This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infection/malware?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently (@ a week ago) infected by the "InternetSecurity 2010" virus, which put up virus warning on desktop wallpaper and shuts down computer, I think attempting to install spyware or malware. Tried several virus and spyware programs. Spybot S+D seemed to eliminate the problem, but with the following lingering effects: ACTIVITY and LAN are constantly flickering a mile a minute, whereas before the LAN was mostly constant with some blinking, and the ACTIVITY light would only illuminate when browsing/changing web pages. CPU usage is very high. I'd say the average usage is 50-60%, even when the only thing I'm running is the task manager. Range most times is 25% all the way to 100%. This causes the computer to be slow and laggy when I'm typing or browsing. Was able to manually remove the "virus wallpaper", and I can change my wallpaper by selecting image or picture, right-click, and set as wallpaper. Cannot change wallpaper by using the desktop properties window. Any removal I have done (spyware, trojans, etc.) temporarily eliminates the problems, but they soon return. No apparent stealing of passwords or personal info yet. Ran Malawarebytes an hour ago. CPU usage has dropped. Modem activity looked normal for a while, but is now flickering again. I have all logs requested in the getting started portion of this site. Thanks!
DDS log:

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:47:11.71 on Fri 02/19/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.895.429 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8KOA8ZTB\dds[1].scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.facebook.com/
mSearchAssistant = hxxp://toolbar.inbox.com/search/ie.aspx?tbid=80305
mCustomizeSearch = hxxp://toolbar.inbox.com/help/sa_customize.aspx?tbid=80305
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SunKistEM] "c:\program files\digital media reader\shwiconem.exe"
mRun: []
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] "nwiz.exe" /install
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [CHotkey] zHotkey.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\deskto~1.lnk - c:\program files\research in motion\blackberry\DesktopMgr.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: myfantasyleague.com
Trusted Zone: buy-is2010.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {7E9D8851-2735-4B13-9CE4-C5102A25CA2D} = 137.118.1.32,137.118.1.33
Notify: WRNotifier - WRLogonNTF.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]

=============== Created Last 30 ================

2010-02-19 09:27 411,368 a——- c:\windows\system32\deploytk.dll
2010-02-19 09:27 73,728 a——- c:\windows\system32\javacpl.cpl
2010-02-19 08:52 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2010-02-19 08:52 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-19 08:52 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-19 08:52 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-19 08:52 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-19 06:19 –d—– c:\docume~1\alluse~1\applic~1\SpeedyPC
2010-02-13 05:40 –d—– c:\docume~1\owner\applic~1\Uniblue
2010-02-13 05:40 –d—– c:\program files\Uniblue
2010-02-12 23:23 351,526 a——- c:\windows\WBDDA34I.DLL
2010-02-11 23:07 408 a——- c:\windows\wininit.ini
2010-02-11 22:05 –d—– c:\program files\Spybot - Search & Destroy
2010-02-11 22:05 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-02-11 19:30 767,952 a——- c:\windows\BDTSupport.dll.old
2010-02-11 19:30 1,640,400 a——- c:\windows\PCTBDCore.dll.old
2010-02-11 19:26 –d—– c:\program files\common files\PC Tools
2010-02-11 19:26 –d—– c:\docume~1\alluse~1\applic~1\PC Tools
2010-02-11 19:22 –d—– c:\docume~1\owner\applic~1\GetRightToGo

==================== Find3M ====================

2010-02-19 10:44 256 a——- c:\documents and settings\owner\pool.bin
2009-12-31 11:14 352,640 a——- c:\windows\system32\drivers\srv.sys
2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-16 07:58 343,040 a——- c:\windows\system32\mspaint.exe
2009-12-14 02:35 33,280 a——- c:\windows\system32\csrsrv.dll
2009-12-08 13:55 2,180,352 a——- c:\windows\system32\ntoskrnl.exe
2009-12-08 13:19 2,057,728 a——- c:\windows\system32\ntkrnlpa.exe
2009-11-27 12:04 1,291,776 a——- c:\windows\system32\quartz.dll
2009-11-27 12:04 17,920 a——- c:\windows\system32\msyuv.dll
2009-11-27 11:37 84,992 a——- c:\windows\system32\avifil32.dll
2009-11-27 11:37 48,128 a——- c:\windows\system32\iyuv_32.dll
2009-11-27 11:37 28,672 a——- c:\windows\system32\msvidc32.dll
2009-11-27 11:37 11,264 a——- c:\windows\system32\msrle32.dll
2009-11-27 11:37 8,704 a——- c:\windows\system32\tsbyuv.dll
2009-11-21 11:36 470,528 a——- c:\windows\apppatch\aclayers.dll
2009-09-05 15:25 866 a——- c:\docume~1\owner\applic~1\wklnhst.dat
2007-11-22 11:37 94,208 a——- c:\program files\Bast..d.doc
2007-11-22 11:31 1,848,526 a——- c:\program files\BestBeerCommercialoftheYear.wmv
2007-11-22 11:18 736,914 a——- c:\program files\Tequila.wmv
2007-11-22 11:09 34,590 a——- c:\program files\web_071105-N-4776G-279.zip
2007-04-09 16:02 43,132,528 a——- c:\program files\TAV15.1_GM_TAV11Upgrade_32bit.exe

============= FINISH: 10:47:22.60 ===============


GMER Log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-19 10:42:38
Windows 5.1.2600 Service Pack 2
Running: m9qeq6ti.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kgriqpog.sys


—- System - GMER 1.0.15 —-

Code 8497B385 pIofCallDriver

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF65B6360, 0x1FE48D, 0xE8000020]
.text tcpip.sys!IPTransmit + 10BC F374ACFA 6 Bytes CALL 8497B368
.text tcpip.sys!IPTransmit + 263D F374C27B 6 Bytes CALL 8497B368
.text tcpip.sys!ARPRcv + 521E F37514BE 6 Bytes CALL 8497B368
.text wanarp.sys F77D13FD 7 Bytes CALL 8497B375
? C:\DOCUME~1\Owner\LOCALS~1\Temp\kgriqpod.sys The system cannot find the file specified. !

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] 8497A576
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] 8497A56C

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@Group SCSI miniport
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@Tag 42
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@Type 1

—- EOF - GMER 1.0.15 —-
Hi,

If you already have a copy of ComboFix, please delete it.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 10-02-19.04 - Owner 02/20/2010 11:07:21.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.895.439 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix-fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Internet Explorer\SET28F3.tmp
c:\program files\Internet Explorer\SET28F4.tmp
c:\program files\Internet Explorer\SET28F6.tmp
c:\recycler\S-1-5-21-11457409-3420883336-2810106368-500
c:\recycler\S-1-5-21-1590580893-40798335-178600853-500
c:\recycler\S-1-5-21-3462389463-4017558345-1778031126-500
c:\recycler\S-1-5-21-4148369516-415066616-1619009671-500
c:\windows\system32\config\42736510.Evt
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_asc3550p


((((((((((((((((((((((((( Files Created from 2010-01-20 to 2010-02-20 )))))))))))))))))))))))))))))))
.

