This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] All browser search results hijacked

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is hjt log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:46:18 PM, on 6/21/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Users\Steve\Downloads\hthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\QuickSet.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2298B88-F5A2-486E-9EA8-DDD3100CB629}: NameServer = 85.255.112.216,85.255.112.135
O17 - HKLM\System\CCS\Services\Tcpip\..\{E72DCB11-9FF5-4A1A-8140-5242BA681454}: NameServer = 85.255.112.216,85.255.112.135
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.216,85.255.112.135
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.216,85.255.112.135
O18 - Protocol: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - C:\Program Files\Cozi Express\CoziProtocolHandler.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: Marvell Yukon Service (yksvc) - Unknown owner - RUNDLL32.EXE (file missing)

–
End of file - 8377 bytes

pls help!
[external image: Posted Image]

Hi exsurfer, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I will be back to you shortly with instructions. :)
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log. Please be patient and I'd be grateful if you would note the following:

  • I will be working on your malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • If you don't know or understand something, please don't hesitate to say or ask! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Please do not use any tools such as Combofix, Vundofix, or HijackThis fixes without instruction to do so!
  • Finally, stay with this topic until I give you the final 'All clear' post! :thumbup:

As you are running Vista, please run all programs I instruct you to by right clicking and selecting 'Run as Administrator'

0.5) Disable Windows Defender
Windows Defender might interfere with out fixes. To disable your Windows Defender Real-time Protection.

  • Open Windows Defender
  • Click Tools
  • Click General Settings
  • Scroll down to Real Time Protection Options
  • Uncheck Turn on Real Time Protection (recommended)
  • Close Windows Defender

Note:Once your log is clean you can re-enable Windows Defender Real Time Protection.

1) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

2) DDS
[external image: Posted Image]
Please download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop.

3) GMER
Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.

Double click on gmer.exe to run it. It will start running a scan. If it detects rootkit activity, you will receive a prompt to run a full scan. Click Yes.

  • When done, you may receive another notice. Click OK.
  • Click on Save … to save a log.
  • Copy and paste in Gmer.txt and click Save.
  • Close Gmer.

If you receive no notice, click on the Scan button.

  • It will start scanning again.
  • When done, click on Save … to save a log.
  • Copy and paste in Gmer.txt and click Save.
  • Close Gmer.


4) What You Will Need To Post:
  • MBAM log
  • DDS logs
  • GMER log
I am not able to run Malwarebytes. Here is error msg log:

Problem signature:

Problem Event Name: APPCRASH

Application Name: mbam.exe

Application Version: 1.38.0.0

Application Timestamp: 4a39169f

Fault Module Name: mbam.exe

Fault Module Version: 1.38.0.0

Fault Module Timestamp: 4a39169f

Exception Code: 80000003

Exception Offset: 00002dd0

OS Version: 6.0.6001.2.1.0.768.3

Locale ID: 1033

Additional Information 1: 9642

Additional Information 2: ae4d667f021e2f38615b5829d1b89b9c

Additional Information 3: ad9c

Additional Information 4: 55232aa3e729cd7dc71289e429099fb7

I could not download it from the link u gave, but I had previously obtained it in anticipation of this need (on another computer and transfered it to this one.) Version is latest as of last week. I tried in safe mode, I tried renaming.. nothing works. This malware blocks anything it thinks is antimalware download or program. it's Nasty and Smart.

Awaiting instruction.

Steve.
DDS LOG DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 19:30:21.68 on Tue 06/23/2009 Internet Explorer: 8.0.6001.18702 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3545.2331 [GMT -7:00] AV: Trend Micro Internet Security *On-access scanning enabled* (Outdated) {7D2296BC-32CC-4519-917E-52E652474AF5} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\svchost.exe -k LocalService C:\Windows\System32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\STacSV.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Program Files\Dell\DellDock\DockLogin.exe C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\aestsrv.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\RUNDLL32.EXE C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\Windows\system32\taskeng.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\Program Files\IDT\WDM\sttray.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Steve\Desktop\dds.scr ============== Pseudo HJT Report =============== uLocal Page = \blank.htm uWindow Title = Internet Explorer provided by Dell BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [QuickSet] c:\program files\dell\quickset\QuickSet.exe mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe" mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe" mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\mapp\mbamgui.exe /install /silent mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab TCP: NameServer = 85.255.112.216,85.255.112.135 TCP: {C2298B88-F5A2-486E-9EA8-DDD3100CB629} = 85.255.112.216,85.255.112.135 TCP: {E72DCB11-9FF5-4A1A-8140-5242BA681454} = 85.255.112.216,85.255.112.135 Handler: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\program files\cozi express\CoziProtocolHandler.dll Notify: igfxcui - igfxdev.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\steve\appdata\roaming\mozilla\firefox\profiles\0xvqyk2s.default\ FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll ============= SERVICES / DRIVERS =============== R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-6-19 28544] R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\drivers\tmlwf.sys [2008-10-2 142352] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_ae0b52e0\AEstSrv.exe [2009-4-18 81920] R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-12-18 155648] R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512] R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-10-2 52624] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-10-2 36368] R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\drivers\tmwfp.sys [2008-10-2 234512] R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc –> RUNDLL32.EXE ykx32coinst,serviceStartProc [?] R3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2009-6-2 488768] R3 tmproxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2009-6-2 648456] S3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\dellsu~1\hwdiag\bin\PCD5SRVC.pkms [2008-11-4 22904] =============== Created Last 30 ================ 2009-06-23 19:28 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-23 19:28 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-23 19:28 –d—– c:\programdata\Malwarebytes 2009-06-23 19:28 –d—– c:\program files\Mapp 2009-06-23 19:28 –d—– c:\progra~2\Malwarebytes 2009-06-22 18:44 –d—– c:\program files\Mobiola Camera S60 2009-06-22 18:03 114,688 a——- c:\windows\system32\BTCamVideoSource.dll 2009-06-19 17:46 28,544 a——- c:\windows\system32\drivers\pavboot.sys 2009-06-19 17:46 –d—– c:\program files\Panda Security 2009-06-12 19:32 –d—– c:\users\steve\DoctorWeb 2009-06-11 11:06 –d—– C:\SDFix 2009-06-10 01:17 a-d—– c:\programdata\TEMP 2009-06-09 18:37 –d—– c:\program files\NoAdware 2009-06-06 15:53 815,104 a——- c:\windows\system32\xvidcore.dll 2009-06-06 15:53 180,224 a——- c:\windows\system32\xvidvfw.dll 2009-06-06 15:53 77,824 a——- c:\windows\system32\xvid.ax 2009-06-06 15:53 –d—– c:\program files\Xvid 2009-06-06 14:29 –d—– c:\users\steve\appdata\roaming\AVS4YOU 2009-06-06 14:29 –d—– c:\programdata\AVS4YOU 2009-06-06 14:29 –d—– c:\progra~2\AVS4YOU 2009-06-06 10:55 271,704 a——- c:\windows\system32\hpzids01.dll 2009-06-06 10:55 118,272 a——- c:\windows\system32\hpz3l692.dll 2009-06-06 10:16 –d—– c:\program files\common files\AVSMedia 2009-06-06 10:16 1,700,352 a——- c:\windows\system32\GdiPlus.dll 2009-06-06 10:16 974,848 a——- c:\windows\system32\mfc70.dll 2009-06-06 10:16 487,424 a——- c:\windows\system32\msvcp70.dll 2009-06-06 10:16 344,064 a——- c:\windows\system32\msvcr70.dll 2009-06-06 10:16 24,576 a——- c:\windows\system32\msxml3a.dll 2009-06-06 10:16 –d—– c:\program files\AVS4YOU 2009-06-06 09:23 –d—– c:\program files\Smart FLV Converter 2009-06-05 01:17 –d—– c:\windows\system32\QuickTime 2009-06-04 18:40 –d—– c:\program files\uTorrent 2009-06-04 18:39 –d—– c:\users\steve\appdata\roaming\uTorrent 2009-06-04 17:35 3,426,072 a——- c:\windows\system32\d3dx9_32.dll 2009-06-02 21:15 –d—– c:\programdata\Yahoo! 2009-06-02 21:15 –d—– c:\program files\Yahoo! 2009-06-02 20:32 105,016 a——- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll 2009-06-02 20:32 97,800 a——- c:\windows\system32\infocardapi.dll 2009-06-02 20:32 622,080 a——- c:\windows\system32\icardagt.exe 2009-06-02 20:32 43,544 a——- c:\windows\system32\PresentationHostProxy.dll 2009-06-02 20:32 37,384 a——- c:\windows\system32\infocardcpl.cpl 2009-06-02 20:32 11,264 a——- c:\windows\system32\icardres.dll 2009-06-02 20:32 781,344 a——- c:\windows\system32\PresentationNative_v0300.dll 2009-06-02 20:32 326,160 a——- c:\windows\system32\PresentationHost.exe 2009-06-02 20:26 96,760 a——- c:\windows\system32\dfshim.dll 2009-06-02 20:26 282,112 a——- c:\windows\system32\mscoree.dll 2009-06-02 20:26 41,984 a——- c:\windows\system32\netfxperf.dll 2009-06-02 20:25 158,720 a——- c:\windows\system32\mscorier.dll 2009-06-02 20:25 83,968 a——- c:\windows\system32\mscories.dll 2009-06-02 20:18 268,288 a——- c:\windows\system32\schannel.dll 2009-06-02 20:18 7,680 a——- c:\windows\system32\spwmp.dll 2009-06-02 20:18 8,147,456 a——- c:\windows\system32\wmploc.DLL 2009-06-02 20:18 4,096 a——- c:\windows\system32\msdxm.ocx 2009-06-02 20:18 4,096 a——- c:\windows\system32\dxmasf.dll 2009-06-02 20:18 562,176 a——- c:\windows\system32\msdtcprx.dll 2009-06-02 20:18 38,912 a——- c:\windows\system32\xolehlp.dll 2009-06-02 20:18 376,832 a——- c:\windows\system32\winhttp.dll 2009-06-02 20:18 241,152 a——- c:\windows\system32\PortableDeviceApi.dll 2009-06-02 20:18 147,456 a——- c:\windows\system32\Faultrep.dll 2009-06-02 20:18 125,952 a——- c:\windows\system32\wersvc.dll 2009-06-02 20:17 2,033,152 a——- c:\windows\system32\win32k.sys 2009-06-02 20:09 1,524,736 a——- c:\windows\system32\wucltux.dll 2009-06-02 20:09 83,456 a——- c:\windows\system32\wudriver.dll 2009-06-02 20:09 162,064 a——- c:\windows\system32\wuwebv.dll 2009-06-02 20:09 31,232 a——- c:\windows\system32\wuapp.exe 2009-06-02 19:45 –d—– c:\windows\system32\log 2009-06-01 23:25 –d—– c:\users\steve\Tracing 2009-06-01 10:04 –d—– c:\users\steve\appdata\roaming\Dell 2009-06-01 10:04 –d—– c:\users\Steve 2009-06-01 10:00 –dsh— c:\programdata\Documents 2009-06-01 10:00 –dsh— C:\Documents and Settings ==================== Find3M ==================== 2009-06-06 10:55 143,360 a——- c:\windows\inf\infstrng.dat 2009-06-06 10:55 86,016 a——- c:\windows\inf\infstor.dat 2009-06-06 10:55 51,200 a——- c:\windows\inf\infpub.dat 2009-04-18 04:14 665,600 a——- c:\windows\inf\drvindex.dat 2009-04-18 04:13 26,112 a——- c:\windows\system32\hidserv.dll 2009-04-18 04:13 22,016 a——- c:\windows\system32\hid.dll 2009-04-18 04:12 1,191,936 a——- c:\windows\system32\msxml3.dll 2009-04-18 04:11 468,992 a——- c:\windows\system32\newdev.dll 2009-04-18 04:11 74,752 a——- c:\windows\system32\newdev.exe 2009-04-18 04:11 180,224 a——- c:\windows\system32\scrobj.dll 2009-04-18 04:11 172,032 a——- c:\windows\system32\scrrun.dll 2009-04-18 04:11 155,648 a——- c:\windows\system32\wscript.exe 2009-04-18 04:11 135,168 a——- c:\windows\system32\cscript.exe 2009-04-18 04:11 90,112 a——- c:\windows\system32\wshext.dll 2009-04-18 04:09 1,645,568 a——- c:\windows\system32\connect.dll 2009-04-18 04:08 296,960 a——- c:\windows\system32\gdi32.dll 2009-04-18 04:08 2,927,104 a——- c:\windows\explorer.exe 2009-04-18 04:07 738,304 a——- c:\windows\system32\inetcomm.dll 2009-04-18 04:06 269,312 a——- c:\windows\system32\es.dll 2009-04-18 04:03 2,048 a——- c:\windows\system32\tzres.dll 2009-04-18 04:02 428,544 a——- c:\windows\system32\EncDec.dll 2009-04-18 04:02 293,376 a——- c:\windows\system32\psisdecd.dll 2009-04-18 04:02 361,984 a——- c:\windows\system32\IPSECSVC.DLL 2009-04-18 04:00 303,616 a——- c:\windows\system32\wmpeffects.dll 2009-04-18 03:57 885,248 a——- c:\windows\system32\RacEngn.dll 2009-04-18 03:56 1,314,816 a——- c:\windows\system32\quartz.dll 2009-04-18 03:55 425,472 a——- c:\windows\system32\PhotoMetadataHandler.dll 2009-04-18 03:55 712,704 a——- c:\windows\system32\WindowsCodecs.dll 2009-04-18 03:55 347,648 a——- c:\windows\system32\WindowsCodecsExt.dll 2009-04-18 03:54 12,240,896 a——- c:\windows\system32\NlsLexicons0007.dll 2009-04-18 03:54 2,644,480 a——- c:\windows\system32\NlsLexicons0009.dll 2009-04-18 03:54 801,280 a——- c:\windows\system32\NaturalLanguage6.dll 2009-04-18 03:50 1,334,272 a——- c:\windows\system32\msxml6.dll 2009-04-18 03:49 2,868,736 a——- c:\windows\system32\mf.dll 2009-04-18 03:49 996,352 a——- c:\windows\system32\WMNetMgr.dll 2009-04-18 03:49 94,720 a——- c:\windows\system32\logagent.exe 2009-04-18 03:49 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll 2009-04-18 03:49 2,154,496 a——- c:\windows\apppatch\AcGenral.dll 2009-04-18 03:49 1,695,744 a——- c:\windows\system32\gameux.dll 2009-04-18 03:49 541,696 a——- c:\windows\apppatch\AcLayers.dll 2009-04-18 03:49 460,288 a——- c:\windows\apppatch\AcSpecfc.dll 2009-04-18 03:49 173,056 a——- c:\windows\apppatch\AcXtrnal.dll 2009-04-18 03:49 52,736 a——- c:\windows\apppatch\iebrshim.dll 2009-04-18 03:49 28,672 a——- c:\windows\system32\Apphlpdm.dll 2009-04-18 03:48 408,064 a——- c:\windows\system32\msinfo32.exe 2009-04-18 03:48 15,872 a——- c:\windows\system32\hcrstco.dll 2009-04-18 03:48 8,704 a——- c:\windows\system32\hccoin.dll 2009-04-18 03:48 2,560 a——- c:\windows\apppatch\AcRes.dll 2009-04-18 03:48 246,840 a——- c:\windows\system32\clfs.sys 2009-04-18 03:48 320,512 a——- c:\windows\system32\imapi2.dll 2009-04-18 03:48 1,312,256 a——- c:\windows\system32\WMALFXGFXDSP.dll 2009-04-18 03:48 338,944 a——- c:\windows\system32\SysFxUI.dll 2009-04-18 03:48 177,208 a——- c:\windows\system32\halmacpi.dll 2009-04-18 03:48 141,880 a——- c:\windows\system32\halacpi.dll 2008-01-20 19:43 174 a–sh— c:\program files\desktop.ini 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 05:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 05:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 02:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 02:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 19:31:03.86 =============== DDS "Attach" log: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-05-14.01) Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 4/17/2009 8:25:08 PM System Uptime: 6/23/2009 7:24:27 PM (0 hours ago) Motherboard: Dell Inc. | | 0G848F Processor: Intel® Pentium® Dual CPU T3400 @ 2.16GHz | Microprocessor | 2167/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 134 GiB total, 84.069 GiB free. E: is FIXED (NTFS) - 15 GiB total, 7.752 GiB free. F: is CDROM (CDFS) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== ==== Installed Programs ====================== µTorrent Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Reader 9 AVS Update Manager 1.0 AVS Video Converter 6 AVS4YOU Software Navigator 1.3 Choice Guard Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Compatibility Pack for the 2007 Office system Consumer In-Home Service Agreement Cozi Dell Dock Dell Edoc Viewer Dell Getting Started Guide Dell Support Center (Support Software) Dell Touchpad Dell Wireless WLAN Card Utility DELL0703 FLV Player 2.0 (build 25) HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel® Matrix Storage Manager Java™ 6 Update 13 Junk Mail filter update Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works Mobiola Web Camera for S60 3.0.15 Move Media Player Mozilla Firefox (3.0.11) MSVCRT Panda ActiveScan 2.0 PowerDVD QuickSet Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Smart FLV Converter [removed] Trend Micro Internet Security WildTangent Games Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer WinRAR archiver Xvid 1.2.1 final uninstall Yahoo! Messenger ==== End Of File ===========================
Ok, let's start cleaning.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
1) Batch Fix
Launch Notepad, and copy/paste everything in the codebox below into the new document. Go up to "File Save As" and click the drop-down box to change the "Save As Type" to "All Files" and save it to your desktop as runme.bat.

@echo off
sc stop yksvc
sc delete yksvc
del %0

2) Run the Fix
Locate runme.bat on your Desktop and double-click on it.

3) Kaspersky Online
I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.


Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

As you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan. Otherwise it will not work

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

4) What You Will Need To Post:
  • Kaspersky log
The logs are clean. :thumbup: Everything performing well now?

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]
The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

Do not install more than one firewall program because they will conflict with each other

4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

8. Finally, I strongly recommend that you read Miekiemoses' good advice - How to prevent Malware

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI