWS\System32\dlcico ms.exe [2006-12-08 06:17]
S2 P32LOAD;Intel(R) AnyPoint(R) 3240 USB Modem Firmware Loader;C:\WINDOWS\System32\DRIVERS\p31usbld.sys [2002-04-24 00:15]
S3 PRO3200P;Intel(R) USB ADSL Modem;C:\WINDOWS\System32\DRIVERS\p32d2kP.sys [2002-04-27 05:23]
*Newly Created Service* - CATCHME
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Microsoft Webcam Enhance V2.1]
C:\WINDOWS\runtfs32.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-22 20:00:02 C:\WINDOWS\Tasks\A5C420909273DC70.job"
- c:\docume~1\laura\applic~1\meetbi~1\DART TRANS FIVE.exe
"2004-04-14 10:45:04 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
************************************************** ************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-22 20:58:06
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCICATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItim e.dll,_RunDLLEntry@16????????????????????????????? ?????????????????????????????????????????????????? ?????????????????????????????????????????????????? ??????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-04-22 21:01:02
ComboFix-quarantined-files.txt 2008-04-22 20:00:35
Pre-Run: 71,302,402,048 bytes free
Post-Run: 71,350,583,296 bytes free
winxpsp1_en_pro_bf.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Professional" /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
121 --- E O F --- 2008-04-20 02:03:41
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:08:20, on 22/04/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\dlcicoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\INTEL\DSLSetup\ProDsl.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Dell AIO Printer 946\dlcimon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
O1 - Hosts: 127.0.0.0 localhost
O1 - Hosts: 127.0.0.2 auditmypc.com
O1 - Hosts: 127.0.0.3 boards.cexx.org
O1 - Hosts: 127.0.0.4 bulletproofsoft.net
O1 - Hosts: 127.0.0.5 camtech2000.net
O1 - Hosts: 127.0.0.6 cexx.org
O1 - Hosts: 127.0.0.7 computercops.us
O1 - Hosts: 127.0.0.8 ct7support.com
O1 - Hosts: 127.0.0.9 doxdesk.com
O1 - Hosts: 127.0.0.20 kellys-korner-xp.com
O1 - Hosts: 127.0.0.21 kephyr.com
O1 - Hosts: 127.0.0.22 lavasoft.de
O1 - Hosts: 127.0.0.23 lavasoftusa.com
O1 - Hosts: 127.0.0.24 lurkhere.com
O1 - Hosts: 127.0.0.25 majorgeeks.com
O1 - Hosts: 127.0.0.26 merijn.org
O1 - Hosts: 127.0.0.27 mjc1.com
O1 - Hosts: 127.0.0.28 moosoft.com
O1 - Hosts: 127.0.0.29 mvps.org
O1 - Hosts: 127.0.0.30 net-integration.net
O1 - Hosts: 127.0.0.31 noadware.net
O1 - Hosts: 127.0.0.32 no-spybot.com
O1 - Hosts: 127.0.0.33 onlinepcfix.com
O1 - Hosts: 127.0.0.34 pchell.com
O1 - Hosts: 127.0.0.35 pestpatrol.com
O1 - Hosts: 127.0.0.36 safer-networking.org
O1 - Hosts: 127.0.0.37 secure.spykiller.com
O1 - Hosts: 127.0.0.38 secureie.com
O1 - Hosts: 127.0.0.39 security.kolla.de
O1 - Hosts: 127.0.0.40 spybot.info
O1 - Hosts: 127.0.0.41 spychecker.com
O1 - Hosts: 127.0.0.42 spychecker.com
O1 - Hosts: 127.0.0.43 spycop.com
O1 - Hosts: 127.0.0.44 spyguard.com
O1 - Hosts: 127.0.0.45 spykiller.com
O1 - Hosts: 127.0.0.46 spyware.co.uk
O1 - Hosts: 127.0.0.47 spyware-cop.com
O1 - Hosts: 127.0.0.48 spywareinfo.com
O1 - Hosts: 127.0.0.49 spywarenuker.com
O1 - Hosts: 127.0.0.50 spywareremove.com
O1 - Hosts: 127.0.0.51 spywareremove.com
O1 - Hosts: 127.0.0.52 stopzillapro.com
O1 - Hosts: 127.0.0.53 sunbelt-software.com
O1 - Hosts: 127.0.0.54 thiefware.com
O1 - Hosts: 127.0.0.55 tomcoyote.org
O1 - Hosts: 127.0.0.56 unwantedlinks.com
O1 - Hosts: 127.0.0.57 webattack.com
O1 - Hosts: 127.0.0.58 wilders.org
O1 - Hosts: 127.0.0.59
Firewall Test, Web Tools and Free Internet Security Audit
O1 - Hosts: 127.0.0.60
BulletProofSoft Home Page - Spyware Remover Spyware Adware Remover Free Spyware Removal Adware Removal AntiSpyware Free Anti Spyware Software MP3 to WAV converter, MP3 converter, MP3 to WAV decoder, WAV to MP3 encoder - PC System Tweak - BPS Phishing
O1 - Hosts: 127.0.0.61
Counterexploitation [cexx.org]
O1 - Hosts: 127.0.0.62
CastleCops®
O1 - Hosts: 127.0.0.63
ct7Support Site
O1 - Hosts: 127.0.0.64
doxdesk.com: home
O1 - Hosts: 127.0.0.65
eblocs™ - Protection With Early Detection
O1 - Hosts: 127.0.0.66
Enigma Software Group, Inc.
