kennystyle33
New member
So obviously, i have been struck with a virus. I have had a massive amount of pop ups, corrupted files and folders, and my computer has slowed down a lot. Also, I tried running spybot but it keeps shutting down right in the middle of scanning taking me to a blue screen saying something about a problem which needed to be fixed in order to not damage the computer. Please help.
Here is my log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:54, on 09-01-02
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\AntiVir PersonalEdition Classic\sched.exe
D:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
D:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
D:\WINDOWS\System32\WgaTray.exe
D:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\WINDOWS\System32\taskmgr.exe
D:\Program Files\Search Settings\SearchSettings.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
D:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\System32\regsvr32.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
D:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
D:\WINDOWS\explorer.exe
O2 - BHO: (no name) - {042D47DD-9277-4B69-A8D4-0ADC3C0741F2} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {067A68A2-A3A8-422D-9EC1-218F700FBE4F} - (no file)
O2 - BHO: (no name) - {0C1ABC0D-A085-414A-B890-AD99A2745760} - (no file)
O2 - BHO: (no name) - {11400A5A-B3E7-4642-B4FB-38237FC731B1} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {1580C92F-B963-4DE6-A691-FF2E335198A5} - (no file)
O2 - BHO: (no name) - {19DEC775-377F-4B53-86B5-E4078970AC7C} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {1A5D91D0-138D-4E17-934F-8FAA8C22B1A5} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {29F6A488-A7DB-426B-A523-51682159648C} - (no file)
O2 - BHO: (no name) - {37DB7EB2-8348-4AF5-90A6-26260B55B720} - (no file)
O2 - BHO: (no name) - {3A06BD51-F572-4E79-9AD4-86AC4229F867} - (no file)
O2 - BHO: (no name) - {3BDA0C53-A8F6-4EC2-A117-646D0BBAABC0} - (no file)
O2 - BHO: (no name) - {3FC4359F-1EBA-4036-954E-B62A8A313A39} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {434E7974-4459-48D2-B13A-2E5CC024B0CA} - (no file)
O2 - BHO: (no name) - {470F051A-4EBB-49D7-98F8-1D8CD25FA635} - (no file)
O2 - BHO: (no name) - {4F908782-69E6-4C37-AEF3-5D073289C6EB} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5ce9c114-fb54-402e-9de4-ce8deb1dbc57} - (no file)
O2 - BHO: (no name) - {5F3E6D90-5C75-46F4-9F01-2A0A12544ACC} - (no file)
O2 - BHO: (no name) - {65157A31-C4DD-4212-87E6-FA71179FB93F} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: {d3bb069f-3e7c-4cc8-94f4-53deda979286} - {682979ad-ed35-4f49-8cc4-c7e3f960bb3d} - D:\WINDOWS\System32\hdhuki.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\hgGYpnlj.dll
O2 - BHO: (no name) - {701B2C4C-31B4-47F7-9897-324E3D728635} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: globaladsolution - {70fa49a6-cab3-5fa3-b743-d5eb5968ac28} - D:\WINDOWS\System32\nsj1090.dll
O2 - BHO: (no name) - {725BD744-3910-4BF1-9B5A-941C314FAC58} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {815cea56-cfda-412f-a775-166b8069aad4} - D:\WINDOWS\System32\wuzoviwa.dll
O2 - BHO: (no name) - {834B805D-9B49-4FAC-A48C-7B8E2948E41D} - (no file)
O2 - BHO: GrandBar IE Helper - {84BA8988-33E1-4c89-A150-BF428E8D3213} - D:\Program Files\GrandPack\GrandPack2.dll
O2 - BHO: (no name) - {8EFB66D1-5DA9-4449-BF3D-2C0B9522A82E} - (no file)
O2 - BHO: (no name) - {9ABE79AD-6C40-4124-87B7-D2B2F3ADD432} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: globaladsolution browser enhancer - {A18458E8-995B-BE6A-F597-9C7A4319B6E1} - D:\WINDOWS\System32\pdktpxafshadfsgtj.dll
O2 - BHO: (no name) - {A87C08B3-2B56-4DCD-BCEB-6B224043B944} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - D:\Program Files\RapidSolution\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
O2 - BHO: (no name) - {ACABFC97-A9B6-40BE-A823-6C62F1131754} - (no file)
O2 - BHO: (no name) - {BADE2FC0-59B5-4A8D-849B-97F347F90DDC} - (no file)
O2 - BHO: (no name) - {C3011452-12C8-4800-B788-ABCD68D3B924} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {D4202706-3387-4FC2-A573-B1F052DC209C} - (no file)
O2 - BHO: (no name) - {D4F33541-2B5C-45F0-8390-354B74227B00} - (no file)
O2 - BHO: (no name) - {DE2C1371-2789-4838-AB28-B33EC8115C28} - (no file)
O2 - BHO: (no name) - {DE663F5A-AEC5-43AC-A2FB-D9EF25CB6905} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {E6C146C9-6C3B-446D-A32C-752D983FEC22} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {E8B3DB89-8F35-4C7A-8F27-C086D7E8BC74} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {FF066F2C-184A-4940-A749-CBA375873A51} - D:\WINDOWS\System32\qoMeFyxV.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [OutpostFeedBack] D:\Program Files\Agnitum\Outpost Firewall 1.0\feedback.exe /dump
s_startup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SearchSettings] D:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [Train Your Brain] D:\Program Files\Train Your Brain\TrainYourBrain.exe -minimized
O4 - HKLM\..\Run: [UnlockerAssistant] "D:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [brastk] D:\WINDOWS\System32\brastk.exe
O4 - HKLM\..\Run: [WD Drive Manager] D:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [kccexjwjoesjzvt] D:\WINDOWS\System32\regsvr32.exe /s "D:\WINDOWS\System32\pdktpxafshadfsgtj.dll"
O4 - HKLM\..\Run: [wokeluhozi] Rundll32.exe "D:\WINDOWS\System32\numegara.dll",s
O4 - HKLM\..\Run: [cc883b4b] rundll32.exe "D:\WINDOWS\System32\vbaqbdno.dll",b
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] D:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [ares ultra] "D:\Program Files\Ares Ultra\Ares Ultra.exe" -h
O4 - HKCU\..\Run: [updateMgr] "D:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SVCHOST.EXE] D:\WINDOWS\System32\drivers\svchost.exe
O4 - HKCU\..\Run: [brastk] D:\WINDOWS\System32\brastk.exe
O4 - HKCU\..\Run: [GetModule32] D:\Program Files\GetModule\GetModule32.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [wokeluhozi] Rundll32.exe "D:\WINDOWS\System32\numegara.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [wokeluhozi] Rundll32.exe "D:\WINDOWS\System32\numegara.dll",s (User 'NETWORK SERVICE')
O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Set Color Now.lnk = D:\Program Files\12Ghosts\12color.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Orbit.lnk = D:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - D:\Program Files\Agnitum\Outpost Firewall 1.0\Plugins\BrowserBar\ie_bar.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {92D0D610-A6FA-48D8-94CB-BD47FDF68655} (Launcher Class) - http://dl.ipop.co.kr/ipop/ipopx.cab
O16 - DPF: {9CDD57AC-CA86-464C-B920-3228A388CC78} (NaverFileControl Control) - http://file.naver.com/activex/NaverFile.cab
O16 - DPF: {CB5C683C-416A-4701-B018-0F1B21D64D6B} (SKCInst1 Class) - http://cyimg7.cyworld.com/cymusic/package/skcinst.cab
O20 - AppInit_DLLs: ,D:\WINDOWS\System32\miguteki.dll hdhuki.dll
O20 - Winlogon Notify: hgGYpnlj - D:\WINDOWS\SYSTEM32\hgGYpnlj.dll
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - D:\Program Files\WinPcap\rpcapd.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - D:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
O23 - Service: WUSB54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
--
End of file - 12071 bytes
Here is my log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:54, on 09-01-02
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\AntiVir PersonalEdition Classic\sched.exe
D:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
D:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
D:\WINDOWS\System32\WgaTray.exe
D:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\WINDOWS\System32\taskmgr.exe
D:\Program Files\Search Settings\SearchSettings.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
D:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\System32\regsvr32.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
D:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
D:\WINDOWS\explorer.exe
O2 - BHO: (no name) - {042D47DD-9277-4B69-A8D4-0ADC3C0741F2} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {067A68A2-A3A8-422D-9EC1-218F700FBE4F} - (no file)
O2 - BHO: (no name) - {0C1ABC0D-A085-414A-B890-AD99A2745760} - (no file)
O2 - BHO: (no name) - {11400A5A-B3E7-4642-B4FB-38237FC731B1} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {1580C92F-B963-4DE6-A691-FF2E335198A5} - (no file)
O2 - BHO: (no name) - {19DEC775-377F-4B53-86B5-E4078970AC7C} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {1A5D91D0-138D-4E17-934F-8FAA8C22B1A5} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {29F6A488-A7DB-426B-A523-51682159648C} - (no file)
O2 - BHO: (no name) - {37DB7EB2-8348-4AF5-90A6-26260B55B720} - (no file)
O2 - BHO: (no name) - {3A06BD51-F572-4E79-9AD4-86AC4229F867} - (no file)
O2 - BHO: (no name) - {3BDA0C53-A8F6-4EC2-A117-646D0BBAABC0} - (no file)
O2 - BHO: (no name) - {3FC4359F-1EBA-4036-954E-B62A8A313A39} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {434E7974-4459-48D2-B13A-2E5CC024B0CA} - (no file)
O2 - BHO: (no name) - {470F051A-4EBB-49D7-98F8-1D8CD25FA635} - (no file)
O2 - BHO: (no name) - {4F908782-69E6-4C37-AEF3-5D073289C6EB} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5ce9c114-fb54-402e-9de4-ce8deb1dbc57} - (no file)
O2 - BHO: (no name) - {5F3E6D90-5C75-46F4-9F01-2A0A12544ACC} - (no file)
O2 - BHO: (no name) - {65157A31-C4DD-4212-87E6-FA71179FB93F} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: {d3bb069f-3e7c-4cc8-94f4-53deda979286} - {682979ad-ed35-4f49-8cc4-c7e3f960bb3d} - D:\WINDOWS\System32\hdhuki.dll
O2 - BHO: (no name) - {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - D:\WINDOWS\system32\hgGYpnlj.dll
O2 - BHO: (no name) - {701B2C4C-31B4-47F7-9897-324E3D728635} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: globaladsolution - {70fa49a6-cab3-5fa3-b743-d5eb5968ac28} - D:\WINDOWS\System32\nsj1090.dll
O2 - BHO: (no name) - {725BD744-3910-4BF1-9B5A-941C314FAC58} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {815cea56-cfda-412f-a775-166b8069aad4} - D:\WINDOWS\System32\wuzoviwa.dll
O2 - BHO: (no name) - {834B805D-9B49-4FAC-A48C-7B8E2948E41D} - (no file)
O2 - BHO: GrandBar IE Helper - {84BA8988-33E1-4c89-A150-BF428E8D3213} - D:\Program Files\GrandPack\GrandPack2.dll
O2 - BHO: (no name) - {8EFB66D1-5DA9-4449-BF3D-2C0B9522A82E} - (no file)
O2 - BHO: (no name) - {9ABE79AD-6C40-4124-87B7-D2B2F3ADD432} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: globaladsolution browser enhancer - {A18458E8-995B-BE6A-F597-9C7A4319B6E1} - D:\WINDOWS\System32\pdktpxafshadfsgtj.dll
O2 - BHO: (no name) - {A87C08B3-2B56-4DCD-BCEB-6B224043B944} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - D:\Program Files\RapidSolution\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
O2 - BHO: (no name) - {ACABFC97-A9B6-40BE-A823-6C62F1131754} - (no file)
O2 - BHO: (no name) - {BADE2FC0-59B5-4A8D-849B-97F347F90DDC} - (no file)
O2 - BHO: (no name) - {C3011452-12C8-4800-B788-ABCD68D3B924} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {D4202706-3387-4FC2-A573-B1F052DC209C} - (no file)
O2 - BHO: (no name) - {D4F33541-2B5C-45F0-8390-354B74227B00} - (no file)
O2 - BHO: (no name) - {DE2C1371-2789-4838-AB28-B33EC8115C28} - (no file)
O2 - BHO: (no name) - {DE663F5A-AEC5-43AC-A2FB-D9EF25CB6905} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {E6C146C9-6C3B-446D-A32C-752D983FEC22} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {E8B3DB89-8F35-4C7A-8F27-C086D7E8BC74} - D:\WINDOWS\System32\qoMeFyxV.dll
O2 - BHO: (no name) - {FF066F2C-184A-4940-A749-CBA375873A51} - D:\WINDOWS\System32\qoMeFyxV.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [OutpostFeedBack] D:\Program Files\Agnitum\Outpost Firewall 1.0\feedback.exe /dump

O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SearchSettings] D:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [Train Your Brain] D:\Program Files\Train Your Brain\TrainYourBrain.exe -minimized
O4 - HKLM\..\Run: [UnlockerAssistant] "D:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] D:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [brastk] D:\WINDOWS\System32\brastk.exe
O4 - HKLM\..\Run: [WD Drive Manager] D:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [kccexjwjoesjzvt] D:\WINDOWS\System32\regsvr32.exe /s "D:\WINDOWS\System32\pdktpxafshadfsgtj.dll"
O4 - HKLM\..\Run: [wokeluhozi] Rundll32.exe "D:\WINDOWS\System32\numegara.dll",s
O4 - HKLM\..\Run: [cc883b4b] rundll32.exe "D:\WINDOWS\System32\vbaqbdno.dll",b
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] D:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [ares ultra] "D:\Program Files\Ares Ultra\Ares Ultra.exe" -h
O4 - HKCU\..\Run: [updateMgr] "D:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SVCHOST.EXE] D:\WINDOWS\System32\drivers\svchost.exe
O4 - HKCU\..\Run: [brastk] D:\WINDOWS\System32\brastk.exe
O4 - HKCU\..\Run: [GetModule32] D:\Program Files\GetModule\GetModule32.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [wokeluhozi] Rundll32.exe "D:\WINDOWS\System32\numegara.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [wokeluhozi] Rundll32.exe "D:\WINDOWS\System32\numegara.dll",s (User 'NETWORK SERVICE')
O4 - Startup: Adobe Gamma.lnk = D:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Set Color Now.lnk = D:\Program Files\12Ghosts\12color.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Orbit.lnk = D:\Program Files\Orbitdownloader\orbitdm.exe
O8 - Extra context menu item: &Download by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://D:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - D:\Program Files\Agnitum\Outpost Firewall 1.0\Plugins\BrowserBar\ie_bar.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {92D0D610-A6FA-48D8-94CB-BD47FDF68655} (Launcher Class) - http://dl.ipop.co.kr/ipop/ipopx.cab
O16 - DPF: {9CDD57AC-CA86-464C-B920-3228A388CC78} (NaverFileControl Control) - http://file.naver.com/activex/NaverFile.cab
O16 - DPF: {CB5C683C-416A-4701-B018-0F1B21D64D6B} (SKCInst1 Class) - http://cyimg7.cyworld.com/cymusic/package/skcinst.cab
O20 - AppInit_DLLs: ,D:\WINDOWS\System32\miguteki.dll hdhuki.dll
O20 - Winlogon Notify: hgGYpnlj - D:\WINDOWS\SYSTEM32\hgGYpnlj.dll
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - D:\Program Files\WinPcap\rpcapd.exe
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - D:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
O23 - Service: WUSB54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
--
End of file - 12071 bytes