This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32:Rootkit [Rtk] infection, help please :)

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ive been having some strnage issues with my computer, such as certain applications not being able to update, for some time, but its only after i installed Avast! that it realised it was malware. Avast! now flags up saying that its found: Win32:Rootkit [Rtk], in a file ghhd.tmp, in the TEMP folder, and it does it whenever i start an application. The executable for the application im starting trys to access that file, and Avast blocks it. Id be eternally greatful for some help with this ive done a DDS report, but its not letting me post it in the topic title lol
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
MBR Check: MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000003c Kernel Drivers (total 130): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E2000 \WINDOWS\system32\hal.dll 0xBA5A8000 \WINDOWS\system32\KDCOM.DLL 0xBA4B8000 \WINDOWS\system32\BOOTVID.dll 0xB9F79000 ACPI.sys 0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xB9F68000 pci.sys 0xBA0A8000 isapnp.sys 0xB9F55000 sfsync04.sys 0xBA670000 pciide.sys 0xBA328000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xBA0B8000 MountMgr.sys 0xB9F36000 ftdisk.sys 0xBA330000 PartMgr.sys 0xBA0C8000 sfsync02.sys 0xBA0D8000 VolSnap.sys 0xB9F1E000 atapi.sys 0xBA0E8000 disk.sys 0xBA0F8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xB9EFE000 fltMgr.sys 0xB9EEC000 sr.sys 0xB9ED5000 KSecDD.sys 0xB9E48000 Ntfs.sys 0xB9E34000 inspect.sys 0xB9E07000 \WINDOWS\System32\DRIVERS\NDIS.SYS 0xBA338000 \WINDOWS\System32\DRIVERS\TDI.SYS 0xBA5AC000 sonyhcb.sys 0xB9DF0000 sfvfs02.sys 0xBA340000 sfhlp02.sys 0xB9DDC000 sfdrv01a.sys 0xB9DCA000 sfdrv01.sys 0xBA4BC000 RecAgent.sys 0xB9DAF000 Mup.sys 0xBA2E8000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xB8B67000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xB8B53000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xBA458000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xB8B30000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xBA460000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xB8B0B000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xBA2F8000 \SystemRoot\system32\DRIVERS\imapi.sys 0xBA308000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xBA318000 \SystemRoot\system32\DRIVERS\redbook.sys 0xB8AE8000 \SystemRoot\system32\DRIVERS\ks.sys 0xBA468000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0xB8A85000 \SystemRoot\system32\DRIVERS\slntamr.sys 0xB9D8B000 \SystemRoot\system32\DRIVERS\SlWdmSup.sys 0xB8A66000 \SystemRoot\system32\DRIVERS\Mtlmnt5.sys 0xBA470000 \SystemRoot\System32\Drivers\Modem.SYS 0xB8A52000 \SystemRoot\system32\DRIVERS\Rtnicxp.sys 0xBA478000 \SystemRoot\system32\DRIVERS\fdc.sys 0xBA128000 \SystemRoot\system32\DRIVERS\serial.sys 0xB9D83000 \SystemRoot\system32\DRIVERS\serenum.sys 0xB8A3E000 \SystemRoot\system32\DRIVERS\parport.sys 0xBA138000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xBA480000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xBA488000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xBA76F000 \SystemRoot\system32\DRIVERS\audstub.sys 0xBA148000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xB9D7F000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xB8A27000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xBA158000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xBA168000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xB8A16000 \SystemRoot\system32\DRIVERS\psched.sys 0xBA178000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xBA490000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xBA498000 \SystemRoot\system32\DRIVERS\raspti.sys 0xB9D77000 \SystemRoot\system32\DRIVERS\pnetmdm.sys 0xBA188000 \SystemRoot\system32\DRIVERS\termdd.sys 0xBA5EE000 \SystemRoot\system32\DRIVERS\swenum.sys 0xB89BD000 \SystemRoot\system32\DRIVERS\update.sys 0xB9D73000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xBA198000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xBA1B8000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xBA5F0000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xB4E58000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xB4E36000 \SystemRoot\system32\drivers\portcls.sys 0xB91FB000 \SystemRoot\system32\drivers\drmk.sys 0xBA584000 \SystemRoot\system32\drivers\MODEMCSA.sys 0xB4DC7000 \SystemRoot\System32\DRIVERS\cmdguard.sys 0xBA5F4000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xBA70A000 \SystemRoot\System32\Drivers\Null.SYS 0xBA5F6000 \SystemRoot\System32\Drivers\Beep.SYS 