This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

W32/Agent.NM

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

NTL Netguard has identified the following virus: W32/Agent.NM in file: D:\WINDOWS\FONTS\INETIP.DLL

I've tried to use the NTL virus software to resolve without any luck, i.e. delete the file after next reboot.

Can you offer any guidance for removing this virus?

Would this particular virus also account for a slugish system performance?

HiJackThis log file attached below.

Thanks in advance.





Logfile of HijackThis v1.99.1
Scan saved at 16:29:54, on 01/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearchIndexer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\STEVEP~1\LOCALS~1\Temp\Temporary Directory 2 for HijackThis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: MSEvents Object - {44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44} - C:\WINDOWS\Fonts\inetip.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: &Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Note this (Google Note&book) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll/gn_menu1.html
O8 - Extra context menu item: Note this (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll/gn_menu2.html
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/229?7af113f5563447ffaed555254019ce98
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/230?7af113f5563447ffaed555254019ce98
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: inetip - C:\WINDOWS\Fonts\inetip.dll
O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Welcome to the forum :wavey:

Download VundoFix.exe to your desktop from here:

VundoFix.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

1. Double-click VundoFix.exe to run it.
2. Click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. If it doesn't find anything, in the main program window, choose "Add more files?".
Type the next line into the box EXACTLY AS SHOWN:

C:\WINDOWS\Fonts\inetip.dll

Click Close Window, then Remove Vundo.

5. You will receive a prompt asking if you want to remove the files, click YES.
6. Once you click yes, your desktop will go blank as it starts removing Vundo.
7. When completed, it will prompt that it will shutdown your computer, click OK.
8. Turn your computer back on.

Post a new HijackThis! log, along with the contents of this file:

C:\vundofix.txt


into this thread.
:)
Hi and thanks

I've run the Vundo as instructed; however Vundo didn't find anything, didn't even find it when i added it as an "add more files"

Please find attached the vundofix.txt log & new hijackthis log.

Vundofix log:


VundoFix V6.1.2

Checking Java version…

Scan started at 18:55:16 01/09/2006

Listing files found while scanning….

No infected files were found.


Beginning removal…

Beginning removal…

Beginning removal…


Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 19:20:12, on 01/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearchIndexer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\STEVEP~1\LOCALS~1\Temp\Temporary Directory 3 for HijackThis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: MSEvents Object - {44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44} - C:\WINDOWS\Fonts\inetip.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: &Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Note this (Google Note&book) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll/gn_menu1.html
O8 - Extra context menu item: Note this (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll/gn_menu2.html
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/229?7af113f5563447ffaed555254019ce98
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/230?7af113f5563447ffaed555254019ce98
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: inetip - C:\WINDOWS\Fonts\inetip.dll
O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Copy the text in the following quote box into Notepad:

dir C:\WINDOWS\Fonts\ /ah > files.txt
dir C:\WINDOWS\Fonts\ >> files.txt
notepad files.txt


Save it to your desktop as ff.bat

CLOSE NOTEPAD!!! NOT "MINIMIZE" - CLOSE!!!!

Now, the ff.bat file on the desktop. A Notepad window will open up.

Please paste it's contents into your next post.
Hi, Cheers, done that and here you go: Volume in drive C has no label. Volume Serial Number is 8841-B0C7 Directory of C:\WINDOWS\Fonts 29/08/2002 06:00 10,976 8514FIX.FON 29/08/2002 06:00 10,976 8514FIXE.FON 29/08/2002 06:00 11,520 8514FIXG.FON 29/08/2002 06:00 10,976 8514FIXR.FON 29/08/2002 06:00 11,488 8514FIXT.FON 29/08/2002 06:00 12,288 8514OEM.FON 29/08/2002 06:00 13,248 8514OEME.FON 29/08/2002 06:00 12,800 8514OEMG.FON 29/08/2002 06:00 13,200 8514OEMR.FON 29/08/2002 06:00 12,720 8514OEMT.FON 29/08/2002 06:00 9,280 8514SYS.FON 29/08/2002 06:00 9,504 8514SYSE.FON 29/08/2002 06:00 9,856 8514SYSG.FON 29/08/2002 06:00 10,064 8514SYSR.FON 29/08/2002 06:00 9,792 8514SYST.FON 29/08/2002 06:00 12,304 85775.FON 29/08/2002 06:00 12,256 85855.FON 29/08/2002 06:00 10,976 85F1257.FON 29/08/2002 06:00 9,472 85S1257.FON 29/08/2002 06:00 35,808 APP775.FON 29/08/2002 06:00 36,672 APP850.FON 29/08/2002 06:00 36,656 APP852.FON 29/08/2002 06:00 37,296 APP855.FON 29/08/2002 06:00 36,672 APP857.FON 29/08/2002 06:00 37,472 APP866.FON 29/08/2002 06:00 7,216 CGA40737.FON 29/08/2002 06:00 6,352 CGA40850.FON 29/08/2002 06:00 6,672 CGA40852.FON 29/08/2002 06:00 6,672 CGA40857.FON 29/08/2002 06:00 7,232 CGA40866.FON 29/08/2002 06:00 7,216 CGA40869.FON 29/08/2002 06:00 5,168 CGA80737.FON 29/08/2002 06:00 4,320 CGA80850.FON 29/08/2002 06:00 5,200 CGA80852.FON 29/08/2002 06:00 4,640 CGA80857.FON 29/08/2002 06:00 5,168 CGA80866.FON 29/08/2002 06:00 5,168 CGA80869.FON 29/08/2002 06:00 23,440 COUE1257.FON 29/08/2002 06:00 31,760 COUF1257.FON 29/08/2002 06:00 23,440 COUREE.FON 29/08/2002 06:00 25,024 COUREG.FON 29/08/2002 06:00 23,440 COURER.FON 29/08/2002 06:00 25,024 COURET.FON 29/08/2002 06:00 31,776 COURFE.FON 29/08/2002 06:00 33,344 COURFG.FON 29/08/2002 06:00 31,808 COURFR.FON 29/08/2002 06:00 33,360 COURFT.FON 03/09/2002 09:59 67 DESKTOP.INI 29/08/2002 06:00 36,336 DOS737.FON 29/08/2002 06:00 36,656 DOSAPP.FON 29/08/2002 06:00 9,248 EGA40737.FON 29/08/2002 06:00 8,384 EGA40850.FON 29/08/2002 06:00 8,368 EGA40852.FON 29/08/2002 06:00 8,704 EGA40857.FON 29/08/2002 06:00 9,232 EGA40866.FON 29/08/2002 06:00 9,248 EGA40869.FON 29/08/2002 06:00 6,192 EGA80737.FON 29/08/2002 06:00 5,328 EGA80850.FON 29/08/2002 06:00 5,344 EGA80852.FON 29/08/2002 06:00 5,648 EGA80857.FON 29/08/2002 06:00 5,280 EGA80866.FON 29/08/2002 06:00 6,192 EGA80869.FON 02/05/2005 20:00 468,500 inetip.dll 29/08/2002 06:00 24,124 MARLETT.TTF 10/12/2005 13:09 505,883 piteni.bak2 01/09/2006 20:02 1,129 piteni.ini 13/08/2006 23:53 335,655 piteni.ini2 29/08/2002 06:00 59,024 SERE1257.FON 29/08/2002 06:00 84,080 SERF1257.FON 29/08/2002 06:00 59,952 SERIFEE.FON 29/08/2002 06:00 60,752 SERIFEG.FON 29/08/2002 06:00 63,296 SERIFER.FON 29/08/2002 06:00 61,024 SERIFET.FON 29/08/2002 06:00 85,360 SERIFFE.FON 29/08/2002 06:00 86,256 SERIFFG.FON 29/08/2002 06:00 90,736 SERIFFR.FON 29/08/2002 06:00 84,848 SERIFFT.FON 29/08/2002 06:00 24,672 SMAE1257.FON 29/08/2002 06:00 19,904 SMAF1257.FON 29/08/2002 06:00 24,784 SMALLEE.FON 29/08/2002 06:00 28,912 SMALLEG.FON 29/08/2002 06:00 24,832 SMALLER.FON 29/08/2002 06:00 29,200 SMALLET.FON 29/08/2002 06:00 19,600 SMALLFE.FON 29/08/2002 06:00 23,120 SMALLFG.FON 29/08/2002 06:00 19,760 SMALLFR.FON 29/08/2002 06:00 23,008 SMALLFT.FON 29/08/2002 06:00 65,456 SSEE1257.FON 29/08/2002 06:00 90,336 SSEF1257.FON 29/08/2002 06:00 66,464 SSERIFEE.FON 29/08/2002 06:00 65,328 SSERIFEG.FON 29/08/2002 06:00 68,848 SSERIFER.FON 29/08/2002 06:00 64,400 SSERIFET.FON 29/08/2002 06:00 92,032 SSERIFFE.FON 29/08/2002 06:00 90,288 SSERIFFG.FON 29/08/2002 06:00 98,256 SSERIFFR.FON 29/08/2002 06:00 89,456 SSERIFFT.FON 29/08/2002 06:00 56,336 SYMBOLE.FON 29/08/2002 06:00 5,168 VGA737.FON 29/08/2002 06:00 5,168 VGA775.FON 29/08/2002 06:00 5,232 VGA850.FON 29/08/2002 06:00 6,160 VGA852.FON 29/08/2002 06:00 5,120 VGA855.FON 29/08/2002 06:00 5,552 VGA857.FON 29/08/2002 06:00 5,184 VGA860.FON 29/08/2002 06:00 5,200 VGA863.FON 29/08/2002 06:00 5,184 VGA865.FON 29/08/2002 06:00 6,128 VGA866.FON 29/08/2002 06:00 5,184 VGA869.FON 29/08/2002 06:00 5,376 VGAF1257.FON 29/08/2002 06:00 5,360 VGAFIX.FON 29/08/2002 06:00 5,376 VGAFIXE.FON 29/08/2002 06:00 6,112 VGAFIXG.FON 29/08/2002 06:00 5,600 VGAFIXR.FON 29/08/2002 06:00 6,112 VGAFIXT.FON 29/08/2002 06:00 5,168 VGAOEM.FON 29/08/2002 06:00 6,656 VGAS1257.FON 29/08/2002 06:00 7,280 VGASYS.FON 29/08/2002 06:00 6,608 VGASYSE.FON 29/08/2002 06:00 7,008 VGASYSG.FON 29/08/2002 06:00 6,912 VGASYSR.FON 29/08/2002 06:00 6,912 VGASYST.FON 122 File(s) 4,243,310 bytes 0 Dir(s) 13,103,734,784 bytes free Volume in drive C has no label. Volume Serial Number is 8841-B0C7 Directory of C:\WINDOWS\Fonts 29/07/1998 21:02 47,688 Absalom_.TTF 29/07/1998 21:20 63,596 Alibi___.TTF 29/08/2002 06:00 80,896 app932.fon 29/08/2002 06:00 70,000 app936.fon 29/08/2002 06:00 80,896 app949.fon 29/08/2002 06:00 70,000 app950.fon 17/07/2004 19:39 367,112 arial.ttf 17/07/2004 19:39 352,224 arialbd.ttf 29/08/2002 06:00 226,748 ARIALBI.TTF 29/08/2002 06:00 207,808 ARIALI.TTF 01/08/1997 00:00 123,976 arialn.ttf 01/08/1997 00:00 127,720 arialnb.ttf 01/08/1997 00:00 126,980 arialnbi.ttf 01/08/1997 00:00 130,180 arialni.ttf 29/08/2002 06:00 117,028 ARIBLK.TTF 29/08/2002 06:00 16,258,580 batang.ttc 29/07/1998 21:10 45,268 Batavia_.TTF 01/08/1997 00:00 150,412 bookos.ttf 01/08/1997 00:00 143,368 bookosb.ttf 01/08/1997 00:00 150,900 bookosbi.ttf 01/08/1997 00:00 149,704 bookosi.ttf 17/04/2002 05:55 105,296 BradhITC.TTF 01/08/1997 00:00 63,448 bssym1.ttf 01/08/1997 00:00 35,800 bssym2.ttf 01/08/1997 00:00 25,252 bssym3.ttf 01/08/1997 00:00 38,836 bssym4.ttf 01/08/1997 00:00 62,936 bssym5.ttf 29/08/2002 06:00 10,992 c8514fix.fon 29/08/2002 06:00 13,552 c8514oem.fon 29/08/2002 06:00 17,760 c8514sys.fon 11/12/1998 03:05 74,336 casmira_.TTF 29/08/2002 06:00 6,336 cga40woa.fon 29/08/2002 06:00 4,304 cga80woa.fon 17/07/2004 19:39 127,596 comic.ttf 29/08/2002 06:00 111,476 COMICBD.TTF 17/04/2002 05:55 61,552 Coprgtb.TTF 17/04/2002 05:55 62,716 Coprgtl.TTF 29/08/2002 06:00 303,296 COUR.TTF 29/08/2002 06:00 312,920 COURBD.TTF 29/08/2002 06:00 236,148 COURBI.TTF 29/08/2002 06:00 23,408 coure.fon 29/08/2002 06:00 31,712 courf.fon 29/08/2002 06:00 245,032 COURI.TTF 17/04/2002 05:55 69,480 Curlz___.TTF 29/08/2002 06:00 5,600 cvgafix.fon 29/08/2002 06:00 12,896 cvgasys.fon 29/08/2002 06:00 8,368 ega40woa.fon 29/08/2002 06:00 5,312 ega80woa.fon 18/09/2001 03:31 36,860 Elegance.TTF 29/07/1998 21:18 72,060 Ellis___.TTF 25/06/1999 05:23 49,768 Engr.TTF 25/06/1999 05:23 43,768 Engrb.TTF 17/03/1999 08:07 59,996 Erasdemi.TTF 17/03/1999 08:07 68,656 Eraslght.TTF 29/08/2002 06:00 79,744 ESTRE.TTF 17/04/2002 05:55 43,704 Eurosti.TTF 17/04/2002 05:55 44,304 Eurostib.TTF 29/07/1998 21:17 58,116 Excess__.TTF 17/04/2002 05:55 45,952 Felixti.TTF 10/01/2001 07:32 152,700 Frabk.TTF 10/01/2001 07:32 169,620 Frabkit.TTF 23/04/1999 09:22 142,932 Fradm.TTF 23/04/1999 09:22 135,904 Fradmit.TTF 29/08/2002 06:00 135,984 FRAMD.TTF 17/04/2002 05:55 132,516 Framdcn.TTF 29/08/2002 06:00 152,844 FRAMDIT.TTF 17/04/2002 05:55 58,580 Frscript.TTF 01/08/1997 00:00 185,680 gara.ttf 01/08/1997 00:00 186,744 garabd.ttf 01/08/1997 00:00 176,916 garait.ttf 29/08/2002 06:00 214,936 GAUTAMI.TTF 29/07/1998 21:21 49,960 Genuine_.TTF 29/08/2002 06:00 155,068 GEORGIA.TTF 29/08/2002 06:00 141,032 GEORGIAB.TTF 29/08/2002 06:00 157,388 GEORGIAI.TTF 29/08/2002 06:00 159,736 GEORGIAZ.TTF 17/04/2002 05:55 137,568 Gothic.TTF 17/04/2002 05:55 129,676 Gothicb.TTF 17/04/2002 05:55 139,084 Gothicbi.TTF 17/04/2002 05:55 148,520 Gothici.TTF 29/08/2002 06:00 13,518,660 gulim.ttc 29/08/2002 06:00 11,056 h8514fix.fon 29/08/2002 06:00 12,400 h8514oem.fon 29/08/2002 06:00 10,032 h8514sys.fon 01/08/1997 00:00 41,408 hatten.ttf 29/07/1998 21:14 63,124 Helte___.TTF 29/07/1998 21:17 77,384 Herman__.TTF 29/08/2002 06:00 5,680 hvgafix.fon 29/08/2002 06:00 6,512 hvgasys.fon 29/08/2002 06:00 136,076 IMPACT.TTF 29/07/1998 21:16 104,864 Isabelle.TTF 17/04/2002 05:55 132,372 ITCBlkad.TTF 17/04/2002 05:55 64,056 ITCEdscr.TTF 17/04/2002 05:55 59,712 ITCKrist.TTF 29/08/2002 06:00 12,896 j8514fix.fon 29/08/2002 06:00 14,432 j8514oem.fon 29/08/2002 06:00 10,656 j8514sys.fon 29/07/1998 21:15 65,852 Joan____.TTF 29/08/2002 06:00 41,584 jsmalle.fon 29/08/2002 06:00 38,480 jsmallf.fon 29/07/1998 21:08 71,068 Justice_.TTF 29/08/2002 06:00 6,528 jvgafix.fon 29/08/2002 06:00 7,728 jvgasys.fon 17/07/2004 19:39 121,452 kartika.ttf 29/08/2002 06:00 73,292 LATHA.TTF 17/04/2002 05:55 64,608 Lsans.TTF 17/04/2002 05:55 59,976 Lsansd.TTF 17/04/2002 05:55 66,320 Lsansdi.TTF 17/04/2002 05:55 65,412 Lsansi.TTF 17/04/2002 05:55 323,980 lsansuni.ttf 29/08/2002 06:00 115,068 LUCON.TTF 29/08/2002 06:00 323,980 L_10646.TTF 17/04/2002 05:55 61,384 Maian.TTF 17/04/2002 05:55 60,716 Maiandb.TTF 17/04/2002 05:55 70,280 Maiandit.TTF 29/07/1998 21:28 54,540 Mandela_.TTF 29/08/2002 06:00 143,864 MANGAL.TTF 01/08/1997 00:00 7,360 mapsym.ttf 17/04/2002 05:55 67,648 matisse_.ttf 29/07/1998 21:23 61,272 Matte___.TTF 31/07/2006 11:50 0 mcrh.tmp 29/07/1998 21:29 60,156 Microdot.TTF 18/07/2004 06:54 460,728 micross.ttf 29/08/2002 06:00 8,823,308 mingliu.ttc 17/04/2002 05:55 191,716 Mistral.TTF 29/08/2002 06:00 8,704 MODERN.FON 29/08/2002 06:00 8,272,028 msgothic.ttc 29/08/2002 06:00 9,135,960 msmincho.ttc 01/08/1997 00:00 76,920 mtsorts.ttf 29/08/2002 06:00 40,500 MVBOLI.TTF 29/07/1998 21:26 57,976 Natur___.TTF 29/07/1998 21:24 46,212 Neolith_.TTF 29/07/1998 21:30 48,508 Openc___.TTF 01/08/1997 00:00 6,272 outlook.ttf 29/08/2002 06:00 489,884 PALA.TTF 29/08/2002 06:00 434,004 PALAB.TTF 29/08/2002 06:00 344,288 PALABI.TTF 29/08/2002 06:00 430,800 PALAI.TTF 17/04/2002 05:55 161,416 PAPYRUS.TTF 17/04/2002 05:55 75,620 Perbi___.TTF 17/04/2002 05:55 58,512 Perb____.TTF 17/04/2002 05:55 76,080 Peri____.TTF 17/04/2002 05:55 60,216 Per_____.TTF 29/07/1998 21:25 64,916 Pretext_.TTF 29/07/1998 21:25 44,876 Puppy___.TTF 29/08/2002 06:00 57,348 RAAVI.TTF 29/07/1998 21:30 51,668 Radagund.TTF 29/07/1998 21:28 38,944 Realv___.TTF 17/04/2002 05:55 49,168 Rockeb.TTF 29/08/2002 06:00 13,312 ROMAN.FON 29/08/2002 06:00 11,056 s8514fix.fon 29/08/2002 06:00 12,384 s8514oem.fon 29/08/2002 06:00 17,760 s8514sys.fon 29/08/2002 06:00 12,288 SCRIPT.FON 29/08/2002 06:00 57,936 serife.fon 29/08/2002 06:00 81,728 seriff.fon 29/07/1998 21:27 52,336 Shelman_.TTF 29/08/2002 06:00 234,280 SHRUTI.TTF 29/08/2002 06:00 10,044,356 simhei.ttf 29/08/2002 06:00 10,500,792 simsun.ttc 29/08/2002 06:00 26,112 smalle.fon 29/08/2002 06:00 21,504 smallf.fon 29/08/2002 06:00 64,656 sserife.fon 29/08/2002 06:00 89,856 sseriff.fon 29/08/2002 06:00 5,680 svgafix.fon 29/08/2002 06:00 12,896 svgasys.fon 29/08/2002 06:00 221,676 SYLFAEN.TTF 29/08/2002 06:00 69,464 SYMBOL.TTF 18/07/2004 06:54 383,140 tahoma.ttf 18/07/2004 06:54 355,436 tahomabd.ttf 17/04/2002 05:55 76,100 TempsITC.TTF 17/07/2004 19:39 409,280 times.ttf 17/07/2004 19:39 398,372 timesbd.ttf 29/08/2002 06:00 239,692 TIMESBI.TTF 29/08/2002 06:00 248,368 TIMESI.TTF 29/08/2002 06:00 134,108 TREBUC.TTF 29/08/2002 06:00 123,096 TREBUCBD.TTF 29/08/2002 06:00 131,188 TREBUCBI.TTF 29/08/2002 06:00 139,288 TREBUCIT.TTF 29/07/1998 21:31 58,088 Trendy__.TTF 29/08/2002 06:00 148,636 TUNGA.TTF 29/08/2002 06:00 171,792 VERDANA.TTF 29/08/2002 06:00 137,616 VERDANAB.TTF 29/08/2002 06:00 155,076 VERDANAI.TTF 29/08/2002 06:00 154,800 VERDANAZ.TTF 29/08/2002 06:00 7,232 vga932.fon 29/08/2002 06:00 6,272 vga936.fon 29/08/2002 06:00 6,304 vga949.fon 29/08/2002 06:00 6,272 vga950.fon 17/04/2002 05:55 64,748 Vivaldii.TTF 17/07/2004 19:39 252,820 vrinda.ttf 29/08/2002 06:00 118,752 WEBDINGS.TTF 29/08/2002 06:00 81,000 WINGDING.TTF 22/01/2002 09:22 65,788 WINGDNG2.TTF 22/01/2002 09:22 35,328 WINGDNG3.TTF 29/08/2002 06:00 18,880 WST_CZEC.FON 29/08/2002 06:00 18,880 WST_ENGL.FON 29/08/2002 06:00 18,880 WST_FREN.FON 29/08/2002 06:00 18,880 WST_GERM.FON 29/08/2002 06:00 18,880 WST_ITAL.FON 29/08/2002 06:00 18,880 WST_SPAN.FON 29/08/2002 06:00 18,880 WST_SWED.FON 202 File(s) 96,545,024 bytes 0 Dir(s) 13,103,718,400 bytes free
Download The Avenger Copyright © Swandog46
You must extract avenger.exe to your desktop, before you run it.

Copy all the text contained in the code box below to your Clipboard.


Files to delete:
C:\WINDOWS\Fonts\inetip.dll
C:\WINDOWS\Fonts\piteni.bak2
C:\WINDOWS\Fonts\piteni.ini
C:\WINDOWS\Fonts\piteni.ini2


The above script is for this user only, if you need help please start your own thread.


Start the Avenger.
Under "Script file to execute" choose "Input Script Manually".
Click on the Magnifying Glass icon which will open a new window titled "View/edit script".
Paste the entire text in into this window.
Click done, now click on the Green Light
Answer "Yes" twice when prompted.
Your computer shoud reboot, and briefly open a black command window on your desktop, this is normal.

After the restart, it will create a log file that should open.
This log file will be located at C:\avenger.txt
Paste the contents of the file into your reply along with a fresh HJT log.

Also: Avenger has made backups of all the files, etc., that you asked it to delete, located at C:\avenger\backup.zip.
Hello again,

Avenger run sucessfully, PC rebooted.

Please find below the avenger and HJT log

Cheers

Avenger Log

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\whtdxukv

*******************

Script file located at: \??\C:\WINDOWS\system32\qwknfvss.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\Fonts\inetip.dll deleted successfully.
File C:\WINDOWS\Fonts\piteni.bak2 deleted successfully.
File C:\WINDOWS\Fonts\piteni.ini deleted successfully.
File C:\WINDOWS\Fonts\piteni.ini2 deleted successfully.

Completed script processing.

*******************

Finished! Terminate.


u]HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 21:09:30, on 01/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\system32\BacsTray.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\ntl\ntl Netguard\RPS.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearchIndexer.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\STEVEP~1\LOCALS~1\Temp\Temporary Directory 4 for HijackThis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ntlworld.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali 10.0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: MSEvents Object - {44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44} - C:\WINDOWS\Fonts\inetip.dll (file missing)
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: &Google Notebook - {CCCCCCD3-666F-4F81-8B69-745DE9F6D897} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: &Google Notebook - {CCCCCCDB-4DDB-4703-95D4-DD2C526397BF} - C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [ntl Netguard] "C:\Program Files\ntl\ntl Netguard\RPS.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: AOL 8.0 Tray Icon.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Note this (Google Note&book) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll/gn_menu1.html
O8 - Extra context menu item: Note this (Google Notebook) - res://C:\Program Files\Google\Google Notebook\gnotes1.0.2.6–392145900.dll/gn_menu2.html
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/229?7af113f5563447ffaed555254019ce98
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/230?7af113f5563447ffaed555254019ce98
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://69.44.122.156/scanner/ppctlcab.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: inetip - C:\WINDOWS\Fonts\inetip.dll (file missing)
O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: MSEvents Object - {44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44} - C:\WINDOWS\Fonts\inetip.dll (file missing)

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

O20 - Winlogon Notify: inetip - C:\WINDOWS\Fonts\inetip.dll (file missing)

O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot.

How's it running now?
:unsure:

Securing Your PC After An Attack
Hi Miah_6:8, That seems to have sorted it! Performance is spot on and no more virus pop up warning. Many thanks for your help. Cheers Steve :D
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI