There are several programs I question, only because I find no or very little information about them;
This running process for instance, from the Temp file....It should not be running from the temp file PLUS it is known for creating keys for Malware
C:\DOCUME~1\Dad\LOCALS~1\Temp\Temporary Directory 6 for gmer(2).zip\gmer.exe
These files I have not found decent info for;
Advanced Registry Doctor
UnHackMe
Pixoria\Konfabulator
debug.nfo
HotC.exe (which can be a legal program, though I am not certain what it does, but also can be the email worm W32.Silly.D).
Since you say that files are missing or have been changed I am really questioning that Registry program. There are very few which should be run in the background, or all the time. Registry fixing is very tricky and should only be attempted after all other fixes have been applied.
I really, at this point, only see one file for certain which is very suspect for malware and that is the debug.nfo.
How about downloading and running WPFind
Download WinPFind.zip and extract it to your C:\ folder. This will create a folder called WinPFind in the C:\ folder. Inside c:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.
When it is done, it will show the results of the scan. Click on the Copy to Clipboard button and then paste the contents of the log in your clipboard as a reply.
Please NOTE: not all files found with this program are necessarily bad. So don't remove anything noted there until we have had a chance to go through the log and see if there are suspicious items in it.


Reply With Quote