2010-02-19 14:27 . 2010-02-19 14:27 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-19 14:26 . 2010-02-19 14:26 152576 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-19 14:26 . 2010-02-19 14:26 79488 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-19 13:52 . 2010-02-19 13:52 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-02-19 13:52 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-19 13:52 . 2010-02-19 13:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-19 13:52 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-19 13:52 . 2010-02-19 13:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-19 11:19 . 2010-02-19 11:29 ——– d—–w- c:\documents and settings\All Users\Application Data\SpeedyPC
2010-02-13 10:40 . 2010-02-13 10:40 ——– d—–w- c:\documents and settings\Owner\Application Data\Uniblue
2010-02-13 10:40 . 2010-02-13 10:40 ——– d—–w- c:\program files\Uniblue
2010-02-13 04:23 . 2003-01-10 18:58 351526 —-a-w- c:\windows\WBDDA34I.DLL
2010-02-12 03:05 . 2010-02-19 14:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-12 03:05 . 2010-02-19 14:23 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-12 00:40 . 2010-02-12 00:40 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Threat Expert
2010-02-12 00:36 . 2010-02-12 00:36 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-02-12 00:26 . 2010-02-19 14:41 ——– d—–w- c:\program files\Common Files\PC Tools
2010-02-12 00:26 . 2010-02-19 14:21 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-02-12 00:25 . 2010-02-19 14:21 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-12 00:22 . 2010-02-12 02:48 ——– d—–w- c:\documents and settings\Owner\Application Data\GetRightToGo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-20 16:13 . 2009-05-09 02:49 256 —-a-w- c:\windows\system32\pool.bin
2010-02-19 15:44 . 2010-01-13 08:20 256 —-a-w- c:\documents and settings\Owner\pool.bin
2010-02-19 14:27 . 2005-10-30 06:06 ——– d—–w- c:\program files\Java
2010-02-19 14:13 . 2007-11-24 22:59 ——– d—–w- c:\program files\Yahoo!
2010-02-12 00:31 . 2009-11-16 00:08 ——– d—–w- c:\program files\CA Yahoo! Anti-Spy
2010-01-22 08:12 . 2009-07-01 07:45 ——– d—–w- c:\program files\Microsoft Silverlight
2009-12-31 16:14 . 2005-01-09 23:48 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2005-01-09 23:48 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 12:58 . 2005-01-10 01:05 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2005-01-09 23:47 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:55 . 2005-01-09 23:48 2180352 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-04 05:59 2057728 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2005-01-09 23:48 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:04 . 2005-01-09 23:48 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:04 . 2004-08-04 07:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:37 . 2005-01-09 23:48 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37 . 2005-01-09 23:48 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:37 . 2005-01-09 23:47 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37 . 2004-08-04 07:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37 . 2001-08-18 05:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2007-11-22 16:37 . 2007-11-22 16:37 94208 —-a-w- c:\program files\Bast..d.doc
2007-11-22 16:31 . 2007-11-22 16:31 1848526 —-a-w- c:\program files\BestBeerCommercialoftheYear.wmv
2007-11-22 16:18 . 2007-11-22 16:18 736914 —-a-w- c:\program files\Tequila.wmv
2007-11-22 16:09 . 2007-11-22 16:09 34590 —-a-w- c:\program files\web_071105-N-4776G-279.zip
2007-04-09 21:02 . 2007-04-09 21:01 43132528 —-a-w- c:\program files\TAV15.1_GM_TAV11Upgrade_32bit.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"nwiz"="nwiz.exe" [2005-09-18 1519616]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"CHotkey"="zHotkey.exe" [2005-05-03 543232]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-14 14820864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-19 149280]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-06 177472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-09-19 236016]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-11-4 1545488]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 18:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-02-20 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.facebook.com/
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
Trusted Zone: myfantasyleague.com
Trusted Zone: buy-is2010.com
TCP: {7E9D8851-2735-4B13-9CE4-C5102A25CA2D} = [removed],[removed]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
SafeBoot-svcWRSSSDK
AddRemove-Desktop Weather by The Weather Channel - c:\program files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe
AddRemove-MyLayout Profile Editor - c:\progra~1\Freeze.com\MyLayout Profile Editor\UNINSTAL.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-20 11:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2228)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\zHotkey.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\dwwin.exe
c:\program files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
c:\program files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2010-02-20 11:23:51 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-20 16:23

Pre-Run: 175,508,594,688 bytes free
Post-Run: 175,373,176,832 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

- - End Of File - - 1BFD0C6D89BEBF96EF10DB1E4DB231FF
Glad to hear it, there's just a few things to clear up :thumbup:

We need to run a batch file.
  • Copy the contents of the Code Box below to Notepad.
  • Name the file as del.bat
  • Change the Save as Type to All Files
  • and Save it on your Desktop
@echo off
echo Deleting files…>log.txt
for %%g in (
c:\program files\Bast..d.doc
c:\program files\BestBeerCommercialoftheYear.wmv
c:\program files\Tequila.wmv
c:\program files\web_071105-N-4776G-279.zip
c:\program files\TAV15.1_GM_TAV11Upgrade_32bit.exe
) do (
if exist %%g (
attrib -h -s %%g
del /Q %%g
if exist %%g (
echo Unable to delete %%g >>log.txt
)else echo %%g deleted successfully>>log.txt
) else echo %%g not found >>log.txt
)
start notepad log.txt
del /Q %0
Then double-click on the del.bat file. A log will open, please post the contents of that log in your next reply.


Eset online scannner

You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
Let me know how things are running now, and please post a new DDS log (just DDS.txt).
Here are the requested logs.

del.bat:

Deleting files…
c:\program not found
files\Bast..d.doc not found
c:\program not found
files\BestBeerCommercialoftheYear.wmv not found
c:\program not found
files\Tequila.wmv not found
c:\program not found
files\web_071105-N-4776G-279.zip not found
c:\program not found
files\TAV15.1_GM_TAV11Upgrade_32bit.exe not found


ESET log:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=eaeaea00b6204a438d163469bffe8816
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-02-21 03:24:21
# local_time=2010-02-21 10:24:21 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=79690
# found=6
# cleaned=0
# scan_time=3840
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentwu.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZangoShoppingReport10.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\22\10453ed6-1230636b probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-3ad601a5-32d01c60.zip probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Qoobox\Quarantine\C\WINDOWS\system32\config\42736510.Evt.vir Win32/Nulprot trojan 00000000000000000000000000000000 I
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NJBDKCX7\exe[1].exe Win32/TrojanDownloader.FakeAlert.AED trojan 00000000000000000000000000000000 I



DDS log:

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:33:32.03 on Sun 02/21/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.895.432 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\MBBCYKJ3\dds[1].scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.facebook.com/
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SunKistEM] "c:\program files\digital media reader\shwiconem.exe"
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] "nwiz.exe" /install
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [CHotkey] zHotkey.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\deskto~1.lnk - c:\program files\research in motion\blackberry\DesktopMgr.exe
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: myfantasyleague.com
Trusted Zone: buy-is2010.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {7E9D8851-2735-4B13-9CE4-C5102A25CA2D} = 137.118.1.32,137.118.1.33
Notify: WRNotifier - WRLogonNTF.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]

=============== Created Last 30 ================

2010-02-21 09:17 –d—– c:\program files\ESET
2010-02-20 11:05 a-dshr– C:\cmdcons
2010-02-20 11:04 261,632 a——- c:\windows\PEV.exe
2010-02-20 11:04 161,792 a——- c:\windows\SWREG.exe
2010-02-20 11:04 98,816 a——- c:\windows\sed.exe
2010-02-20 11:04 77,312 a——- c:\windows\MBR.exe
2010-02-19 09:27 411,368 a——- c:\windows\system32\deploytk.dll
2010-02-19 09:27 73,728 a——- c:\windows\system32\javacpl.cpl
2010-02-19 08:52 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2010-02-19 08:52 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-19 08:52 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-19 08:52 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-19 08:52 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-19 06:19 –d—– c:\docume~1\alluse~1\applic~1\SpeedyPC
2010-02-13 05:40 –d—– c:\docume~1\owner\applic~1\Uniblue
2010-02-13 05:40 –d—– c:\program files\Uniblue
2010-02-12 23:23 351,526 a——- c:\windows\WBDDA34I.DLL
2010-02-11 23:07 408 a——- c:\windows\wininit.ini
2010-02-11 22:05 –d—– c:\program files\Spybot - Search & Destroy
2010-02-11 22:05 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-02-11 19:30 767,952 a——- c:\windows\BDTSupport.dll.old
2010-02-11 19:30 1,640,400 a——- c:\windows\PCTBDCore.dll.old
2010-02-11 19:26 –d—– c:\program files\common files\PC Tools
2010-02-11 19:26 –d—– c:\docume~1\alluse~1\applic~1\PC Tools
2010-02-11 19:22 –d—– c:\docume~1\owner\applic~1\GetRightToGo

==================== Find3M ====================

2010-02-19 10:44 256 a——- c:\documents and settings\owner\pool.bin
2009-12-31 11:14 352,640 a——- c:\windows\system32\drivers\srv.sys
2009-12-21 14:14 916,480 ——– c:\windows\system32\wininet.dll
2009-12-16 07:58 343,040 a——- c:\windows\system32\mspaint.exe
2009-12-14 02:35 33,280 a——- c:\windows\system32\csrsrv.dll
2009-12-08 13:55 2,180,352 ——– c:\windows\system32\ntoskrnl.exe
2009-12-08 13:19 2,057,728 ——– c:\windows\system32\ntkrnlpa.exe
2009-11-27 12:04 1,291,776 a——- c:\windows\system32\quartz.dll
2009-11-27 12:04 17,920 a——- c:\windows\system32\msyuv.dll
2009-11-27 11:37 84,992 a——- c:\windows\system32\avifil32.dll
2009-11-27 11:37 48,128 a——- c:\windows\system32\iyuv_32.dll
2009-11-27 11:37 28,672 a——- c:\windows\system32\msvidc32.dll
2009-11-27 11:37 11,264 a——- c:\windows\system32\msrle32.dll
2009-11-27 11:37 8,704 a——- c:\windows\system32\tsbyuv.dll
2009-09-05 15:25 866 a——- c:\docume~1\owner\applic~1\wklnhst.dat
2007-11-22 11:37 94,208 a——- c:\program files\Bast..d.doc
2007-11-22 11:31 1,848,526 a——- c:\program files\BestBeerCommercialoftheYear.wmv
2007-11-22 11:18 736,914 a——- c:\program files\Tequila.wmv
2007-11-22 11:09 34,590 a——- c:\program files\web_071105-N-4776G-279.zip
2007-04-09 16:02 43,132,528 a——- c:\program files\TAV15.1_GM_TAV11Upgrade_32bit.exe

============= FINISH: 10:34:00.64 ===============


Again, everything seems to be running very well. Very fast again.
Hi,

Just a few more things to clear up, then if all is still running well we can clean up our tools and wrap this one up.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\program files\Bast..d.doc
c:\program files\BestBeerCommercialoftheYear.wmv
c:\program files\Tequila.wmv
c:\program files\web_071105-N-4776G-279.zip
c:\program files\TAV15.1_GM_TAV11Upgrade_32bit.exe

DDS::
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: 1 (0x1) - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post ComboFix.txt in your next reply.Thanks.
ComboFix 10-02-19.04 - Owner 02/21/2010 11:20:11.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.895.487 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix-fix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt

FILE ::
"c:\program files\Bast..d.doc"
"c:\program files\BestBeerCommercialoftheYear.wmv"
"c:\program files\TAV15.1_GM_TAV11Upgrade_32bit.exe"
"c:\program files\Tequila.wmv"
"c:\program files\web_071105-N-4776G-279.zip"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Bast..d.doc
c:\program files\BestBeerCommercialoftheYear.wmv
c:\program files\TAV15.1_GM_TAV11Upgrade_32bit.exe
c:\program files\Tequila.wmv
c:\program files\web_071105-N-4776G-279.zip

.
((((((((((((((((((((((((( Files Created from 2010-01-21 to 2010-02-21 )))))))))))))))))))))))))))))))
.

2010-02-21 14:17 . 2010-02-21 14:17 ——– d—–w- c:\program files\ESET
2010-02-19 14:27 . 2010-02-19 14:27 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-19 14:26 . 2010-02-19 14:26 152576 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-19 14:26 . 2010-02-19 14:26 79488 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-19 13:52 . 2010-02-19 13:52 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-02-19 13:52 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-19 13:52 . 2010-02-19 13:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-19 13:52 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-19 13:52 . 2010-02-19 13:52 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-19 11:19 . 2010-02-19 11:29 ——– d—–w- c:\documents and settings\All Users\Application Data\SpeedyPC
2010-02-13 10:40 . 2010-02-13 10:40 ——– d—–w- c:\documents and settings\Owner\Application Data\Uniblue
2010-02-13 10:40 . 2010-02-13 10:40 ——– d—–w- c:\program files\Uniblue
2010-02-13 04:23 . 2003-01-10 18:58 351526 —-a-w- c:\windows\WBDDA34I.DLL
2010-02-12 03:05 . 2010-02-19 14:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-12 03:05 . 2010-02-19 14:23 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-02-12 00:40 . 2010-02-12 00:40 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Threat Expert
2010-02-12 00:36 . 2010-02-12 00:36 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-02-12 00:26 . 2010-02-19 14:41 ——– d—–w- c:\program files\Common Files\PC Tools
2010-02-12 00:26 . 2010-02-19 14:21 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-02-12 00:25 . 2010-02-19 14:21 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-12 00:22 . 2010-02-12 02:48 ——– d—–w- c:\documents and settings\Owner\Application Data\GetRightToGo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-20 16:25 . 2009-05-09 02:49 256 —-a-w- c:\windows\system32\pool.bin
2010-02-19 15:44 . 2010-01-13 08:20 256 —-a-w- c:\documents and settings\Owner\pool.bin
2010-02-19 14:27 . 2005-10-30 06:06 ——– d—–w- c:\program files\Java
2010-02-19 14:13 . 2007-11-24 22:59 ——– d—–w- c:\program files\Yahoo!
2010-02-12 00:31 . 2009-11-16 00:08 ——– d—–w- c:\program files\CA Yahoo! Anti-Spy
2010-01-22 08:12 . 2009-07-01 07:45 ——– d—–w- c:\program files\Microsoft Silverlight
2009-12-31 16:14 . 2005-01-09 23:48 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2005-01-09 23:48 916480 ——w- c:\windows\system32\wininet.dll
2009-12-16 12:58 . 2005-01-10 01:05 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:35 . 2005-01-09 23:47 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:55 . 2005-01-09 23:48 2180352 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-04 05:59 2057728 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2005-01-09 23:48 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:04 . 2005-01-09 23:48 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:04 . 2004-08-04 07:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:37 . 2005-01-09 23:48 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:37 . 2005-01-09 23:48 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:37 . 2005-01-09 23:47 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:37 . 2004-08-04 07:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:37 . 2001-08-18 05:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864]
"nwiz"="nwiz.exe" [2005-09-18 1519616]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"CHotkey"="zHotkey.exe" [2005-05-03 543232]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-14 14820864]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-19 149280]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-06 177472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-09-19 236016]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-11-4 1545488]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 18:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Outlook Express\\msimn.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-02-21 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.facebook.com/
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
Trusted Zone: myfantasyleague.com
Trusted Zone: buy-is2010.com
TCP: {7E9D8851-2735-4B13-9CE4-C5102A25CA2D} = [removed],[removed]
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-21 11:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-02-21 11:26:25
ComboFix-quarantined-files.txt 2010-02-21 16:26
ComboFix2.txt 2010-02-20 16:23

Pre-Run: 175,417,335,808 bytes free
Post-Run: 175,382,290,432 bytes free

- - End Of File - - A623DB88BA9115FC0CB4F1F4DB171CDC
Hi,

Log looks good :thumbup:

Click Start >> Run, and then type ComboFix /Uninstall and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.

Now that your system appears to be clean, there's just a few steps I'd like you to take to prevent any future infections.
  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Thanks so much for the help. Here is a testimonial, feel free to use it, because you guys are fantastic: My computer was infected by trojans and God knows what else in a major way. After a week of searching (probably 40 hours work, all told), I finally came across whatthetech.com. They guided me through step-by-step (my computer skills are at best adequate) and took care of my problems quickly and painlessly. My computer runs like new. This is the ONLY help site I visited (and there were plenty) that I even considered donating to, and I only wish I could have afforded more. Thanks again!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI