When I opened VundoFix I did not recieve an option to check a box saying "Run VundoFix as a task." It went straight to the "Scan for Vundo" step, so I just did that. I ran VundoFix multiple times and it did removes some items. But there were two that were unremovable even after reboot multiple times. C:\WINDOWS\system32\winuqw3.dll & C:\WINDOWS\system32\jkhfc.dll. I tried to remove them manually, but a notice appeared saying that the could not be removed because another program or person was using them. Here is the VundoFix log, ActiveScan, and HiJack This:
VundoFix
VundoFix V6.2.6
Checking Java version...
Java version is 1.4.2.3
Java version is 1.5.0.6
Scan started at 10:31:31 PM 10/27/2006
Listing files found while scanning....
C:\WINDOWS\system32\ifqyccm.dll
C:\WINDOWS\system32\isnrwye.dll
C:\WINDOWS\system32\krlqwun.dll
C:\WINDOWS\system32\pmnkkkk.dll
C:\WINDOWS\system32\ttvfkcxq.dll
C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\yjfxgfbo.dll
C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.bak2
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ifqyccm.dll
C:\WINDOWS\system32\ifqyccm.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\isnrwye.dll
C:\WINDOWS\system32\isnrwye.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\krlqwun.dll
C:\WINDOWS\system32\krlqwun.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\pmnkkkk.dll
C:\WINDOWS\system32\pmnkkkk.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvfkcxq.dll
C:\WINDOWS\system32\ttvfkcxq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\winuqw32.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\yjfxgfbo.dll
C:\WINDOWS\system32\yjfxgfbo.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\jkhfe.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\efhkj.bak2
C:\WINDOWS\system32\efhkj.bak2 Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\winuqw32.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\jkhfe.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.2.6
Checking Java version...
Java version is 1.4.2.3
Java version is 1.5.0.6
Scan started at 9:28:03 AM 10/29/2006
Listing files found while scanning....
C:\WINDOWS\system32\swhmpkia.dll
C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.bak2
Beginning removal...
Attempting to delete C:\WINDOWS\system32\swhmpkia.dll
C:\WINDOWS\system32\swhmpkia.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\winuqw32.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\jkhfe.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\efhkj.bak2
C:\WINDOWS\system32\efhkj.bak2 Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.2.6
Checking Java version...
Java version is 1.4.2.3
Java version is 1.5.0.6
Scan started at 10:11:19 AM 10/29/2006
Listing files found while scanning....
C:\WINDOWS\system32\swhmpkia.dll
C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\efhkj.ini
Beginning removal...
Attempting to delete C:\WINDOWS\system32\swhmpkia.dll
C:\WINDOWS\system32\swhmpkia.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\winuqw32.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\jkhfe.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.ini Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\winuqw32.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\jkhfe.dll Could not be deleted.
Performing Repairs to the registry.
Done!
VundoFix V6.2.6
Checking Java version...
Java version is 1.4.2.3
Java version is 1.5.0.6
Scan started at 10:34:33 AM 10/29/2006
Listing files found while scanning....
C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\efhkj.ini
Beginning removal...
Attempting to delete C:\WINDOWS\system32\winuqw32.dll
C:\WINDOWS\system32\winuqw32.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\jkhfe.dll
C:\WINDOWS\system32\jkhfe.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\efhkj.ini
C:\WINDOWS\system32\efhkj.ini Has been deleted!
Performing Repairs to the registry.
Done!
ActiveScan
Incident Status Location
Virus:Trj/DNSChanger.NF Disinfected Operating system
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\zutn5ed5.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.advertising.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.winantivirus.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[www.winantivirus.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.go.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Application Data\Mozilla\Firefox\Profiles\casdaykx.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Cookies\sayer kanakriyeh@2o7[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Cookies\sayer kanakriyeh@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Cookies\sayer kanakriyeh@atwola[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Cookies\sayer_kanakriyeh@mediaplex[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Cookies\sayer_kanakriyeh@winantivirus[2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\Cookies\
[email protected][1].txt
Virus:Trj/DNSChanger.MN Disinfected C:\Documents and Settings\Sayer Kanakriyeh\Local Settings\Temporary Internet Files\Content.IE5\498ZUFW3\L2[1].exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\My Documents\Desktop Stuff\VundoFix\VundoFix\process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\My Documents\Desktop Stuff\VundoFix.exe[process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Sayer Kanakriyeh\My Documents\My Downloads\VirtumundoBeGone.exe[²ƒÇ]
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{340F3D26-0BB0-1033-1028-050520050001}\Activate.exe
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{340F3D26-0BB0-1033-1028-050520050001}\MyToolBar.dll
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\Common Files\{340F3D26-0BB0-1033-1028-050520050001}\Uninst.exe
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{B40F3D26-0BB0-1033-1028-050520050001}\services.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Program Files\VSToolbar\VSToolBar.dll
Possible Virus. Not disinfected C:\Program Files\?racle\netdde.exe
Possible Virus. Not disinfected C:\VundoFix Backups\jkhfe.dll.bad
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\pmnkkkk.dll.bad
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\swhmpkia.dll.bad
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\ttvfkcxq.dll.bad
Virus:Trj/DNSChanger.NF Disinfected C:\VundoFix Backups\winuqw32.dll.bad
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\yjfxgfbo.dll.bad
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\system32\components\flx7.dll
Adware:Adware/PornMagPass Not disinfected C:\WINDOWS\system32\ismini.exe
Possible Virus. Not disinfected C:\WINDOWS\system32\jkhfe.dll.vir
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\rhgeqaev.exe
Virus:Trj/DNSChanger.NF Disinfected C:\WINDOWS\system32\winuqw32.dll
HiJack This
Logfile of HijackThis v1.99.1
Scan saved at 2:47:55 PM, on 10/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Documents and Settings\Sayer Kanakriyeh\Desktop\VundoFix.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunes.exe
C:\Documents and Settings\Sayer Kanakriyeh\My Documents\My Downloads\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/mywayR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://my.msn.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\RunOnce: [VundoFix] "C:\Documents and Settings\Sayer Kanakriyeh\Desktop\vundofix.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta (file missing)
O9 - Extra 'Tools' menuitem: &Toolbar Wallpaper - {c23dd370-cb79-11d2-898a-00c04f80a47f} - C:\Program Files\Internet Explorer\Toolbar\toolbar.hta (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {22D4879A-92DB-470D-8A83-E158797D8176} (Liquid.LiquidHelper) - file://D:\components\Liquid.ocx
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) -
http://www.vzwpix.co...loadControl.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
http://by104fd.bay10...ex/HMAtchmt.ocxO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe