This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This log

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm having a problem with Winfixer/Winantispyware causing popups to appear randomly on my pc. Any help?


Logfile of HijackThis v1.99.1
Scan saved at 3:33:32 PM, on 10/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\iFtpSvc\iFtpSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lauren\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dellnet.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Lauren\Application Data\Mozilla\Profiles\default\uwmez9u1.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lauren\Application Data\Mozilla\Profiles\default\uwmez9u1.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\hardc.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ChatSpace Full Java Client 4.0.0.301 - http://63.102.226.240:8000/Java/cfs40301.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotdate/NPC…otDateTeleX.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {435583D3-F647-4943-BB40-B0D64CB02718} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab
O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} (MaxisSuperstarTeleX Control) - http://thesims.ea.com/teleport/superstar/M…erstarTeleX.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O20 - Winlogon Notify: hardc - C:\WINDOWS\Fonts\hardc.dll
O20 - Winlogon Notify: javadb - C:\WINDOWS\Help\javadb.dll
O20 - Winlogon Notify: msdb - C:\WINDOWS\Help\Tours\msdb.dll
O20 - Winlogon Notify: unkey - C:\WINDOWS\Fonts\unkey.dll
O20 - Winlogon Notify: utils - C:\WINDOWS\system\utils.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Ipswitch WS_FTP Server (iFtpSvc) - Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. - C:\iFtpSvc\iFtpSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


This is my startup log file:

StartupList report, 10/10/2005, 3:53:57 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Lauren\Desktop\hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\iFtpSvc\iFtpSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Documents and Settings\Lauren\Desktop\hijackthis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Lauren\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
AIM = C:\Program Files\AIM\aim.exe -cnetwait.odl

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

————————————————–

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

————————————————–

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

————————————————–

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install

[{8b15971b-5355-4c82-8c07-7e181ea07608}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser

————————————————–

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\SGALLERY.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

————————————————–

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

————————————————–

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

————————————————–

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\WINDOWS\Fonts\hardc.dll - {827DC836-DD9F-4A68-A602-5812EB50A834}

————————————————–

Enumerating Task Scheduler jobs:

ISP signup reminder 1.job

————————————————–

Enumerating Download Program Files:

[ChatSpace Full Java Client 4.0.0.301]
CODEBASE = http://63.102.226.240:8000/Java/cfs40301.cab
OSD = C:\WINDOWS\Downloaded Program Files\ChatSpace Full Java Client 4.0.0.301.osd

[DirectAnimation Java Classes]
CODEBASE = file://C:\WINDOWS\Java\classes\dajava.cab
OSD = C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINDOWS\Java\classes\xmldso.cab
OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd

[Yahoo! Pool 2]
CODEBASE = http://download.games.yahoo.com/games/clients/y/potc_x.cab
OSD = C:\WINDOWS\Downloaded Program Files\Yahoo! Pool 2.osd

[Support.com Configuration Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\tgctlcm.dll
CODEBASE = http://support.cox.com/sdccommon/download/tgctlcm.cab

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[MaxisHotDateTeleX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\MAXISH~1.OCX
CODEBASE = http://thesims.ea.com/teleport/hotdate/NPC…otDateTeleX.cab

[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab

[Cult3D ActiveX Player]
InProcServer32 = C:\WINDOWS\System32\Cult3D\IECult.dll
CODEBASE = http://www.cult3d.com/download/cult.cab

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[Snapfish File Upload ActiveX Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\SnapfishUpload1402.ocx
CODEBASE = http://www.snapfish.com/SnapfishUpload.cab

[{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}]
CODEBASE = http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab

[MaxisSuperstarTeleX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\MAXISS~1.OCX
CODEBASE = http://thesims.ea.com/teleport/superstar/M…erstarTeleX.cab

[Symantec RuFSI Utility Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab

[Java Plug-in 1.4.2_05]
InProcServer32 = C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
CODEBASE = http://java.sun.com/products/plugin/autodl…indows-i586.cab

[{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}]
CODEBASE = http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab

[Java Plug-in 1.4.1_02]
InProcServer32 = C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll
CODEBASE = http://java.sun.com/products/plugin/1.4/ji…indows-i586.cab

[Java Plug-in 1.4.2_05]
InProcServer32 = C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
CODEBASE = http://java.sun.com/products/plugin/autodl…indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\MACROMED\Flash\Flash.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shock…ash/swflash.cab

[Secure Delivery]
CODEBASE = http://www.gamespot.com/KDX/kdx.cab

[IWinAmpActiveX Class]
InProcServer32 = C:\Program Files\Common Files\Nullsoft\ActiveX\2.0\AmpX.dll
CODEBASE = http://cdn.digitalcity.com/_media/dalaillama/ampx.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll

————————————————–

Enumerating Windows NT/2000/XP services

abp480n5: \SystemRoot\System32\DRIVERS\ABP480N5.SYS (disabled)
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
adpu160m: \SystemRoot\System32\DRIVERS\adpu160m.sys (disabled)
aeaudio: system32\drivers\aeaudio.sys (manual start)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (system)
Intel AGP Bus Filter: \SystemRoot\System32\DRIVERS\agp440.sys (system)
Compaq AGP Bus Filter: \SystemRoot\System32\DRIVERS\agpCPQ.sys (disabled)
Aha154x: \SystemRoot\System32\DRIVERS\aha154x.sys (disabled)
aic78u2: \SystemRoot\System32\DRIVERS\aic78u2.sys (disabled)
aic78xx: \SystemRoot\System32\DRIVERS\aic78xx.sys (disabled)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AliIde: \SystemRoot\System32\DRIVERS\aliide.sys (disabled)
ALI AGP Bus Filter: \SystemRoot\System32\DRIVERS\alim1541.sys (disabled)
AMD AGP Bus Filter Driver: \SystemRoot\System32\DRIVERS\amdagp.sys (disabled)
amsint: \SystemRoot\System32\DRIVERS\amsint.sys (disabled)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
asc: \SystemRoot\System32\DRIVERS\asc.sys (disabled)
asc3350p: \SystemRoot\System32\DRIVERS\asc3350p.sys (disabled)
asc3550: \SystemRoot\System32\DRIVERS\asc3550.sys (disabled)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart)
AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system)
AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system)
AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsxp.sys (system)
AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
AVG Network Redirector: \??\C:\WINDOWS\System32\Drivers\avgtdi.sys (autostart)
BCM V.92 56K Modem: System32\DRIVERS\BCMSM.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
cbidf: \SystemRoot\System32\DRIVERS\cbidf2k.sys (disabled)
cd20xrnt: \SystemRoot\System32\DRIVERS\cd20xrnt.sys (disabled)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (autostart)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
CmdIde: \SystemRoot\System32\DRIVERS\cmdide.sys (disabled)
COM+ System Application: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cpqarray: \SystemRoot\System32\DRIVERS\cpqarray.sys (disabled)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
d347bus: system32\DRIVERS\d347bus.sys (system)
d347prt: System32\Drivers\d347prt.sys (system)
dac2w2k: \SystemRoot\System32\DRIVERS\dac2w2k.sys (disabled)
dac960nt: \SystemRoot\System32\DRIVERS\dac960nt.sys (disabled)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
dpti2o: \SystemRoot\System32\DRIVERS\dpti2o.sys (disabled)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Intel® PRO Adapter Driver: System32\DRIVERS\e100b325.sys (manual start)
3Com EtherLink XL 90XB/C Adapter Driver: System32\DRIVERS\el90xbc5.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Fax: %systemroot%\system32\fxssvc.exe (autostart)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\drivers\fltmgr.sys (system)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
giveio: system32\giveio.sys (system)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
hpn: \SystemRoot\System32\DRIVERS\hpn.sys (disabled)
IEEE-1284.4 Driver HPZid412: system32\DRIVERS\HPZid412.sys (manual start)
Print Class Driver for IEEE-1284.4 HPZipr12: system32\DRIVERS\HPZipr12.sys (manual start)
USB to IEEE-1284.4 Translation Driver HPZius12: system32\DRIVERS\HPZius12.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i2omp: \SystemRoot\System32\DRIVERS\i2omp.sys (disabled)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
i81x: System32\DRIVERS\i81xnt5.sys (manual start)
iAimFP0: System32\DRIVERS\wADV01nt.sys (manual start)
iAimFP1: System32\DRIVERS\wADV02NT.sys (manual start)
iAimFP2: System32\DRIVERS\wADV05NT.sys (manual start)
iAimFP3: System32\DRIVERS\wSiINTxx.sys (manual start)
iAimFP4: System32\DRIVERS\wVchNTxx.sys (manual start)
iAimTV0: System32\DRIVERS\wATV01nt.sys (manual start)
iAimTV1: System32\DRIVERS\wATV02NT.sys (manual start)
iAimTV2: System32\DRIVERS\wATV03nt.sys (manual start)
iAimTV3: System32\DRIVERS\wATV04nt.sys (manual start)
iAimTV4: System32\DRIVERS\wCh7xxNT.sys (manual start)
Ipswitch WS_FTP Server: C:\iFtpSvc\iFtpSvc.exe (autostart)
CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\System32\imapi.exe (manual start)
ini910u: \SystemRoot\System32\DRIVERS\ini910u.sys (disabled)
IntelIde: \SystemRoot\System32\DRIVERS\intelide.sys (disabled)
Intel Processor Driver: System32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\drivers\ip6fw.sys (manual start)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
Messenger: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
Unimodem Streaming Filter Device: system32\drivers\MODEMCSA.sys (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
mraid35x: \SystemRoot\System32\DRIVERS\mraid35x.sys (disabled)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: System32\DRIVERS\mssmbios.sys (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Intel NCS NetService: C:\Program Files\Intel\NCS\Sync\NetSvc.exe (manual start)
Network Location Awareness (NLA): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: System32\DRIVERS\nv4_mini.sys (manual start)
NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
OMCI WDM Device Driver: System32\DRIVERS\omci.sys (system)
Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
Intel PentiumIII Processor Driver: System32\DRIVERS\p3.sys (system)
Parallel port driver: System32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
PCIIde: System32\DRIVERS\pciide.sys (system)
perc2: \SystemRoot\System32\DRIVERS\perc2.sys (disabled)
perc2hib: \SystemRoot\System32\DRIVERS\perc2hib.sys (disabled)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
Pml Driver HPZ12: C:\WINDOWS\system32\HPZipm12.exe (manual start)
IPSEC Services: %SystemRoot%\System32\lsass.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Processor Driver: System32\DRIVERS\processr.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: System32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\Drivers\PxHelp20.sys (system)
ql1080: \SystemRoot\System32\DRIVERS\ql1080.sys (disabled)
Ql10wnt: \SystemRoot\System32\DRIVERS\ql10wnt.sys (disabled)
ql12160: \SystemRoot\System32\DRIVERS\ql12160.sys (disabled)
ql1240: \SystemRoot\System32\DRIVERS\ql1240.sys (disabled)
ql1280: \SystemRoot\System32\DRIVERS\ql1280.sys (disabled)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: System32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: System32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SIS AGP Bus Filter: \SystemRoot\System32\DRIVERS\sisagp.sys (disabled)
smwdm: system32\drivers\smwdm.sys (manual start)
Sparrow: \SystemRoot\System32\DRIVERS\sparrow.sys (disabled)
speedfan: system32\speedfan.sys (system)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Filter Driver: \SystemRoot\System32\DRIVERS\sr.sys (disabled)
System Restore Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{F79A1568-D6C5-4C69-A086-936CF52DBBE3} (manual start)
symc810: \SystemRoot\System32\DRIVERS\symc810.sys (disabled)
symc8xx: \SystemRoot\System32\DRIVERS\symc8xx.sys (disabled)
sym_hi: \SystemRoot\System32\DRIVERS\sym_hi.sys (disabled)
sym_u3: \SystemRoot\System32\DRIVERS\sym_u3.sys (disabled)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: System32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TosIde: \SystemRoot\System32\DRIVERS\toside.sys (disabled)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
ultra: \SystemRoot\System32\DRIVERS\ultra.sys (disabled)
Windows User Mode Driver Framework: C:\WINDOWS\System32\wdfmgr.exe (autostart)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
Microsoft USB PRINTER Class: system32\DRIVERS\usbprint.sys (manual start)
USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
uscbs108: System32\DRIVERS\uscbs108.sys (manual start)
uscsc108: System32\DRIVERS\uscsc108.sys (manual start)
VGA Display Controller.: \SystemRoot\System32\drivers\vga.sys (system)
VIA AGP Bus Filter: \SystemRoot\System32\DRIVERS\viaagp.sys (disabled)
ViaIde: \SystemRoot\System32\DRIVERS\viaide.sys (disabled)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

End of report, 38,038 bytes
Report generated in 0.219 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
I'm having a problem with Winfixer/Winantispyware causing popups to appear randomly on my pc. Any help?


Logfile of HijackThis v1.99.1
Scan saved at 3:33:32 PM, on 10/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\iFtpSvc\iFtpSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Lauren\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dellnet.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Lauren\Application Data\Mozilla\Profiles\default\uwmez9u1.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lauren\Application Data\Mozilla\Profiles\default\uwmez9u1.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\hardc.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ChatSpace Full Java Client 4.0.0.301 - http://63.102.226.240:8000/Java/cfs40301.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotdate/NPC…otDateTeleX.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {435583D3-F647-4943-BB40-B0D64CB02718} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab
O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} (MaxisSuperstarTeleX Control) - http://thesims.ea.com/teleport/superstar/M…erstarTeleX.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O20 - Winlogon Notify: hardc - C:\WINDOWS\Fonts\hardc.dll
O20 - Winlogon Notify: javadb - C:\WINDOWS\Help\javadb.dll
O20 - Winlogon Notify: msdb - C:\WINDOWS\Help\Tours\msdb.dll
O20 - Winlogon Notify: unkey - C:\WINDOWS\Fonts\unkey.dll
O20 - Winlogon Notify: utils - C:\WINDOWS\system\utils.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Ipswitch WS_FTP Server (iFtpSvc) - Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. - C:\iFtpSvc\iFtpSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


This is my startup log file:

StartupList report, 10/10/2005, 3:53:57 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Lauren\Desktop\hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\iFtpSvc\iFtpSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Documents and Settings\Lauren\Desktop\hijackthis\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Lauren\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

AVG7_CC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
AVG7_EMC = C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
AIM = C:\Program Files\AIM\aim.exe -cnetwait.odl

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

————————————————–

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

————————————————–

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

————————————————–

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install

[{8b15971b-5355-4c82-8c07-7e181ea07608}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser

————————————————–

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\SGALLERY.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

————————————————–

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

————————————————–

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

————————————————–

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\WINDOWS\Fonts\hardc.dll - {827DC836-DD9F-4A68-A602-5812EB50A834}

————————————————–

Enumerating Task Scheduler jobs:

ISP signup reminder 1.job

————————————————–

Enumerating Download Program Files:

[ChatSpace Full Java Client 4.0.0.301]
CODEBASE = http://63.102.226.240:8000/Java/cfs40301.cab
OSD = C:\WINDOWS\Downloaded Program Files\ChatSpace Full Java Client 4.0.0.301.osd

[DirectAnimation Java Classes]
CODEBASE = file://C:\WINDOWS\Java\classes\dajava.cab
OSD = C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINDOWS\Java\classes\xmldso.cab
OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd

[Yahoo! Pool 2]
CODEBASE = http://download.games.yahoo.com/games/clients/y/potc_x.cab
OSD = C:\WINDOWS\Downloaded Program Files\Yahoo! Pool 2.osd

[Support.com Configuration Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\tgctlcm.dll
CODEBASE = http://support.cox.com/sdccommon/download/tgctlcm.cab

[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[MaxisHotDateTeleX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\MAXISH~1.OCX
CODEBASE = http://thesims.ea.com/teleport/hotdate/NPC…otDateTeleX.cab

[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab

[Cult3D ActiveX Player]
InProcServer32 = C:\WINDOWS\System32\Cult3D\IECult.dll
CODEBASE = http://www.cult3d.com/download/cult.cab

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB

[Snapfish File Upload ActiveX Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\SnapfishUpload1402.ocx
CODEBASE = http://www.snapfish.com/SnapfishUpload.cab

[{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}]
CODEBASE = http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab

[MaxisSuperstarTeleX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\MAXISS~1.OCX
CODEBASE = http://thesims.ea.com/teleport/superstar/M…erstarTeleX.cab

[Symantec RuFSI Utility Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab

[Java Plug-in 1.4.2_05]
InProcServer32 = C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
CODEBASE = http://java.sun.com/products/plugin/autodl…indows-i586.cab

[{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}]
CODEBASE = http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab

[Java Plug-in 1.4.1_02]
InProcServer32 = C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll
CODEBASE = http://java.sun.com/products/plugin/1.4/ji…indows-i586.cab

[Java Plug-in 1.4.2_05]
InProcServer32 = C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
CODEBASE = http://java.sun.com/products/plugin/autodl…indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\MACROMED\Flash\Flash.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shock…ash/swflash.cab

[Secure Delivery]
CODEBASE = http://www.gamespot.com/KDX/kdx.cab

[IWinAmpActiveX Class]
InProcServer32 = C:\Program Files\Common Files\Nullsoft\ActiveX\2.0\AmpX.dll
CODEBASE = http://cdn.digitalcity.com/_media/dalaillama/ampx.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll

————————————————–

Enumerating Windows NT/2000/XP services

abp480n5: \SystemRoot\System32\DRIVERS\ABP480N5.SYS (disabled)
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
adpu160m: \SystemRoot\System32\DRIVERS\adpu160m.sys (disabled)
aeaudio: system32\drivers\aeaudio.sys (manual start)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (system)
Intel AGP Bus Filter: \SystemRoot\System32\DRIVERS\agp440.sys (system)
Compaq AGP Bus Filter: \SystemRoot\System32\DRIVERS\agpCPQ.sys (disabled)
Aha154x: \SystemRoot\System32\DRIVERS\aha154x.sys (disabled)
aic78u2: \SystemRoot\System32\DRIVERS\aic78u2.sys (disabled)
aic78xx: \SystemRoot\System32\DRIVERS\aic78xx.sys (disabled)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AliIde: \SystemRoot\System32\DRIVERS\aliide.sys (disabled)
ALI AGP Bus Filter: \SystemRoot\System32\DRIVERS\alim1541.sys (disabled)
AMD AGP Bus Filter Driver: \SystemRoot\System32\DRIVERS\amdagp.sys (disabled)
amsint: \SystemRoot\System32\DRIVERS\amsint.sys (disabled)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
asc: \SystemRoot\System32\DRIVERS\asc.sys (disabled)
asc3350p: \SystemRoot\System32\DRIVERS\asc3350p.sys (disabled)
asc3550: \SystemRoot\System32\DRIVERS\asc3550.sys (disabled)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
AVG7 Alert Manager Server: C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (autostart)
AVG7 Kernel: \SystemRoot\System32\Drivers\avg7core.sys (system)
AVG7 Wrap Driver: \SystemRoot\System32\Drivers\avg7rsw.sys (system)
AVG7 Rezident Driver: \SystemRoot\System32\Drivers\avg7rsxp.sys (system)
AVG7 Update Service: C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (autostart)
AVG Network Redirector: \??\C:\WINDOWS\System32\Drivers\avgtdi.sys (autostart)
BCM V.92 56K Modem: System32\DRIVERS\BCMSM.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
cbidf: \SystemRoot\System32\DRIVERS\cbidf2k.sys (disabled)
cd20xrnt: \SystemRoot\System32\DRIVERS\cd20xrnt.sys (disabled)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (autostart)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
CmdIde: \SystemRoot\System32\DRIVERS\cmdide.sys (disabled)
COM+ System Application: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cpqarray: \SystemRoot\System32\DRIVERS\cpqarray.sys (disabled)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
d347bus: system32\DRIVERS\d347bus.sys (system)
d347prt: System32\Drivers\d347prt.sys (system)
dac2w2k: \SystemRoot\System32\DRIVERS\dac2w2k.sys (disabled)
dac960nt: \SystemRoot\System32\DRIVERS\dac960nt.sys (disabled)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
dpti2o: \SystemRoot\System32\DRIVERS\dpti2o.sys (disabled)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Intel® PRO Adapter Driver: System32\DRIVERS\e100b325.sys (manual start)
3Com EtherLink XL 90XB/C Adapter Driver: System32\DRIVERS\el90xbc5.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Fax: %systemroot%\system32\fxssvc.exe (autostart)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\drivers\fltmgr.sys (system)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
giveio: system32\giveio.sys (system)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
hpn: \SystemRoot\System32\DRIVERS\hpn.sys (disabled)
IEEE-1284.4 Driver HPZid412: system32\DRIVERS\HPZid412.sys (manual start)
Print Class Driver for IEEE-1284.4 HPZipr12: system32\DRIVERS\HPZipr12.sys (manual start)
USB to IEEE-1284.4 Translation Driver HPZius12: system32\DRIVERS\HPZius12.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i2omp: \SystemRoot\System32\DRIVERS\i2omp.sys (disabled)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
i81x: System32\DRIVERS\i81xnt5.sys (manual start)
iAimFP0: System32\DRIVERS\wADV01nt.sys (manual start)
iAimFP1: System32\DRIVERS\wADV02NT.sys (manual start)
iAimFP2: System32\DRIVERS\wADV05NT.sys (manual start)
iAimFP3: System32\DRIVERS\wSiINTxx.sys (manual start)
iAimFP4: System32\DRIVERS\wVchNTxx.sys (manual start)
iAimTV0: System32\DRIVERS\wATV01nt.sys (manual start)
iAimTV1: System32\DRIVERS\wATV02NT.sys (manual start)
iAimTV2: System32\DRIVERS\wATV03nt.sys (manual start)
iAimTV3: System32\DRIVERS\wATV04nt.sys (manual start)
iAimTV4: System32\DRIVERS\wCh7xxNT.sys (manual start)
Ipswitch WS_FTP Server: C:\iFtpSvc\iFtpSvc.exe (autostart)
CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\System32\imapi.exe (manual start)
ini910u: \SystemRoot\System32\DRIVERS\ini910u.sys (disabled)
IntelIde: \SystemRoot\System32\DRIVERS\intelide.sys (disabled)
Intel Processor Driver: System32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\drivers\ip6fw.sys (manual start)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
Messenger: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
Unimodem Streaming Filter Device: system32\drivers\MODEMCSA.sys (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
mraid35x: \SystemRoot\System32\DRIVERS\mraid35x.sys (disabled)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: System32\DRIVERS\mssmbios.sys (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Intel NCS NetService: C:\Program Files\Intel\NCS\Sync\NetSvc.exe (manual start)
Network Location Awareness (NLA): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: System32\DRIVERS\nv4_mini.sys (manual start)
NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
OMCI WDM Device Driver: System32\DRIVERS\omci.sys (system)
Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
Intel PentiumIII Processor Driver: System32\DRIVERS\p3.sys (system)
Parallel port driver: System32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
PCIIde: System32\DRIVERS\pciide.sys (system)
perc2: \SystemRoot\System32\DRIVERS\perc2.sys (disabled)
perc2hib: \SystemRoot\System32\DRIVERS\perc2hib.sys (disabled)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
Pml Driver HPZ12: C:\WINDOWS\system32\HPZipm12.exe (manual start)
IPSEC Services: %SystemRoot%\System32\lsass.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Processor Driver: System32\DRIVERS\processr.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: System32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\Drivers\PxHelp20.sys (system)
ql1080: \SystemRoot\System32\DRIVERS\ql1080.sys (disabled)
Ql10wnt: \SystemRoot\System32\DRIVERS\ql10wnt.sys (disabled)
ql12160: \SystemRoot\System32\DRIVERS\ql12160.sys (disabled)
ql1240: \SystemRoot\System32\DRIVERS\ql1240.sys (disabled)
ql1280: \SystemRoot\System32\DRIVERS\ql1280.sys (disabled)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: System32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: System32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SIS AGP Bus Filter: \SystemRoot\System32\DRIVERS\sisagp.sys (disabled)
smwdm: system32\drivers\smwdm.sys (manual start)
Sparrow: \SystemRoot\System32\DRIVERS\sparrow.sys (disabled)
speedfan: system32\speedfan.sys (system)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Filter Driver: \SystemRoot\System32\DRIVERS\sr.sys (disabled)
System Restore Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{F79A1568-D6C5-4C69-A086-936CF52DBBE3} (manual start)
symc810: \SystemRoot\System32\DRIVERS\symc810.sys (disabled)
symc8xx: \SystemRoot\System32\DRIVERS\symc8xx.sys (disabled)
sym_hi: \SystemRoot\System32\DRIVERS\sym_hi.sys (disabled)
sym_u3: \SystemRoot\System32\DRIVERS\sym_u3.sys (disabled)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: System32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TosIde: \SystemRoot\System32\DRIVERS\toside.sys (disabled)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
ultra: \SystemRoot\System32\DRIVERS\ultra.sys (disabled)
Windows User Mode Driver Framework: C:\WINDOWS\System32\wdfmgr.exe (autostart)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
Microsoft USB PRINTER Class: system32\DRIVERS\usbprint.sys (manual start)
USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
uscbs108: System32\DRIVERS\uscbs108.sys (manual start)
uscsc108: System32\DRIVERS\uscsc108.sys (manual start)
VGA Display Controller.: \SystemRoot\System32\drivers\vga.sys (system)
VIA AGP Bus Filter: \SystemRoot\System32\DRIVERS\viaagp.sys (disabled)
ViaIde: \SystemRoot\System32\DRIVERS\viaide.sys (disabled)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

End of report, 38,038 bytes
Report generated in 0.219 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Run Hijack This!

Click the "Open the Misc Tools section" button.

Click the "Open process manager" button.

Check the "Show DLLs" box (upper right).

Click on each item in the upper window, then look in the lower window.

Check to see which processes are using these DLL's:

C:\WINDOWS\Fonts\hardc.dll
C:\WINDOWS\Help\javadb.dll
C:\WINDOWS\Help\Tours\msdb.dll
C:\WINDOWS\Fonts\unkey.dll
C:\WINDOWS\system\utils.dll

Post back letting me know all processes using those DLL's.

Copy the text in the following quote box into Notepad:

dir C:\WINDOWS\Fonts\ /ah > files.txt
dir C:\WINDOWS\Fonts\ >> files.txt
dir C:\WINDOWS\Help\ /ah >> files.txt
dir C:\WINDOWS\Help\ >> files.txt
dir C:\WINDOWS\Help\Tours\ /ah >> files.txt
dir C:\WINDOWS\Help\Tours\ >> files.txt
dir C:\WINDOWS\system\ /ah >> files.txt
dir C:\WINDOWS\system\ >> files.txt
notepad files.txt


Save it to your desktop as ff.bat.

Close Notepad

Now, the ff.bat file on the desktop.

Wait for a Notepad window to open up.

Please paste it's contents into your next post.
:)
Ok, here are the results: hardc.dll C:\windows\system32\winlogon.exe C:\Windows\explorer.exe javadb.dll C:\windows\system32\winlogon.exe msdb.dll C:\windows\system32\winlogon.exe unkey.dll C:\windows\system32\winlogon.exe utils.dll C:\windows\system32\winlogon.exe ff.bat file: Volume in drive C has no label. Volume Serial Number is C0F9-BD73 Directory of C:\WINDOWS\Fonts 08/29/2002 05:00 AM 10,976 8514FIX.FON 08/29/2002 05:00 AM 10,976 8514FIXE.FON 08/29/2002 05:00 AM 11,520 8514FIXG.FON 08/29/2002 05:00 AM 10,976 8514FIXR.FON 08/29/2002 05:00 AM 11,488 8514FIXT.FON 08/29/2002 05:00 AM 12,288 8514OEM.FON 08/29/2002 05:00 AM 13,248 8514OEME.FON 08/29/2002 05:00 AM 12,800 8514OEMG.FON 08/29/2002 05:00 AM 13,200 8514OEMR.FON 08/29/2002 05:00 AM 12,720 8514OEMT.FON 08/29/2002 05:00 AM 9,280 8514SYS.FON 08/29/2002 05:00 AM 9,504 8514SYSE.FON 08/29/2002 05:00 AM 9,856 8514SYSG.FON 08/29/2002 05:00 AM 10,064 8514SYSR.FON 08/29/2002 05:00 AM 9,792 8514SYST.FON 08/29/2002 05:00 AM 12,304 85775.FON 08/29/2002 05:00 AM 12,256 85855.FON 08/29/2002 05:00 AM 10,976 85F1257.FON 08/29/2002 05:00 AM 9,472 85S1257.FON 08/29/2002 05:00 AM 35,808 APP775.FON 08/29/2002 05:00 AM 36,672 APP850.FON 08/29/2002 05:00 AM 36,656 APP852.FON 08/29/2002 05:00 AM 37,296 APP855.FON 08/29/2002 05:00 AM 36,672 APP857.FON 08/29/2002 05:00 AM 37,472 APP866.FON 10/14/2005 12:43 PM 348,587 cdrah.bak1 10/13/2005 12:43 PM 337,291 cdrah.bak2 09/14/2005 06:16 AM 181,326 cdrah.ini 10/15/2005 10:01 AM 352,155 cdrah.ini2 09/14/2005 06:16 AM 181,326 cdrah.tmp 08/29/2002 05:00 AM 7,216 CGA40737.FON 08/29/2002 05:00 AM 6,352 CGA40850.FON 08/29/2002 05:00 AM 6,672 CGA40852.FON 08/29/2002 05:00 AM 6,672 CGA40857.FON 08/29/2002 05:00 AM 7,232 CGA40866.FON 08/29/2002 05:00 AM 7,216 CGA40869.FON 08/29/2002 05:00 AM 5,168 CGA80737.FON 08/29/2002 05:00 AM 4,320 CGA80850.FON 08/29/2002 05:00 AM 5,200 CGA80852.FON 08/29/2002 05:00 AM 4,640 CGA80857.FON 08/29/2002 05:00 AM 5,168 CGA80866.FON 08/29/2002 05:00 AM 5,168 CGA80869.FON 08/29/2002 05:00 AM 23,440 COUE1257.FON 08/29/2002 05:00 AM 31,760 COUF1257.FON 08/29/2002 05:00 AM 23,440 COUREE.FON 08/29/2002 05:00 AM 25,024 COUREG.FON 08/29/2002 05:00 AM 23,440 COURER.FON 08/29/2002 05:00 AM 25,024 COURET.FON 08/29/2002 05:00 AM 31,776 COURFE.FON 08/29/2002 05:00 AM 33,344 COURFG.FON 08/29/2002 05:00 AM 31,808 COURFR.FON 08/29/2002 05:00 AM 33,360 COURFT.FON 09/03/2002 08:59 AM 67 DESKTOP.INI 08/29/2002 05:00 AM 36,336 DOS737.FON 08/29/2002 05:00 AM 36,656 DOSAPP.FON 08/29/2002 05:00 AM 9,248 EGA40737.FON 08/29/2002 05:00 AM 8,384 EGA40850.FON 08/29/2002 05:00 AM 8,368 EGA40852.FON 08/29/2002 05:00 AM 8,704 EGA40857.FON 08/29/2002 05:00 AM 9,232 EGA40866.FON 08/29/2002 05:00 AM 9,248 EGA40869.FON 08/29/2002 05:00 AM 6,192 EGA80737.FON 08/29/2002 05:00 AM 5,328 EGA80850.FON 08/29/2002 05:00 AM 5,344 EGA80852.FON 08/29/2002 05:00 AM 5,648 EGA80857.FON 08/29/2002 05:00 AM 5,280 EGA80866.FON 08/29/2002 05:00 AM 6,192 EGA80869.FON 09/06/2005 05:50 PM 516,116 hardc.dll 08/29/2002 05:00 AM 24,124 MARLETT.TTF 08/29/2002 05:00 AM 59,024 SERE1257.FON 08/29/2002 05:00 AM 84,080 SERF1257.FON 08/29/2002 05:00 AM 59,952 SERIFEE.FON 08/29/2002 05:00 AM 60,752 SERIFEG.FON 08/29/2002 05:00 AM 63,296 SERIFER.FON 08/29/2002 05:00 AM 61,024 SERIFET.FON 08/29/2002 05:00 AM 85,360 SERIFFE.FON 08/29/2002 05:00 AM 86,256 SERIFFG.FON 08/29/2002 05:00 AM 90,736 SERIFFR.FON 08/29/2002 05:00 AM 84,848 SERIFFT.FON 08/29/2002 05:00 AM 24,672 SMAE1257.FON 08/29/2002 05:00 AM 19,904 SMAF1257.FON 08/29/2002 05:00 AM 24,784 SMALLEE.FON 08/29/2002 05:00 AM 28,912 SMALLEG.FON 08/29/2002 05:00 AM 24,832 SMALLER.FON 08/29/2002 05:00 AM 29,200 SMALLET.FON 08/29/2002 05:00 AM 19,600 SMALLFE.FON 08/29/2002 05:00 AM 23,120 SMALLFG.FON 08/29/2002 05:00 AM 19,760 SMALLFR.FON 08/29/2002 05:00 AM 23,008 SMALLFT.FON 08/29/2002 05:00 AM 65,456 SSEE1257.FON 08/29/2002 05:00 AM 90,336 SSEF1257.FON 08/29/2002 05:00 AM 66,464 SSERIFEE.FON 08/29/2002 05:00 AM 65,328 SSERIFEG.FON 08/29/2002 05:00 AM 68,848 SSERIFER.FON 08/29/2002 05:00 AM 64,400 SSERIFET.FON 08/29/2002 05:00 AM 92,032 SSERIFFE.FON 08/29/2002 05:00 AM 90,288 SSERIFFG.FON 08/29/2002 05:00 AM 98,256 SSERIFFR.FON 08/29/2002 05:00 AM 89,456 SSERIFFT.FON 08/29/2002 05:00 AM 56,336 SYMBOLE.FON 09/05/2005 05:49 PM 516,116 unkey.dll 08/29/2002 05:00 AM 5,168 VGA737.FON 08/29/2002 05:00 AM 5,168 VGA775.FON 08/29/2002 05:00 AM 5,232 VGA850.FON 08/29/2002 05:00 AM 6,160 VGA852.FON 08/29/2002 05:00 AM 5,120 VGA855.FON 08/29/2002 05:00 AM 5,552 VGA857.FON 08/29/2002 05:00 AM 5,184 VGA860.FON 08/29/2002 05:00 AM 5,200 VGA863.FON 08/29/2002 05:00 AM 5,184 VGA865.FON 08/29/2002 05:00 AM 6,128 VGA866.FON 08/29/2002 05:00 AM 5,184 VGA869.FON 08/29/2002 05:00 AM 5,376 VGAF1257.FON 08/29/2002 05:00 AM 5,360 VGAFIX.FON 08/29/2002 05:00 AM 5,376 VGAFIXE.FON 08/29/2002 05:00 AM 6,112 VGAFIXG.FON 08/29/2002 05:00 AM 5,600 VGAFIXR.FON 08/29/2002 05:00 AM 6,112 VGAFIXT.FON 08/29/2002 05:00 AM 5,168 VGAOEM.FON 08/29/2002 05:00 AM 6,656 VGAS1257.FON 08/29/2002 05:00 AM 7,280 VGASYS.FON 08/29/2002 05:00 AM 6,608 VGASYSE.FON 08/29/2002 05:00 AM 7,008 VGASYSG.FON 08/29/2002 05:00 AM 6,912 VGASYSR.FON 08/29/2002 05:00 AM 6,912 VGASYST.FON 09/05/2005 05:49 PM 303 yeknu.ini 126 File(s) 5,365,363 bytes 0 Dir(s) 50,601,177,088 bytes free Volume in drive C has no label. Volume Serial Number is C0F9-BD73 Directory of C:\WINDOWS\Fonts 02/24/2004 05:56 PM 11,408 08 Underground.TTF 03/07/2003 05:08 AM 52,800 Alleg_Rg.ttf 07/28/1995 05:04 PM 69,796 ANGLOSAX.TTF 11/12/1998 09:18 AM 151,000 ANTQUAB.TTF 11/12/1998 09:18 AM 150,416 ANTQUABI.TTF 11/12/1998 09:18 AM 149,092 ANTQUAI.TTF 08/29/2002 05:00 AM 80,896 app932.fon 08/29/2002 05:00 AM 70,000 app936.fon 08/29/2002 05:00 AM 80,896 app949.fon 08/29/2002 05:00 AM 70,000 app950.fon 07/17/2004 01:39 PM 367,112 arial.ttf 07/17/2004 01:39 PM 352,224 arialbd.ttf 08/29/2002 05:00 AM 226,748 ARIALBI.TTF 08/29/2002 05:00 AM 207,808 ARIALI.TTF 11/12/1998 05:39 PM 134,200 ARIALN.TTF 11/12/1998 05:39 PM 139,128 ARIALNB.TTF 11/12/1998 05:39 PM 138,568 ARIALNBI.TTF 11/12/1998 05:39 PM 141,408 ARIALNI.TTF 11/18/2002 06:44 PM 23,275,812 ARIALUNI.TTF 08/29/2002 05:00 AM 117,028 ARIBLK.TTF 03/07/2003 05:08 AM 37,000 AVGARDD.TTF 03/07/2003 05:08 AM 37,976 AVGARDDO.TTF 03/07/2003 05:08 AM 37,432 AVGARDM.TTF 03/07/2003 05:08 AM 38,752 AVGARDMI.TTF 08/29/2002 05:00 AM 16,258,580 batang.ttc 03/07/2003 05:08 AM 49,004 BENGUIAB.TTF 03/07/2003 05:08 AM 48,360 BernFash.ttf 03/07/2003 05:08 AM 55,968 BernModB.ttf 03/07/2003 05:08 AM 54,496 BernModT.ttf 11/12/1998 09:18 AM 155,528 BKANT.TTF 03/02/1998 09:23 AM 154,720 BLACKADD.TTF 01/29/1992 05:46 PM 41,868 Blackcha.TTF 03/07/2003 05:08 AM 35,412 BNKGOTHM.TTF 11/04/1998 06:30 PM 160,940 BOOKOS.TTF 11/04/1998 06:30 PM 154,576 BOOKOSB.TTF 11/04/1998 06:30 PM 162,460 BOOKOSBI.TTF 08/18/1999 02:53 PM 161,020 BOOKOSI.TTF 03/07/2003 05:08 AM 44,356 BremenBd.ttf 12/12/2003 12:42 PM 54,412 BSSYM7.TTF 08/29/2002 05:00 AM 10,992 c8514fix.fon 08/29/2002 05:00 AM 13,552 c8514oem.fon 08/29/2002 05:00 AM 17,760 c8514sys.fon 11/12/2002 11:26 AM 165,248 CENTURY.TTF 08/29/2002 05:00 AM 6,336 cga40woa.fon 08/29/2002 05:00 AM 4,304 cga80woa.fon 03/07/2003 05:08 AM 56,924 CHRLWRTB.TTF 03/07/2003 05:08 AM 22,088 COMBULN.TTF 07/17/2004 01:39 PM 127,596 comic.ttf 08/29/2002 05:00 AM 111,476 COMICBD.TTF 03/07/2003 05:08 AM 45,440 COPGOTHB.TTF 08/29/2002 05:00 AM 303,296 COUR.TTF 08/29/2002 05:00 AM 312,920 COURBD.TTF 08/29/2002 05:00 AM 236,148 COURBI.TTF 08/29/2002 05:00 AM 23,408 coure.fon 08/29/2002 05:00 AM 31,712 courf.fon 08/29/2002 05:00 AM 245,032 COURI.TTF 08/29/2002 05:00 AM 5,600 cvgafix.fon 08/29/2002 05:00 AM 12,896 cvgasys.fon 03/07/2003 05:08 AM 43,792 DAUPHINN.TTF 08/29/2002 05:00 AM 8,368 ega40woa.fon 08/29/2002 05:00 AM 5,312 ega80woa.fon 03/07/2003 05:08 AM 62,316 Eng111Vi.ttf 08/29/2002 05:00 AM 79,744 ESTRE.TTF 05/29/2003 12:06 PM 29,424 Evanescence Font.ttf 10/14/1999 12:49 PM 8,312 Ezlabel.ttf 05/06/2004 11:18 PM Fonts 08/29/2002 05:00 AM 135,984 FRAMD.TTF 08/29/2002 05:00 AM 152,844 FRAMDIT.TTF 03/07/2003 05:08 AM 38,788 FutuBdIt.ttf 03/07/2003 05:08 AM 38,324 FutuBd__.ttf 03/07/2003 05:08 AM 32,976 FutuBl__.ttf 03/07/2003 05:08 AM 38,884 FutuEBl_.ttf 03/07/2003 05:08 AM 37,728 FutuLtIt.ttf 03/07/2003 05:08 AM 37,008 FutuLt__.ttf 11/10/1998 03:52 PM 196,616 GARA.TTF 11/10/1998 03:52 PM 198,604 GARABD.TTF 11/10/1998 03:52 PM 188,988 GARAIT.TTF 08/29/2002 05:00 AM 214,936 GAUTAMI.TTF 08/29/2002 05:00 AM 155,068 GEORGIA.TTF 08/29/2002 05:00 AM 141,032 GEORGIAB.TTF 08/29/2002 05:00 AM 157,388 GEORGIAI.TTF 08/29/2002 05:00 AM 159,736 GEORGIAZ.TTF 09/03/1999 08:58 AM 32,902 glastonb.TTF 09/03/1999 08:58 AM 63,416 GLAST_SW.TTF 09/03/1999 08:58 AM 70,324 GLAST__S.TTF 09/03/1999 08:58 AM 34,760 GLAST__W.TTF 11/12/1998 05:39 PM 137,568 GOTHIC.TTF 11/12/1998 05:39 PM 129,676 GOTHICB.TTF 11/12/1998 05:39 PM 139,084 GOTHICBI.TTF 11/12/1998 05:39 PM 148,520 GOTHICI.TTF 03/07/2003 05:08 AM 83,172 GoudyHan.ttf 03/07/2003 05:08 AM 60,644 GoudyOSB.ttf 03/07/2003 05:08 AM 57,428 GoudyOSI.ttf 03/07/2003 05:08 AM 58,628 GoudyOST.ttf 03/07/2003 05:08 AM 61,600 GoudyOS_.ttf 08/29/2002 05:00 AM 13,518,660 gulim.ttc 08/29/2002 05:00 AM 11,056 h8514fix.fon 08/29/2002 05:00 AM 12,400 h8514oem.fon 08/29/2002 05:00 AM 10,032 h8514sys.fon 07/28/1995 03:57 PM 62,776 HOGB.TTF 07/28/1995 06:16 PM 68,032 HOGK.TTF 03/07/2003 05:08 AM 36,688 Hum521Bd.ttf 03/07/2003 05:08 AM 37,248 Hum521BI.ttf 03/07/2003 05:08 AM 36,740 Hum521It.ttf 03/07/2003 05:08 AM 36,800 Hum521Rm.ttf 08/29/2002 05:00 AM 5,680 hvgafix.fon 08/29/2002 05:00 AM 6,512 hvgasys.fon 08/29/2002 05:00 AM 136,076 IMPACT.TTF 02/05/2005 04:22 PM 1,409 INK2CHOR.FOT 02/05/2005 04:22 PM 35,460 INK2CHOR.TTF 02/05/2005 04:22 PM 1,409 INK2SCRI.FOT 02/05/2005 04:22 PM 55,568 INK2SCRI.TTF 02/05/2005 04:22 PM 1,409 INK2SPEC.FOT 02/05/2005 04:22 PM 58,276 INK2SPEC.TTF 02/05/2005 04:22 PM 1,409 INK2TEXT.FOT 02/05/2005 04:22 PM 19,804 INK2TEXT.TTF 02/05/2005 04:22 PM 1,409 INKPEN2_.FOT 02/05/2005 04:22 PM 19,632 INKPEN2_.TTF 08/29/2002 05:00 AM 12,896 j8514fix.fon 08/29/2002 05:00 AM 14,432 j8514oem.fon 08/29/2002 05:00 AM 10,656 j8514sys.fon 07/29/1995 04:28 PM 51,728 JOTM.TTF 08/29/2002 05:00 AM 41,584 jsmalle.fon 08/29/2002 05:00 AM 38,480 jsmallf.fon 08/08/1993 09:05 AM 45,310 JUDAS.TTF 08/29/2002 05:00 AM 6,528 jvgafix.fon 08/29/2002 05:00 AM 7,728 jvgasys.fon 03/07/2003 05:08 AM 37,956 KABELN.TTF 03/07/2003 05:08 AM 40,632 KABELU.TTF 07/17/2004 01:39 PM 121,452 kartika.ttf 05/21/1996 12:04 PM 28,700 KINGARTH.TTF 03/30/1998 10:50 PM 47,032 KINGDOM.TTF 06/15/2004 05:22 PM 36,684 kingdomhearts.ttf 08/29/2002 05:00 AM 73,292 LATHA.TTF 03/07/2003 05:08 AM 49,152 LITHOGRB.TTF 03/07/2003 05:08 AM 61,484 LITHOGRL.TTF 08/29/2002 05:00 AM 115,068 LUCON.TTF 08/29/2002 05:00 AM 323,980 L_10646.TTF 10/06/1992 04:25 PM 12,812 MAGDELEN.TTF 08/29/2002 05:00 AM 143,864 MANGAL.TTF 07/28/1995 06:46 PM 36,916 MARITAM.TTF 07/28/1995 07:43 PM 53,352 MARITAS.TTF 10/10/2005 04:54 PM 189 mcrh.tmp 07/18/2004 12:54 AM 460,728 micross.ttf 08/29/2002 05:00 AM 8,823,308 mingliu.ttc 04/01/1999 03:41 PM 16,716 MISFIT.TTF 08/29/2002 05:00 AM 8,704 MODERN.FON 08/29/2002 05:00 AM 8,272,028 msgothic.ttc 08/29/2002 05:00 AM 9,135,960 msmincho.ttc 11/10/1998 03:52 PM 157,360 MTCORSVA.TTF 03/07/2003 05:08 AM 7,672 MTEXTRA.TTF 08/29/2002 05:00 AM 40,500 MVBOLI.TTF 02/05/2005 04:22 PM 1,409 OPUSC___.FOT 02/05/2005 04:22 PM 29,700 OPUSC___.TTF 02/05/2005 04:22 PM 1,409 OPUSPC__.FOT 02/05/2005 04:22 PM 27,084 OPUSPC__.TTF 02/05/2005 04:22 PM 1,409 OPUSP___.FOT 02/05/2005 04:22 PM 33,748 OPUSP___.TTF 02/05/2005 04:22 PM 1,409 OPUSS___.FOT 02/05/2005 04:22 PM 42,072 OPUSS___.TTF 02/05/2005 04:22 PM 1,409 OPUSTEXT.FOT 02/05/2005 04:22 PM 16,620 OPUSTEXT.TTF 02/05/2005 04:22 PM 1,409 OPUS____.FOT 02/05/2005 04:22 PM 18,780 OPUS____.TTF 04/08/2003 02:41 PM 17,672 OUTLOOK.TTF 03/07/2003 05:08 AM 50,668 OzHandRm.ttf 08/29/2002 05:00 AM 489,884 PALA.TTF 08/29/2002 05:00 AM 434,004 PALAB.TTF 08/29/2002 05:00 AM 344,288 PALABI.TTF 08/29/2002 05:00 AM 430,800 PALAI.TTF 02/05/1997 08:31 AM 52,720 priory.TTF 03/07/2003 05:08 AM 46,492 PSTRBODN.TTF 08/29/2002 05:00 AM 57,348 RAAVI.TTF 05/06/1999 12:59 PM 220,172 REFSAN.TTF 09/03/1998 04:14 PM 53,288 REFSPCL.TTF 05/28/2000 12:15 PM 7,216 RM2000.fon 05/29/2000 11:28 AM 7,312 RMG2000.fon 08/29/2002 05:00 AM 13,312 ROMAN.FON 08/29/2002 05:00 AM 11,056 s8514fix.fon 08/29/2002 05:00 AM 12,384 s8514oem.fon 08/29/2002 05:00 AM 17,760 s8514sys.fon 08/29/2002 05:00 AM 12,288 SCRIPT.FON 03/07/2003 05:08 AM 39,640 SerifBd_.ttf 08/29/2002 05:00 AM 57,936 serife.fon 08/29/2002 05:00 AM 81,728 seriff.fon 03/07/2003 05:08 AM 40,248 SerifIt_.ttf 03/07/2003 05:08 AM 39,468 SerifRm_.ttf 03/07/2003 05:08 AM 38,168 SerifTh_.ttf 03/11/1999 12:38 PM 78,892 SHOWCARD.TTF 08/29/2002 05:00 AM 234,280 SHRUTI.TTF 08/29/2002 05:00 AM 10,044,356 simhei.ttf 08/29/2002 05:00 AM 10,500,792 simsun.ttc 08/29/2002 05:00 AM 26,112 smalle.fon 08/29/2002 05:00 AM 21,504 smallf.fon 03/07/2003 05:08 AM 52,672 SOUVNRDI.TTF 03/07/2003 05:08 AM 54,420 SOUVNRL.TTF 03/07/2003 05:08 AM 55,000 SOUVNRLI.TTF 08/29/2002 05:00 AM 64,656 sserife.fon 08/29/2002 05:00 AM 89,856 sseriff.fon 03/07/2003 05:08 AM 119,532 Stacc222.ttf 08/29/2002 05:00 AM 5,680 svgafix.fon 08/29/2002 05:00 AM 12,896 svgasys.fon 03/07/2003 05:08 AM 38,380 Sw911ExC.ttf 08/29/2002 05:00 AM 221,676 SYLFAEN.TTF 08/29/2002 05:00 AM 69,464 SYMBOL.TTF 07/18/2004 12:54 AM 383,140 tahoma.ttf 07/18/2004 12:54 AM 355,436 tahomabd.ttf 07/17/2004 01:39 PM 409,280 times.ttf 07/17/2004 01:39 PM 398,372 timesbd.ttf 08/29/2002 05:00 AM 239,692 TIMESBI.TTF 08/29/2002 05:00 AM 248,368 TIMESI.TTF 08/29/2002 05:00 AM 134,108 TREBUC.TTF 08/29/2002 05:00 AM 123,096 TREBUCBD.TTF 08/29/2002 05:00 AM 131,188 TREBUCBI.TTF 08/29/2002 05:00 AM 139,288 TREBUCIT.TTF 07/28/1995 08:47 PM 75,412 TROTSLT.TTF 07/28/1995 09:15 PM 76,208 TROTSMED.TTF 07/17/1993 04:00 AM 67,988 TT0107M_.TTF 07/17/1993 04:00 AM 58,984 TT0108M_.TTF 07/17/1993 04:00 AM 63,156 TT0109M_.TTF 07/17/1993 04:00 AM 61,204 TT0110M_.TTF 07/17/1993 04:00 AM 51,236 TT0129M_.TTF 07/17/1993 04:00 AM 49,788 TT0130M_.TTF 07/17/1993 04:00 AM 38,764 TT0142M_.TTF 07/17/1993 04:00 AM 39,172 TT0143M_.TTF 07/17/1993 04:00 AM 40,028 TT0148M_.TTF 07/17/1993 04:00 AM 40,468 TT0149M_.TTF 07/17/1993 04:00 AM 36,336 TT0201M_.TTF 07/17/1993 04:00 AM 41,036 TT0204M_.TTF 07/17/1993 04:00 AM 41,644 TT0205M_.TTF 07/17/1993 04:00 AM 53,000 TT0328M_.TTF 07/17/1993 04:00 AM 53,416 TT0329M_.TTF 07/17/1993 04:00 AM 53,528 TT0330M_.TTF 07/17/1993 04:00 AM 50,588 TT0331M_.TTF 07/17/1993 04:00 AM 51,728 TT0362M_.TTF 07/17/1993 04:00 AM 74,592 TT0581M_.TTF 07/17/1993 04:00 AM 60,680 TT0604M_.TTF 07/17/1993 04:00 AM 126,680 TT0610M_.TTF 07/17/1993 04:00 AM 58,344 TT0729M_.TTF 07/17/1993 04:00 AM 64,196 TT0976M_.TTF 07/17/1993 04:00 AM 63,728 TT0990M_.TTF 07/17/1993 04:00 AM 64,488 TT1040M_.TTF 07/17/1993 04:00 AM 60,904 TT1043M_.TTF 07/17/1993 04:00 AM 51,084 TT1046M_.TTF 07/17/1993 04:00 AM 48,616 TT1051M_.TTF 07/17/1993 04:00 AM 47,344 TT1064M_.TTF 07/17/1993 04:00 AM 51,320 TT1154M_.TTF 07/17/1993 04:00 AM 52,020 TT1178M_.TTF 07/17/1993 04:00 AM 51,364 TT1221M_.TTF 06/21/1994 04:10 AM 36,856 TT3004M_.TTF 08/29/2002 05:00 AM 148,636 TUNGA.TTF 03/07/2003 05:08 AM 56,780 TypoUpri.ttf 08/29/2002 05:00 AM 171,792 VERDANA.TTF 08/29/2002 05:00 AM 137,616 VERDANAB.TTF 08/29/2002 05:00 AM 155,076 VERDANAI.TTF 08/29/2002 05:00 AM 154,800 VERDANAZ.TTF 08/29/2002 05:00 AM 7,232 vga932.fon 08/29/2002 05:00 AM 6,272 vga936.fon 08/29/2002 05:00 AM 6,304 vga949.fon 08/29/2002 05:00 AM 6,272 vga950.fon 08/06/1996 12:00 AM 99,556 vineritc.TTF 07/17/2004 01:39 PM 252,820 vrinda.ttf 08/29/2002 05:00 AM 118,752 WEBDINGS.TTF 08/29/2002 05:00 AM 81,000 WINGDING.TTF 01/22/2002 05:22 PM 65,788 WINGDNG2.TTF 01/22/2002 05:22 PM 35,328 WINGDNG3.TTF 03/07/2003 05:08 AM 33,272 Wpce08n_.ttf 03/07/2003 05:08 AM 58,224 Wpco01na.ttf 03/07/2003 05:08 AM 13,960 WPCO01NB.TTF 03/07/2003 05:08 AM 20,376 Wpco03n_.ttf 03/07/2003 05:08 AM 29,412 Wpco08n_.ttf 03/07/2003 05:08 AM 32,180 Wpdv09n_.ttf 03/07/2003 05:08 AM 50,780 WPHV01NA.TTF 03/07/2003 05:08 AM 6,332 Wphv01nb.ttf 03/07/2003 05:08 AM 28,392 Wphv02n_.ttf 03/07/2003 05:08 AM 29,092 Wphv04n_.ttf 03/07/2003 05:08 AM 71,392 Wphv05na.ttf 03/07/2003 05:08 AM 9,408 Wphv05nb.ttf 03/07/2003 05:08 AM 52,140 Wphv06na.ttf 03/07/2003 05:08 AM 5,556 Wphv06nb.ttf 03/07/2003 05:08 AM 36,196 Wphv07na.ttf 03/07/2003 05:08 AM 2,920 Wphv07nb.ttf 03/07/2003 05:08 AM 28,236 Wphv08n_.ttf 03/07/2003 05:08 AM 20,028 Wphv11n_.ttf 03/07/2003 05:08 AM 66,388 WPRO01NA.TTF 03/07/2003 05:08 AM 8,084 WPRO01NB.TTF 03/07/2003 05:08 AM 63,408 Wpro10na.ttf 03/07/2003 05:08 AM 15,400 Wpro10nb.ttf 03/07/2003 05:08 AM 57,644 WPSI13N_.TTF 03/07/2003 05:08 AM 69,756 WPSI14N_.TTF 08/29/2002 05:00 AM 18,880 WST_CZEC.FON 08/29/2002 05:00 AM 18,880 WST_ENGL.FON 08/29/2002 05:00 AM 18,880 WST_FREN.FON 08/29/2002 05:00 AM 18,880 WST_GERM.FON 08/29/2002 05:00 AM 18,880 WST_ITAL.FON 08/29/2002 05:00 AM 18,880 WST_SPAN.FON 08/29/2002 05:00 AM 18,880 WST_SWED.FON 03/07/2003 05:08 AM 61,432 ZapE711B.ttf 03/07/2003 05:08 AM 59,592 ZapE711I.ttf 03/07/2003 05:08 AM 59,192 ZapE711R.ttf 03/07/2003 05:08 AM 60,732 ZapE711t.ttf 03/07/2003 05:08 AM 37,016 ZuricExt.ttf 301 File(s) 122,914,260 bytes 1 Dir(s) 50,601,160,704 bytes free Volume in drive C has no label. Volume Serial Number is C0F9-BD73 Directory of C:\WINDOWS\Help 09/05/2005 05:48 PM 179,801 bdavaj.bak1 09/06/2005 05:48 PM 182,924 bdavaj.bak2 09/06/2005 07:01 PM 181,325 bdavaj.ini 08/30/2005 05:48 PM 516,116 javadb.dll 02/28/2004 09:33 AM 10,820 update.GID 5 File(s) 1,070,986 bytes 0 Dir(s) 50,601,160,704 bytes free Volume in drive C has no label. Volume Serial Number is C0F9-BD73 Directory of C:\WINDOWS\Help 10/04/2005 11:25 PM . 10/04/2005 11:25 PM .. 08/29/2002 05:00 AM 35,919 ACCESS.CHM 08/29/2002 05:00 AM 34,032 ACCESS.HLP 08/29/2002 05:00 AM 20,704 ACCESSIB.CHM 08/29/2002 05:00 AM 20,284 ACC_DIS.CHM 08/29/2002 05:00 AM 16,669 ACLUI.HLP 08/29/2002 05:00 AM 15,481 ADDREMOV.CHM 08/29/2002 05:00 AM 27,532 ADE.HLP 08/29/2002 05:00 AM 33,360 ADMTOOLS.CHM 08/29/2002 05:00 AM 105,608 ADPROP.HLP 08/29/2002 05:00 AM 8,669 agt0404.hlp 08/29/2002 05:00 AM 8,975 AGT0405.HLP 08/29/2002 05:00 AM 8,783 AGT0406.HLP 08/29/2002 05:00 AM 8,856 AGT0407.HLP 08/29/2002 05:00 AM 9,001 AGT0408.HLP 08/29/2002 05:00 AM 8,648 AGT0409.HLP 08/29/2002 05:00 AM 8,662 AGT040B.HLP 08/29/2002 05:00 AM 8,882 AGT040C.HLP 08/29/2002 05:00 AM 8,987 AGT040E.HLP 08/29/2002 05:00 AM 8,746 AGT0410.HLP 08/29/2002 05:00 AM 8,524 agt0411.hlp 08/29/2002 05:00 AM 9,188 agt0412.hlp 08/29/2002 05:00 AM 9,309 AGT0413.HLP 08/29/2002 05:00 AM 8,654 AGT0414.HLP 08/29/2002 05:00 AM 8,917 AGT0415.HLP 08/29/2002 05:00 AM 8,758 AGT0416.HLP 08/29/2002 05:00 AM 8,799 AGT0419.HLP 08/29/2002 05:00 AM 9,251 AGT041D.HLP 08/29/2002 05:00 AM 9,041 AGT041F.HLP 08/29/2002 05:00 AM 8,226 agt0804.hlp 08/29/2002 05:00 AM 8,799 AGT0816.HLP 08/29/2002 05:00 AM 8,830 AGT0C0A.HLP 10/23/1997 12:40 PM 16,005 amovie.chm 08/25/1997 01:34 PM 9,394 amovie.hlp 08/04/2004 03:02 AM 79,996 apps.chm 08/04/2004 03:02 AM 299,152 apps_sp.chm 08/29/2002 05:00 AM 2,698,341 ARTICLE.CHM 07/17/2004 01:40 PM 22,219 atm.chm 08/29/2002 05:00 AM 11,445 AUDIOCDC.HLP 08/29/2002 05:00 AM 35,135 BCKG.CHM 08/29/2002 05:00 AM 19,007 BLURBS.CHM 07/17/2004 01:43 PM 50,059 blutooth.chm 08/29/2002 05:00 AM 152,576 BNTS.DLL 08/29/2002 05:00 AM 39,622 BOOTCONS.CHM 08/29/2002 05:00 AM 18,991 BRIEF.CHM 08/29/2002 05:00 AM 24,551 CALC.CHM 08/29/2002 05:00 AM 32,195 CALC.HLP 08/29/2002 05:00 AM 21,924 CAMERA.CHM 08/29/2002 05:00 AM 31,178 CAMERA.HLP 08/29/2002 05:00 AM 20,544 CDMEDIA.CHM 08/29/2002 05:00 AM 11,627 CDMEDIA.HLP 08/29/2002 05:00 AM 14,103 CERTMGR.CHM 08/29/2002 05:00 AM 26,345 CERTMGR.HLP 08/29/2002 05:00 AM 21,704 CHARMAP.CHM 08/29/2002 05:00 AM 12,961 CHARMAP.HLP 08/29/2002 05:00 AM 27,978 CHKR.CHM 08/29/2002 05:00 AM 11,797 CHNSCSVR.HLP 08/29/2002 05:00 AM 11,288 CHOOSER.HLP 08/29/2002 05:00 AM 315 CIADMIN.HTM 08/29/2002 05:00 AM 21,352 CIQUERY.HTM 08/29/2002 05:00 AM 25,129 CLIPBRD.CHM 08/29/2002 05:00 AM 45,445 CLIPBRD.HLP 08/29/2002 05:00 AM 66,669 cmconcepts.chm 08/29/2002 05:00 AM 20,549 COLORMGT.CHM 07/17/2004 01:33 PM 269,916 comexp.chm 08/29/2002 05:00 AM 47,768 COMEXP.HLP 08/29/2002 05:00 AM 17,081 COMMON.CHM 08/29/2002 05:00 AM 17,080 COMPFLDR.CHM 08/29/2002 05:00 AM 19,921 COMPMGMT.CHM 08/29/2002 05:00 AM 18,134 COMPSTUI.HLP 08/29/2002 05:00 AM 91,007 CONF.CHM 08/29/2002 05:00 AM 106 CONF.CNT 08/29/2002 05:00 AM 30,848 CONF.HLP 08/29/2002 05:00 AM 129 CONNECT.CNT 08/29/2002 05:00 AM 57,305 CONNECT.HLP 11/11/2003 04:46 PM 20,480 corelts.FTS 08/29/2002 05:00 AM 19,691 CPANEL.CHM 07/18/2004 12:54 AM 364,966 cpanel.chq 08/29/2002 05:00 AM 14,504 CSCUI.HLP 08/29/2002 05:00 AM 10,483 CYYCOINS.CHM 08/29/2002 05:00 AM 10,743 CYZCOINS.CHM 07/17/2004 01:40 PM 18,855 datetime.chm 08/29/2002 05:00 AM 18,629 DDESHARE.CHM 08/29/2002 05:00 AM 33,495 DDESHARE.HLP 08/29/2002 05:00 AM 13,041 DEFRAG.CHM 08/29/2002 05:00 AM 12,550 DEFRAG.HLP 08/29/2002 05:00 AM 53,709 DEVMGR.CHM 08/29/2002 05:00 AM 63,440 DEVMGR.HLP 08/29/2002 05:00 AM 29,366 DFS.HLP 08/29/2002 05:00 AM 29,762 DIAGBOOT.CHM 08/29/2002 05:00 AM 39,969 DIALER.CHM 08/29/2002 05:00 AM 30,693 DIALER.HLP 08/29/2002 05:00 AM 73,882 DIGIRAS.CHM 08/29/2002 05:00 AM 20,460 DIJOY.HLP 08/29/2002 05:00 AM 66,896 DISKMGMT.CHM 08/29/2002 05:00 AM 30,063 DISKMGMT.HLP 08/29/2002 05:00 AM 46,073 DISPLAY.CHM 08/29/2002 05:00 AM 51,408 DISPLAY.HLP 08/29/2002 05:00 AM 34,296 dkconcepts.chm 08/29/2002 05:00 AM 12,817 DRVVFP.CHM 08/29/2002 05:00 AM 20,406 DRWTSN32.CHM 08/29/2002 05:00 AM 14,161 DRWTSN32.HLP 08/29/2002 05:00 AM 20,220 DSCLIENT.HLP 07/17/2004 01:40 PM 54,004 dskquoui.chm 08/29/2002 05:00 AM 17,396 DSKQUOUI.HLP 06/28/2004 09:02 AM 24,759 dxdiag.chm 08/29/2002 05:00 AM 14,805 ELS.CHM 08/29/2002 05:00 AM 37,251 ELS.HLP 10/04/2005 11:25 PM 41,472 eqnedt32.FTS 08/29/2002 05:00 AM 23,754 EUDCEDIT.CHM 08/29/2002 05:00 AM 18,509 EUDCEDIT.HLP 07/17/2004 01:40 PM 64,768 evconcepts.chm 08/29/2002 05:00 AM 22,988 EVNTWIN.HLP 07/17/2004 01:40 PM 77,511 filefold.chm 08/29/2002 05:00 AM 24,479 FILEFOLD.HLP 08/29/2002 05:00 AM 32,107 FILEMGMT.HLP 07/17/2004 01:40 PM 48,494 file_srv.chm 08/29/2002 05:00 AM 29,132 FIND.CHM 08/29/2002 05:00 AM 26,022 FOLDEROP.CHM 08/29/2002 05:00 AM 17,250 FONTS.CHM 08/29/2002 05:00 AM 18,931 FONTS.HLP 08/29/2002 05:00 AM 15,803 FREECELL.CHM 08/29/2002 05:00 AM 12,457 FREECELL.HLP 08/29/2002 05:00 AM 139,118 FXSCLNT.CHM 08/29/2002 05:00 AM 27,091 FXSCLNT.HLP 08/29/2002 05:00 AM 27,066 FXSCOVER.CHM 08/29/2002 05:00 AM 32,657 FXSSHARE.CHM 08/29/2002 05:00 AM 136,501 Glossary.chm 08/29/2002 05:00 AM 25,153 HALFTONE.HLP 07/17/2004 01:40 PM 32,171 hardware.chm 07/17/2004 01:40 PM 15,071 hardware.hlp 07/17/2004 01:40 PM 42,999 howto.chm 04/18/2004 08:51 PM 101,376 hpprsclt.FTS 04/18/2004 08:51 PM 90,624 hpscanjt.FTS 08/29/2002 05:00 AM 30,260 HRTZ.CHM 08/29/2002 05:00 AM 20,077 HS.CHM 07/17/2004 01:40 PM 29,607 hschelp.chm 08/29/2002 05:00 AM 35,983 HYPERTRM.CHM 08/29/2002 05:00 AM 25,153 HYPERTRM.HLP 08/29/2002 05:00 AM 29,876 ICWDIAL.CHM 08/29/2002 05:00 AM 12,701 IDENT.HLP 08/29/2002 05:00 AM 12,761 IEEULA.CHM 08/29/2002 05:00 AM 12,013 IEOS.CHM 08/29/2002 05:00 AM 35,774 IESHARED.CHM 08/29/2002 05:00 AM 21,919 IESUPP.CHM 08/29/2002 05:00 AM 21,551 IEWEBHLP.CHM 07/17/2004 01:40 PM 204,810 iexplore.chm 08/29/2002 05:00 AM 180,335 IEXPLORE.HLP 08/29/2002 05:00 AM 30,369 IMGPREV.CHM 07/17/2004 01:40 PM 81,568 infrared.chm 08/29/2002 05:00 AM 13,943 INFRARED.HLP 07/17/2004 01:40 PM 34,703 input.chm 07/17/2004 01:40 PM 24,285 input.hlp 07/17/2004 01:40 PM 216,693 ipsecconcepts.chm 08/29/2002 05:00 AM 18,806 IPSECSNP.CHM 08/29/2002 05:00 AM 84,292 IPSECSNP.HLP 07/17/2004 01:40 PM 154,065 ipv6.chm 08/29/2002 05:00 AM 15,432 IS.CHM 08/29/2002 05:00 AM 109,258 isconcepts.chm 08/29/2002 05:00 AM 16,062 IXHELP.HLP 08/29/2002 05:00 AM 2,323 IXQLANG.HTM 08/24/2003 12:45 PM 11,403 JAVAPERM.HLP 08/24/2003 12:45 PM 21,444 JAVASEC.HLP 08/29/2002 05:00 AM 18,949 JOY.CHM 08/29/2002 05:00 AM 16,494 KEYB.CHM 08/29/2002 05:00 AM 17,762 KEYSHORT.CHM 08/29/2002 05:00 AM 20,585 LANG.CHM 07/17/2004 01:40 PM 78,519 langbar.chm 07/17/2004 01:40 PM 32,564 license.chm 08/29/2002 05:00 AM 19,677 MAGNIFY.CHM 08/29/2002 05:00 AM 12,115 MAGNIFY.HLP 08/29/2002 05:00 AM 121,327 MAIL.CHM 08/29/2002 05:00 AM 23,439 MFCUIX.HLP 08/29/2002 05:00 AM 2,575 MIGWIZ.HTM 08/29/2002 05:00 AM 1,644 MIGWIZ2.HTM 07/17/2004 01:40 PM 66,838 misc.chm 08/29/2002 05:00 AM 17,135 MLS_TRB.CHM 08/29/2002 05:00 AM 151,662 MMC.CHM 08/29/2002 05:00 AM 37,298 MMC_DLG.HLP 08/29/2002 05:00 AM 18,920 MOBSYNC.CHM 08/29/2002 05:00 AM 16,149 MOBSYNC.HLP 07/17/2004 01:40 PM 56,768 mode.chm 08/29/2002 05:00 AM 20,366 MODEM.HLP 08/29/2002 05:00 AM 20,877 MOUSE.CHM 08/29/2002 05:00 AM 15,998 MOUSE.HLP 08/29/2002 05:00 AM 161,429 mpconcepts.chm 08/29/2002 05:00 AM 1,885 MPLAYER2.CNT 08/29/2002 05:00 AM 97,117 MPLAYER2.HLP 08/29/2002 05:00 AM 11,187 MPNETWRK.HLP 08/29/2002 05:00 AM 17,240 MSCONFIG.CHM 08/29/2002 05:00 AM 15,723 MSDASC.CHM 08/29/2002 05:00 AM 15,051 MSHEARTS.CHM 08/29/2002 05:00 AM 227 MSHEARTS.CNT 08/29/2002 05:00 AM 11,211 MSHEARTS.HLP 07/17/2004 01:40 PM 44,271 msinfo32.chm 09/18/2005 11:47 PM 508,928 msmapp.FTS 08/29/2002 05:00 AM 173 MSNAUTH.CNT 08/29/2002 05:00 AM 10,556 MSNAUTH.HLP 07/17/2004 01:39 PM 253,201 msoe.chm 08/29/2002 05:00 AM 117,006 MSOE.HLP 08/29/2002 05:00 AM 35,240 MSOEACCT.HLP 08/29/2002 05:00 AM 15,245 MSORCL32.CHM 08/29/2002 05:00 AM 45,590 MSPAINT.CHM 09/15/2005 06:49 PM 39,763 mspaint.chw 08/29/2002 05:00 AM 19,181 MSPAINT.HLP 07/17/2004 01:40 PM 37,318 mstask.chm 08/29/2002 05:00 AM 28,371 MSTASK.HLP 07/17/2004 01:40 PM 67,569 mstsc.chm 09/28/2005 01:13 AM 332,288 Multisim.FTS 07/17/2004 01:40 PM 528,110 netcfg.chm 08/29/2002 05:00 AM 281,595 NETCFG.HLP 07/17/2004 01:40 PM 101,275 network.chm 08/29/2002 05:00 AM 25,517 NEWFEAT1.CHM 08/29/2002 05:00 AM 16,162 NEWFEAT1.HLP 08/29/2002 05:00 AM 11,047 NEWFEAT2.CHM 08/29/2002 05:00 AM 4,536 NEWFEAT2.HLP 08/29/2002 05:00 AM 11,047 NEWFEAT3.CHM 08/29/2002 05:00 AM 4,536 NEWFEAT3.HLP 08/29/2002 05:00 AM 11,047 NEWFEAT4.CHM 08/29/2002 05:00 AM 4,536 NEWFEAT4.HLP 08/29/2002 05:00 AM 11,047 NEWFEAT5.CHM 08/29/2002 05:00 AM 4,536 NEWFEAT5.HLP 08/29/2002 05:00 AM 11,563 NMCHAT.CHM 08/29/2002 05:00 AM 22,553 NMWHITEB.CHM 08/29/2002 05:00 AM 84 NOCONTNT.CNT 08/29/2002 05:00 AM 11,562 NOFTS.CHM 08/29/2002 05:00 AM 25,236 NOTEPAD.CHM 08/29/2002 05:00 AM 12,521 NOTEPAD.HLP 08/29/2002 05:00 AM 1,215,489 NTART.CHM 07/17/2004 01:40 PM 20,257 ntchowto.chm 08/29/2002 05:00 AM 430,941 NTCMDS.CHM 07/17/2004 01:40 PM 81,926 ntdef.chm 08/29/2002 05:00 AM 20,427 NTHELP.CHM 08/29/2002 05:00 AM 306,870 NTSHARED.CHM 08/29/2002 05:00 AM 12,760 NTSHRUI.HLP 07/17/2004 01:40 PM 271,335 nusrmgr.chm 08/02/2005 04:35 PM 168,844 nvcpl.hlp 08/02/2005 04:35 PM 55,444 nvwcplen.hlp 08/29/2002 05:00 AM 15,256 NWDOC.CHM 08/29/2002 05:00 AM 26,845 OBJSEL.HLP 08/29/2002 05:00 AM 16,119 ODBCINST.CHM 08/29/2002 05:00 AM 34,381 ODBCJET.CHM 08/29/2002 05:00 AM 28,305 OE_MSGR.CHM 08/29/2002 05:00 AM 28,344 OMC.CHM 08/29/2002 05:00 AM 19,605 OSK.CHM 08/29/2002 05:00 AM 12,387 OSK.HLP 08/29/2002 05:00 AM 20,067 PACKAGER.CHM 07/17/2004 01:40 PM 20,189 password.chm 11/11/2003 04:46 PM 34,304 pfit11en.FTS 11/29/2004 09:45 PM 33,280 pfod11en.FTS 08/29/2002 05:00 AM 17,269 PHOWTO.CHM 08/29/2002 05:00 AM 39,590 PINBALL.CHM 09/09/2003 03:42 PM 26,635 pinball.chw 08/29/2002 05:00 AM 22,398 PINBALL.HLP 08/29/2002 05:00 AM 73,572 PINTLPAD.CHM 08/29/2002 05:00 AM 56,563 PINTLPAE.CHM 07/17/2004 01:45 PM 77,307 plyr_err.chm 07/17/2004 01:40 PM 97,317 printing.chm 01/15/2005 11:55 PM 70,538 printing.chw 08/29/2002 05:00 AM 695 PROGMAN.CNT 08/29/2002 05:00 AM 25,771 PROGMAN.HLP 03/28/2004 03:05 PM 557,568 Psp.FTS 08/29/2002 05:00 AM 31,663 PWRMN.CHM 08/29/2002 05:00 AM 44,213 PWRMN.HLP 08/29/2002 05:00 AM 12,752 qosconcepts.chm 11/11/2003 04:46 PM 567,296 qp11en.FTS 11/11/2003 04:46 PM 478,720 qp11fnen.FTS 08/29/2002 05:00 AM 19,598 RATINGS.CHM 08/29/2002 05:00 AM 294 RATINGS.CNT 08/29/2002 05:00 AM 27,225 RATINGS.HLP 08/29/2002 05:00 AM 22,853 READER.CHM 08/29/2002 05:00 AM 11,953 READER.HLP 08/29/2002 05:00 AM 19,107 RECYCLE.CHM 08/29/2002 05:00 AM 46,684 REGEDIT.CHM 02/07/2005 04:06 AM 38,468 regedit.chw 08/29/2002 05:00 AM 12,886 REGEDIT.HLP 07/17/2004 01:40 PM 24,567 regopt.chm 07/17/2004 01:40 PM 20,126 remasst.chm 08/26/2004 07:04 PM 198,656 RPG2003.FTS 08/29/2002 05:00 AM 14,678 RSM.CHM 08/29/2002 05:00 AM 35,699 RSM.HLP 08/29/2002 05:00 AM 56,352 rsmconcepts.chm 08/29/2002 05:00 AM 25,815 RVSE.CHM 08/29/2002 05:00 AM 10,111 SAPICPL.HLP 08/21/2003 09:50 AM SBSI 08/29/2002 05:00 AM 13,955 SCARDDLG.HLP 11/11/2003 04:46 PM 24,576 scrpbken.FTS 08/29/2002 05:00 AM 38,163 SECAUTH.HLP 07/17/2004 01:40 PM 18,379 sendcmsg.chm 08/29/2002 05:00 AM 11,941 SENDCMSG.HLP 08/29/2002 05:00 AM 15,957 SFMMGR.HLP 08/29/2002 05:00 AM 21,787 SHELL.HLP 08/29/2002 05:00 AM 32,162 SHVL.CHM 08/29/2002 05:00 AM 8,953 SIGNIN.HLP 08/29/2002 05:00 AM 12,249 SIGVERIF.HLP 08/29/2002 05:00 AM 18,988 SMLOGCFG.CHM 08/29/2002 05:00 AM 16,645 SNDVOL32.CHM 08/29/2002 05:00 AM 11,290 SNDVOL32.HLP 08/04/2004 02:56 AM 34,816 sniffpol.dll 08/29/2002 05:00 AM 42,000 snmpconcepts.chm 08/29/2002 05:00 AM 16,043 SNMPSNAP.HLP 08/29/2002 05:00 AM 16,962 SOL.CHM 08/29/2002 05:00 AM 13,517 SOL.HLP 08/29/2002 05:00 AM 34,041 SOUNDREC.CHM 08/29/2002 05:00 AM 20,246 SOUNDREC.HLP 08/29/2002 05:00 AM 20,163 SOUNDS.CHM 07/17/2004 01:40 PM 20,233 spad.chm 08/29/2002 05:00 AM 42,687 SPEECH.CHM 08/29/2002 05:00 AM 15,961 SPIDER.CHM 08/29/2002 05:00 AM 11,594 SPIDER.HLP 08/29/2002 05:00 AM 12,492 SPLASH.CHM 07/17/2004 01:40 PM 17,290 sr_ui.chm 08/04/2004 02:56 AM 33,280 sstub.dll 10/26/2004 03:28 PM starter 08/29/2002 05:00 AM 17,336 SUPP_ED.CHM 08/29/2002 05:00 AM 41,881 SYSDM.CHM 08/29/2002 05:00 AM 75,448 SYSDM.HLP 08/29/2002 05:00 AM 17,784 SYSMON.CHM 08/29/2002 05:00 AM 62,118 SYSMON.HLP 08/29/2002 05:00 AM 33,152 SYSPROP.CHM 07/17/2004 01:40 PM 33,149 sysrestore.chm 08/29/2002 05:00 AM 11,603 sysrestore.hlp 07/17/2004 01:40 PM 32,400 sys_srv.chm 08/29/2002 05:00 AM 35,334 TAPI.CHM 08/29/2002 05:00 AM 20,688 TAPI.HLP 08/29/2002 05:00 AM 33,991 TASKBAR.CHM 08/29/2002 05:00 AM 37,803 TASKMGR.CHM 08/29/2002 05:00 AM 13,228 TASKMGR.HLP 08/29/2002 05:00 AM 38,234 TCPIP.CHM 08/29/2002 05:00 AM 12,693 TCPMON.HLP 08/29/2002 05:00 AM 30,107 TELNET.CHM 08/29/2002 05:00 AM 14,698 TELNET.HLP 08/29/2002 05:00 AM 19,459 TIMESRV.CHM 08/30/2005 05:48 PM Tours 08/29/2002 05:00 AM 313,676 TSHOOT.CHM 08/04/2004 02:56 AM 279,040 tshoot.dll 07/17/2004 01:40 PM 45,068 twclient.chm 07/17/2004 01:40 PM 12,488 twclient.hlp 11/29/2004 09:45 PM 205,824 uawp11en.FTS 08/29/2002 05:00 AM 193 UPDATE.CNT 07/18/2004 12:54 AM 62,317 update1.chm 07/17/2004 01:40 PM 27,765 useract.chm 08/29/2002 05:00 AM 16,660 UTILMGR.CHM 08/29/2002 05:00 AM 12,244 UTILMGR.HLP 08/29/2002 05:00 AM 14,384 VERIFIER.HLP 08/29/2002 05:00 AM 74,905 WAB.CHM 08/29/2002 05:00 AM 59,142 WAB.HLP 08/29/2002 05:00 AM 44,441 WBEMTEST.CHM 07/17/2004 01:40 PM 16,643 webpub.chm 07/17/2004 01:40 PM 44,082 whatsnew.chm 08/29/2002 05:00 AM 17,782 WINCHAT.CHM 08/29/2002 05:00 AM 12,377 WINCHAT.HLP 08/29/2002 05:00 AM 690,641 WINDOWS.CHM 07/18/2004 12:54 AM 544,750 windows.chq 08/29/2002 05:00 AM 64 WINDOWS.CNT 08/29/2002 05:00 AM 300,163 WINDOWS.HLP 08/29/2002 05:00 AM 51,767 wingb.chm 08/29/2002 05:00 AM 69 WINHLP32.CNT 08/29/2002 05:00 AM 21,111 WINHLP32.HLP 08/29/2002 05:00 AM 171,874 winime.chm 08/29/2002 05:00 AM 56,661 WININSTL.CHM 08/29/2002 05:00 AM 15,071 WINMINE.CHM 08/29/2002 05:00 AM 11,476 WINMINE.HLP 08/29/2002 05:00 AM 39,829 winpy.chm 08/29/2002 05:00 AM 45,113 winsp.chm 08/29/2002 05:00 AM 158,219 winzm.chm 08/29/2002 05:00 AM 21,286 WIN_DOS.CHM 08/11/2004 01:45 AM 611,873 wmp10.chm 08/11/2004 01:45 AM 89,413 wmperr10.chm 08/29/2002 05:00 AM 415,082 wmplayer.bak 07/17/2004 01:45 PM 613,334 wmplayer.chm 08/29/2002 05:00 AM 32,887 WORDPAD.CHM 09/27/2003 02:38 AM 29,862 wordpad.chw 08/29/2002 05:00 AM 19,706 WORDPAD.HLP 08/29/2002 05:00 AM 25,089 WPA.CHM 11/11/2003 04:46 PM 19,968 wpta11en.FTS 11/29/2004 09:45 PM 598,016 wpwp11en.FTS 07/17/2004 01:40 PM 46,130 wschelp.chm 08/29/2002 05:00 AM 25,712 WSCRIPT.CHM 08/29/2002 05:00 AM 12,377 WSCRIPT.HLP 08/29/2002 05:00 AM 13,307 wshconcepts.chm 11/11/2003 04:46 PM 50,176 wt11cmen.FTS 07/18/2004 12:54 AM 20,170 wuau.chm 05/26/2005 04:16 AM 74,909 wuauhelp.chm 380 File(s) 25,640,095 bytes 5 Dir(s) 50,601,119,744 bytes free Volume in drive C has no label. Volume Serial Number is C0F9-BD73 Directory of C:\WINDOWS\Help\Tours 08/30/2005 05:48 PM 303 bdsm.ini 08/30/2005 05:48 PM 516,116 msdb.dll 2 File(s) 516,419 bytes 0 Dir(s) 50,601,140,224 bytes free Volume in drive C has no label. Volume Serial Number is C0F9-BD73 Directory of C:\WINDOWS\Help\Tours 08/30/2005 05:48 PM . 08/30/2005 05:48 PM .. 10/26/2004 03:21 PM htmlTour 08/21/2003 09:50 AM mmTour 08/21/2003 09:50 AM WindowsMediaPlayer 0 File(s) 0 bytes 5 Dir(s) 50,601,140,224 bytes free Volume in drive C has no label. Volume Serial Number is C0F9-BD73 Directory of C:\WINDOWS\system 08/30/2005 05:56 PM 303 slitu.ini 08/30/2005 05:56 PM 516,116 utils.dll 2 File(s) 516,419 bytes 0 Dir(s) 50,601,140,224 bytes free Volume in drive C has no label. Volume Serial Number is C0F9-BD73 Directory of C:\WINDOWS\system 08/30/2005 05:56 PM . 08/30/2005 05:56 PM .. 08/29/1993 03:56 PM 137,232 AAPLAY.DLL 12/09/1992 06:29 PM 13,840 AAVGA.DLL 08/29/2002 05:00 AM 69,584 AVICAP.DLL 08/29/2002 05:00 AM 109,456 AVIFILE.DLL 04/28/1993 01:00 AM 18,688 CMDIALOG.VBX 08/29/2002 05:00 AM 32,816 COMMDLG.DLL 07/01/1994 12:00 AM 21,008 CTL3D.DLL 03/30/1994 05:00 PM 39,424 DDEML.DLL 06/15/1993 06:26 PM 45,136 GRID.VBX 08/21/1996 08:00 PM 4,992 HPW1DEL.EXE 08/21/1996 08:00 PM 147,872 HPW1ST1.EXE 08/21/1996 08:00 PM 12,282 HPW1ST1.INI 08/21/1996 08:00 PM 12,256 HPW1ST2.DLL 09/02/1994 12:19 AM 17,756 KANA.DLL 08/29/2002 05:00 AM 2,000 KEYBOARD.DRV 06/05/1995 03:13 PM 127,456 KSIANNIE.DLL 08/29/2002 05:00 AM 9,936 LZEXPAND.DLL 04/28/1993 01:00 AM 30,112 MCI.VBX 06/29/1992 03:47 PM 16,912 MCIAAP.DRV 08/29/2002 05:00 AM 73,376 MCIAVI.DRV 08/29/2002 05:00 AM 25,264 MCISEQ.DRV 08/29/2002 05:00 AM 28,160 MCIWAVE.DRV 08/04/2004 12:51 AM 68,768 mmsystem.dll 08/29/2002 05:00 AM 1,152 MMTASK.TSK 08/29/2002 05:00 AM 2,032 MOUSE.DRV 08/29/2002 05:00 AM 126,912 MSVIDEO.DLL 03/22/1993 03:00 PM 12,288 MVAPI2.DLL 03/22/1993 03:00 PM 138,864 MVBMP2.DLL 03/22/1993 03:00 PM 19,968 MVBRKR2.DLL 03/22/1993 03:00 PM 52,224 MVFS2.DLL 09/22/1993 07:00 AM 160,768 MVFTSUI2.DLL 09/22/1993 07:00 AM 286,768 MVIEWER2.EXE 03/22/1993 03:00 PM 93,184 MVMCI2.DLL 08/02/1995 02:14 PM 34,288 MVMGX.DLL 07/13/1995 10:35 PM 17,872 MVMGXKSI.DLL 03/22/1993 03:00 PM 53,760 MVSRCH2.DLL 03/22/1993 03:00 PM 24,576 MVTITLE2.DLL 08/29/2002 05:00 AM 82,944 OLECLI.DLL 08/29/2002 05:00 AM 24,064 OLESVR.DLL 09/11/2000 07:00 AM 9,597 RDB16.EXE 08/29/2002 05:00 AM 59,167 SETUP.INF 04/27/1993 05:00 PM 7,008 SETUPKIT.DLL 08/29/2002 05:00 AM 5,120 SHELL.DLL 08/29/2002 05:00 AM 1,744 SOUND.DRV 08/29/2002 05:00 AM 5,532 STDOLE.TLB 08/29/2002 05:00 AM 3,360 SYSTEM.DRV 08/29/2002 05:00 AM 19,200 TAPI.DLL 07/16/1993 04:28 PM 64,432 THREED.VBX 08/29/2002 05:00 AM 4,048 TIMER.DRV 05/09/1991 06:00 PM 271,264 VBRUN100.DLL 10/20/1992 04:00 PM 356,992 VBRUN200.DLL 11/18/1993 05:00 PM 398,416 VBRUN300.DLL 08/29/2002 05:00 AM 9,008 VER.DLL 08/29/2002 05:00 AM 2,176 VGA.DRV 01/10/1994 05:00 PM 14,933 VSHARE.386 08/29/2002 05:00 AM 13,600 WFWNET.DRV 08/04/2004 02:56 AM 146,432 winspool.drv 57 File(s) 3,588,019 bytes 2 Dir(s) 50,601,136,128 bytes free
Step 1:

Please download Process Explorer by Systernals from:

Process Explorer

Also download/unzip KillBox by Option^Explicit from:

Killbox.zip

Step 2:

Download this file and save it to your desktop:

FixVundo Registry File

Copy/paste the text in the Quote box below into Notepad, and save it on the desktop as "killme.txt"

C:\WINDOWS\Fonts\cdrah.bak1
C:\WINDOWS\Fonts\cdrah.bak2
C:\WINDOWS\Fonts\cdrah.ini
C:\WINDOWS\Fonts\cdrah.ini2
C:\WINDOWS\Fonts\cdrah.tmp
C:\WINDOWS\Fonts\hardc.dll
C:\WINDOWS\Help\bdavaj.bak1
C:\WINDOWS\Help\bdavaj.bak2
C:\WINDOWS\Help\bdavaj.ini
C:\WINDOWS\Help\javadb.dll
C:\WINDOWS\Help\Tours\bdsm.ini
C:\WINDOWS\Help\Tours\msdb.dll
C:\WINDOWS\system\slitu.ini
C:\WINDOWS\system\utils.dll


Step 3:

Print out the following instructions as you will not have Internet Access for the rest of this fix.

Reboot in "safe" mode.

The rest of this fix must be done in safe mode.

Unzip Process Explorer and double click on procexp.exe

In the top section of the Process Exlporer screen double-click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of:

hardc.dll

once and then click the kill button.

After you have killed all of:

hardc.dll

under winlogon click OK.

If you see any of the files listed below, kill them as well.

Files to look for:
————————–
cdrah.bak1
cdrah.bak2
cdrah.ini
cdrah.ini2
cdrah.tmp
bdavaj.bak1
bdavaj.bak2
bdavaj.ini
javadb.dll
bdsm.ini
msdb.dll
slitu.ini
utils.dll

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present. That is OK.

Next double-click on explorer.exe, select the Threads tab, and again click once on each instance of:

hardc.dll

then click the kill button.

If you see any of the files listed below kill them as well.

Files to look for:
————————–
cdrah.bak1
cdrah.bak2
cdrah.ini
cdrah.ini2
cdrah.tmp
bdavaj.bak1
bdavaj.bak2
bdavaj.ini
javadb.dll
bdsm.ini
msdb.dll
slitu.ini
utils.dll

BE SURE TO KILL ONLY THESE FILES!!!

Probably not all of them will be present. That is OK

Once you have done that click OK again.

Next run Hijack This! and place a check beside each of the following.

O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\Fonts\hardc.dll

O20 - Winlogon Notify: hardc - C:\WINDOWS\Fonts\hardc.dll

O20 - Winlogon Notify: javadb - C:\WINDOWS\Help\javadb.dll

O20 - Winlogon Notify: msdb - C:\WINDOWS\Help\Tours\msdb.dll

O20 - Winlogon Notify: unkey - C:\WINDOWS\Fonts\unkey.dll

O20 - Winlogon Notify: utils - C:\WINDOWS\system\utils.dll

Now click Fix checked and close HijackThis.

Now double-click on the vundo.reg file that you saved on your desktop earlier and allow it to merge with the registry.

Step 4:

On the desktop, open the "killme.txt" file with Notepad.

Then copy the all file names in the "killme.txt" to the clipboard by highlighting them and pressing C (hold the key down, then press C):

Close "killme.txt".

Double click on Killbox.exe and then check the Delete on reboot button.

In Killbox, click File (in the upper left of Killbox), and choose "Paste from Clipboard".

Click the red dot with the white X in it, in the upper right of Killbox, then click "Yes", and "Yes" again.

After the reboot, "copy/paste" a new Hijack This! log file into this thread. :)
My new HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 11:25:46 AM, on 10/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\iFtpSvc\iFtpSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Lauren\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dellnet.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Lauren\Application Data\Mozilla\Profiles\default\uwmez9u1.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lauren\Application Data\Mozilla\Profiles\default\uwmez9u1.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {827DC836-DD9F-4A68-A602-5812EB50A834} - (no file)
O2 - BHO: Bho - {BFFA51A0-0B64-4aa3-AAC4-325F9338D0BE} - C:\WINDOWS\system32\bvbcvema.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ChatSpace Full Java Client 4.0.0.301 - http://63.102.226.240:8000/Java/cfs40301.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotdate/NPC…otDateTeleX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {435583D3-F647-4943-BB40-B0D64CB02718} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab
O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} (MaxisSuperstarTeleX Control) - http://thesims.ea.com/teleport/superstar/M…erstarTeleX.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {C228AEDD-FC47-11D3-AF87-D128A9381404} (LSICapture Control) - http://www.link-systems.com/~sdk/SDK/paste/lsiw2k.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Ipswitch WS_FTP Server (iFtpSvc) - Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. - C:\iFtpSvc\iFtpSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Please disable Teatimer, it can interfere with the cleaning process:

How to Disable Teatimer

After we have cleaned your system, please be sure to reverse this process, and re-enable Teatimer.

Reboot after disabling Teatimer.

We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft AntiSpyware.
  • Click on Options, Settings.
  • In the left pane, click on Real-time Protection.
  • Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
  • Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
  • After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
  • Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {827DC836-DD9F-4A68-A602-5812EB50A834} - (no file)

O2 - BHO: Bho - {BFFA51A0-0B64-4aa3-AAC4-325F9338D0BE} - C:\WINDOWS\system32\bvbcvema.dll

Then click "Fix checked" and close Hijack This!.

Reboot and "copy/paste" a new log file into this thread. :)
Ok, here's the new log file:

Logfile of HijackThis v1.99.1
Scan saved at 12:23:19 PM, on 10/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\iFtpSvc\iFtpSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Documents and Settings\Lauren\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dellnet.msn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Lauren\Application Data\Mozilla\Profiles\default\uwmez9u1.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lauren\Application Data\Mozilla\Profiles\default\uwmez9u1.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ChatSpace Full Java Client 4.0.0.301 - http://63.102.226.240:8000/Java/cfs40301.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotdate/NPC…otDateTeleX.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {435583D3-F647-4943-BB40-B0D64CB02718} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…74/mcinsctl.cab
O16 - DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} (MaxisSuperstarTeleX Control) - http://thesims.ea.com/teleport/superstar/M…erstarTeleX.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmg…,15/mcgdmgr.cab
O16 - DPF: {C228AEDD-FC47-11D3-AF87-D128A9381404} (LSICapture Control) - http://www.link-systems.com/~sdk/SDK/paste/lsiw2k.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX/kdx.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Ipswitch WS_FTP Server (iFtpSvc) - Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. - C:\iFtpSvc\iFtpSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Looks good now. :thumbup:

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI