This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Constant Internet Activity on our PC

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all,

This PC runs Windows XP with service pack 3 installed. We want to get Windows 7 when we can afford it.

The Query : - My mothers PC has constant internet activity going on even when idle. She runs Zonealarm free addition and is running Avira anti-virus. We have not been able to detect any malware using superantispyware, A Squared or Windowssystemcare pro. I am wondering if there is a nasty trojan in mums PC which is yet to be detected or she simply has an incompatibility issue between softwares such as Zonealarm and maybe Avira? I decided to run hijackthis and post the result here in case one of the experts of the forum can notice something bad in the list of processes detected. Much appreciated of any help. cheers Pete

PS. I think that mum has too many security programs but its her PC so I can't complain about it.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:16:28 PM, on 7/22/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tadaustconnect.org.au/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.muuler.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.avg.com/ww.special-old-os-app
R3 - URLSearchHook: (no name) - {0fc85f5d-6207-4515-a490-45a549d285c0} - (no file)
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
R3 - URLSearchHook: (no name) - {2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
R3 - URLSearchHook: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: ZoneAlarm Toolbar - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://host.cycore.net/plugins/windows/ie/…E_5.3.0.228.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1041404858196
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1041404844206
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…039/mcfscan.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0295041276158955) (0295041276158955mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\029504~1.EXE (file missing)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag 2000 (OOD2000) - O&O Software GmbH - C:\WINDOWS\system32\OOD2000.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - Unknown owner - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)

–
End of file - 10196 bytes
Posted Image


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Hi, thank you for the instructions. I followed them all and here is my combofix scan result:-

ComboFix 10-07-22.06 - admin 07/24/2010 0:34.3.1 - x86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Install.exe
c:\windows\10377942.exe
c:\windows\41194604.exe
c:\windows\45331403.exe

.
((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.

2010-07-22 13:11 . 2010-07-22 13:11 ——– d—–w- c:\program files\FotoSketcher
2010-07-22 11:14 . 2010-07-22 11:14 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\dotPDN_LLC
2010-07-22 11:14 . 2010-07-22 11:14 ——– d—–w- c:\documents and settings\admin\Application Data\CustomBrushesMini
2010-07-22 04:08 . 2010-07-22 04:08 ——– d—–w- c:\program files\Imagenomic
2010-07-22 02:13 . 2010-07-22 02:13 388096 —-a-r- c:\documents and settings\admin\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-21 03:21 . 2010-07-21 03:21 ——– d—–w- c:\program files\Trend Micro
2010-07-17 10:21 . 2010-07-06 17:28 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-07-16 08:52 . 2010-03-01 00:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-07-16 08:52 . 2010-02-16 04:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-07-16 08:52 . 2009-05-11 02:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-07-16 08:52 . 2009-05-11 02:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-07-16 08:52 . 2010-07-16 08:52 ——– d—–w- c:\program files\Avira
2010-07-16 08:52 . 2010-07-16 08:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-07-16 06:46 . 2010-07-16 06:56 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-07-16 06:21 . 2010-07-16 06:21 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-16 04:37 . 2010-07-16 07:20 71888 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-07-12 03:53 . 2010-07-12 03:53 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-07-12 01:52 . 2010-07-06 17:28 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-07-12 01:51 . 2010-07-12 01:51 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-07-12 01:41 . 2010-07-12 01:41 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\Sunbelt Software
2010-07-12 01:27 . 2010-07-12 01:27 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{65893B95-F47B-4483-B883-86BA181E9B54}
2010-07-12 01:27 . 2010-07-06 17:29 2979280 -c–a-w- c:\documents and settings\All Users\Application Data\{65893B95-F47B-4483-B883-86BA181E9B54}\Ad-AwareInstall.exe
2010-07-12 01:26 . 2010-07-12 01:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-07-12 01:26 . 2010-07-12 01:26 ——– d—–w- c:\program files\Lavasoft
2010-07-10 06:55 . 2010-07-10 08:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-07-10 06:18 . 2010-07-10 06:18 20136 —-a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-10 04:52 . 2010-07-11 05:22 ——– d—–w- c:\program files\Exterminate It!
2010-07-10 04:51 . 2010-07-16 08:04 ——– d—–w- c:\program files\ewido anti-malware
2010-07-10 00:25 . 2010-07-10 00:25 ——– d—–w- c:\windows\McAfee.com
2010-07-08 06:51 . 2010-07-08 07:42 ——– d—–w- c:\documents and settings\admin\Local Settings\Application Data\ZoneAlarm
2010-07-08 06:51 . 2010-07-08 06:51 ——– d—–w- c:\program files\ZoneAlarm
2010-07-08 06:49 . 2010-06-23 03:51 69120 —-a-w- c:\windows\system32\zlcomm.dll
2010-07-08 06:49 . 2010-06-23 03:51 103936 —-a-w- c:\windows\system32\zlcommdb.dll
2010-07-08 06:49 . 2010-07-08 06:53 ——– d—–w- c:\windows\system32\ZoneLabs
2010-07-08 06:49 . 2010-06-23 03:51 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2010-07-08 06:49 . 2010-07-08 06:49 ——– d—–w- c:\program files\Zone Labs
2010-07-06 19:56 . 2010-07-06 19:56 61440 —-a-w- c:\documents and settings\admin\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4abb6d95-n\decora-sse.dll
2010-07-06 19:56 . 2010-07-06 19:56 12800 —-a-w- c:\documents and settings\admin\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4abb6d95-n\decora-d3d.dll
2010-07-05 06:54 . 2010-07-05 06:54 4 —-a-w- c:\windows\10377942.dat
2010-07-05 03:49 . 2010-07-05 03:49 4 —-a-w- c:\windows\9262679.dat
2010-07-04 07:40 . 2010-07-04 07:40 4 —-a-w- c:\windows\2081543.dat
2010-07-03 23:52 . 2010-07-03 23:52 4 —-a-w- c:\windows\45331403.dat
2010-07-03 11:59 . 2010-07-03 11:59 4 —-a-w- c:\windows\2561473.dat
2010-07-03 11:15 . 2010-07-03 11:15 266 —-a-w- c:\windows\41194604.dat
2010-07-02 13:19 . 2010-07-02 13:20 ——– d—–w- c:\program files\Stereo Video Maker
2010-07-02 13:17 . 2010-07-02 13:18 ——– d—–w- c:\program files\Stereo Photo Maker
2010-07-02 13:15 . 2010-07-21 10:28 ——– d—–w- c:\program files\Virtual Dub

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 14:31 . 2009-10-10 02:22 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-23 14:11 . 2009-10-08 04:44 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-07-23 01:52 . 2010-07-10 08:29 9333195 —-a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-07-23 01:50 . 2010-07-23 01:52 1955840 —-a-w- c:\windows\Internet Logs\xDB2.tmp
2010-07-23 01:50 . 2010-07-23 01:52 404992 —-a-w- c:\windows\Internet Logs\xDB1.tmp
2010-07-22 22:11 . 2009-10-11 01:02 ——– d—–w- c:\program files\a-squared Free
2010-07-22 22:00 . 2009-10-10 06:53 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-07-22 21:58 . 2009-11-25 18:43 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-20 04:26 . 2010-05-04 00:42 63488 —-a-w- c:\documents and settings\admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-20 04:26 . 2009-10-10 06:56 117760 —-a-w- c:\documents and settings\admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-20 04:20 . 2009-11-25 19:07 ——– d—–w- c:\documents and settings\admin\Application Data\Registry Mechanic
2010-07-17 02:21 . 2010-07-17 02:21 46295 —-a-w- c:\windows\Internet Logs\vsmon_2nd_2010_07_17_12_11_30_small.dmp.zip
2010-07-17 02:21 . 2010-07-17 02:21 42307 —-a-w- c:\windows\Internet Logs\vsmon_2nd_2010_07_17_12_10_27_small.dmp.zip
2010-07-12 04:25 . 2010-03-26 01:10 ——– d—–w- c:\documents and settings\admin\Application Data\GlarySoft
2010-07-12 04:23 . 2009-10-13 00:30 ——– d—–w- c:\program files\Google
2010-07-12 01:18 . 2010-03-26 01:09 ——– d—–w- c:\program files\Glary Utilities
2010-07-08 06:49 . 2010-04-20 09:00 ——– d—–w- c:\program files\CheckPoint
2010-07-08 05:50 . 2010-04-20 09:00 ——– d—–w- c:\documents and settings\admin\Application Data\CheckPoint
2010-06-22 06:41 . 2010-06-22 06:41 ——– d—–w- c:\program files\Common Files\Gogago
2010-06-22 06:41 . 2010-06-22 06:41 ——– d—–w- c:\program files\Gogago
2010-06-22 06:36 . 2010-06-22 06:35 ——– d—–w- c:\program files\FlashPlayer Plus
2010-06-22 01:32 . 2009-11-14 05:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-06-21 02:12 . 2010-06-21 02:04 ——– d—–w- c:\program files\Windows Live
2010-06-21 02:05 . 2010-06-21 02:05 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-06-21 01:10 . 2010-06-21 01:10 ——– d—–w- c:\program files\Common Files\Windows Live
2010-06-18 12:59 . 2010-03-30 14:03 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-06-18 12:58 . 2009-10-10 07:30 ——– d—–w- c:\program files\IObit
2010-06-14 14:31 . 2009-10-07 06:39 744448 —-a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-12 06:37 . 2010-06-12 06:37 ——– d—–w- c:\documents and settings\All Users\Application Data\iolo
2010-06-12 06:37 . 2010-06-12 06:37 ——– d—–w- c:\documents and settings\admin\Application Data\iolo
2010-06-10 00:18 . 2010-06-08 12:33 ——– d—–w- c:\documents and settings\admin\Application Data\DVD Flick
2010-06-09 04:00 . 2010-06-09 04:00 ——– d—–w- c:\program files\Paint.NET
2010-06-08 12:33 . 2010-06-08 12:33 ——– d—–w- c:\program files\DVD Flick
2010-06-07 13:56 . 2010-06-07 13:41 ——– d—–w- c:\program files\AviSynth 2.5
2010-06-07 13:42 . 2010-06-07 13:42 ——– d—–w- c:\program files\Gabest
2010-06-07 13:42 . 2010-06-07 13:42 ——– d—–w- c:\program files\Xvid
2010-06-07 12:27 . 2010-06-07 12:26 ——– d—–w- c:\program files\Common Files\Solveig Multimedia
2010-06-07 12:26 . 2010-06-07 12:26 ——– d—–w- c:\program files\Solveig Multimedia
2010-06-07 12:09 . 2010-06-07 12:09 ——– d—–w- c:\program files\Thugs at Bay
2010-06-07 09:51 . 2010-06-07 08:47 ——– d—–w- c:\program files\Video Enhancer
2010-06-07 09:32 . 2009-10-07 06:56 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-07 09:32 . 2010-06-07 09:32 ——– d—–w- c:\program files\MainConcept
2010-06-07 09:31 . 2009-10-07 06:56 ——– d—–w- c:\program files\Common Files\InstallShield
2010-06-07 08:06 . 2009-10-08 09:21 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-03 02:41 . 2010-06-03 02:41 3600384 —-a-w- c:\windows\system32\GPhotos.scr
2010-05-20 20:32 . 2009-10-07 06:40 4313598 —-a-w- c:\windows\java\Packages\TN9FHFDV.ZIP
2010-05-06 10:41 . 2006-06-23 01:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2002-08-29 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 05:39 . 2009-10-09 21:25 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 05:39 . 2009-10-09 21:25 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-25 06:53 . 2010-04-25 06:53 323624 —-a-w- c:\windows\system32\wiaaut.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]
2010-05-09 01:50 2517088 —-a-w- c:\program files\ZoneAlarm\tbZone.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD}"= "c:\program files\ZoneAlarm\tbZone.dll" [2010-05-09 2517088]

[HKEY_CLASSES_ROOT\clsid\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"SoundMan"="SOUNDMAN.EXE" [2005-03-24 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoPopUpsOnBoot"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-12 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 04:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ShellHWDetection"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"NVIDIA nForce APU1 Utilities"=NVATray.exe
"nwiz"=nwiz.exe /install
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/12/2010 11:52 AM 64288]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [9/15/2009 10:42 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 10:42 AM 67656]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [10/17/2009 8:29 AM 1872320]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7/16/2010 6:52 PM 135336]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2/19/2010 7:43 PM 380928]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 11:35 PM 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 11:35 PM 493032]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\progra~1\mcafee\SITEAD~1\mcsacore.exe [3/26/2010 7:15 AM 93320]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [11/26/2009 5:01 AM 632792]
S2 0295041276158955mcinstcleanup;McAfee Application Installer Cleanup (0295041276158955);c:\windows\TEMP\029504~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service –> c:\windows\TEMP\029504~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/23/2010 4:38 PM 136176]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/7/2010 3:28 AM 1352832]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [4/7/2010 9:54 AM 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [4/7/2010 9:54 AM 3072]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 10:42 AM 12872]

— Other Services/Drivers In Memory —

*NewlyCreated* - SASDIFSV

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-07-23 c:\windows\Tasks\Ad-Aware Scan (schedule).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-06 17:28]

2010-07-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-07-06 17:28]

2010-07-23 c:\windows\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-07-08 04:11]

2010-07-23 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-03-26 01:14]

2010-07-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-11-14 06:28]

2010-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-23 06:37]

2010-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-23 06:37]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.tadaustconnect.org.au/
mStart Page = hxxp://www.muuler.com/
uInternet Connection Wizard,ShellNext = hxxp://www.avg.com/ww.special-old-os-app
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{0fc85f5d-6207-4515-a490-45a549d285c0} - (no file)
URLSearchHooks-{2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
WebBrowser-{2BAE58C2-79F9-45D1-A286-81F911301C3A} - (no file)
WebBrowser-{0FC85F5D-6207-4515-A490-45A549D285C0} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-24 00:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,12,62,ba,b8,77,7c,97,47,96,13,c3,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,12,62,ba,b8,77,7c,97,47,96,13,c3,\

[HKEY_USERS\S-1-5-21-725345543-706699826-1957994488-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{423220B2-C5B4-00F2-F4D2-14AB0DA359E5}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(576)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll

- - - - - - - > 'lsass.exe'(632)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2010-07-24 00:44:18
ComboFix-quarantined-files.txt 2010-07-23 14:44
ComboFix2.txt 2010-04-21 09:28

Pre-Run: 24,438,390,784 bytes free
Post-Run: 24,409,358,336 bytes free

- - End Of File - - 07F6CE1D5B46C511EFB6F079091C761B

my typing is coming up slow on the screen and a hour glass keeps flashing on and off rapidly where the curser is as I type. There is still a lot of mysterrious internet activity going on according to the monitor icon for LAN and zonealarms icon in the system tray. There are lots of red X's in fields such as Bold and Italic on the web pages.

cheers
Peter
Lets try something. Activate Windows Firewall and uninstall Zonealarm Did you have McAfee at one time? I see leftovers from it.
Hi LDTate I've given it a go. I wish I was more PC savvy. The internet activity stopped after I uninstalled zone alarm and macafee was deleted although Im not sure about all traces of it. Mum is fond of zone alarm and has put an earlier addition of it back on to her PC and the activity started up again. I don't know what is going on or what to do. She says don't worry about it but I always worry about the unexplained.
The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

To be on the safe side, I would also change all my passwords.


This infection appears to have been cleaned, but as the malware could be configured to run any program a remote attacker requires, it's impossible to be 100% sure that any machine is clean.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI