This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Computer/Firefox slow

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm assuming my twofold problem is actually one issue. It started with Firefox taking 30 seconds to come up after I clicked the button. Now, it takes 5 minutes minimum, and the entire computer is slow. Minimizing windows takes painfully long as does opening docs.

I do disk cleanup and defrag once a week. I have the latest Windows update; My F-Secure is up-to-date as well. I've done the ATF cleaner, Malwarebytes' scan, and HiJackThis. Computer was rebooted. Still having problems. My HiJackThis log and Malwarebytes log are below:

HiJackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:03:31 AM, on 8/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure Internet Security\FSAUA\program\fsus.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\PROGRA~1\HPQ\SHARED\HPQTOA~1.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\yael\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: Add to AMV Converter… - C:\Program Files\MP3 Player Utilities 4.15\AMVConverter\grab.html
O8 - Extra context menu item: Add to Media Manager… - C:\Program Files\MP3 Player Utilities 4.15\MediaManager\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: PUFLITE - http://kathleenhartson.point2agent.com/Off…rol/PUFLITE.CAB
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/framework/contr…vex/TmHcmsX.CAB
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {5CE72DD0-4695-4D18-A4D3-3367ACD37578} (F-Secure Health Check 1.0) - http://support.f-secure.com/enu/home/onlin…/fshc/fscax.cab
O16 - DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} (PowerTeam HTML Printing Behavior) - file:///C:/DOCUME~1/KATHLE~1/LOCALS~1/Temp/IXP000.TMP/setup.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1177562162625
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1177564770375
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-27b0f8353e96399c.spaces.live.co…ad/MsnPUpld.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: VNC Server (winvnc) - TightVNC Group - C:\Program Files\TightVNC\WinVNC.exe

–
End of file - 8957 bytes


Malwarebytes' scan:

Malwarebytes' Anti-Malware 1.40
Database version: 2559
Windows 5.1.2600 Service Pack 3

8/4/2009 1:44:56 PM
mbam-log-2009-08-04 (13-44-26).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 193436
Time elapsed: 4 hour(s), 0 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 135

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\moreltech\Start Menu\usa (Rogue.USAntiSpy) -> No action taken.

Files Infected:
C:\Documents and Settings\moreltech\Start Menu\usa\brdp128c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp128c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp129c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp129c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp130c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp130c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp131c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp131c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp329c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp329c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp330c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp330c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp331c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp331c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp540c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp540c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp75cn.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp75cn.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp75cw.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brdp75cw.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brfx1860.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brfx1860.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brfx1960.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brfx1960.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brfx2480.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brfx2480.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brfx2580.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brfx2580.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\bril06a.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brimbh72.cat (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brimbh72.inf (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brio06a.da_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brio06a.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brio06a.hl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brio06aa.bc_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brio06ab.bc_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brio06ac.bc_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brio06af.bc_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brio06ag.bc_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\briu06a.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\briwm06a.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf239c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf239c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf240c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf240c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf3360.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf3360.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf440c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf440c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf460c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf460c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf5460.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf5460.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf5860.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf5860.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf63cd.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf63cd.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf660c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf660c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf665c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf665c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf845c.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf845c.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf85cd.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf85cd.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf86cd.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brmf86cd.pd_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brpobh72.cat (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brpobh72.inf (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brprbh72.cat (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brprbh72.inf (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brqikmon.ex_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brqikmon.hl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brs05lng.hl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brscndev.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brscnusb.sy_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brserif.sy_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brsti06a.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brstiif.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brtwdfe.ds_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brtwdlng.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brtwds.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brtwdscn.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brtwdsui.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brusbser.sy_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brusi06a.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\brwia06a.dl_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc128cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc129cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc130cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc131cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc329cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc330cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc331cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc540cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc750cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\dc750cwu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf239cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf240cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf3260cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf3360cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf440cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf460cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf5460cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf5860cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf630cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf660cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf665cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf845cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf850cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\mf860cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc128cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc129cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc130cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc131cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc329cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc330cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc331cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc540cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc750cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twdc750cwu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf239cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf240cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf3260cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf3360cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf440cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf460cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf5460cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf5860cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf630cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf660cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf665cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf845cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf850cu.in_ (Rogue.USAntiSpy) -> No action taken.
C:\Documents and Settings\moreltech\Start Menu\usa\twmf860cu.in_ (Rogue.USAntiSpy) -> No action taken.


The moreltech files are actually used by an old tech support person who checked our computer remotely. Malwarebytes says the files are infected, but scan usually don't like those files.

Help?
Hi Yoli,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

The moreltech files are actually used by an old tech support person who checked our computer remotely. Malwarebytes says the files are infected, but scan usually don't like those files.

Those files all appear to be compressed .ini files for every brothers brand printer ever made. Why do you keep them?

Please download gmer.zip from Gmer and save it to your desktop.

  • Right click on gmer.zip and select Extract All….
  • Click Next on seeing the Welcome to the Compressed (zipped) Folders Extraction Wizard.
  • Click on the Browse button. Click on Desktop. Then click OK.
  • Click Next. It will start extracting.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Double click on gmer.exe to run it.
  • Select the Rootkit tab.
  • On the right hand side, check all the items to be scanned, but leave Show All box unchecked.
  • Select all drives that are connected to your system to be scanned.
  • Click on the Scan button.
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard.
  • Open Notepad or a similar text editor.
  • Paste the clipboard contents into the text editor.
  • Save the Gmer scan log and post it in your next reply.

Note: Do not run any programs while Gmer is running.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Thank you so much for helping me out! I have followed your instructions and pasted the requested logs below.

Those files all appear to be compressed .ini files for every brothers brand printer ever made. Why do you keep them?


Really? I had no idea. If they aren't necessary, I'd like to remove them.

Here's the gmer scan log:

GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-11 13:56:01
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwCreateProcess [0xF7664740]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwCreateProcessEx [0xF766475A]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwLoadDriver [0xF7663FB2]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwOpenSection [0xF7664266]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwRenameKey [0xF766514E]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwSetSystemInformation [0xF7664160]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwSuspendProcess [0xF76639C6]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwSuspendThread [0xF7663C12]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwSystemDebugControl [0xF7663E8E]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwTerminateProcess [0xF76638AC]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwTerminateThread [0xF7663ADE]
SSDT \??\C:\Program Files\F-Secure Internet Security\HIPS\fshs.sys ZwWriteVirtualMemory [0xF7663D46]

Code \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation) IoCreateDevice

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2758 80501F90 12 Bytes [C6, 39, 66, F7, 12, 3C, 66, …]
PAGE ntkrnlpa.exe!IoCreateDevice 8056AB56 5 Bytes JMP F77AAB14 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisRegisterProtocol F724417F 5 Bytes JMP F77AA900 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisOpenAdapter F7244399 5 Bytes JMP F77AAF76 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisCloseAdapter F724E642 5 Bytes JMP F77AAA16 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENPNP NDIS.SYS!NdisDeregisterProtocol F724E821 5 Bytes JMP F77AAD88 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisReturnPackets F7251810 5 Bytes JMP F77AC3EC \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisRequest F725197B 5 Bytes JMP F77AB792 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisSend F7254986 5 Bytes JMP F77ACDF2 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisSendPackets F72549A3 5 Bytes JMP F77ACEC4 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENDSP NDIS.SYS!NdisTransferData F72549BE 5 Bytes JMP F77AC4EA \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoCreateVc F725B186 5 Bytes JMP F77AA970 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoDeleteVc F725C557 5 Bytes JMP F77AA9DE \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
PAGENDCO NDIS.SYS!NdisCoSendPackets F725CAF1 5 Bytes JMP F77ACBC0 \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 EABFiltr.sys (QLB PS/2 Keyboard filter driver/Hewlett-Packard Development Company, L.P.)

Device \Driver\Tcpip \Device\Tcp fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
Device \Driver\Tcpip \Device\Udp fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
Device \Driver\Tcpip \Device\RawIp fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)
Device \Driver\Tcpip \Device\IPMULTICAST fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-



The DDS log:


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 13:40:21.44 on Tue 08/11/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.584 [GMT -7:00]

AV: F-Secure Internet Security 2008 8.00 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: F-Secure Internet Security 2008 8.00 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Documents and Settings\yael\Desktop\gmer\gmer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\yael\Desktop\dds.scr
C:\Program Files\F-Secure Internet Security\Common\FSLAUNCHER0.EXE

============== Pseudo HJT Report ===============

uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [F-Secure Manager] "c:\program files\f-secure internet security\common\FSM32.EXE" /splash
mRun: [F-Secure TNB] "c:\program files\f-secure internet security\fsgui\TNBUtil.exe" /CHECKALL /WAITFORSW
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hppsc2~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpobnz08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe
IE: Add to AMV Converter… - c:\program files\mp3 player utilities 4.15\amvconverter\grab.html
IE: Add to Media Manager… - c:\program files\mp3 player utilities 4.15\mediamanager\grab.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {200DB664-75B5-47c0-8B45-A44ACCF73C00} - {D68926FD-18FD-4B0E-A1C7-917D13FAB760} - c:\program files\f-secure internet security\fspc\fspcmsie.dll
IE: {200DB664-75B5-47c0-8B45-A44ACCF73F01} - {D68926FD-18FD-4B0E-A1C7-917D13FAB760} - c:\program files\f-secure internet security\fspc\fspcmsie.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: PUFLITE - hxxp://kathleenhartson.point2agent.com/Office/ColpaControls/Photo/Control/PUFLITE.CAB
DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} - hxxp://www.trendsecure.com/framework/control/en-US/activex/TmHcmsX.CAB
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1005.cab
DPF: {5CE72DD0-4695-4D18-A4D3-3367ACD37578} - hxxp://support.f-secure.com/enu/home/onlineservices/fshc/fscax.cab
DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} - file:///C:/DOCUME~1/KATHLE~1/LOCALS~1/Temp/IXP000.TMP/setup.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1177562162625
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1177564770375
DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - hxxp://cid-27b0f8353e96399c.spaces.live.com/PhotoUpload/MsnPUpld.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\yael\applic~1\mozilla\firefox\profiles\5vgvii0k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2008-2-21 58128]
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\f-secure internet security\hips\fshs.sys [2008-2-21 41184]
R2 F-Secure Gatekeeper Handler Starter;FSGKHS;c:\program files\f-secure internet security\anti-virus\fsgk32st.exe [2008-2-21 48072]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\f-secure internet security\anti-virus\minifilter\fsgk.sys [2008-2-21 77824]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2005-8-22 231424]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-12-5 33752]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\f-secure internet security\anti-virus\win2k\fsfilter.sys [2008-2-21 40048]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\f-secure internet security\anti-virus\win2k\fsrec.sys [2008-2-21 25456]

=============== Created Last 30 ================

2009-08-11 13:32 –d-h— c:\windows\PIF
2009-08-08 11:05 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat
2009-08-08 00:05 –d—– c:\windows\system32\XPSViewer
2009-08-07 23:59 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-07 23:59 117,760 ——– c:\windows\system32\prntvpt.dll
2009-08-07 23:59 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-07 23:59 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-07 23:59 575,488 ——– c:\windows\system32\xpsshhdr.dll
2009-08-07 23:59 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2009-08-07 23:59 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2009-08-07 23:59 -cd—– C:\2c36467c8f9d22182ad7a956ed
2009-08-04 09:12 –d—– c:\docume~1\yael\applic~1\Malwarebytes
2009-08-04 09:11 -cd—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-04 08:46 –d—– c:\program files\Trend Micro
2009-08-02 13:21 –dsh— c:\documents and settings\yael\PrivacIE

==================== Find3M ====================

2009-07-25 05:23 411,368 a——- c:\windows\system32\deploytk.dll
2009-07-03 10:09 915,456 a——- c:\windows\system32\wininet.dll
2009-06-16 07:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 07:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 12:09 1,291,264 a——- c:\windows\system32\quartz.dll
2008-06-07 14:48 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008060720080608\index.dat

============= FINISH: 13:40:51.89 ===============



The Attach log is attached.

Attachments:

Yoli,

Rerun Malwarebytes and this time be sure that everything is checked, and click Remove Selected.

JavaRa …by: Paul McLain and Fred de Vries

Please download JavaRa (Copyright © 2008 RaProducts.org) and unzip it to your desktop.
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English or the appropriate language…and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.
  • Copy and paste the contents of the JavaRa log, in your next reply.

Please download the OTM by OldTimer.
  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
    (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Files
    C:\Documents and Settings/kathleen/Local Settings/Temp/IXP000.TMP/setup.cab
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Here is my JavaRa log:


JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Wed Aug 12 13:06:29 2009

Found and removed: C:\Program Files\Java\jre1.6.0_01

Found and removed: C:\Documents and Settings\yael\Application Data\Sun\Java\jre1.6.0_10

Found and removed: C:\Documents and Settings\yael\Application Data\Sun\Java\jre1.6.0_11

Found and removed: C:\Documents and Settings\yael\Application Data\Sun\Java\jre1.6.0_12

Found and removed: C:\Documents and Settings\yael\Application Data\Sun\Java\jre1.6.0_14

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Classes\JavaPlugin.160_01

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_01

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610001

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160010}

Found and removed: Software\Classes\JavaPlugin.160_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_01

Found and removed: Software\JavaSoft\Java2D\1.6.0_01

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_01\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_01.b06\

JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Wed Aug 12 13:13:01 2009

————————————

Finished reporting.




And here is the OTM log:


All processes killed
Error: Unable to interpret in the current context!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Kathleen hartson
->Temp folder emptied: 26494327 bytes
->Temporary Internet Files folder emptied: 65938 bytes
->Java cache emptied: 39018526 bytes
->FireFox cache emptied: 72228795 bytes

User: LocalService
->Temp folder emptied: 0 bytes
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
->Temporary Internet Files folder emptied: 33170 bytes

User: moreltech
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 456565 bytes
->FireFox cache emptied: 28893185 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 49554 bytes

User: yael
->Temp folder emptied: 12728597 bytes
->Temporary Internet Files folder emptied: 6219145 bytes
->Java cache emptied: 160894238 bytes
->FireFox cache emptied: 63165968 bytes
->Google Chrome cache emptied: 56386448 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1138887 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 81151 bytes
RecycleBin emptied: 836 bytes

Total Files Cleaned = 446.18 mb


OTM by OldTimer - Version 3.0.0.6 log created on 08122009_132606

Files moved on Reboot…

Registry entries deleted on Reboot…




I am unable to get the Kaspersky download to work. It gets an error during the Updating the Database phase. The error says the update has failed, close and open again, you must be online (which I am), key is expired. I have tried several times to get it to work; I even restarted the computer. I've tried it with my F-secure unloaded. Still didn't work, and now my internet shield is malfunctioning.
Yoli,

It's not you. Apparently Kaspersky is having some issues on their website. Let's run a different scanner.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI