This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected PC! virus disabled my connectivity!

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi i recently downloaded something this morning and i'm pretty sure it had a bug in it. after i downloaded this program, i was bombarded with multiple popups whenever i opened up firefox. After i rebooted my computer, it wont even let me connect to my router for internet! So here i am now on my other laptop posting a hijackthis log file. any help is appreciated. thanks in advanced! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:34:37 PM, on 3/1/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\IPSBHO.DLL O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{A74F18AE-4998-4C2D-9C93-DA46DED16F2E}: NameServer = 85.255.114.41,85.255.112.25 O17 - HKLM\System\CCS\Services\Tcpip\..\{E990BAB6-3786-40F0-924E-708A73A4F085}: NameServer = 85.255.114.41,85.255.112.25 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.41,85.255.112.25 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.41,85.255.112.25 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.41,85.255.112.25 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe – End of file - 6089 bytes
Hi,

Can you download things to this clean laptop and transfer them to the infected machine?

If so, please do the following, downloading the tools via the clean laptop.

Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.
Try connecting to the Internet after running this tool.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Thanks.
Hi I downloaded and updated the Malwarebytes' Anti-Malware then scanned it. My internet works now! However i noticed that i am not able to open my C: disk drive. Anyways, heres the log.. the DDS txt log is below it it. Malwarebytes' Anti-Malware 1.34 Database version: 1814 Windows 5.1.2600 Service Pack 2 3/2/2009 8:36:19 PM mbam-log-2009-03-02 (20-36-19).txt Scan type: Full Scan (C:\|) Objects scanned: 99976 Time elapsed: 31 minute(s), 40 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Dell User\Local Settings\Temp\DivX.Codec.9.0.beta.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully. DDS txt.. DDS (Ver_09-02-01.01) - NTFSx86 Run by [removed] at 21:06:55.62 on Mon 03/02/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.88 [GMT -8:00] AV: Norton AntiVirus *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Dell User\Desktop\dds.scr ============== Pseudo HJT Report =============== uInternet Settings,ProxyOverride = *.local mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.1.0.33\IPSBHO.DLL BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL Notify: AtiExtEvent - Ati2evxx.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\dellus~1\applic~1\mozilla\firefox\profiles\vu3hdij8.default\ FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1001000.021\SymEFA.sys [2009-3-1 309296] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1001000.021\BHDrvx86.sys [2009-3-1 255536] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1001000.021\cchpx86.sys [2009-3-1 362544] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20090225.002\IDSxpx86.sys [2009-3-2 276344] R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.1.0.33\ccSvcHst.exe [2009-3-1 115560] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-2-21 24652] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-3-2 101936] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090302.040\NAVENG.SYS [2009-3-2 89104] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20090302.040\NAVEX15.SYS [2009-3-2 876144] S3 ATIXPGAA;ATIXPGAA;c:\dell\drivers\r101351\ATIXPGAA.SYS [2009-2-21 12032] =============== Created Last 30 ================ 2009-03-02 19:38 –d—– c:\docume~1\dellus~1\applic~1\Malwarebytes 2009-03-02 19:38 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-03-02 19:38 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-03-02 19:38 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-03-02 19:38 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-03-01 14:31 35,888 a—-r– c:\windows\system32\drivers\SymIM.sys 2009-03-01 14:31 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-03-01 14:31 60,808 a——- c:\windows\system32\S32EVNT1.DLL 2009-03-01 14:31 10,635 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-03-01 14:31 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-03-01 14:31 –d—– c:\program files\Symantec 2009-03-01 14:30 –d—– c:\windows\system32\drivers\NAV 2009-03-01 14:30 –d—– c:\program files\Norton AntiVirus 2009-03-01 14:30 –d—– c:\docume~1\alluse~1\applic~1\Norton 2009-03-01 14:30 –d—– c:\program files\NortonInstaller 2009-03-01 14:30 –d—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-03-01 14:07 306,688 a——- c:\windows\IsUninst.exe 2009-03-01 14:07 272 a——- c:\windows\_delis32.ini 2009-03-01 14:06 –d—– c:\program files\common files\Symantec Shared 2009-03-01 14:06 –d—– c:\docume~1\dellus~1\applic~1\Symantec 2009-03-01 14:06 –d—– c:\docume~1\alluse~1\applic~1\Symantec 2009-03-01 13:20 12,160 ac—— c:\windows\system32\dllcache\mouhid.sys 2009-03-01 13:20 12,160 a——- c:\windows\system32\drivers\mouhid.sys 2009-03-01 11:43 –d—– c:\program files\Trend Micro 2009-03-01 11:25 4 a——- c:\windows\system32\gaopdxcounter 2009-03-01 11:25 366 —shr– C:\autorun.inf 2009-03-01 11:25 0 a——- c:\windows\system32\budda 2009-03-01 11:21 –d—– c:\program files\Batch Watermark Creator 2009-03-01 10:51 107,368 a——- c:\windows\system32\GEARAspi.dll 2009-03-01 10:51 15,464 a——- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-03-01 10:51 –d—– c:\program files\iPod 2009-03-01 10:51 –d—– c:\program files\iTunes 2009-03-01 10:51 –d—– c:\docume~1\alluse~1\applic~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2009-03-01 10:50 –d—– c:\program files\Bonjour 2009-03-01 00:25 –d—– c:\program files\My Product Name 2009-02-28 11:56 –d—– c:\program files\Exact Audio Copy 2009-02-24 20:29 32,592 a——- c:\windows\system32\msonpmon.dll 2009-02-24 20:23 –d—– c:\windows\SHELLNEW 2009-02-24 19:57 –d—– c:\program files\CCleaner 2009-02-22 09:54 –d—– c:\docume~1\dellus~1\applic~1\Intel 2009-02-22 09:53 –d—– c:\documents and settings\Dell User 2009-02-21 22:07 –d—– c:\windows\RegisteredPackages 2009-02-21 21:50 –d—– c:\windows\system32\LogFiles 2009-02-21 21:30 9,600 ac—— c:\windows\system32\dllcache\hidusb.sys 2009-02-21 21:30 9,600 a——- c:\windows\system32\drivers\hidusb.sys 2009-02-21 21:30 31,616 ac—— c:\windows\system32\dllcache\usbccgp.sys 2009-02-21 21:30 31,616 a——- c:\windows\system32\drivers\usbccgp.sys 2009-02-21 21:24 –d—– c:\program files\Serato 2009-02-21 21:13 –d—– c:\program files\common files\Software Update Utility 2009-02-21 21:13 –d—– c:\program files\AIM Toolbar 2009-02-21 21:13 –d—– c:\docume~1\alluse~1\applic~1\AIM Toolbar 2009-02-21 21:13 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint 2009-02-21 21:13 –d—– c:\program files\Viewpoint 2009-02-21 21:13 –d—– c:\docume~1\alluse~1\applic~1\acccore 2009-02-21 21:12 –d—– c:\program files\common files\AOL 2009-02-21 21:12 –d—– c:\program files\AIM6 2009-02-21 21:12 370 a—h— C:\IPH.PH 2009-02-21 20:57 21,425 a——- c:\windows\system32\drivers\AegisP.sys 2009-02-21 20:56 2,732,032 a——- c:\windows\system32\Netw2r32.dll 2009-02-21 20:56 2,209,408 a——- c:\windows\system32\drivers\w29n51.sys 2009-02-21 20:56 557,056 a——- c:\windows\system32\Netw2c32.dll 2009-02-21 20:55 –d—– c:\program files\ATI Technologies 2009-02-21 20:54 –d—– c:\program files\SigmaTel 2009-02-21 20:52 –d—– c:\windows\system32\ReinstallBackups 2009-02-21 20:47 –d—– c:\program files\Broadcom 2009-02-21 20:47 –d—– c:\windows\Downloaded Installations 2009-02-21 20:47 –d—– C:\dell 2009-02-21 20:46 26,496 ac—— c:\windows\system32\dllcache\usbstor.sys 2009-02-21 19:22 –ds—- c:\windows\system32\Microsoft 2009-02-21 19:22 8,192 a——- c:\windows\REGLOCS.OLD 2009-02-21 19:14 229,439 ac—— c:\windows\system32\dllcache\multibox.dll 2009-02-21 19:13 43,520 ac—— c:\windows\system32\dllcache\EXCH_fcachdll.dll 2009-02-21 19:12 2,577 a——- c:\windows\system32\CONFIG.NT 2009-02-21 19:12 0 a——- c:\windows\control.ini 2009-02-21 19:12 23,392 a——- c:\windows\system32\nscompat.tlb 2009-02-21 19:12 16,832 a——- c:\windows\system32\amcompat.tlb 2009-02-21 19:12 316,640 a——- c:\windows\WMSysPr9.prx 2009-02-21 19:11 –dsh— c:\documents and settings\all users\DRM 2009-02-21 19:11 488 a—hr– c:\windows\system32\WindowsLogon.manifest 2009-02-21 19:11 488 a—hr– c:\windows\system32\logonui.exe.manifest 2009-02-21 19:11 –ds—- c:\windows\Downloaded Program Files 2009-02-21 19:11 –d–r– c:\windows\Offline Web Pages 2009-02-21 19:11 749 a—hr– c:\windows\WindowsShell.Manifest 2009-02-21 19:11 749 a—hr– c:\windows\system32\wuaucpl.cpl.manifest 2009-02-21 19:11 749 a—hr– c:\windows\system32\sapi.cpl.manifest 2009-02-21 19:11 749 a—hr– c:\windows\system32\nwc.cpl.manifest 2009-02-21 19:11 749 a—hr– c:\windows\system32\ncpa.cpl.manifest 2009-02-21 19:11 749 a—hr– c:\windows\system32\cdplayer.exe.manifest 2009-02-21 19:11 –d-h— c:\program files\WindowsUpdate 2009-02-21 19:10 –d—– c:\program files\common files\MSSoap 2009-02-21 19:08 –d—– c:\program files\Online Services 2009-02-21 19:08 –d—– c:\program files\Messenger 2009-02-21 19:08 –d—– c:\program files\MSN Gaming Zone 2009-02-21 19:07 –d—– c:\program files\Windows NT 2009-02-21 10:58 –d—– c:\program files\common files\ODBC 2009-02-21 10:58 –d—– c:\program files\common files\SpeechEngines 2009-02-21 10:58 –d–r– c:\documents and settings\all users\Documents ==================== Find3M ==================== 2009-02-21 19:27 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-02-21 19:08 21,640 a——- c:\windows\system32\emptyregdb.dat ============= FINISH: 21:07:20.73 ===============

Attachments:

Hi,

Please download OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    c:\windows\system32\gaopdxcounter
    C:\autorun.inf
    c:\windows\system32\budda

    :Commands
    [emptytemp]
    [Reboot]

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please run this online scan, using Internet Explorer with Administrator priviledges (Vista users right-click and select Run As Administrator…):

Panda Activescan
  • Once you are on the Panda site, click the Scan now button
  • When prompted to install ActiveX control click Install
  • On the update page, click on the security warning at the top of the page and select "Run ActiveX control…"
  • Panda should now start scanning your system.
  • When the scan completes, if anything malicious is detected, click the Export To…(with a little notepad icon) button, then Save the report to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log. Also, please give a detailed description of how your computer is running and behaving at the moment, listing any remaining problems.

Thanks.
My computer seems to be running smoother so far and i can now access the :C drive. I dont know if theres any other problems but it seems like its running smooth. Does it look like I still have a bug? Thanks for all your help!

OTMoveIt:

========== FILES ==========
c:\windows\system32\gaopdxcounter moved successfully.
C:\autorun.inf moved successfully.
c:\windows\system32\budda moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\DELLUS~1\LOCALS~1\Temp\etilqs_00y0M6I3CEAb3JgpoQ6H scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\JET8DA9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_338.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Documents and Settings\Dell User\Local Settings\Application Data\Mozilla\Firefox\Profiles\vu3hdij8.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Dell User\Local Settings\Application Data\Mozilla\Firefox\Profiles\vu3hdij8.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Dell User\Local Settings\Application Data\Mozilla\Firefox\Profiles\vu3hdij8.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Dell User\Local Settings\Application Data\Mozilla\Firefox\Profiles\vu3hdij8.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Dell User\Local Settings\Application Data\Mozilla\Firefox\Profiles\vu3hdij8.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03032009_173023


PANDA ACTIVE SCAN

;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2009-03-03 19:38:50
PROTECTIONS: 1
MALWARE: 7
SUSPECTS: 0
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
Norton AntiVirus [removed] Yes Yes
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Administrator\Cookies\administrator@doubleclick[1].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Andre\Cookies\andre@doubleclick[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Andre\Cookies\andre@atdmt[2].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Andre\Cookies\andre@247realmedia[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Andre\Cookies\[removed][2].txt
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\Andre\Cookies\andre@atwola[1].txt
00590315 Rootkit/Agent.LNB HackTools No 0 Yes No C:\System Volume Information\_restore{8400DD3F-208C-454F-897E-C8473A145A1E}\RP15\A0001666.sys
05117593 Generic Malware Virus/Trojan No 0 Yes No C:\Documents and Settings\Dell User\Desktop\New Folder (3)\Batch.Watermark.Creator.v6.5.Keygen.exe
;===============================================================================
=================================================================================
===================
SUSPECTS
Sent Location 7*
;===============================================================================
=================================================================================
===================
;===============================================================================
=================================================================================
===================
VULNERABILITIES
Id Severity Description 7*
;===============================================================================
=================================================================================
===================
184380 MEDIUM MS08-002 7*
184379 MEDIUM MS08-001 7*
182048 HIGH MS07-069 7*
182046 HIGH MS07-067 7*
182043 HIGH MS07-064 7*
179553 HIGH MS07-061 7*
176382 HIGH MS07-057 7*
176383 HIGH MS07-058 7*
170911 HIGH MS07-050 7*
170907 HIGH MS07-046 7*
170906 HIGH MS07-045 7*
170904 HIGH MS07-043 7*
164915 HIGH MS07-035 7*
164913 HIGH MS07-033 7*
164911 HIGH MS07-031 7*
160623 HIGH MS07-027 7*
157262 HIGH MS07-022 7*
157261 HIGH MS07-021 7*
157260 HIGH MS07-020 7*
157259 HIGH MS07-019 7*
156477 HIGH MS07-017 7*
150253 HIGH MS07-016 7*
150249 HIGH MS07-013 7*
150248 HIGH MS07-012 7*
150247 HIGH MS07-011 7*
150243 HIGH MS07-008 7*
150242 HIGH MS07-007 7*
150241 MEDIUM MS07-006 7*
141034 HIGH MS06-076 7*
141033 MEDIUM MS06-075 7*
141030 HIGH MS06-072 7*
137571 HIGH MS06-070 7*
137568 HIGH MS06-067 7*
133387 MEDIUM MS06-065 7*
133386 MEDIUM MS06-064 7*
133385 MEDIUM MS06-063 7*
133379 HIGH MS06-057 7*
131654 HIGH MS06-055 7*
129977 MEDIUM MS06-053 7*
129976 MEDIUM MS06-052 7*
126093 HIGH MS06-051 7*
126092 MEDIUM MS06-050 7*
126087 HIGH MS06-046 7*
126086 MEDIUM MS06-045 7*
126083 HIGH MS06-042 7*
126082 HIGH MS06-041 7*
126081 HIGH MS06-040 7*
123421 HIGH MS06-036 7*
123420 HIGH MS06-035 7*
120825 MEDIUM MS06-032 7*
120823 MEDIUM MS06-030 7*
120818 HIGH MS06-025 7*
120815 HIGH MS06-022 7*
120814 HIGH MS06-021 7*
117384 MEDIUM MS06-018 7*
114666 HIGH MS06-015 7*
114664 HIGH MS06-013 7*
108744 MEDIUM MS06-008 7*
108743 MEDIUM MS06-007 7*
108742 MEDIUM MS06-006 7*
104567 HIGH MS06-002 7*
104237 HIGH MS06-001 7*
96574 HIGH MS05-053 7*
93395 HIGH MS05-051 7*
93394 HIGH MS05-050 7*
93454 MEDIUM MS05-049 7*
;===============================================================================
=================================================================================
===================


HIJACK THIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:35 PM, on 3/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\IPSBHO.DLL
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.1.0.33\ccSvcHst.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 5454 bytes
Hi,

Here's where your problem probably came from:
C:\Documents and Settings\Dell User\Desktop\New Folder (3)\Batch.Watermark.Creator.v6.5.Keygen.exe

Cracks/Keygens are a great source of Malware. For your own sake, don't use them. If you come back here with Malware problems and you are using cracks again you will likely be refused assistance.

Anyway - things are looking a lot better.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Any more problems?

Thanks.
Hi nikeman

Glad to hear things are running better :thumbup:

Clean up with OTMoveIt3
  • Double-click OTMoveIt3.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
You can now delete any other tools I had you download and use, unless you wish to keep them.

Set correct settings for files that should be hidden in Windows XP
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please checkHide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK

Now that your system appears to be clean, there's just a few steps I'd like you to take to prevent any future infections.
  • System restore:
    We will now clear your existing system restore points and establish a new clean restore point:
    • Go to Start > All Programs > Accessories > System Tools > System Restore
    • Select Create a restore point, and Ok it.
    • Next, go to Start > Run and type in cleanmgr
    • Select the More options tab
    • Choose the option to clean up system restore and OK it.

      This will remove all restore points except the new one you just created.
    Make sure you do this now, as your System Restore currently has infected files in it.

  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • You don't appear to be running any third party Firewall software.

    Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
    1) Comodo
    2) Agnitum
    3) Sunbelt/Kerio

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI