O2 - BHO: offersfortoday - {cee59dec-6653-6f26-0fb7-e97d032a4767} - C:\WINDOWS\system32\nsr76.dll
O2 - BHO: offersfortoday browser enhancer - {E2C2DD6E-11FA-1103-F513-3705263F433C} - C:\WINDOWS\system32\xfilqmbuluvuyn.dll
O4 - HKLM\..\Run: [locks tick title proc] C:\Documents and Settings\All Users\Application Data\bags readme locks tick\Wipe media.exe
O4 - HKLM\..\Run: [sfempdnxreznvsgrr] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\xfilqmbuluvuyn.dll"
O4 - HKCU\..\Run: [ChinHtm] C:\DOCUME~1\Paddy\APPLIC~1\LESSRO~1\Barblongintra.exe