Logfile of HijackThis v1.99.1
Scan saved at 4:23:26 PM, on 9/21/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Armour\bin\ZLH.EXE
C:\Program Files\QuickTime\qttask.exe
D:\Bryan\winamp5\Winamp\winampa.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Armour\bin\ZANDA.EXE
C:\Program Files\Tiny Personal Firewall\persfw.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\ups.exe
C:\Armour\bin\NJEEVES.EXE
D:\Bryan\winamp5\Winamp\winamp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Armour\Nvc\bin\nvcoas.exe
C:\Armour\Nvc\BIN\NIP.EXE
C:\Armour\Nvc\BIN\NVCSCHED.EXE
C:\Armour\Nvc\BIN\nipsvc.exe
C:\Armour\Nvc\bin\cclaw.exe
C:\HijackThis\HijackThis.exe
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\fontc.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Armour\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Bryan\winamp5\Winamp\winampa.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) -
http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: fontc - C:\WINDOWS\Fonts\fontc.dll
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Armour\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Armour\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Armour\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Armour\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Armour\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe
Logfile of HijackThis v1.99.1
Scan saved at 4:23:26 PM, on 9/21/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Armour\bin\ZLH.EXE
C:\Program Files\QuickTime\qttask.exe
D:\Bryan\winamp5\Winamp\winampa.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Armour\bin\ZANDA.EXE
C:\Program Files\Tiny Personal Firewall\persfw.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\ups.exe
C:\Armour\bin\NJEEVES.EXE
D:\Bryan\winamp5\Winamp\winamp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Armour\Nvc\bin\nvcoas.exe
C:\Armour\Nvc\BIN\NIP.EXE
C:\Armour\Nvc\BIN\NVCSCHED.EXE
C:\Armour\Nvc\BIN\nipsvc.exe
C:\Armour\Nvc\bin\cclaw.exe
C:\HijackThis\HijackThis.exe
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\fontc.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Armour\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Bryan\winamp5\Winamp\winampa.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) -
http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: fontc - C:\WINDOWS\Fonts\fontc.dll
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Armour\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Armour\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Armour\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Armour\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Armour\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe
Hi! I've done as requested. Below are the results from APM:
712-c:\windows\system32\winlogon.exe
1396-c:\windows\explorer.exe
2636-c:\program files\internet explorer\iexplorer.exe
The results from ff.bat are as follows :
Volume in drive C has no label.
Volume Serial Number is D0EB-D940
Directory of C:\WINDOWS\Fonts
08/23/2001 12:00 PM 10,976 8514fix.fon
08/23/2001 12:00 PM 10,976 8514fixe.fon
08/23/2001 12:00 PM 11,520 8514fixg.fon
08/23/2001 12:00 PM 10,976 8514fixr.fon
08/23/2001 12:00 PM 11,488 8514fixt.fon
08/23/2001 12:00 PM 12,288 8514oem.fon
08/23/2001 12:00 PM 13,248 8514oeme.fon
08/23/2001 12:00 PM 12,800 8514oemg.fon
08/23/2001 12:00 PM 13,200 8514oemr.fon
08/23/2001 12:00 PM 12,720 8514oemt.fon
08/23/2001 12:00 PM 9,280 8514sys.fon
08/23/2001 12:00 PM 9,504 8514syse.fon
08/23/2001 12:00 PM 9,856 8514sysg.fon
08/23/2001 12:00 PM 10,064 8514sysr.fon
08/23/2001 12:00 PM 9,792 8514syst.fon
08/23/2001 12:00 PM 12,304 85775.fon
08/23/2001 12:00 PM 12,256 85855.fon
08/23/2001 12:00 PM 10,976 85f1257.fon
08/23/2001 12:00 PM 9,472 85s1257.fon
08/23/2001 12:00 PM 35,808 app775.fon
08/23/2001 12:00 PM 36,672 app850.fon
08/23/2001 12:00 PM 36,656 app852.fon
08/23/2001 12:00 PM 37,296 app855.fon
05/12/2005 01:10 PM 67 desktop.ini
08/23/2001 12:00 PM 36,672 app857.fon
08/23/2001 12:00 PM 37,472 app866.fon
08/23/2001 12:00 PM 7,216 cga40737.fon
08/23/2001 12:00 PM 6,352 cga40850.fon
08/23/2001 12:00 PM 6,672 cga40852.fon
08/23/2001 12:00 PM 6,672 cga40857.fon
08/23/2001 12:00 PM 7,232 cga40866.fon
08/23/2001 12:00 PM 7,216 cga40869.fon
08/23/2001 12:00 PM 5,168 cga80737.fon
08/23/2001 12:00 PM 4,320 cga80850.fon
08/23/2001 12:00 PM 5,200 cga80852.fon
08/23/2001 12:00 PM 4,640 cga80857.fon
08/23/2001 12:00 PM 5,168 cga80866.fon
08/23/2001 12:00 PM 5,168 cga80869.fon
08/23/2001 12:00 PM 23,440 coue1257.fon
08/23/2001 12:00 PM 31,760 couf1257.fon
08/23/2001 12:00 PM 23,440 couree.fon
08/23/2001 12:00 PM 25,024 coureg.fon
08/23/2001 12:00 PM 23,440 courer.fon
08/23/2001 12:00 PM 25,024 couret.fon
08/23/2001 12:00 PM 31,712 courf.fon
08/23/2001 12:00 PM 31,776 courfe.fon
08/23/2001 12:00 PM 33,344 courfg.fon
08/23/2001 12:00 PM 31,808 courfr.fon
08/23/2001 12:00 PM 33,360 courft.fon
08/23/2001 12:00 PM 36,336 dos737.fon
08/23/2001 12:00 PM 36,816 dos869.fon
08/23/2001 12:00 PM 9,248 ega40737.fon
08/23/2001 12:00 PM 8,384 ega40850.fon
08/23/2001 12:00 PM 8,368 ega40852.fon
08/23/2001 12:00 PM 8,704 ega40857.fon
08/23/2001 12:00 PM 9,232 ega40866.fon
08/23/2001 12:00 PM 9,248 ega40869.fon
08/23/2001 12:00 PM 6,192 ega80737.fon
08/23/2001 12:00 PM 5,328 ega80850.fon
08/23/2001 12:00 PM 5,344 ega80852.fon
08/23/2001 12:00 PM 5,648 ega80857.fon
08/23/2001 12:00 PM 5,280 ega80866.fon
08/23/2001 12:00 PM 6,192 ega80869.fon
08/23/2001 12:00 PM 59,024 sere1257.fon
08/23/2001 12:00 PM 84,080 serf1257.fon
08/23/2001 12:00 PM 59,952 serifee.fon
08/23/2001 12:00 PM 60,752 serifeg.fon
08/23/2001 12:00 PM 63,296 serifer.fon
08/23/2001 12:00 PM 61,024 serifet.fon
08/23/2001 12:00 PM 81,728 seriff.fon
08/23/2001 12:00 PM 85,360 seriffe.fon
08/23/2001 12:00 PM 86,256 seriffg.fon
08/23/2001 12:00 PM 90,736 seriffr.fon
08/23/2001 12:00 PM 84,848 serifft.fon
08/23/2001 12:00 PM 24,672 smae1257.fon
08/23/2001 12:00 PM 19,904 smaf1257.fon
08/23/2001 12:00 PM 24,784 smallee.fon
08/23/2001 12:00 PM 28,912 smalleg.fon
08/23/2001 12:00 PM 24,832 smaller.fon
08/23/2001 12:00 PM 29,200 smallet.fon
08/23/2001 12:00 PM 21,504 smallf.fon
08/23/2001 12:00 PM 19,600 smallfe.fon
08/23/2001 12:00 PM 23,120 smallfg.fon
08/23/2001 12:00 PM 19,760 smallfr.fon
08/23/2001 12:00 PM 23,008 smallft.fon
08/23/2001 12:00 PM 65,456 ssee1257.fon
08/23/2001 12:00 PM 90,336 ssef1257.fon
08/23/2001 12:00 PM 66,464 sserifee.fon
08/23/2001 12:00 PM 65,328 sserifeg.fon
08/23/2001 12:00 PM 68,848 sserifer.fon
08/23/2001 12:00 PM 64,400 sserifet.fon
08/23/2001 12:00 PM 89,856 sseriff.fon
08/23/2001 12:00 PM 92,032 sseriffe.fon
08/23/2001 12:00 PM 90,288 sseriffg.fon
08/23/2001 12:00 PM 98,256 sseriffr.fon
08/23/2001 12:00 PM 89,456 sserifft.fon
08/23/2001 12:00 PM 80,912 symbolf.fon
08/23/2001 12:00 PM 5,232 vga850.fon
08/23/2001 12:00 PM 5,184 vga860.fon
08/23/2001 12:00 PM 5,184 vga861.fon
08/23/2001 12:00 PM 5,200 vga863.fon
08/23/2001 12:00 PM 5,184 vga865.fon
08/23/2001 12:00 PM 5,376 vgafixe.fon
08/23/2001 12:00 PM 6,112 vgafixg.fon
08/23/2001 12:00 PM 5,600 vgafixr.fon
08/23/2001 12:00 PM 6,112 vgafixt.fon
08/23/2001 12:00 PM 6,656 vgas1257.fon
08/23/2001 12:00 PM 6,608 vgasyse.fon
08/23/2001 12:00 PM 7,008 vgasysg.fon
08/23/2001 12:00 PM 6,912 vgasysr.fon
08/23/2001 12:00 PM 6,912 vgasyst.fon
08/23/2001 12:00 PM 12,288 85f874.fon
08/23/2001 12:00 PM 10,240 85s874.fon
08/23/2001 12:00 PM 55,808 msdlg874.fon
08/23/2001 12:00 PM 72,192 ssee874.fon
08/23/2001 12:00 PM 102,400 ssef874.fon
08/23/2001 12:00 PM 7,168 vgaf874.fon
08/23/2001 12:00 PM 8,704 vgas874.fon
08/23/2001 12:00 PM 12,336 85f1255.fon
08/23/2001 12:00 PM 10,224 85s1255.fon
08/23/2001 12:00 PM 5,952 vgaf1255.fon
08/23/2001 12:00 PM 25,216 smae1255.fon
08/23/2001 12:00 PM 20,448 smaf1255.fon
08/23/2001 12:00 PM 26,432 coue1255.fon
08/23/2001 12:00 PM 35,888 couf1255.fon
08/23/2001 12:00 PM 62,944 sere1255.fon
08/23/2001 12:00 PM 89,456 serf1255.fon
08/23/2001 12:00 PM 69,232 ssee1255.fon
08/23/2001 12:00 PM 95,840 ssef1255.fon
08/23/2001 12:00 PM 7,104 vgas1255.fon
08/23/2001 12:00 PM 12,384 85f1256.fon
08/23/2001 12:00 PM 10,608 85s1256.fon
08/23/2001 12:00 PM 6,528 vgaf1256.fon
08/23/2001 12:00 PM 32,512 smae1256.fon
08/23/2001 12:00 PM 37,952 smaf1256.fon
08/23/2001 12:00 PM 26,544 coue1256.fon
