This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Winfix

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 4:23:26 PM, on 9/21/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Armour\bin\ZLH.EXE
C:\Program Files\QuickTime\qttask.exe
D:\Bryan\winamp5\Winamp\winampa.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Armour\bin\ZANDA.EXE
C:\Program Files\Tiny Personal Firewall\persfw.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\ups.exe
C:\Armour\bin\NJEEVES.EXE
D:\Bryan\winamp5\Winamp\winamp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Armour\Nvc\bin\nvcoas.exe
C:\Armour\Nvc\BIN\NIP.EXE
C:\Armour\Nvc\BIN\NVCSCHED.EXE
C:\Armour\Nvc\BIN\nipsvc.exe
C:\Armour\Nvc\bin\cclaw.exe
C:\HijackThis\HijackThis.exe

O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\fontc.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Armour\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Bryan\winamp5\Winamp\winampa.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: fontc - C:\WINDOWS\Fonts\fontc.dll
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Armour\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Armour\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Armour\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Armour\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Armour\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe
Logfile of HijackThis v1.99.1
Scan saved at 4:23:26 PM, on 9/21/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Armour\bin\ZLH.EXE
C:\Program Files\QuickTime\qttask.exe
D:\Bryan\winamp5\Winamp\winampa.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Armour\bin\ZANDA.EXE
C:\Program Files\Tiny Personal Firewall\persfw.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\ups.exe
C:\Armour\bin\NJEEVES.EXE
D:\Bryan\winamp5\Winamp\winamp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Armour\Nvc\bin\nvcoas.exe
C:\Armour\Nvc\BIN\NIP.EXE
C:\Armour\Nvc\BIN\NVCSCHED.EXE
C:\Armour\Nvc\BIN\nipsvc.exe
C:\Armour\Nvc\bin\cclaw.exe
C:\HijackThis\HijackThis.exe

O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\fontc.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Armour\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Bryan\winamp5\Winamp\winampa.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O20 - Winlogon Notify: fontc - C:\WINDOWS\Fonts\fontc.dll
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Armour\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Armour\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Armour\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Armour\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Armour\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe
Greetings and welcome to TomCoyote.org!

Download/install APM

Run APM

Click on each item in the upper window, then look in the lower window.

Check to see which processes are using:

C:\WINDOWS\Fonts\fontc.dll

Post back letting me know all processes using that DLL.

Copy the text in the following quote box into Notepad:

dir C:\WINDOWS\Fonts\ /ah > files.txt
dir C:\WINDOWS\Fonts\ >> files.txt
notepad files.txt


Save it to your desktop as ff.bat.

Close Notepad

Now, the ff.bat file on the desktop.

Wait for a Notepad window to open up.

Please paste it's contents into your next post.
:)
Hi! I've done as requested. Below are the results from APM: 712-c:\windows\system32\winlogon.exe 1396-c:\windows\explorer.exe 2636-c:\program files\internet explorer\iexplorer.exe The results from ff.bat are as follows : Volume in drive C has no label. Volume Serial Number is D0EB-D940 Directory of C:\WINDOWS\Fonts 08/23/2001 12:00 PM 10,976 8514fix.fon 08/23/2001 12:00 PM 10,976 8514fixe.fon 08/23/2001 12:00 PM 11,520 8514fixg.fon 08/23/2001 12:00 PM 10,976 8514fixr.fon 08/23/2001 12:00 PM 11,488 8514fixt.fon 08/23/2001 12:00 PM 12,288 8514oem.fon 08/23/2001 12:00 PM 13,248 8514oeme.fon 08/23/2001 12:00 PM 12,800 8514oemg.fon 08/23/2001 12:00 PM 13,200 8514oemr.fon 08/23/2001 12:00 PM 12,720 8514oemt.fon 08/23/2001 12:00 PM 9,280 8514sys.fon 08/23/2001 12:00 PM 9,504 8514syse.fon 08/23/2001 12:00 PM 9,856 8514sysg.fon 08/23/2001 12:00 PM 10,064 8514sysr.fon 08/23/2001 12:00 PM 9,792 8514syst.fon 08/23/2001 12:00 PM 12,304 85775.fon 08/23/2001 12:00 PM 12,256 85855.fon 08/23/2001 12:00 PM 10,976 85f1257.fon 08/23/2001 12:00 PM 9,472 85s1257.fon 08/23/2001 12:00 PM 35,808 app775.fon 08/23/2001 12:00 PM 36,672 app850.fon 08/23/2001 12:00 PM 36,656 app852.fon 08/23/2001 12:00 PM 37,296 app855.fon 05/12/2005 01:10 PM 67 desktop.ini 08/23/2001 12:00 PM 36,672 app857.fon 08/23/2001 12:00 PM 37,472 app866.fon 08/23/2001 12:00 PM 7,216 cga40737.fon 08/23/2001 12:00 PM 6,352 cga40850.fon 08/23/2001 12:00 PM 6,672 cga40852.fon 08/23/2001 12:00 PM 6,672 cga40857.fon 08/23/2001 12:00 PM 7,232 cga40866.fon 08/23/2001 12:00 PM 7,216 cga40869.fon 08/23/2001 12:00 PM 5,168 cga80737.fon 08/23/2001 12:00 PM 4,320 cga80850.fon 08/23/2001 12:00 PM 5,200 cga80852.fon 08/23/2001 12:00 PM 4,640 cga80857.fon 08/23/2001 12:00 PM 5,168 cga80866.fon 08/23/2001 12:00 PM 5,168 cga80869.fon 08/23/2001 12:00 PM 23,440 coue1257.fon 08/23/2001 12:00 PM 31,760 couf1257.fon 08/23/2001 12:00 PM 23,440 couree.fon 08/23/2001 12:00 PM 25,024 coureg.fon 08/23/2001 12:00 PM 23,440 courer.fon 08/23/2001 12:00 PM 25,024 couret.fon 08/23/2001 12:00 PM 31,712 courf.fon 08/23/2001 12:00 PM 31,776 courfe.fon 08/23/2001 12:00 PM 33,344 courfg.fon 08/23/2001 12:00 PM 31,808 courfr.fon 08/23/2001 12:00 PM 33,360 courft.fon 08/23/2001 12:00 PM 36,336 dos737.fon 08/23/2001 12:00 PM 36,816 dos869.fon 08/23/2001 12:00 PM 9,248 ega40737.fon 08/23/2001 12:00 PM 8,384 ega40850.fon 08/23/2001 12:00 PM 8,368 ega40852.fon 08/23/2001 12:00 PM 8,704 ega40857.fon 08/23/2001 12:00 PM 9,232 ega40866.fon 08/23/2001 12:00 PM 9,248 ega40869.fon 08/23/2001 12:00 PM 6,192 ega80737.fon 08/23/2001 12:00 PM 5,328 ega80850.fon 08/23/2001 12:00 PM 5,344 ega80852.fon 08/23/2001 12:00 PM 5,648 ega80857.fon 08/23/2001 12:00 PM 5,280 ega80866.fon 08/23/2001 12:00 PM 6,192 ega80869.fon 08/23/2001 12:00 PM 59,024 sere1257.fon 08/23/2001 12:00 PM 84,080 serf1257.fon 08/23/2001 12:00 PM 59,952 serifee.fon 08/23/2001 12:00 PM 60,752 serifeg.fon 08/23/2001 12:00 PM 63,296 serifer.fon 08/23/2001 12:00 PM 61,024 serifet.fon 08/23/2001 12:00 PM 81,728 seriff.fon 08/23/2001 12:00 PM 85,360 seriffe.fon 08/23/2001 12:00 PM 86,256 seriffg.fon 08/23/2001 12:00 PM 90,736 seriffr.fon 08/23/2001 12:00 PM 84,848 serifft.fon 08/23/2001 12:00 PM 24,672 smae1257.fon 08/23/2001 12:00 PM 19,904 smaf1257.fon 08/23/2001 12:00 PM 24,784 smallee.fon 08/23/2001 12:00 PM 28,912 smalleg.fon 08/23/2001 12:00 PM 24,832 smaller.fon 08/23/2001 12:00 PM 29,200 smallet.fon 08/23/2001 12:00 PM 21,504 smallf.fon 08/23/2001 12:00 PM 19,600 smallfe.fon 08/23/2001 12:00 PM 23,120 smallfg.fon 08/23/2001 12:00 PM 19,760 smallfr.fon 08/23/2001 12:00 PM 23,008 smallft.fon 08/23/2001 12:00 PM 65,456 ssee1257.fon 08/23/2001 12:00 PM 90,336 ssef1257.fon 08/23/2001 12:00 PM 66,464 sserifee.fon 08/23/2001 12:00 PM 65,328 sserifeg.fon 08/23/2001 12:00 PM 68,848 sserifer.fon 08/23/2001 12:00 PM 64,400 sserifet.fon 08/23/2001 12:00 PM 89,856 sseriff.fon 08/23/2001 12:00 PM 92,032 sseriffe.fon 08/23/2001 12:00 PM 90,288 sseriffg.fon 08/23/2001 12:00 PM 98,256 sseriffr.fon 08/23/2001 12:00 PM 89,456 sserifft.fon 08/23/2001 12:00 PM 80,912 symbolf.fon 08/23/2001 12:00 PM 5,232 vga850.fon 08/23/2001 12:00 PM 5,184 vga860.fon 08/23/2001 12:00 PM 5,184 vga861.fon 08/23/2001 12:00 PM 5,200 vga863.fon 08/23/2001 12:00 PM 5,184 vga865.fon 08/23/2001 12:00 PM 5,376 vgafixe.fon 08/23/2001 12:00 PM 6,112 vgafixg.fon 08/23/2001 12:00 PM 5,600 vgafixr.fon 08/23/2001 12:00 PM 6,112 vgafixt.fon 08/23/2001 12:00 PM 6,656 vgas1257.fon 08/23/2001 12:00 PM 6,608 vgasyse.fon 08/23/2001 12:00 PM 7,008 vgasysg.fon 08/23/2001 12:00 PM 6,912 vgasysr.fon 08/23/2001 12:00 PM 6,912 vgasyst.fon 08/23/2001 12:00 PM 12,288 85f874.fon 08/23/2001 12:00 PM 10,240 85s874.fon 08/23/2001 12:00 PM 55,808 msdlg874.fon 08/23/2001 12:00 PM 72,192 ssee874.fon 08/23/2001 12:00 PM 102,400 ssef874.fon 08/23/2001 12:00 PM 7,168 vgaf874.fon 08/23/2001 12:00 PM 8,704 vgas874.fon 08/23/2001 12:00 PM 12,336 85f1255.fon 08/23/2001 12:00 PM 10,224 85s1255.fon 08/23/2001 12:00 PM 5,952 vgaf1255.fon 08/23/2001 12:00 PM 25,216 smae1255.fon 08/23/2001 12:00 PM 20,448 smaf1255.fon 08/23/2001 12:00 PM 26,432 coue1255.fon 08/23/2001 12:00 PM 35,888 couf1255.fon 08/23/2001 12:00 PM 62,944 sere1255.fon 08/23/2001 12:00 PM 89,456 serf1255.fon 08/23/2001 12:00 PM 69,232 ssee1255.fon 08/23/2001 12:00 PM 95,840 ssef1255.fon 08/23/2001 12:00 PM 7,104 vgas1255.fon 08/23/2001 12:00 PM 12,384 85f1256.fon 08/23/2001 12:00 PM 10,608 85s1256.fon 08/23/2001 12:00 PM 6,528 vgaf1256.fon 08/23/2001 12:00 PM 32,512 smae1256.fon 08/23/2001 12:00 PM 37,952 smaf1256.fon 08/23/2001 12:00 PM 26,544 coue1256.fon 08/23/2001 12:00 PM 36,032 couf1256.fon 08/23/2001 12:00 PM 65,392 sere1256.fon 08/23/2001 12:00 PM 95,488 serf1256.fon 08/23/2001 12:00 PM 73,216 ssee1256.fon 08/23/2001 12:00 PM 67,328 ssef1256.fon 08/23/2001 12:00 PM 7,648 vgas1256.fon 08/23/2001 12:00 PM 5,168 vga737.fon 08/23/2001 12:00 PM 5,168 vga775.fon 08/23/2001 12:00 PM 6,160 vga852.fon 08/23/2001 12:00 PM 5,120 vga855.fon 08/23/2001 12:00 PM 5,552 vga857.fon 08/23/2001 12:00 PM 6,128 vga866.fon 08/23/2001 12:00 PM 5,184 vga869.fon 08/23/2001 12:00 PM 5,376 vgaf1257.fon 08/30/2005 11:16 AM 516,116 fontc.dll 09/23/2005 12:16 AM 423,917 ctnof.ini 08/30/2005 11:16 AM 178,314 ctnof.bak1 09/22/2005 02:56 PM 423,672 ctnof.bak2 08/23/2001 12:00 PM 5,168 vgaoem.fon 08/23/2001 12:00 PM 7,280 vgasys.fon 08/23/2001 12:00 PM 5,360 vgafix.fon 08/23/2001 12:00 PM 36,656 dosapp.fon 08/23/2001 12:00 PM 5,312 ega80woa.fon 08/23/2001 12:00 PM 8,368 ega40woa.fon 08/23/2001 12:00 PM 4,304 cga80woa.fon 08/23/2001 12:00 PM 6,336 cga40woa.fon 08/23/2001 12:00 PM 26,112 smalle.fon 08/23/2001 12:00 PM 56,336 symbole.fon 08/23/2001 12:00 PM 23,408 coure.fon 08/23/2001 12:00 PM 64,656 sserife.fon 08/23/2001 12:00 PM 57,936 serife.fon 08/23/2001 12:00 PM 24,124 marlett.ttf 168 File(s) 6,219,810 bytes 0 Dir(s) 3,413,032,960 bytes free Volume in drive C has no label. Volume Serial Number is D0EB-D940 Directory of C:\WINDOWS\Fonts 03/26/2005 11:50 AM . 03/26/2005 11:50 AM .. 08/23/2001 12:00 PM 148,636 tunga.ttf 08/23/2001 12:00 PM 296,712 arial.ttf 08/23/2001 12:00 PM 126,796 trebuc.ttf 08/23/2001 12:00 PM 123,096 trebucbd.ttf 08/23/2001 12:00 PM 149,752 verdana.ttf 08/23/2001 12:00 PM 288,496 arialbd.ttf 08/23/2001 12:00 PM 226,748 arialbi.ttf 08/23/2001 12:00 PM 207,808 ariali.ttf 08/23/2001 12:00 PM 117,028 ariblk.ttf 08/23/2001 12:00 PM 126,364 comic.ttf 08/23/2001 12:00 PM 111,476 comicbd.ttf 08/23/2001 12:00 PM 303,296 cour.ttf 08/23/2001 12:00 PM 312,920 courbd.ttf 08/23/2001 12:00 PM 236,148 courbi.ttf 08/23/2001 12:00 PM 245,032 couri.ttf 08/23/2001 12:00 PM 149,628 georgia.ttf 08/23/2001 12:00 PM 141,032 georgiab.ttf 08/23/2001 12:00 PM 157,388 georgiai.ttf 08/23/2001 12:00 PM 159,736 georgiaz.ttf 08/23/2001 12:00 PM 136,076 impact.ttf 08/23/2001 12:00 PM 323,980 l_10646.ttf 08/23/2001 12:00 PM 115,068 lucon.ttf 08/23/2001 12:00 PM 489,884 pala.ttf 08/23/2001 12:00 PM 434,004 palab.ttf 08/23/2001 12:00 PM 344,288 palabi.ttf 08/23/2001 12:00 PM 430,800 palai.ttf 08/23/2001 12:00 PM 69,464 symbol.ttf 08/23/2001 12:00 PM 334,944 timesbd.ttf 08/23/2001 12:00 PM 239,692 timesbi.ttf 08/23/2001 12:00 PM 248,368 timesi.ttf 08/23/2001 12:00 PM 131,188 trebucbi.ttf 08/23/2001 12:00 PM 139,288 trebucit.ttf 08/23/2001 12:00 PM 155,076 verdanai.ttf 08/23/2001 12:00 PM 154,800 verdanaz.ttf 08/23/2001 12:00 PM 118,752 webdings.ttf 08/23/2001 12:00 PM 81,000 wingding.ttf 08/23/2001 12:00 PM 347,988 times.ttf 08/23/2001 12:00 PM 137,616 verdanab.ttf 08/23/2001 12:00 PM 135,984 framd.ttf 08/23/2001 12:00 PM 152,844 framdit.ttf 10/24/1997 03:42 PM 65,544 ARBLI___.TTF 05/28/1998 02:38 PM 134,188 ARIALN.TTF 05/28/1998 02:38 PM 139,056 ARIALNB.TTF 05/28/1998 02:38 PM 138,468 ARIALNBI.TTF 05/28/1998 02:38 PM 141,328 ARIALNI.TTF 11/30/2000 06:40 PM 23,274,572 ARIALUNI.TTF 01/11/1999 05:42 PM 15,519,828 BATANG.TTF 11/12/1998 07:18 AM 151,000 ANTQUAB.TTF 11/12/1998 07:18 AM 150,416 ANTQUABI.TTF 08/23/2001 12:00 PM 221,676 sylfaen.ttf 11/12/1998 07:18 AM 149,092 ANTQUAI.TTF 11/12/1998 07:18 AM 155,528 BKANT.TTF 11/04/1998 04:30 PM 160,940 BOOKOS.TTF 11/04/1998 04:30 PM 154,576 BOOKOSB.TTF 11/04/1998 04:30 PM 162,460 BOOKOSBI.TTF 11/04/1998 04:30 PM 160,920 BOOKOSI.TTF 04/28/1998 07:19 AM 163,828 CENTURY.TTF 09/01/1998 01:13 PM 137,568 GOTHIC.TTF 09/01/1998 01:13 PM 129,676 GOTHICB.TTF 09/01/1998 01:13 PM 139,084 GOTHICBI.TTF 09/01/1998 01:13 PM 148,520 GOTHICI.TTF 05/21/1998 12:30 PM 196,588 GARA.TTF 05/21/1998 12:30 PM 198,540 GARABD.TTF 05/21/1998 12:30 PM 188,916 GARAIT.TTF 07/05/1995 12:31 PM 101,592 HATTEN.TTF 07/03/1998 11:23 AM 9,081,312 MSMINCHO.TTF 08/23/2001 12:00 PM 18,880 wst_czec.fon 01/08/1998 04:26 PM 10,028 OUTLOOK.TTF 08/23/2001 12:00 PM 18,880 wst_engl.fon 11/10/1998 01:52 PM 157,360 MTCORSVA.TTF 08/23/2001 12:00 PM 18,880 wst_fren.fon 10/28/1998 12:55 AM 10,499,104 SIMSUN.TTF 08/23/2001 12:00 PM 18,880 wst_germ.fon 04/15/1996 05:38 PM 59,696 WINGDNG2.TTF 08/23/2001 12:00 PM 18,880 wst_ital.fon 04/15/1996 05:39 PM 29,236 WINGDNG3.TTF 08/23/2001 12:00 PM 18,880 wst_span.fon 07/01/1997 10:22 AM 49,920 A012000T.TTF 08/23/2001 12:00 PM 18,880 wst_swed.fon 07/10/1997 02:15 PM 48,736 AMECLAB.TTF 07/01/1997 10:26 AM 47,952 ASHLYCRA.TTF 07/01/1997 10:31 AM 55,840 B025000D.TTF 07/01/1997 10:31 AM 90,532 B026000D.TTF 07/10/1997 02:46 PM 56,132 C093000I.TTF 07/01/1997 01:12 PM 59,996 CARMINE.TTF 07/01/1997 01:19 PM 45,848 E029000D.TTF 07/10/1997 03:12 PM 52,772 E046014T.TTF 07/17/1997 09:46 AM 68,484 GRETMONO.TTF 07/01/1997 01:47 PM 67,280 H008000D.TTF 07/01/1997 01:49 PM 147,572 I008000D.TTF 07/01/1997 01:50 PM 54,964 I011000D.TTF 07/01/1997 01:52 PM 47,668 ISABELLA.TTF 07/01/1997 01:52 PM 103,040 L006000D.TTF 07/01/1997 02:12 PM 73,900 L028013T.TTF 07/01/1997 02:17 PM 86,636 M014000D.TTF 07/01/1997 02:20 PM 53,308 M025094D.TTF 07/10/1997 03:42 PM 84,068 N009000D.TTF 07/24/1997 09:35 AM 89,468 N010013T.TTF 07/01/1997 02:37 PM 67,944 P016000D.TTF 07/01/1997 02:39 PM 57,640 POSTBOD.TTF 07/10/1997 03:04 PM 34,444 QUILL.TTF 07/17/1997 09:34 AM 60,740 R006000D.TTF 07/01/1997 02:44 PM 107,388 S017016D.TTF 07/01/1997 02:45 PM 100,640 S022803T.TTF 07/01/1997 02:51 PM 34,556 SYMPHO.TTF 07/18/1997 10:11 AM 58,248 T005002T.TTF 07/01/1997 03:02 PM 57,256 V003000D.TTF 07/10/1997 03:14 PM 114,212 V012000D.TTF 07/01/1997 02:59 PM 60,164 U003008T.TTF 04/01/2005 03:15 PM 905 acrsecI.fon 04/01/2005 03:15 PM 1,761 acrsecB.fon 04/01/2005 03:12 PM 1,607 acrsec.fon 08/18/1999 06:13 PM 80,388 COOPBL.ttf 08/24/1999 05:33 PM 77,296 wendymed.ttf 08/24/1999 05:33 PM 103,852 erasdust.ttf 07/01/1997 12:02 AM 156,000 papyrus.ttf 07/01/2003 06:31 PM 82,836 myriadc.ttf 07/01/2003 06:31 PM 89,788 myriadci.ttf 07/01/2003 06:31 PM 83,948 myriad.ttf 07/01/2003 06:31 PM 91,636 myriadb.ttf 07/01/2003 06:31 PM 85,748 myriadi.ttf 08/23/2001 12:00 PM 13,312 roman.fon 08/23/2001 12:00 PM 12,288 script.fon 08/23/2001 12:00 PM 8,704 modern.fon 08/23/2001 12:00 PM 296,872 tahomabd.ttf 08/23/2001 12:00 PM 310,752 tahoma.ttf 08/23/2001 12:00 PM 305,724 micross.ttf 08/23/2001 12:00 PM 79,744 estre.ttf 08/23/2001 12:00 PM 214,936 gautami.ttf 08/23/2001 12:00 PM 73,292 latha.ttf 08/23/2001 12:00 PM 143,864 mangal.ttf 08/23/2001 12:00 PM 40,500 mvboli.ttf 08/23/2001 12:00 PM 57,348 raavi.ttf 08/23/2001 12:00 PM 234,280 shruti.ttf 134 File(s) 75,386,725 bytes 2 Dir(s) 3,413,286,912 bytes free
Here are two methods to remove Winfixer.

Choose the one you want to use.

===================================================

METHOD 1

Step 1:

Please download Process Explorer by Systernals from:

Process Explorer

Also download/unzip KillBox by Option^Explicit from:

Killbox.zip

Step 2:

Download this file and save it to your desktop:

FixVundo Registry File

Copy/paste the text in the Quote box below into Notepad, and save it on the desktop as "killme.txt"

C:\WINDOWS\Fonts\fontc.dll
C:\WINDOWS\Fonts\ctnof.ini
C:\WINDOWS\Fonts\ctnof.bak1
C:\WINDOWS\Fonts\ctnof.bak2


Step 3:

Print out the following instructions as you will not have Internet Access for the rest of this fix.

Reboot in "safe" mode.

The rest of this fix must be done in safe mode.

Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double-click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of:

fontc.dll

once and then click the kill button.

After you have killed all of:

fontc.dll

under winlogon click OK.

If you see any of the files listed below, kill them as well.

Files to look for:
————————–
ctnof.ini
ctnof.bak1
ctnof.bak2

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present. That is OK.

Next double-click on explorer.exe, select the Threads tab, and again click once on each instance of:

fontc.dll

then click the kill button.

If you see any of the files listed below kill them as well.

Files to look for:
————————–
ctnof.ini
ctnof.bak1
ctnof.bak2

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present. That is OK

Once you have done that click OK again.

Next run Hijack This! and place a check beside each of the following.

O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\fontc.dll

O20 - Winlogon Notify: fontc - C:\WINDOWS\Fonts\fontc.dll

Now click Fix checked and close HijackThis.

Now double-click on the vundo.reg file that you saved on your desktop earlier and allow it to merge with the registry.

Step 4:

On the desktop, open the "killme.txt" file with Notepad.

Then copy the all file names in the "killme.txt" to the clipboard by highlighting them and pressing C (hold the key down, then press C):

Close "killme.txt".

Double click on Killbox.exe and then check the Delete on reboot button.

In Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new Hijack This! log file into this thread. :)

===================================================

METHOD 2

Please print these instructions out for use in Safe Mode.

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to extract the files

  • This will create a VundoFix folder on your desktop.

  • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.

  • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat

  • You will first be presented with a warning and a list of forums to seek help at.
    it should look like this

    VundoFix V2.1 by Atri
    By pressing enter you agree that you are using this at your own risk
    Please seek assistance at one of the following forums:
    http://www.atribune.org/forums
    http://www.247fixes.com/forums
    http://www.geekstogo.com/forum
    http://forums.net-integration.net


  • At this point press enter one time.

  • Next you will see:

    Type in the filepath as instructed by the forum staff
    Then Press Enter, Then F6, Then Enter Again to continue with the fix.

  • At this point please type the following file path (make sure to enter it exactly as below!):
    • C:\WINDOWS\Fonts\fontc.dll
  • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
  • Next you will see:

    Please type in the second filepath as instructed by the forum staff
    Then Press Enter, Then F6, Then Enter Again to continue with the fix.

  • At this point please type the following file path (make sure to enter it exactly as below!):C:\WINDOWS\Fonts\ctnof.*
  • Press Enter, then press the F6 key, then press Enter one more time to continue with the fix.
  • The fix will run then HijackThis will open.
  • In HijackThis, please place a check next to the following items and click FIX CHECKED:
    O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\fontc.dll

    O20 - Winlogon Notify: fontc - C:\WINDOWS\Fonts\fontc.dll
  • After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer.
  • Pressing any key will cause a "Blue Screen of Death" this is normal, do not worry!
  • Once your machine reboots please continue with the instructions below.
Copy a new HijackThis log and the vundofix.txt file from the vundofix folder into this topic.
Hi Micah!
Used Method 2 and below are the results :
Curiously the 02-BHO line was not to be seen and the 020 Winlogon had a message in brackets - (file missing)

Logfile of HijackThis v1.99.1
Scan saved at 2:05:37 PM, on 9/23/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Armour\bin\ZLH.EXE
C:\Program Files\QuickTime\qttask.exe
D:\Bryan\winamp5\Winamp\winampa.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Armour\bin\ZANDA.EXE
C:\Program Files\Tiny Personal Firewall\persfw.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\ups.exe
C:\Armour\Nvc\BIN\NIP.EXE
C:\Armour\bin\NJEEVES.EXE
C:\Armour\Nvc\BIN\NVCSCHED.EXE
C:\Armour\Nvc\BIN\nipsvc.exe
C:\Armour\Nvc\bin\nvcoas.exe
C:\HijackThis\HijackThis.exe
C:\Armour\Nvc\bin\cclaw.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\Armour\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] D:\Bryan\winamp5\Winamp\winampa.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &WordWeb… - res://C:\WINDOWS\wweb32.dll/lookup.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Armour\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Armour\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Armour\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Armour\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Armour\Nvc\BIN\NVCSCHED.EXE
O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe

Vundofix Result :
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Suspending PID 148 'smss.exe'
Threads [152][156][160]

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 716 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Error, Cannot find a process with an image name of rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 232 'winlogon.exe'
File Deleted sucessfully.
Files Deleted sucessfully.
Looks good!!! :thumbup:

GOD bless you!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI