Have HJT fix:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\wizard\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {5A86CD8E-5A67-49E3-87AB-78E82D4A8C8D} - C:\WINDOWS\System32\olkn.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/25b8674...ip/RdxIE601.cab
The Temp\sp.html hijack can be persistent, check out the suggestions given in the following threads:
http://www.daniweb.com/techtalkforums/search.php?searchid=97885
After running the removal utilities:
- For every user account on your system: In C:\Documents and Settings\username\Local Settings you will find Cookie, History, Temp, and Temporary Internet Files folders. Delete the contents of all of those folders.
- In C:\Windows\Temp you'll also find another set of History and Temporary Internet Files folders. Delete the contents of C:\Windows\Temp.
- Empty the Recycle Bin.
- Reboot.
also, is this a bad file? RUNDLL32.EXE-451FC2C0.pf
Looks like it to me; it certainly isn't a normal Windows system file.spybot continuoulsy finds DSOexploit, and i'll say fix and it'll fix it, but then i'll have it search again and it'll come up again. i've read that that this is just a bug in spybot, it that right?
It is a known bug; you can ignore it.