0xBA350000 \SystemRoot\System32\drivers\vga.sys 0xBA5F8000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xBA5FA000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xBA390000 \SystemRoot\System32\Drivers\Msfs.SYS 0xBA398000 \SystemRoot\System32\Drivers\Npfs.SYS 0xB89B5000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xB4D94000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xB4D3C000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xB91DB000 \SystemRoot\System32\Drivers\aswTdi.SYS 0xBA3A0000 \SystemRoot\System32\DRIVERS\cmdhlp.sys 0xB4CEC000 \SystemRoot\system32\DRIVERS\netbt.sys 0xB4CCA000 \SystemRoot\System32\drivers\afd.sys 0xB91CB000 \SystemRoot\system32\DRIVERS\netbios.sys 0xB4C9F000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xB4C30000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xB91BB000 \SystemRoot\System32\Drivers\Fips.SYS 0xB4C0F000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xB4BE8000 \SystemRoot\System32\Drivers\aswSP.SYS 0xBA3B0000 \SystemRoot\System32\Drivers\Aavmker4.SYS 0xB91AB000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xBA1E8000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xB4BA8000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xBA60A000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xB4DE6000 \SystemRoot\System32\drivers\Dxapi.sys 0xBA3C8000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xBA7E5000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xB4BE4000 \SystemRoot\System32\Drivers\aswFsBlk.SYS 0xB4850000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xB46E9000 \SystemRoot\System32\Drivers\aswMon2.SYS 0xB443C000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xBA5CA000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xB42A5000 \SystemRoot\system32\DRIVERS\srv.sys 0xB425D000 \SystemRoot\system32\DRIVERS\secdrv.sys 0xBA65A000 \??\C:\WINDOWS\nvoclock.sys 0xBA3A8000 \SystemRoot\System32\Drivers\aswRdr.SYS 0xB3D90000 \SystemRoot\system32\drivers\wdmaud.sys 0xB3F1D000 \SystemRoot\system32\drivers\sysaudio.sys 0xB43DC000 \SystemRoot\System32\Drivers\usbaapl.sys 0xB3C61000 \SystemRoot\System32\Drivers\HTTP.sys 0xB3E95000 \SystemRoot\system32\DRIVERS\usbscan.sys 0xB29A4000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0xB235F000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 47): 0 System Idle Process 4 System 724 C:\WINDOWS\system32\smss.exe 772 csrss.exe 796 C:\WINDOWS\system32\winlogon.exe 848 C:\WINDOWS\system32\services.exe 860 C:\WINDOWS\system32\lsass.exe 1036 C:\WINDOWS\system32\svchost.exe 1112 svchost.exe 1152 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe 1184 C:\WINDOWS\system32\svchost.exe 1312 svchost.exe 1336 svchost.exe 1464 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe 1816 C:\WINDOWS\system32\spoolsv.exe 1924 svchost.exe 1960 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 1972 C:\Program Files\Bonjour\mDNSResponder.exe 2020 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe 180 C:\Program Files\Java\jre6\bin\jqs.exe 236 C:\Program Files\Google\Update\GoogleUpdate.exe 252 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE 396 C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe 648 C:\WINDOWS\system32\nvsvc32.exe 692 C:\WINDOWS\system32\slserv.exe 716 C:\WINDOWS\system32\svchost.exe 1892 alg.exe 2524 C:\WINDOWS\system32\wscntfy.exe 2620 C:\WINDOWS\explorer.exe 2764 C:\Program Files\Alwil Software\Avast5\AvastUI.exe 2780 C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe 2788 C:\Program Files\Common Files\Java\Java Update\jusched.exe 2880 C:\WINDOWS\RTHDCPL.EXE 2916 C:\WINDOWS\system32\imapi.exe 3032 C:\WINDOWS\system32\rundll32.exe 3140 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe 3172 C:\Program Files\iTunes\iTunesHelper.exe 2984 C:\Program Files\COMODO\COMODO Internet Security\cfp.exe 3056 C:\WINDOWS\zHotkey.exe 3132 C:\Program Files\Windows Live\Messenger\msnmsgr.exe 3328 C:\Program Files\Electronic Arts\EADM\Core.exe 3336 C:\WINDOWS\system32\ctfmon.exe 3364 C:\Program Files\iPod\bin\iPodService.exe 3512 C:\Program Files\PdaNet for iPhone\PdaNetPC.exe 3864 C:\Program Files\Windows Live\Contacts\wlcomm.exe 228 C:\Program Files\Mozilla Firefox\firefox.exe 2680 C:\Documents and Settings\Ian\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\F: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: SAMSUNGSP2504C, Rev: VT100-50 PhysicalDrive1 Model Number: WDCWD1600JD-22HBB0, Rev: 08.02D08 Size Device Name MBR Status ——————————————– 232 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A 149 GB \\.\PhysicalDrive1 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done!
DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 10:56:41.35 on 12/09/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3070.2433 [GMT 1:00] AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\imapi.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\WINDOWS\zHotkey.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Electronic Arts\EADM\Core.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\PdaNet for iPhone\PdaNetPC.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Mozilla Firefox\firefox.exe F:\Ian\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\hypercam toolbar\tbcore3.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: HyperCam Toolbar: {338b4dfe-2e2c-4338-9e41-e176d497299e} - c:\program files\hypercam toolbar\tbcore3.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [EA Core] c:\program files\electronic arts\eadm\Core.exe -silent uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [ShowWnd] ShowWnd.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun: [CHotkey] zHotkey.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\ian\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe StartupFolder: c:\docume~1\ian\startm~1\programs\startup\pdanet~1.lnk - c:\program files\pdanet for iphone\PdaNetPC.exe StartupFolder: c:\docume~1\ian\startm~1\programs\startup\xfire.lnk - c:\program files\xfire\Xfire.exe IE: E&xport to Microsoft Excel - f:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - f:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} - hxxp://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/mjss/MJSS.cab109791.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: {1699235A-DC9B-4C1A-ACB4-6B1AC1C44665} = 68.28.114.91 68.28.122.93 TCP: {791BA8B0-9824-437D-B593-03913AA02AAF} = 192.168.1.2 AppInit_DLLs: winmm.dll LSA: Notification Packages = scecli scecli ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\ian\applic~1\mozilla\firefox\profiles\b5362naz.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q= FF - prefs.js: browser.search.selectedEngine - Yahoo.co.uk FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/?ref=home FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q= FF - component: c:\program files\google\google gears\firefox\lib\ff36\gears.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\musicnotes\npmusicn.dll FF - plugin: c:\program files\musicnotes\NPSibelius.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: f:\ian\my documents\sparkplay media\sparkplayer (beta)\npSparkPlayerNS.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
—- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS =============== R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2006-7-5 63352] R0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [2007-7-8 6097] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-9-7 165584] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-6-14 132168] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-6-14 25160] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-9-7 17744] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-7 40384] R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2009-6-14 715392] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-7 40384] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-7 40384] R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [2009-8-12 9472] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-4 135664] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2008-12-11 1684736] S3 OEMFVNETusb(505 2958)®;OEM FVNETusb(505 2958)® Service for 802.11b Pen Size Wireless USB Adapter;c:\windows\system32\drivers\vnet558x.sys [2010-8-18 98176] S3 pnicml;pnicml;\??\c:\docume~1\ian\locals~1\temp\pnicml.sys –> c:\docume~1\ian\locals~1\temp\pnicml.sys [?] S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys [2007-7-8 299923] S3 XDva344;XDva344;\??\c:\windows\system32\xdva344.sys –> c:\windows\system32\XDva344.sys [?] =============== Created Last 30 ================ 2010-09-11 10:53 –d—– c:\docume~1\ian\applic~1\Malwarebytes 2010-09-11 10:53 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-09-11 10:53 20,952 a——- c:\windows\system32\drivers\mbam.sys 2010-09-11 10:53 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-09-11 10:53 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-09-08 20:29 181 a——- c:\windows\wininit.ini 2010-09-07 19:57 38,848 a——- c:\windows\avastSS.scr 2010-09-07 19:57 –d—– c:\docume~1\alluse~1\applic~1\Alwil Software 2010-09-07 19:39 –d—– c:\program files\Steam 2010-09-02 10:43 1,970,176 a——- c:\windows\system32\d3dx9.dll 2010-09-02 10:43 679,936 a——- c:\windows\system32\D3DX81ab.dll 2010-09-02 10:43 –d—– c:\program files\Cheat Engine 2010-08-31 16:19 –d—– c:\docume~1\ian\applic~1\Toolbar4 2010-08-31 16:19 –d—– c:\program files\HyperCam Toolbar 2010-08-31 16:18 –d—– c:\program files\HyCam2 2010-08-30 20:58 –d—– c:\program files\Fiesta Online(EU_English) 2010-08-30 19:36 –d—– c:\program files\common files\DirectX 2010-08-30 19:26 118,176 a——- c:\windows\patchw.dll 2010-08-30 19:18 –d—– c:\program files\Outspark 2010-08-30 16:45 –d—– C:\fb9724e9ee31c0e7443ee6a3 2010-08-29 11:10 –d—– C:\a990d76d4996e0a254d3 2010-08-29 11:08 549,376 a——- c:\windows\system32\oleaut32.dll 2010-08-29 10:57 221,184 a——- c:\windows\system32\wmpns.dll 2010-08-28 09:50 423,656 a——- c:\windows\system32\deployJava1.dll 2010-08-27 17:34 –d—– c:\docume~1\ian\applic~1\LimeWire 2010-08-27 17:34 73,728 a——- c:\windows\system32\javacpl.cpl 2010-08-27 17:33 –d—– c:\program files\LimeWire 2010-08-27 15:57 –dsh— c:\documents and settings\ian\IECompatCache 2010-08-27 15:39 –d—– c:\windows\ie8updates 2010-08-27 13:32 –d-h— c:\windows\msdownld.tmp 2010-08-27 13:22 –d—– c:\docume~1\alluse~1\applic~1\PMB Files 2010-08-27 13:21 –d—– c:\program files\Pando Networks 2010-08-27 12:59 599,040 -c—— c:\windows\system32\dllcache\msfeeds.dll 2010-08-27 12:59 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll 2010-08-27 12:59 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll 2010-08-27 12:59 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll 2010-08-27 12:59 743,424 -c—— c:\windows\system32\dllcache\iedvtool.dll 2010-08-27 12:59 247,808 -c—— c:\windows\system32\dllcache\ieproxy.dll 2010-08-27 12:59 11,076,096 -c—— c:\windows\system32\dllcache\ieframe.dll 2010-08-27 12:47 –dsh— c:\documents and settings\ian\PrivacIE 2010-08-27 12:47 –d—– c:\windows\system32\CatRoot_bak 2010-08-27 12:19 –d—– c:\windows\system32\wbem\Repository 2010-08-27 12:18 –d—– c:\windows\system32\en 2010-08-27 12:18 –d—– c:\windows\system32\bits 2010-08-27 12:14 –d—– c:\windows\EHome 2010-08-27 11:16 –d—– c:\windows\system32\scripting 2010-08-27 11:16 –d—– c:\windows\l2schemas 2010-08-27 11:11 –d—– c:\windows\network diagnostic 2010-08-27 11:07 764,928 a——- c:\windows\system32\dllcache\winntbbu.dll 2010-08-27 10:58 –dsh— c:\documents and settings\ian\IETldCache 2010-08-26 18:12 –d—– C:\9031e5d399997adc63 2010-08-26 16:47 -cd-h— c:\windows\ie8 2010-08-26 16:13 –d—– C:\c66445dd4b6cdd2c70fb4df583a4bb 2010-08-26 16:13 –d—– C:\6b4feaf3eaa8d23d3b620a15 2010-08-26 16:01 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2 2010-08-26 16:00 –d—– c:\program files\MSXML 6.0 2010-08-26 15:48 –d—– c:\windows\ServicePackFiles 2010-08-26 13:51 293,376 ——– c:\windows\system32\browserchoice.exe 2010-08-26 12:49 274,288 a——- c:\windows\system32\mucltui.dll 2010-08-26 12:49 215,920 a——- c:\windows\system32\muweb.dll 2010-08-26 12:49 16,736 a——- c:\windows\system32\mucltui.dll.mui 2010-08-22 17:10 –d—– c:\program files\SweetIM 2010-08-18 10:50 98,176 a—-r– c:\windows\system32\drivers\vnet558x.sys ==================== Find3M ==================== 2010-08-27 12:29 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2010-06-14 15:30 743,936 a——- c:\windows\system32\dllcache\helpsvc.exe 2010-06-14 15:30 743,936 a——- c:\windows\pchealth\helpctr\binaries\helpsvc.exe ============= FINISH: 10:57:18.20 ===============
tried to run GMER 4 times now, frist time it blue screened part way through the scan. Second time it froze completely, third time it got stuck on a file, i tried to restart the scan, and then it froze. and the 4th time it seemed to be going well and was scanning for at least half an hour, but then the comp crashed and restarted itself. :(
Hi,

Please run this one instead:

Please download Rootkit Unhooker and save it on your desktop.
  • Disable your security programs
  • Double click RKUnhookerLE.exe to run it
  • Click the Report tab, then click Scan
  • Check Drivers and Stealth Code,
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
Note - You may get this warning, it is ok, just ignore it:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

thank you :) RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 2) Number of processors #2 ============================================== >Drivers ============================================== 0xB8D6A000 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 6307840 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Miniport Driver, Version 182.06 ) 0xBF012000 C:\WINDOWS\System32\nv4_disp.dll 6189056 bytes (NVIDIA Corporation, NVIDIA Compatible Windows 2000 Display driver, Version 182.06 ) 0xB5D1B000 C:\WINDOWS\system32\drivers\RtkHDAud.sys 5226496 bytes (Realtek Semiconductor Corp., Realtek® High Definition Audio Function Driver) 0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2142208 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2142208 bytes 0x804D7000 RAW 2142208 bytes 0x804D7000 WMIxWDM 2142208 bytes 0xBF800000 Win32k 1851392 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1851392 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xB9E48000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xB4E12000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xB8C88000 C:\WINDOWS\system32\DRIVERS\slntamr.sys 405504 bytes ( , slntamr driver) 0xB8BC0000 C:\WINDOWS\system32\DRIVERS\update.sys 364544 bytes (Microsoft Corporation, Update Driver) 0xB4F3F000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xB44A8000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver) 0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xB3C0E000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xB9F79000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xB463F000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xB9E07000 C:\WINDOWS\System32\DRIVERS\NDIS.SYS 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xB2115000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xB4E81000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xB4EEF000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xB4DC3000 C:\WINDOWS\System32\Drivers\aswSP.SYS 159744 bytes (AVAST Software, avast! self protection module) 0xB8D0E000 C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 151552 bytes (Windows ® Server 2003 DDK provider, High Definition Audio Bus Driver v1.0a) 0xB8CEB000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xB8D33000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xB4EAC000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xB5CF9000 C:\WINDOWS\system32\drivers\portcls.sys 139264 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xB4ECE000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator) 0x806E2000 ACPI_HAL 134400 bytes 0x806E2000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xB9EFE000 fltMgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xB4FCA000 C:\WINDOWS\System32\DRIVERS\cmdguard.sys 126976 bytes (COMODO, COMODO Internet Security Sandbox Driver) 0xB9F36000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xB8C69000 C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys 126976 bytes ( , mtlmnt5 driver) 0xB9DAF000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xB9F1E000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xB4DAB000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xB484C000 C:\WINDOWS\System32\Drivers\aswMon2.SYS 94208 bytes (AVAST Software, avast! File System Filter Driver for Windows XP) 0xB9ED5000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xB8C2A000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xB9DF0000 sfvfs02.sys 94208 bytes (Protection Technology (StarForce), FrontLine VFS Driver) 0xB3F93000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xB9E34000 inspect.sys 81920 bytes (COMODO, COMODO Internet Security Firewall Driver) 0xB8C41000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xB8C55000 C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 81920 bytes (Realtek Semiconductor Corporation , Realtek 10/100/1000 NDIS 5.1 Driver ) 0xB9DDC000 sfdrv01a.sys 81920 bytes (Protection Technology (StarForce), FrontLine Environment Driver) 0xB8D56000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xB4F97000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xB9F55000 sfsync04.sys 77824 bytes (Protection Technology (StarForce), FrontLine Synchronization Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xB9DCA000 sfdrv01.sys 73728 bytes (Protection Technology (StarForce), FrontLine Environment Driver) 0xB9EEC000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver) 0xB9F68000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xB8C19000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xB936E000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xBA178000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xB93DE000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xBA168000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xB4180000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xB93EE000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xB4048000 C:\WINDOWS\System32\Drivers\usbaapl.sys 57344 bytes (Apple, Inc., Apple Mobile Device USB Driver) 0xBA158000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 53248 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xBA0F8000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xBA188000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xBA198000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xBA0D8000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xBA1B8000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xBA148000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xBA0B8000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xBA1A8000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xB93BE000 C:\WINDOWS\System32\Drivers\aswTdi.SYS 40960 bytes (AVAST Software, avast! TDI Filter Driver) 0xBA1E8000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xB455F000 C:\WINDOWS\system32\DRIVERS\secdrv.sys 40960 bytes (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K., Macrovision SECURITY Driver) 0xBA1D8000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xBA0E8000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xB939E000 C:\WINDOWS\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xBA138000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xBA0A8000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xBA1C8000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xB93AE000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xB4B1B000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xBA0C8000 sfsync02.sys 36864 bytes (Protection Technology, StarForce Protection Synchronization Driver) 0xB938E000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xBA488000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xBA3A8000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xBA340000 sfhlp02.sys 32768 bytes (Protection Technology (StarForce), FrontLine Helper Driver) 0xBA490000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xBA328000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xBA478000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 28672 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xBA3C8000 C:\WINDOWS\System32\Drivers\Aavmker4.SYS 24576 bytes (AVAST Software, avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP) 0xBA480000 C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0xBA4A0000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xBA498000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xBA398000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xBA410000 C:\WINDOWS\System32\Drivers\aswRdr.SYS 20480 bytes (AVAST Software, avast! TDI RDR Driver) 0xBA3B0000 C:\WINDOWS\System32\DRIVERS\cmdhlp.sys 20480 bytes (COMODO, COMODO Internet Security Helper Driver) 0xBA3A0000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xBA330000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xBA4A8000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xBA4B0000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xBA338000 C:\WINDOWS\System32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xBA470000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 20480 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xBA3D0000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xB27D5000 C:\WINDOWS\system32\DRIVERS\asyncmac.sys 16384 bytes (Microsoft Corporation, MS Remote Access serial network driver) 0xBA578000 C:\WINDOWS\system32\drivers\MODEMCSA.sys 16384 bytes (Microsoft Corporation, Unimodem CSA Filter) 0xB9D7F000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xB49BB000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xBA4BC000 RecAgent.sys 16384 bytes ( , Recorder agent driver) 0xBA5A4000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xBA59C000 C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys 16384 bytes ( , SlWdmSup driver) 0xB3C5F000 C:\WINDOWS\system32\DRIVERS\usbscan.sys 16384 bytes (Microsoft Corporation, USB Scanner Driver) 0xB4AE7000 C:\WINDOWS\System32\Drivers\aswFsBlk.SYS 12288 bytes (AVAST Software, avast! File System Access Blocking Driver) 0xBA4B8000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xB5CD1000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xB9D8B000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xB9D83000 C:\WINDOWS\system32\DRIVERS\pnetmdm.sys 12288 bytes (June Fabrics Technology, PdaNet Driver) 0xB8B7B000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xBA604000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xBA618000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xBA602000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xBA5A8000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xBA606000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xBA642000 C:\WINDOWS\nvoclock.sys 8192 bytes (NVidia Corp., NVidia System Utility Driver) 0xBA5DC000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xBA60A000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xBA5AC000 sonyhcb.sys 8192 bytes (Sony Corporation, sonyhcb.sys) 0xBA5FA000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xBA5FC000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xBA5AA000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xBA78A000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xBA7F6000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xBA754000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xBA670000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) ============================================== >Stealth ==============================================
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 10-09-11.03 - Ian 12/09/2010 15:55:51.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.3070.2678 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\HyperCam Toolbar\tbHElper.dll

.
((((((((((((((((((((((((( Files Created from 2010-08-12 to 2010-09-12 )))))))))))))))))))))))))))))))
.

2010-09-11 09:53 . 2010-09-11 09:53 ——– d—–w- c:\documents and settings\Ian\Application Data\Malwarebytes
2010-09-11 09:53 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-11 09:53 . 2010-09-11 09:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-11 09:53 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-11 09:53 . 2010-09-11 09:53 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-09-07 18:58 . 2010-09-07 14:47 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-07 18:58 . 2010-09-07 14:52 165584 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-07 18:58 . 2010-09-07 14:47 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-07 18:58 . 2010-09-07 14:52 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-07 18:58 . 2010-09-07 14:47 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-07 18:58 . 2010-09-07 14:47 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-07 18:58 . 2010-09-07 14:46 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-07 18:57 . 2010-09-07 15:12 38848 —-a-w- c:\windows\avastSS.scr
2010-09-07 18:57 . 2010-09-07 15:11 167592 —-a-w- c:\windows\system32\aswBoot.exe
2010-09-07 18:57 . 2010-09-07 18:57 ——– d—–w- c:\program files\Alwil Software
2010-09-07 18:57 . 2010-09-07 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-09-07 18:39 . 2010-09-12 15:09 ——– d—–w- c:\program files\Steam
2010-09-05 13:22 . 2010-09-05 13:22 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-09-02 09:43 . 2009-11-03 13:07 1970176 —-a-w- c:\windows\system32\d3dx9.dll
2010-09-02 09:43 . 2010-09-11 20:33 ——– d—–w- c:\program files\Cheat Engine
2010-09-02 09:43 . 2009-11-03 13:07 679936 —-a-w- c:\windows\system32\D3DX81ab.dll
2010-08-31 15:19 . 2010-08-31 15:19 ——– d—–w- c:\documents and settings\Ian\Application Data\Toolbar4
2010-08-31 15:19 . 2010-09-12 15:03 ——– d—–w- c:\program files\HyperCam Toolbar
2010-08-31 15:18 . 2010-08-31 15:18 ——– d—–w- c:\program files\HyCam2
2010-08-30 19:58 . 2010-08-30 20:06 ——– d—–w- c:\program files\Fiesta Online(EU_English)
2010-08-30 18:36 . 2010-08-30 18:36 ——– d—–w- c:\program files\Common Files\DirectX
2010-08-30 18:26 . 2010-01-13 16:48 118176 —-a-w- c:\windows\patchw.dll
2010-08-30 18:18 . 2010-08-30 18:48 ——– d—–w- c:\program files\Outspark
2010-08-30 15:45 . 2010-08-30 15:45 ——– d—–w- C:\fb9724e9ee31c0e7443ee6a3
2010-08-29 10:10 . 2010-08-29 10:10 ——– d—–w- C:\a990d76d4996e0a254d3
2010-08-29 10:08 . 2007-05-17 11:28 549376 —-a-w- c:\windows\system32\oleaut32.dll
2010-08-29 09:57 . 2006-02-28 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-08-28 12:35 . 2010-09-11 10:14 ——– d—–w- c:\windows\Sun
2010-08-28 08:50 . 2010-08-28 08:50 ——– d—–w- c:\program files\Common Files\Java
2010-08-28 08:50 . 2010-07-17 04:00 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-27 16:34 . 2010-09-12 11:37 ——– d—–w- c:\documents and settings\Ian\Application Data\LimeWire
2010-08-27 16:33 . 2010-08-28 08:50 ——– d—–w- c:\program files\Java
2010-08-27 16:33 . 2010-08-27 16:34 ——– d—–w- c:\program files\LimeWire
2010-08-27 14:57 . 2010-08-27 14:57 ——– d-sh–w- c:\documents and settings\Ian\IECompatCache
2010-08-27 14:39 . 2010-08-27 14:43 ——– d—–w- c:\windows\ie8updates
2010-08-27 12:22 . 2010-08-30 23:01 ——– d—–w- c:\documents and settings\Ian\Local Settings\Application Data\PMB Files
2010-08-27 12:22 . 2010-08-30 18:51 ——– d—–w- c:\documents and settings\All Users\Application Data\PMB Files
2010-08-27 12:21 . 2010-08-27 12:21 ——– d—–w- c:\program files\Pando Networks
2010-08-27 11:59 . 2010-05-06 10:41 599040 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-08-27 11:59 . 2010-05-06 10:41 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-08-27 11:59 . 2010-05-06 10:41 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-08-27 11:59 . 2010-05-06 10:41 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-08-27 11:59 . 2010-05-06 10:41 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-08-27 11:59 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-08-27 11:59 . 2010-05-06 10:41 11076096 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-08-27 11:47 . 2010-08-27 11:47 ——– d-sh–w- c:\documents and settings\Ian\PrivacIE
2010-08-27 11:47 . 2010-08-27 11:54 ——– d—–w- c:\windows\system32\CatRoot_bak
2010-08-27 11:19 . 2010-08-27 11:21 ——– d—–w- c:\windows\system32\wbem\Repository
2010-08-27 11:18 . 2010-08-27 11:32 ——– d—–w- c:\windows\system32\en
2010-08-27 11:18 . 2010-08-27 11:32 ——– d—–w- c:\windows\system32\bits
2010-08-27 11:14 . 2010-08-27 11:14 ——– d—–w- c:\windows\EHome
2010-08-27 10:16 . 2010-08-27 11:32 ——– d—–w- c:\windows\system32\scripting
2010-08-27 10:16 . 2010-08-27 11:31 ——– d—–w- c:\windows\l2schemas
2010-08-27 10:07 . 2009-12-24 07:05 177664 —-a-w- c:\windows\system32\dllcache\wintrust.dll
2010-08-27 10:00 . 2010-08-27 10:00 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-08-27 09:58 . 2010-08-27 09:58 ——– d-sh–w- c:\documents and settings\Ian\IETldCache
2010-08-26 17:12 . 2010-08-26 17:12 ——– d—–w- C:\9031e5d399997adc63
2010-08-26 15:47 . 2010-08-26 15:48 ——– dc-h–w- c:\windows\ie8
2010-08-26 15:13 . 2010-08-26 15:13 ——– d—–w- C:\c66445dd4b6cdd2c70fb4df583a4bb
2010-08-26 15:13 . 2010-08-26 15:13 ——– d—–w- C:\6b4feaf3eaa8d23d3b620a15
2010-08-26 15:01 . 2010-08-26 15:01 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-08-26 15:00 . 2010-08-26 15:00 ——– d—–w- c:\program files\MSXML 6.0
2010-08-26 14:48 . 2010-08-27 11:38 ——– d—–w- c:\windows\ServicePackFiles
2010-08-26 12:51 . 2010-02-12 10:03 293376 ——w- c:\windows\system32\browserchoice.exe
2010-08-26 11:49 . 2009-08-06 18:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-08-26 11:49 . 2009-08-06 18:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-08-22 16:10 . 2010-09-08 19:29 ——– d—–w- c:\program files\SweetIM
2010-08-18 09:50 . 2003-04-17 08:21 98176 —-a-r- c:\windows\system32\drivers\vnet558x.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-08 19:29 . 2007-07-03 12:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-08 19:05 . 2007-07-03 12:24 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-09-07 18:59 . 2010-01-04 20:33 ——– d—–w- c:\program files\Google
2010-09-05 13:26 . 2006-01-10 16:35 ——– d—–w- c:\program files\Common Files\Adobe
2010-09-05 13:22 . 2010-09-05 13:22 53632 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-08-30 18:48 . 2006-01-06 15:13 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-28 09:52 . 2006-01-07 14:53 80640 —-a-w- c:\documents and settings\Ian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-27 20:46 . 2010-08-27 20:46 503808 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-53101f1d-n\msvcp71.dll
2010-08-27 20:46 . 2010-08-27 20:46 499712 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-53101f1d-n\jmc.dll
2010-08-27 20:46 . 2010-08-27 20:46 348160 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-53101f1d-n\msvcr71.dll
2010-08-27 20:46 . 2010-08-27 20:46 61440 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-632ae020-n\decora-sse.dll
2010-08-27 20:46 . 2010-08-27 20:46 12800 —-a-w- c:\documents and settings\Ian\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-632ae020-n\decora-d3d.dll
2010-08-27 16:34 . 2010-08-27 16:34 8192 —-a-w- c:\documents and settings\Ian\Application Data\LimeWire\browser\xulrunner\AccessibleMarshal.dll
2010-08-27 16:31 . 2010-04-14 13:12 ——– d—–w- c:\documents and settings\Ian\Application Data\uTorrent
2010-08-27 11:29 . 2006-01-06 15:06 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-08-26 14:52 . 2007-01-14 09:26 ——– d—–w- c:\program files\Microsoft Works
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2009-09-14 1217808]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 81920]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2006-02-28 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-27 734264]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"ShowWnd"="ShowWnd.exe" [2003-09-19 36864]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-02 17530368]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"nwiz"="nwiz.exe" [2009-02-09 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13680640]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-07 50688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-08-26 1796368]
"CHotkey"="zHotkey.exe" [2004-05-17 543232]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]

c:\documents and settings\Ian\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-8-19 503808]
PdaNet Desktop.lnk - c:\program files\PdaNet for iPhone\PdaNetPC.exe [2009-12-8 173520]
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2006-8-30 2240080]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CoreCenter.lnk]
backup=c:\windows\pss\CoreCenter.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSON Status Monitor 3 Environment Check 2.lnk]
backup=c:\windows\pss\EPSON Status Monitor 3 Environment Check 2.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Ian^Start Menu^Programs^Startup^Registration .LNK]
backup=c:\windows\pss\Registration .LNKStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Midway Games\\Rise and Fall\\RiseAndFall.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEARMP.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEARXP\\FEARXP.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"f:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"f:\\Program Files\\EA GAMES\\The Battle for Middle-earth ™\\game.dat"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enGB-downloader.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires\\Empires.exe"=
"f:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2300:TCP"= 2300:TCP:age
"2300:UDP"= 2300:UDP:age1
"58097:TCP"= 58097:TCP:Pando Media Booster
"58097:UDP"= 58097:UDP:Pando Media Booster

R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [05/07/2006 13:46 63352]
R0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [08/07/2007 09:06 6097]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [07/09/2010 19:58 165584]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [14/06/2009 21:46 132168]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [14/06/2009 21:46 25160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07/09/2010 19:58 17744]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [12/08/2009 09:51 9472]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [04/01/2010 21:33 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [11/12/2008 22:48 1684736]
S3 OEMFVNETusb(505 2958)®;OEM FVNETusb(505 2958)® Service for 802.11b Pen Size Wireless USB Adapter;c:\windows\system32\drivers\vnet558x.sys [18/08/2010 10:50 98176]
S3 pnicml;pnicml;\??\c:\docume~1\Ian\LOCALS~1\Temp\pnicml.sys –> c:\docume~1\Ian\LOCALS~1\Temp\pnicml.sys [?]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys [08/07/2007 09:06 299923]
S3 XDva344;XDva344;\??\c:\windows\system32\XDva344.sys –> c:\windows\system32\XDva344.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-04 20:33]

2010-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-04 20:33]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - f:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {791BA8B0-9824-437D-B593-03913AA02AAF} = 192.168.1.2
FF - ProfilePath - c:\documents and settings\Ian\Application Data\Mozilla\Firefox\Profiles\b5362naz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q;=
FF - prefs.js: browser.search.selectedEngine - Yahoo.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/?ref=home
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q;=
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff36\gears.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Musicnotes\npmusicn.dll
FF - plugin: c:\program files\Musicnotes\NPSibelius.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: f:\ian\My Documents\Sparkplay Media\Sparkplayer (Beta)\npSparkPlayerNS.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Notify-dimsntfy - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-12 16:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync02.sys >>UNKNOWN [0x8B7CD6E0]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0fcfc3
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> sfsync02.sys @ 0xba0c98b4
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80582414
ParseProcedure -> ntkrnlpa.exe @ 0x80581554
user & kernel MBR OK

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1644491937-1364589140-839522115-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:79,6d,7e,18,87,3a,d5,58,3e,92,0a,6a,54,5e,bf,d8,91,f9,85,a9,d2,69,14,
fd,e4,04,cb,7e,15,d4,ef,87,b6,9d,e0,9c,81,96,b6,0d,4e,ea,61,64,24,23,03,13,\
"??"=hex:5b,ea,67,63,47,83,c4,14,1d,89,60,78,85,d0,4c,af

[HKEY_USERS\S-1-5-21-1644491937-1364589140-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:57,f0,86,a4,c7,a7,0d,84,66,a5,7e,e3,2b,02,4a,b9,d3,27,f8,f5,69,
55,ee,61,3c,b5,95,82,c9,bc,ab,8f,f6,be,8e,33,21,35,0e,e2,3c,8e,d1,69,ac,53,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2444)
c:\windows\system32\WININET.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\imapi.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\zHotkey.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Completion time: 2010-09-12 16:14:15 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-12 15:14

Pre-Run: 94,865,428,480 bytes free
Post-Run: 95,124,279,296 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 59F57C9CC52E912C52EA187188114648
Avast isnt complaining anymore, and those dodgy temporary files arent being created :D but for some reason COMODO updater and Steam updater still arent working.. :S
Hi

Please do the following:


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI