ComboFix 09-11-05.01 - Auberey 11/05/2009 19:10:56.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1055 [GMT -5:00]
Running from: D:\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\$RECYCLE.BIN\S-1-5-21-2152478756-3922319563-605102323-500
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2009-10-06 to 2009-11-06 )))))))))))))))))))))))))))))))
.
2009-11-06 00:21:35 . 2009-11-06 00:26:07 0 d-----w- C:\Users\Auberey\AppData\Local\temp
2009-11-06 00:21:35 . 2009-11-06 00:21:35 0 d-----w- C:\Users\Default\AppData\Local\temp
2009-11-05 22:36:21 . 2009-11-05 22:36:21 0 d-----w- C:\Program Files\Trend Micro
2009-11-05 21:19:51 . 2009-11-05 21:19:51 0 d-----w- C:\Users\Auberey\AppData\Roaming\Malwarebytes
2009-11-05 21:19:47 . 2009-09-10 19:54:06 38224 ----a-w- C:\Windows\system32\drivers\mbamswissarmy.sys
2009-11-05 21:19:45 . 2009-11-05 21:19:50 4096 d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-05 21:19:45 . 2009-11-05 21:19:45 0 d-----w- C:\ProgramData\Malwarebytes
2009-11-05 21:19:45 . 2009-09-10 19:53:50 19160 ----a-w- C:\Windows\system32\drivers\mbam.sys
2009-11-05 02:52:16 . 2009-11-05 02:52:16 0 d-----w- C:\Program Files\ESET
2009-11-05 00:07:36 . 2009-09-10 14:58:28 310784 ----a-w- C:\Windows\system32\unregmp2.exe
2009-11-05 00:07:33 . 2009-09-10 14:59:26 8147456 ----a-w- C:\Windows\system32\wmploc.DLL
2009-11-04 18:40:53 . 2009-08-07 02:24:08 44768 ----a-w- C:\Windows\system32\wups2.dll
2009-11-04 18:40:53 . 2009-08-07 02:24:04 53472 ----a-w- C:\Windows\system32\wuauclt.exe
2009-11-04 18:40:53 . 2009-08-07 02:23:45 1929952 ----a-w- C:\Windows\system32\wuaueng.dll
2009-11-04 18:40:53 . 2009-08-07 01:45:15 2421760 ----a-w- C:\Windows\system32\wucltux.dll
2009-11-04 18:40:36 . 2009-08-07 02:24:09 35552 ----a-w- C:\Windows\system32\wups.dll
2009-11-04 18:40:36 . 2009-08-07 02:23:52 575704 ----a-w- C:\Windows\system32\wuapi.dll
2009-11-04 18:40:36 . 2009-08-07 01:44:40 87552 ----a-w- C:\Windows\system32\wudriver.dll
2009-11-04 18:40:20 . 2009-08-07 00:23:06 171608 ----a-w- C:\Windows\system32\wuwebv.dll
2009-11-04 18:40:20 . 2009-08-06 23:44:46 33792 ----a-w- C:\Windows\system32\wuapp.exe
2009-11-01 01:54:23 . 2009-11-01 01:54:41 0 d-----w- C:\$AVG
2009-11-01 01:53:23 . 2009-11-01 01:53:26 0 d-----w- C:\ProgramData\avg9
2009-10-21 12:38:04 . 2009-10-06 12:15:57 2064152 ----a-w- C:\ProgramData\avg8\update\backup\avgcorex.dll
2009-10-21 11:37:58 . 2009-10-21 11:40:05 0 d-----w- C:\Windows\system32\ca-ES
2009-10-21 11:37:58 . 2009-10-21 11:39:58 0 d-----w- C:\Windows\system32\eu-ES
2009-10-21 11:37:55 . 2009-10-21 11:39:55 0 d-----w- C:\Windows\system32\vi-VN
2009-10-21 11:15:46 . 2009-10-21 11:15:46 0 d-----w- C:\Windows\system32\EventProviders
2009-10-20 17:12:59 . 2009-04-11 06:28:22 406528 ----a-w- C:\Windows\system32\msvcp60.dll
2009-10-20 17:11:59 . 2009-04-11 06:28:26 177664 ----a-w- C:\Windows\system32\WSDMon.dll
2009-10-20 17:10:45 . 2009-04-11 06:28:18 247808 ----a-w- C:\Windows\system32\drvstore.dll
2009-10-20 16:39:05 . 2009-09-10 16:48:01 218624 ----a-w- C:\Windows\system32\msv1_0.dll
2009-10-20 16:39:02 . 2009-08-04 12:34:19 3600456 ----a-w- C:\Windows\system32\ntkrnlpa.exe
2009-10-20 16:39:02 . 2009-08-04 12:34:19 3548216 ----a-w- C:\Windows\system32\ntoskrnl.exe
2009-10-20 16:33:06 . 2009-09-04 11:41:59 60928 ----a-w- C:\Windows\system32\msasn1.dll
2009-10-20 16:32:46 . 2009-09-14 09:29:50 144896 ----a-w- C:\Windows\system32\drivers\srv2.sys
2009-10-20 16:30:40 . 2009-05-08 12:53:00 604672 ----a-w- C:\Windows\system32\WMSPDMOD.DLL
2009-10-20 16:23:46 . 2009-10-01 14:29:14 195440 ----a-w- C:\Windows\system32\MpSigStub.exe
2009-10-20 15:47:24 . 2009-10-20 15:47:24 3584 ----a-r- C:\Users\Auberey\AppData\Roaming\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2009-10-20 15:47:23 . 2009-10-20 15:47:23 0 d-----w- C:\Program Files\Windows Installer Clean Up
2009-10-20 15:47:00 . 2009-10-20 15:47:00 0 d-----w- C:\Program Files\MSECACHE
2009-10-20 15:28:10 . 2009-10-20 15:28:11 86016 ----a-w- C:\ProgramData\NOS\Adobe_Downloads\arh.exe
2009-10-17 12:50:49 . 2009-10-06 12:15:53 2023704 ----a-w- C:\ProgramData\avg8\update\backup\avgtray.exe
2009-10-07 13:59:27 . 2009-10-06 12:15:05 1142552 ----a-w- C:\ProgramData\avg8\update\backup\avgupd.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-06 00:25:06 . 2008-12-31 22:47:11 0 d-----w- C:\Users\Auberey\AppData\Roaming\WTablet
2009-11-04 23:57:55 . 2009-03-23 03:34:02 117760 ----a-w- C:\Users\Auberey\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-11-04 13:17:33 . 2008-09-17 13:09:56 0 d-----w- C:\ProgramData\avg8(1304)
2009-11-04 12:41:39 . 2009-04-20 14:00:48 1356 ----a-w- C:\Users\Auberey\AppData\Local\d3d9caps.dat
2009-11-04 03:27:17 . 2008-09-18 16:04:06 4096 d-----w- C:\Program Files\Common Files\Adobe
2009-11-01 21:22:39 . 2008-09-17 13:09:56 0 d-----w- C:\ProgramData\avg8(1318)
2009-11-01 19:55:59 . 2008-09-17 13:09:56 0 d-----w- C:\ProgramData\avg8(1048)
2009-11-01 19:17:28 . 2008-09-17 13:09:56 0 d-----w- C:\ProgramData\avg8(1132)
2009-11-01 01:53:26 . 2008-09-17 13:09:58 0 d-----w- C:\Program Files\AVG
2009-10-21 11:40:50 . 2006-11-02 12:37:34 0 d-----w- C:\Program Files\Windows Calendar
2009-10-21 11:40:50 . 2006-11-02 11:18:33 4096 d-----w- C:\Program Files\Windows Mail
2009-10-21 11:40:48 . 2006-11-02 12:37:34 4096 d-----w- C:\Program Files\Windows Sidebar
2009-10-21 11:40:47 . 2006-11-02 12:37:34 4096 d-----w- C:\Program Files\Windows Journal
2009-10-21 11:40:47 . 2006-11-02 12:37:34 4096 d-----w- C:\Program Files\Windows Collaboration
2009-10-21 11:40:43 . 2006-11-02 12:37:34 4096 d-----w- C:\Program Files\Windows Photo Gallery
2009-10-21 11:40:37 . 2006-11-02 12:37:34 4096 d-----w- C:\Program Files\Windows Defender
2009-10-21 11:37:46 . 2006-11-02 10:25:05 665600 ----a-w- C:\Windows\inf\drvindex.dat
2009-10-21 11:35:20 . 2009-10-21 11:35:20 0 ---ha-w- C:\Windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-10-20 15:52:39 . 2008-09-18 16:00:14 4096 d-----w- C:\ProgramData\NOS
2009-10-17 14:56:10 . 2008-09-17 13:11:52 4096 d-----w- C:\Program Files\SUPERAntiSpyware
2009-10-05 23:32:14 . 2008-11-01 21:34:49 3766 --sha-w- C:\ProgramData\KGyGaAvL.sys
2009-10-05 23:32:14 . 2008-11-01 21:34:49 3766 --sha-w- C:\ProgramData\KGyGaAvL.sys
2009-10-05 23:32:01 . 2008-11-01 21:34:50 168 --sha-r- C:\ProgramData\46F4CA0B28.sys
2009-10-05 23:32:01 . 2008-11-01 21:34:50 168 --sha-r- C:\ProgramData\46F4CA0B28.sys
2009-09-26 18:45:18 . 2009-09-25 01:49:22 126970 ----a-w- C:\Users\Auberey\AppData\Roaming\Move Networks\uninstall.exe
2009-09-26 18:45:18 . 2009-08-03 21:48:42 4187512 ----a-w- C:\Users\Auberey\AppData\Roaming\Move Networks\plugins\npqmp071505000010.dll
2009-09-25 01:49:21 . 2009-06-16 06:35:40 4183416 ----a-w- C:\Users\Auberey\AppData\Roaming\Move Networks\plugins\npqmp071503000010.dll
2009-09-18 03:47:05 . 2009-09-18 03:47:03 45 ----a-w- C:\Users\Auberey\jagex_runescape_preferences2.dat
2009-09-18 03:47:05 . 2009-09-18 03:46:04 37 ----a-w- C:\Users\Auberey\jagex_runescape_preferences.dat
2009-09-09 23:19:37 . 2008-09-17 10:18:53 4096 d-----w- C:\Program Files\Microsoft Silverlight
2009-09-07 22:33:39 . 2009-09-07 22:33:39 0 ---ha-w- C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-09-07 19:53:36 . 2006-11-02 10:32:57 101888 ----a-w- C:\Windows\system32\ifxcardm.dll
2009-09-07 19:53:33 . 2006-11-02 10:32:57 82432 ----a-w- C:\Windows\system32\axaltocm.dll
2009-09-07 19:36:16 . 2008-11-22 05:57:23 4096 d-----w- C:\Program Files\Java
2009-09-07 18:45:30 . 2009-09-07 18:45:30 0 d-----w- C:\Users\Auberey\AppData\Roaming\PeerNetworking
2009-08-29 00:27:49 . 2009-09-02 23:20:59 4240384 ----a-w- C:\Windows\system32\GameUXLegacyGDFs.dll
2009-08-29 00:14:38 . 2009-09-02 23:20:57 28672 ----a-w- C:\Windows\system32\Apphlpdm.dll
2009-08-27 05:22:28 . 2009-10-20 16:38:11 916480 ----a-w- C:\Windows\system32\wininet.dll
2009-08-27 05:17:43 . 2009-10-20 16:38:09 71680 ----a-w- C:\Windows\system32\iesetup.dll
2009-08-27 05:17:43 . 2009-10-20 16:38:09 109056 ----a-w- C:\Windows\system32\iesysprep.dll
2009-08-27 03:42:29 . 2009-10-20 16:38:09 133632 ----a-w- C:\Windows\system32\ieUnatt.exe
2009-08-26 16:43:18 . 2008-09-16 21:34:43 140960 ----a-w- C:\Users\Auberey\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-18 03:33:52 . 2009-08-18 03:33:52 1193832 ----a-w- C:\Windows\system32\FM20.DLL
2009-08-15 12:36:06 . 2009-02-02 14:48:34 11952 ----a-w- C:\Windows\system32\avgrsstx.dll
2009-08-15 12:36:05 . 2008-09-17 13:10:05 335240 ----a-w- C:\Windows\system32\drivers\avgldx86.sys
2009-08-15 12:36:05 . 2008-09-17 13:10:01 27784 ----a-w- C:\Windows\system32\drivers\avgmfx86.sys
2009-08-14 16:27:34 . 2009-09-09 17:40:55 904776 ----a-w- C:\Windows\system32\drivers\tcpip.sys
2009-08-14 15:53:34 . 2009-09-09 17:40:51 17920 ----a-w- C:\Windows\system32\netevent.dll
2009-08-14 13:49:20 . 2009-09-09 17:40:51 9728 ----a-w- C:\Windows\system32\TCPSVCS.EXE
2009-08-14 13:49:18 . 2009-09-09 17:40:51 17920 ----a-w- C:\Windows\system32\ROUTE.EXE
2009-08-14 13:49:18 . 2009-09-09 17:40:51 11264 ----a-w- C:\Windows\system32\MRINFO.EXE
2009-08-14 13:49:15 . 2009-09-09 17:40:52 27136 ----a-w- C:\Windows\system32\NETSTAT.EXE
2009-08-14 13:49:14 . 2009-09-09 17:40:52 19968 ----a-w- C:\Windows\system32\ARP.EXE
2009-08-14 13:49:14 . 2009-09-09 17:40:51 8704 ----a-w- C:\Windows\system32\HOSTNAME.EXE
2009-08-14 13:49:13 . 2009-09-09 17:40:51 10240 ----a-w- C:\Windows\system32\finger.exe
2009-08-14 13:48:21 . 2009-09-09 17:40:54 30720 ----a-w- C:\Windows\system32\drivers\tcpipreg.sys
2009-08-14 13:48:02 . 2009-09-09 17:40:54 105984 ----a-w- C:\Windows\system32\netiohlp.dll
2009-01-13 20:56:45 . 2009-01-06 22:43:10 88 --sh--r- C:\Windows\System32\46F4CA0B28.sys
2009-01-13 20:59:34 . 2009-01-06 22:43:10 952 --sha-w- C:\Windows\System32\KGyGaAvL.sys
2009-06-19 19:15:45 . 2009-06-19 19:15:45 8975 --sh--w- C:\Windows\System32\vudigoyi.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 13:55:58 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55:58 1090816 ----a-w- C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 13:55:58 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 13:55:58 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-28 12:42:59 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-06-18 18:01:34 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-06-18 18:01:26 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-06-18 18:01:30 133656]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 06:12:02 483328]
"Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 19:53:56 1312080]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\Windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-9-19 25214]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 14:13:36 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-06 13:57:20 548352 ----a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-11-24 14:36:54 73728 ----a-w- C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\Windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):3c,a8,99,f1,43,52,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4215972033-1050644244-1932678965-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\Windows\System32\drivers\avgldx86.sys [9/17/2008 8:10:05 AM 335240]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [9/3/2008 1:07:14 PM 9968]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [9/3/2008 1:07:12 PM 74480]
R1 StarPortLite;StarPort Storage Controller (Lite);C:\Windows\System32\drivers\StarPortLite.sys [10/2/2008 9:01:13 PM 93544]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [5/7/2009 6:11:20 PM 1153368]
R2 TabletServiceWacom;TabletServiceWacom;C:\Windows\System32\Wacom_Tablet.exe [12/31/2008 5:43:14 PM 1373480]
R3 ti21sony;ti21sony;C:\Windows\System32\drivers\ti21sony.sys [9/16/2008 9:48:44 PM 227328]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [7/1/2009 8:20:45 AM 297752]
S2 ColdFusion MX 7 Application Server;ColdFusion MX 7 Application Server;C:\CFusionMX7\runtime\bin\jrunsvc.exe [10/20/2008 11:20:30 AM 61440]
S2 ColdFusion MX 7 Search Server;ColdFusion MX 7 Search Server;C:\CFusionMX7\verity\k2\_nti40\bin\k2admin.exe [10/20/2008 11:19:39 AM 2711312]
S3 fssfltr;FssFltr;C:\Windows\System32\drivers\fssfltr.sys [9/5/2009 6:17:46 PM 54632]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48:42 PM 704864]
S3 getPlus(R) Installer;getPlus(R) Installer;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [8/16/2009 5:24:57 PM 59552]
S3 getPlusHelper;getPlus(R) Helper;C:\Windows\System32\svchost.exe -k getPlusHelper [9/18/2008 7:24:33 AM 21504]
S3 SASENUM;SASENUM;C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [9/3/2008 1:07:16 PM 7408]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-01-03 C:\Windows\Tasks\NSSstub.job
- C:\Windows\system32\Adobe\Shockwave 11\nssstub.exe [2009-01-03 04:24:24 . 2009-01-03 04:24:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
BHO-{744EC540-7CAC-4B6A-8581-CBD7CC81024B} - C:\Windows\system32\jkkKeCtS.dll
AddRemove-_{91CABF8F-A81C-4CB0-A1B0-D55B25F1B150} - C:\Program Files\Corel\Corel Painter X\MSILauncher {91CABF8F-A81C-4CB0-A1B0-D55B25F1B150}
sorry, hope this one is complete