O1 - Hosts: 127.0.0.67
Best Free Spyware Scan and Removal to Cleanup Your PC
O1 - Hosts: 127.0.0.68
Free-Web-Browsers.com Alternative Browsers: Stop Spyware and Browser Hijackers
O1 - Hosts: 127.0.0.69
Home of Gibson Research Corporation
O1 - Hosts: 127.0.0.70
AVG Anti-Virus and Internet Security - Real-time protection against viruses, spyware and malicious websites
O1 - Hosts: 127.0.0.71
The Tech FAQ
O1 - Hosts: 127.0.0.72
The Hare's Lair Web site
O1 - Hosts: 127.0.0.73
Javacool Software
O1 - Hosts: 127.0.0.74
Kellys XP Korner
O1 - Hosts: 127.0.0.75
Welcome to Kephyr.com - Download our free software - Bazooka Adware and Scanner, ConnectBuddy, etc.
O1 - Hosts: 127.0.0.76
Ad-Aware @ Lavasoft - The Original Anti-Spyware Company - Lavasoft
O1 - Hosts: 127.0.0.77
Ad-Aware @ Lavasoft - The Original Anti-Spyware Company - Lavasoft
O1 - Hosts: 127.0.0.78
LurkHere - Information, Links and Support to Help PC Users Optimize Their Computers
O1 - Hosts: 127.0.0.79
MajorGeeks.com - Download Freeware and Shareware Computer Utilities.
O1 - Hosts: 127.0.0.80
Merijn.org
O1 - Hosts: 127.0.0.81
Mjc1.com - HiJack this Resources and Information. This website is for sale!
O1 - Hosts: 127.0.0.82
MooSoft Development Inc : Main - Welcome browse
O1 - Hosts: 127.0.0.83
Welcome to the MVPs.org home page!
O1 - Hosts: 127.0.0.84
Eagle1 Press
O1 - Hosts: 127.0.0.85
Adware, Spyware, Popups - They invade your privacy and harm your PC. Protect Yourself with NoAdware!
O1 - Hosts: 127.0.0.86
default spybot free download spy at no-spybot.com
O1 - Hosts: 127.0.0.87
www.onlinepcfix.com
O1 - Hosts: 127.0.0.88
PC Hell: Computer Hints and Tips to bring you back from the edge
O1 - Hosts: 127.0.0.89
eTrust® PestPatrol® Anti-Spyware
O1 - Hosts: 127.0.0.90
www.safer-networking.org
O1 - Hosts: 127.0.0.91
Winferno Software - Internet Security & Multimedia Software Center
O1 - Hosts: 127.0.0.92
www.security.kolla.de
O1 - Hosts: 127.0.0.93
www.spybot.info
O1 - Hosts: 127.0.0.94
Spychecker - download spyware removal and Internet privacy tools
O1 - Hosts: 127.0.0.95
Spychecker - download spyware removal and Internet privacy tools
O1 - Hosts: 127.0.0.96
SpyCop - Leader In Privacy Protection Software
O1 - Hosts: 127.0.0.97
Computer and Internet Monitoring Software
O1 - Hosts: 127.0.0.98
SpyKiller: spyware removal - FREE SCAN - remove adware
O1 - Hosts: 127.0.0.99
Spyware Watch (UK) - spyware, adware, stealware - stay aware!
O1 - Hosts: 69.64.35.177 auto.search.msn.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1EB014C4-4A82-7807-CE4A-BAADCF30D82A} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DSL Connection Manager] C:\Program Files\INTEL\DSLSetup\ProDsl.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [dlcimon.exe] "C:\Program Files\Dell AIO Printer 946\dlcimon.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [DLCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCItim e.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [url] C:\WINDOWS\System32\Ftp.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Help - {044CDA69-FD11-4662-99D5-71E815904C29} -
http://www.btopenworld.com/helpbb (file missing) (HKCU)
O9 - Extra button: Homepage - {7D3FC5CC-ACA6-404E-A3C6-538C48C5BC95} -
Compare BT broadband internet providers, packages & deals :: BT Broadband Information (file missing) (HKCU)
O9 - Extra button: BT - {C079CF71-08B8-4EBD-B41B-0879D48999F6} -
BT.com: Broadband Internet, mobile and fixed telecommunications products and service from BT for home and business (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {C9AC8D8E-2B1A-4565-A0FC-433B55DF4986} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {C9AC8D8E-2B1A-4565-A0FC-433B55DF4986} - (no file) (HKCU)
O16 - DPF: {00000000-0000-0000-0000-000020030000} -
http://207.234.185.217/ABoxInst.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -
https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) -
https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/micr...?1208592607069
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) -
http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: dlci_device - - C:\WINDOWS\System32\dlcicoms.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
--
End of file - 10347 bytes