This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow computer

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey,

I have a really slow computer upon start up, especially when opening the firefox browser. I have done a MalwareBytes scan, here is a couple of logs from the scan results. Any help to fix slow computer, or diagnose any viruses on my computer?

Cheers

Free

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4406

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

8/08/2010 8:41:29 PM
mbam-log-2010-08-08 (20-41-29).txt

Scan type: Quick scan
Objects scanned: 132496
Time elapsed: 7 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 28

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\PriceGong (Adware.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Hills\Application Data\PriceGong (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data (Adware.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\1.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\a.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\b.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\c.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\d.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\e.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\f.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\g.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\h.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\i.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\J.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\k.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\l.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\m.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\mru.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\n.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\o.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\p.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\q.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\r.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\s.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\t.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\u.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\v.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\w.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\x.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\y.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\z.xml (Adware.Agent) -> Quarantined and deleted successfully.


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4406

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

19/08/2010 11:14:15 AM
mbam-log-2010-08-19 (11-14-15).txt

Scan type: Quick scan
Objects scanned: 133454
Time elapsed: 12 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 28

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\PriceGong (Adware.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Hills\Application Data\PriceGong (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data (Adware.Agent) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\1.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\a.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\b.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\c.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\d.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\e.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\f.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\g.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\h.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\i.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\J.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\k.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\l.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\m.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\mru.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\n.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\o.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\p.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\q.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\r.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\s.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\t.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\u.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\v.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\w.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\x.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\y.xml (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Hills\Application Data\PriceGong\Data\z.xml (Adware.Agent) -> Quarantined and deleted successfully.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:48:27 PM, on 21/08/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://au.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD1.dll
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD1.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DVDVideoSoftTB Toolbar - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files\DVDVideoSoftTB\tbDVD1.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Hills\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1248238891750
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

–
End of file - 6194 bytes
Hi free,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

This may be fairly simple. You've got two anti-virus programs running (bad idea)… and one is garbage. You don't want anything from IObit. Keep your AVAST, but go to add or remove programs in your control panel and uninstall Advanced system care (and anything else that says IObit).

Then let's get a different scan.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.

Please reboot your computer and let me know if you notice any difference.
Hey TomK Have run the DDS Scan, here is the logs you requested. Also should my computer be okay running Standard Windows Firewall or would you suggest adding another program?? Cheers for the help, i will let u know how the comp is running! Free DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 11:57:41.12 on Tue 24/08/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.480.258 [GMT 10:00] AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\Hills\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://au.yahoo.com/ uURLSearchHooks: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\tbDVD1.dll mURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\tbDVD1.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: DVDVideoSoftTB Toolbar: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - c:\program files\dvdvideosofttb\tbDVD1.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\hills\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe IE: Free YouTube to Mp3 Converter - c:\documents and settings\hills\application data\dvdvideosoftiehelpers\youtubetomp3.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248238891750 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\hills\applic~1\mozilla\firefox\profiles\c5apz7ds.default\ FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com.au FF - prefs.js: keyword.URL - hxxp://au.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_au&p= FF - component: c:\documents and settings\hills\application data\mozilla\firefox\profiles\c5apz7ds.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll FF - component: c:\documents and settings\hills\application data\mozilla\firefox\profiles\c5apz7ds.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: browser.cache.memory.capacity - 16000 FF - user.js: browser.chrome.favicons - false FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 4095 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 1000000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 1000000 FF - user.js: dom.disable_window_status_change - true FF - user.js: network.http.max-connections - 48 FF - user.js: network.http.max-connections-per-server - 16 FF - user.js: network.http.max-persistent-connections-per-proxy - 16 FF - user.js: network.http.max-persistent-connections-per-server - 8 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 1000 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-6-20 165456] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-6-20 17744] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-20 40384] R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [2009-7-21 177280] S0 ncnvyc;ncnvyc;c:\windows\system32\drivers\pqnersy.sys –> c:\windows\system32\drivers\pqnersy.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-7-20 136176] S3 alcan5ln;SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [2009-7-22 36256] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-20 40384] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-20 40384] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== Created Last 30 ================ 2010-08-18 11:39:48 0 d—–w- c:\program files\Freemake 2010-08-09 19:15:58 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2010-08-09 19:15:58 69632 —-a-w- c:\windows\system32\QuickTime.qts 2010-08-08 10:27:39 0 d—–w- c:\docume~1\hills\applic~1\Malwarebytes 2010-08-08 10:23:50 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-08-08 10:23:48 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-08-08 10:23:47 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-08-08 10:23:46 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-07-28 08:26:54 758018 —-a-w- c:\windows\system32\xvidcore.dll 2010-07-28 08:26:54 180224 —-a-w- c:\windows\system32\xvidvfw.dll 2010-07-28 08:26:54 139264 —-a-w- c:\windows\system32\xvid.ax ==================== Find3M ==================== 2010-07-16 19:00:04 423656 —-a-w- c:\windows\system32\deployJava1.dll 2010-06-30 12:31:35 149504 —-a-w- c:\windows\system32\schannel.dll 2010-06-28 20:57:33 38848 —-a-w- c:\windows\avastSS.scr 2010-06-24 12:22:03 916480 —-a-w- c:\windows\system32\wininet.dll 2010-06-23 13:44:04 1851904 —-a-w- c:\windows\system32\win32k.sys 2010-06-17 14:03:00 80384 —-a-w- c:\windows\system32\iccvid.dll 2010-06-14 07:41:45 1172480 —-a-w- c:\windows\system32\msxml3.dll 2010-03-31 05:48:14 812344 —-a-w- c:\program files\HJTInstall.exe 2010-04-01 02:51:12 16384 –sha-w- c:\windows\system32\config\systemprofile\cookies\index.dat ============= FINISH: 11:58:13.29 ===============

Attachments:

In my opinion, the Vista firewall is acceptable.

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 21


Then let's get an online scan. (Be prepared… it will take hours)

Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hey Tomk Here is the Log for Kaspersky scan. Computer is still running quite slow especially upon start up and browsing. Can u help me delete the detected trojans?? Cheers Free KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, August 26, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, August 26, 2010 03:33:53 Records in database: 4148936 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Objects scanned: 68488 Threats found: 4 Infected objects found: 4 Suspicious objects found: 0 Scan duration: 03:33:11 File name / Threat / Threats count C:\Documents and Settings\Hills\Application Data\Sun\Java\Deployment\cache\6.0\23\3f3af9d7-68ca71c9 Infected: Trojan-Downloader.Java.Agent.ft 1 C:\Documents and Settings\Hills\Application Data\Sun\Java\Deployment\cache\6.0\23\3f3af9d7-68ca71c9 Infected: Trojan-Downloader.Java.Agent.fu 1 C:\Documents and Settings\Hills\Application Data\Sun\Java\Deployment\cache\6.0\23\3f3af9d7-68ca71c9 Infected: Trojan-Downloader.Java.Agent.fv 1 C:\Documents and Settings\Hills\Local Settings\Temporary Internet Files\Content.IE5\U1L04N32\u[1].asx Infected: Exploit.JS.Agent.bbu 1 Selected area has been scanned.
free,

Sure can. Those are all exploits of your out of date Java.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then lets run a different tool and get a different look at what is going on.

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hey,

Have run TFC, should that have deleted those detected files from Kaspersky online scan?? Here is the log for Combofix. What is the next step??

Cheers

ComboFix 10-08-26.02 - Hills 27/08/2010 14:15:39.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.480.264 [GMT 10:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2010-07-27 to 2010-08-27 )))))))))))))))))))))))))))))))
.

2010-08-27 04:11 . 2010-08-27 04:12 ——– d—–r- C:\32788R22FWJFW
2010-08-19 00:49 . 2010-08-19 00:50 ——– d—–w- c:\program files\QuickTime
2010-08-19 00:49 . 2010-08-19 00:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-08-18 13:48 . 2010-08-18 13:48 120178 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2010-08-18 11:52 . 2010-08-18 11:52 ——– d—–w- c:\program files\Microsoft.NET
2010-08-08 10:27 . 2010-08-08 10:27 ——– d—–w- c:\documents and settings\Hills\Application Data\Malwarebytes
2010-08-08 10:23 . 2010-08-08 10:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-05 00:39 . 2010-08-05 00:39 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\DVDVideoSoftTB
2010-08-05 00:39 . 2010-08-05 00:39 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-08-03 00:50 . 2010-08-15 05:09 ——– d—–w- c:\documents and settings\Hills\Local Settings\Application Data\FLVService
2010-07-28 08:26 . 2009-09-29 10:57 758018 —-a-w- c:\windows\system32\xvidcore.dll
2010-07-28 08:26 . 2008-12-04 11:46 180224 —-a-w- c:\windows\system32\xvidvfw.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-24 08:42 . 2009-07-21 13:47 ——– d—–w- c:\program files\Common Files\Java
2010-08-24 08:41 . 2010-05-07 02:29 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-24 08:21 . 2009-07-21 13:47 ——– d—–w- c:\program files\Java
2010-08-24 01:53 . 2010-07-24 06:36 ——– d—–w- c:\program files\Common Files\DVDVideoSoft
2010-08-21 05:47 . 2010-08-21 05:47 388096 —-a-r- c:\documents and settings\Hills\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-18 11:37 . 2010-07-24 06:36 ——– d—–w- c:\program files\DVDVideoSoft
2010-08-05 23:47 . 2009-11-11 01:41 ——– d—–w- c:\program files\CCleaner
2010-08-05 01:43 . 2010-08-05 01:43 503808 —-a-w- c:\documents and settings\Hills\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-2c756638-n\msvcp71.dll
2010-08-05 01:43 . 2010-08-05 01:43 499712 —-a-w- c:\documents and settings\Hills\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-2c756638-n\jmc.dll
2010-08-05 01:43 . 2010-08-05 01:43 12800 —-a-w- c:\documents and settings\Hills\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-355b040a-n\decora-d3d.dll
2010-08-05 01:43 . 2010-08-05 01:43 61440 —-a-w- c:\documents and settings\Hills\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-355b040a-n\decora-sse.dll
2010-08-05 01:43 . 2010-08-05 01:43 348160 —-a-w- c:\documents and settings\Hills\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-2c756638-n\msvcr71.dll
2010-07-31 04:50 . 2010-07-24 06:37 ——– d—–w- c:\program files\DVDVideoSoftTB
2010-07-24 06:37 . 2010-07-24 06:37 ——– d—–w- c:\documents and settings\Hills\Application Data\DVDVideoSoftIEHelpers
2010-07-20 11:00 . 2009-07-28 02:53 ——– d—–w- c:\program files\Google
2010-07-18 11:31 . 2010-07-18 11:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2010-07-18 11:15 . 2009-07-22 01:53 ——– d—–w- c:\program files\Windows Media Connect 2
2010-07-14 00:14 . 2009-07-21 14:03 1 —-a-w- c:\documents and settings\Hills\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-30 12:31 . 2007-07-27 12:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-28 20:57 . 2010-06-30 04:44 38848 —-a-w- c:\windows\avastSS.scr
2010-06-28 20:57 . 2010-06-20 03:28 165032 —-a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2010-06-20 03:29 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2010-06-20 03:29 165456 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2010-06-20 03:29 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2010-06-20 03:29 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2010-06-20 03:29 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2010-06-20 03:29 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2010-06-20 03:29 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-24 12:22 . 2007-07-27 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2007-07-27 12:00 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2007-07-27 12:00 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2007-07-27 12:00 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-07-20 23:30 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2007-07-27 12:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2010-06-08 01:30 . 2010-08-03 00:52 52224 —-a-w- c:\documents and settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
2010-06-08 01:30 . 2010-08-03 00:52 101376 —-a-w- c:\documents and settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll
2010-03-31 05:48 . 2010-03-31 05:47 812344 —-a-w- c:\program files\HJTInstall.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVD1.dll" [2010-07-24 2736736]

[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]
2010-07-24 11:54 2736736 —-a-w- c:\program files\DVDVideoSoftTB\tbDVD1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{872b5b88-9db5-4310-bdd0-ac189557e5f5}"= "c:\program files\DVDVideoSoftTB\tbDVD1.dll" [2010-07-24 2736736]

[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{872B5B88-9DB5-4310-BDD0-AC189557E5F5}"= "c:\program files\DVDVideoSoftTB\tbDVD1.dll" [2010-07-24 2736736]

[HKEY_CLASSES_ROOT\clsid\{872b5b88-9db5-4310-bdd0-ac189557e5f5}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-09 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Hills\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-06 08:51 3885408 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Tray]
2003-06-26 01:35 303104 —-a-w- c:\windows\system32\SISTRAY.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2004-02-26 17:06 241664 —-a-w- c:\windows\system32\Keyhook.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [20/06/2010 1:29 PM 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [20/06/2010 1:29 PM 17744]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [21/07/2009 9:45 AM 177280]
S0 ncnvyc;ncnvyc;c:\windows\system32\drivers\pqnersy.sys –> c:\windows\system32\drivers\pqnersy.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 1:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [20/07/2010 9:00 PM 136176]
S3 alcan5ln;SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [22/07/2009 10:13 AM 36256]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 1:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder

2010-08-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]

2010-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 10:59]

2010-08-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-20 10:59]

2010-08-27 c:\windows\Tasks\User_Feed_Synchronization-{10E034B1-B71A-4087-9E07-C1D0A21684BB}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 18:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://au.yahoo.com/
IE: Free YouTube to Mp3 Converter - c:\documents and settings\Hills\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm
FF - ProfilePath - c:\documents and settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com.au
FF - prefs.js: keyword.URL - hxxp://au.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_au&p=
FF - component: c:\documents and settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}\components\RadioWMPCore.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-27 14:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(372)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-08-27 14:30:38 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-27 04:30

Pre-Run: 20,253,347,840 bytes free
Post-Run: 20,212,486,144 bytes free

- - End Of File - - 6E76EBEC8C4817F5C5E0489917EEB99B
free,

Have run TFC, should that have deleted those detected files from Kaspersky online scan?


Yes. TFC cleans out Temp files as well as dumping the Java cache (which is where those files were located).

What is the next step??

Well, unfortunately… I'm not seeing malware as the cause of your issue. Therefore, my usefulness to you is at an end. I suggest that your next step is to post in the windows forum and see if the Tech Team can help you speed things up. When you post there, please provide a link back to this thread so they can see your information here (in case there is something useful for them in one of the logs).

Meanwhile, we need to clean up our tools.


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

Any questions?
Hey TomK Cheers for the help. Just one thing, I know it might be out of the question but could you show me how to clean the computer, delete temp files and registry that sort of stuff??? Cheers Free

Hey TomK

Cheers for the help. Just one thing, I know it might be out of the question but could you show me how to clean the computer, delete temp files and registry that sort of stuff???

Cheers

Free

Ah… the simple answer is… yes.

However… multiple answers are required to better address the various situation.

Delete temp file… easy as pie. Run TFC and time you feel like it. It won't hurt anything on your system and will clean out most of the temp files. I doesn't remove them all as some temp files hold save login information, etc.

Clean malware from the computer… I can teach you. It would require you to join the classroom, and commit to alot of hard work, and dedication of time to study and learn. You could expect to spend at least 6 months in the classroom before you would have learned enough to start actually cleaning malware… and at that point you would still be in training and all your fixes would be checked before posting.

Registry… Registry training is part of the classroom experience.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI