R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL =
http://www.the-exit.com/search
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {D776F591-6DEA-12DA-467A-266D71416CAB} - C:\WINDOWS\
rhtmzoxz.dll (file missing)
O2 - BHO: NICKARCADE - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\
NICKAR~1\NICKAR~1.DLL (file missing)
O2 - BHO: (no name) - {5F018A10-44D4-9F7C-96C3-1BCCCEEF6149} - C:\WINDOWS\
rhtmzoxz.dll (file missing)
O2 - BHO: (no name) - {8110581C-FEA4-47AC-ADBC-DE958DD0F354} - (no file)
O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\system32\
richedtr.dll (file missing)
O3 - Toolbar: NICKARCADE - {4E7BD74F-2B8D-469E-9EB4-FE6FA694B13E} - C:\PROGRA~1\NICKAR~1\NICKAR~1.DLL (file missing)
O3 - Toolbar: Search - {B6081F4A-8A1A-9613-0116-85E112417F43} - C:\WINDOWS\rhtmzoxz.dll (file missing)
O4 - HKLM\..\Run: [OrbitUpdate] C:\Program Files\
Orbit\update.exe
O4 - HKLM\..\Run: [OrbitView] C:\Program Files\Orbit\view.exe
O4 - HKLM\..\Run: [windows] xax.exe
O4 - HKLM\..\Run: [Services] C:\DOCUME~1\Lora\LOCALS~1\Temp\
342x43.exe
O4 - HKLM\..\Run: [AdTools Service] C:\Program Files\
AdTools Service\AdTools.exe
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\
tsa\tsl2.exe
O4 - HKLM\..\Run: [f¸ï0+¿ðÇà_-8àaöž–C:\Program Files\
ISTsvc\istsvc.exe] C:\WINDOWS\jqqwe.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\
cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [richup] C:\WINDOWS\system32\
richup.exe
O4 - HKLM\..\Run: [uqeeguy] C:\WINDOWS\
uqeeguy.exe
O4 - HKLM\..\Run: [ekfxkdl] C:\WINDOWS\
ekfxkdl.exe
O4 - HKLM\..\Run: [irassync] C:\WINDOWS\system32\
irasyncd.exe
O4 - HKLM\..\Run: [{B7-7F-F6-62-ZN}] C:\windows\system32\
rrdsregn.exe FI002
O4 - HKLM\..\RunServices: [windows] xax.exe
O4 - HKCU\..\Run: [SpyBlast] C:\Program Files\
SpyBlast\SpyBlast.exe /autorun
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\
System Files\System.exe"
O4 - HKCU\..\Run: [irssyncd] C:\WINDOWS\system32\
irssyncd.exe
O4 - HKCU\..\Run: [EQBranch] "C:\Program Files\
EQBranch\EQBranch.exe"
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Virtual Bouncer.lnk = C:\Program Files\
VBouncer\VirtualBouncer.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\
owinssag.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\
ZIFI002.exe
O8 - Extra context menu item: >>> FREE PORN GALLERIES <<< - javascript
:{document.location='http://sexmaxx.com/freegalleries.htm';}
O9 - Extra button: (no name) - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O9 - Extra 'Tools' menuitem: Java - {9E248641-0E24-4DDB-9A1F-705087832AD6} - (no file)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://static.windupdates.com/cab/Do...bridge-c46.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache...WBInitialSetup 1.0.0.15.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} -
http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} -
http://cabs.elitemediagroup.net/cabs/mediaview.cab
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-288B1E346E99} - C:\Program Files\
FCAdvice\FCAdvice.dll
O20 - AppInit_DLLs: jkcbnjpn.dll,Runner.dll,EQMini.dll
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\
aoadouz.exe (file missing)