08/23/2001 12:00 PM 36,032 couf1256.fon
08/23/2001 12:00 PM 65,392 sere1256.fon
08/23/2001 12:00 PM 95,488 serf1256.fon
08/23/2001 12:00 PM 73,216 ssee1256.fon
08/23/2001 12:00 PM 67,328 ssef1256.fon
08/23/2001 12:00 PM 7,648 vgas1256.fon
08/23/2001 12:00 PM 5,168 vga737.fon
08/23/2001 12:00 PM 5,168 vga775.fon
08/23/2001 12:00 PM 6,160 vga852.fon
08/23/2001 12:00 PM 5,120 vga855.fon
08/23/2001 12:00 PM 5,552 vga857.fon
08/23/2001 12:00 PM 6,128 vga866.fon
08/23/2001 12:00 PM 5,184 vga869.fon
08/23/2001 12:00 PM 5,376 vgaf1257.fon
08/30/2005 11:16 AM 516,116 fontc.dll
09/23/2005 12:16 AM 423,917 ctnof.ini
08/30/2005 11:16 AM 178,314 ctnof.bak1
09/22/2005 02:56 PM 423,672 ctnof.bak2
08/23/2001 12:00 PM 5,168 vgaoem.fon
08/23/2001 12:00 PM 7,280 vgasys.fon
08/23/2001 12:00 PM 5,360 vgafix.fon
08/23/2001 12:00 PM 36,656 dosapp.fon
08/23/2001 12:00 PM 5,312 ega80woa.fon
08/23/2001 12:00 PM 8,368 ega40woa.fon
08/23/2001 12:00 PM 4,304 cga80woa.fon
08/23/2001 12:00 PM 6,336 cga40woa.fon
08/23/2001 12:00 PM 26,112 smalle.fon
08/23/2001 12:00 PM 56,336 symbole.fon
08/23/2001 12:00 PM 23,408 coure.fon
08/23/2001 12:00 PM 64,656 sserife.fon
08/23/2001 12:00 PM 57,936 serife.fon
08/23/2001 12:00 PM 24,124 marlett.ttf
168 File(s) 6,219,810 bytes
0 Dir(s) 3,413,032,960 bytes free
Volume in drive C has no label.
Volume Serial Number is D0EB-D940
Directory of C:\WINDOWS\Fonts
03/26/2005 11:50 AM .
03/26/2005 11:50 AM ..
08/23/2001 12:00 PM 148,636 tunga.ttf
08/23/2001 12:00 PM 296,712 arial.ttf
08/23/2001 12:00 PM 126,796 trebuc.ttf
08/23/2001 12:00 PM 123,096 trebucbd.ttf
08/23/2001 12:00 PM 149,752 verdana.ttf
08/23/2001 12:00 PM 288,496 arialbd.ttf
08/23/2001 12:00 PM 226,748 arialbi.ttf
08/23/2001 12:00 PM 207,808 ariali.ttf
08/23/2001 12:00 PM 117,028 ariblk.ttf
08/23/2001 12:00 PM 126,364 comic.ttf
08/23/2001 12:00 PM 111,476 comicbd.ttf
08/23/2001 12:00 PM 303,296 cour.ttf
08/23/2001 12:00 PM 312,920 courbd.ttf
08/23/2001 12:00 PM 236,148 courbi.ttf
08/23/2001 12:00 PM 245,032 couri.ttf
08/23/2001 12:00 PM 149,628 georgia.ttf
08/23/2001 12:00 PM 141,032 georgiab.ttf
08/23/2001 12:00 PM 157,388 georgiai.ttf
08/23/2001 12:00 PM 159,736 georgiaz.ttf
08/23/2001 12:00 PM 136,076 impact.ttf
08/23/2001 12:00 PM 323,980 l_10646.ttf
08/23/2001 12:00 PM 115,068 lucon.ttf
08/23/2001 12:00 PM 489,884 pala.ttf
08/23/2001 12:00 PM 434,004 palab.ttf
08/23/2001 12:00 PM 344,288 palabi.ttf
08/23/2001 12:00 PM 430,800 palai.ttf
08/23/2001 12:00 PM 69,464 symbol.ttf
08/23/2001 12:00 PM 334,944 timesbd.ttf
08/23/2001 12:00 PM 239,692 timesbi.ttf
08/23/2001 12:00 PM 248,368 timesi.ttf
08/23/2001 12:00 PM 131,188 trebucbi.ttf
08/23/2001 12:00 PM 139,288 trebucit.ttf
08/23/2001 12:00 PM 155,076 verdanai.ttf
08/23/2001 12:00 PM 154,800 verdanaz.ttf
08/23/2001 12:00 PM 118,752 webdings.ttf
08/23/2001 12:00 PM 81,000 wingding.ttf
08/23/2001 12:00 PM 347,988 times.ttf
08/23/2001 12:00 PM 137,616 verdanab.ttf
08/23/2001 12:00 PM 135,984 framd.ttf
08/23/2001 12:00 PM 152,844 framdit.ttf
10/24/1997 03:42 PM 65,544 ARBLI___.TTF
05/28/1998 02:38 PM 134,188 ARIALN.TTF
05/28/1998 02:38 PM 139,056 ARIALNB.TTF
05/28/1998 02:38 PM 138,468 ARIALNBI.TTF
05/28/1998 02:38 PM 141,328 ARIALNI.TTF
11/30/2000 06:40 PM 23,274,572 ARIALUNI.TTF
01/11/1999 05:42 PM 15,519,828 BATANG.TTF
11/12/1998 07:18 AM 151,000 ANTQUAB.TTF
11/12/1998 07:18 AM 150,416 ANTQUABI.TTF
08/23/2001 12:00 PM 221,676 sylfaen.ttf
11/12/1998 07:18 AM 149,092 ANTQUAI.TTF
11/12/1998 07:18 AM 155,528 BKANT.TTF
11/04/1998 04:30 PM 160,940 BOOKOS.TTF
11/04/1998 04:30 PM 154,576 BOOKOSB.TTF
11/04/1998 04:30 PM 162,460 BOOKOSBI.TTF
11/04/1998 04:30 PM 160,920 BOOKOSI.TTF
04/28/1998 07:19 AM 163,828 CENTURY.TTF
09/01/1998 01:13 PM 137,568 GOTHIC.TTF
09/01/1998 01:13 PM 129,676 GOTHICB.TTF
09/01/1998 01:13 PM 139,084 GOTHICBI.TTF
09/01/1998 01:13 PM 148,520 GOTHICI.TTF
05/21/1998 12:30 PM 196,588 GARA.TTF
05/21/1998 12:30 PM 198,540 GARABD.TTF
05/21/1998 12:30 PM 188,916 GARAIT.TTF
07/05/1995 12:31 PM 101,592 HATTEN.TTF
07/03/1998 11:23 AM 9,081,312 MSMINCHO.TTF
08/23/2001 12:00 PM 18,880 wst_czec.fon
01/08/1998 04:26 PM 10,028 OUTLOOK.TTF
08/23/2001 12:00 PM 18,880 wst_engl.fon
11/10/1998 01:52 PM 157,360 MTCORSVA.TTF
08/23/2001 12:00 PM 18,880 wst_fren.fon
10/28/1998 12:55 AM 10,499,104 SIMSUN.TTF
08/23/2001 12:00 PM 18,880 wst_germ.fon
04/15/1996 05:38 PM 59,696 WINGDNG2.TTF
08/23/2001 12:00 PM 18,880 wst_ital.fon
04/15/1996 05:39 PM 29,236 WINGDNG3.TTF
08/23/2001 12:00 PM 18,880 wst_span.fon
07/01/1997 10:22 AM 49,920 A012000T.TTF
08/23/2001 12:00 PM 18,880 wst_swed.fon
07/10/1997 02:15 PM 48,736 AMECLAB.TTF
07/01/1997 10:26 AM 47,952 ASHLYCRA.TTF
07/01/1997 10:31 AM 55,840 B025000D.TTF
07/01/1997 10:31 AM 90,532 B026000D.TTF
07/10/1997 02:46 PM 56,132 C093000I.TTF
07/01/1997 01:12 PM 59,996 CARMINE.TTF
07/01/1997 01:19 PM 45,848 E029000D.TTF
07/10/1997 03:12 PM 52,772 E046014T.TTF
07/17/1997 09:46 AM 68,484 GRETMONO.TTF
07/01/1997 01:47 PM 67,280 H008000D.TTF
07/01/1997 01:49 PM 147,572 I008000D.TTF
07/01/1997 01:50 PM 54,964 I011000D.TTF
07/01/1997 01:52 PM 47,668 ISABELLA.TTF
07/01/1997 01:52 PM 103,040 L006000D.TTF
07/01/1997 02:12 PM 73,900 L028013T.TTF
07/01/1997 02:17 PM 86,636 M014000D.TTF
07/01/1997 02:20 PM 53,308 M025094D.TTF
07/10/1997 03:42 PM 84,068 N009000D.TTF
07/24/1997 09:35 AM 89,468 N010013T.TTF
07/01/1997 02:37 PM 67,944 P016000D.TTF
07/01/1997 02:39 PM 57,640 POSTBOD.TTF
07/10/1997 03:04 PM 34,444 QUILL.TTF
07/17/1997 09:34 AM 60,740 R006000D.TTF
07/01/1997 02:44 PM 107,388 S017016D.TTF
07/01/1997 02:45 PM 100,640 S022803T.TTF
07/01/1997 02:51 PM 34,556 SYMPHO.TTF
07/18/1997 10:11 AM 58,248 T005002T.TTF
07/01/1997 03:02 PM 57,256 V003000D.TTF
07/10/1997 03:14 PM 114,212 V012000D.TTF
07/01/1997 02:59 PM 60,164 U003008T.TTF
04/01/2005 03:15 PM 905 acrsecI.fon
04/01/2005 03:15 PM 1,761 acrsecB.fon
04/01/2005 03:12 PM 1,607 acrsec.fon
08/18/1999 06:13 PM 80,388 COOPBL.ttf
08/24/1999 05:33 PM 77,296 wendymed.ttf
08/24/1999 05:33 PM 103,852 erasdust.ttf
07/01/1997 12:02 AM 156,000 papyrus.ttf
07/01/2003 06:31 PM 82,836 myriadc.ttf
07/01/2003 06:31 PM 89,788 myriadci.ttf
07/01/2003 06:31 PM 83,948 myriad.ttf
07/01/2003 06:31 PM 91,636 myriadb.ttf
07/01/2003 06:31 PM 85,748 myriadi.ttf
08/23/2001 12:00 PM 13,312 roman.fon
08/23/2001 12:00 PM 12,288 script.fon
08/23/2001 12:00 PM 8,704 modern.fon
08/23/2001 12:00 PM 296,872 tahomabd.ttf
08/23/2001 12:00 PM 310,752 tahoma.ttf
08/23/2001 12:00 PM 305,724 micross.ttf
08/23/2001 12:00 PM 79,744 estre.ttf
08/23/2001 12:00 PM 214,936 gautami.ttf
08/23/2001 12:00 PM 73,292 latha.ttf
08/23/2001 12:00 PM 143,864 mangal.ttf
08/23/2001 12:00 PM 40,500 mvboli.ttf
08/23/2001 12:00 PM 57,348 raavi.ttf
08/23/2001 12:00 PM 234,280 shruti.ttf
134 File(s) 75,386,725 bytes
2 Dir(s) 3,413,286,912 bytes free
Here are two methods to remove Winfixer.
Choose the one you want to use.
===================================================
METHOD 1
Step 1:
Please download Process Explorer by Systernals from:
Process Explorer
Also download/unzip KillBox by Option^Explicit from:
Killbox.zip
Step 2:
Download this file and save it to your desktop:
FixVundo Registry File
Copy/paste the text in the Quote box below into Notepad, and save it on the desktop as "
killme.txt "
C:\WINDOWS\Fonts\fontc.dll
C:\WINDOWS\Fonts\ctnof.ini
C:\WINDOWS\Fonts\ctnof.bak1
C:\WINDOWS\Fonts\ctnof.bak2
Step 3:
Print out the following instructions as you will not have Internet Access for the rest of this fix.
Reboot in
"safe" mode .
The rest of this fix must be done in safe mode.
Unzip Process Explorer and double click on
procexp.exe
In the top section of the Process Exlporer screen double-click on
winlogon.exe to bring up the winlogon.exe properties screen. Click on the
Threads tab at the top.
Once you see this screen click on each instance of:
fontc.dll
once and then click the kill button.
After you have killed all of:
fontc.dll
under winlogon click
OK .
If you see any of the files listed below, kill them as well.
Files to look for:
————————–
ctnof.ini
ctnof.bak1
ctnof.bak2
BE SURE TO KILL ONLY THESE FILES!!!
Probably not all of them will be present. That is OK.
Next double-click on
explorer.exe , select the
Threads tab, and again click once on each instance of:
fontc.dll
then click the kill button.
If you see any of the files listed below kill them as well.
Files to look for:
————————–
ctnof.ini
ctnof.bak1
ctnof.bak2
BE SURE TO KILL ONLY THESE FILES!!!
Probably not all of them will be present. That is OK
Once you have done that click
OK again.
Next run Hijack This! and place a check beside each of the following.
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\fontc.dll
O20 - Winlogon Notify: fontc - C:\WINDOWS\Fonts\fontc.dll
Now click
Fix checked and close HijackThis.
Now double-click on the
vundo.reg file that you saved on your desktop earlier and allow it to merge with the registry.
Step 4:
On the desktop, open the "
killme.txt " file with Notepad.
Then copy the all file names in the "
killme.txt " to the clipboard by highlighting them and pressing
C (hold the
key down, then press
C ):
Close "
killme.txt ".
Double click on
Killbox.exe and then check the
Delete on reboot button.
In Killbox, click
File (in the upper left of Killbox), and choose "
Paste from Clipboard ".
Click the
red dot with the white X in it, in the upper right of Killbox, then click "
Yes ", and "
Yes " again.
After the reboot, "copy/paste" a new Hijack This! log file
into this thread .
===================================================
METHOD 2
Please print these instructions out for use in Safe Mode.
Please download
VundoFix.exe to your desktop.
Double-click VundoFix.exe to extract the files
This will create a VundoFix folder on your desktop.
After the files are extracted, please reboot your computer into Safe Mode . You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
You will first be presented with a warning and a list of forums to seek help at.
it should look like this
VundoFix V2.1 by Atri
By pressing enter you agree that you are using this at your own risk
Please seek assistance at one of the following forums:
http://www.atribune.org/forums
http://www.247fixes.com/forums
http://www.geekstogo.com/forum
http://forums.net-integration.net
At this point press enter one time.
Next you will see:
Type in the filepath as instructed by the forum staff
Then Press Enter, Then F6, Then Enter Again to continue with the fix.
At this point please type the following file path (make sure to enter it exactly as below!):C:\WINDOWS\Fonts\fontc.dll Press Enter , then press the F6 key, then press Enter one more time to continue with the fix.
Next you will see:
Please type in the second filepath as instructed by the forum staff
Then Press Enter, Then F6, Then Enter Again to continue with the fix.
At this point please type the following file path (make sure to enter it exactly as below!):C:\WINDOWS\Fonts\ctnof.* Press Enter , then press the F6 key, then press Enter one more time to continue with the fix. The fix will run then HijackThis will open. In HijackThis, please place a check next to the following items and click FIX CHECKED :
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\fontc.dll
O20 - Winlogon Notify: fontc - C:\WINDOWS\Fonts\fontc.dll
After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer. Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry! Once your machine reboots please continue with the instructions below. Copy a new
HijackThis log and the
vundofix.txt file from the vundofix folder into this topic.
Hi Micah!
Used Method 2 and below are the results :
Curiously the 02-BHO line was not to be seen and the 020 Winlogon had a message in brackets - (file missing)
Logfile of HijackThis v1.99.1
Scan saved at 2:05:37 PM, on 9/23/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Armour\bin\ZLH.EXE
C:\Program Files\QuickTime\qttask.exe
D:\Bryan\winamp5\Winamp\winampa.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Armour\bin\ZANDA.EXE
C:\Program Files\Tiny Personal Firewall\persfw.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\ups.exe
C:\Armour\Nvc\BIN\NIP.EXE
C:\Armour\bin\NJEEVES.EXE
C:\Armour\Nvc\BIN\NVCSCHED.EXE
C:\Armour\Nvc\BIN\nipsvc.exe
C:\Armour\Nvc\bin\nvcoas.exe
C:\HijackThis\HijackThis.exe
C:\Armour\Nvc\bin\cclaw.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Armour\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Bryan\winamp5\Winamp\winampa.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) -
http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Armour\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Armour\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Armour\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Armour\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Armour\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe
Vundofix Result :
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Suspending PID 148 'smss.exe'
Threads [152][156][160]
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 716 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Error, Cannot find a process with an image name of rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 232 'winlogon.exe'
File Deleted sucessfully.
Files Deleted sucessfully.