This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

my computer is iratic when opening explorer

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

im getting warnings off microsoft security essentials that a trojan is in my system and i remove it but it comes up again , sometimes explorer either freezes up or takes a long time going there. i cant connect to msn updates and i cant put on my firewall anylonger , sec essentials warns me it needs turning on ??? when i go there it wont allow , i suspect something is interupting my comp hope you can help, im using xp sp 3 , clevo laptop, 2.33ghz with 3gb ram up until yesterday i had no probs the trojan that keeps coming up is a trojan downloader: win32/unruy.h and it keeps recurring
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post






Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.







[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.



In your next reply please post the following.
  • Both OTL logs
  • GMER log
hiMowman, thanks for your help its very much appreciated ive completed the first two scans from otl but this machine wont let me post , every time i try to complete and post it goes to the NO windows internet connection page and diagnostics , also when ive tried to go to windows update it takes me to another page and this goes on randomlly im now trying to attach these logs and try that way ist the otl text then the extrras text
well that seemed to work from this end i can see them in your box awaiting your perusal im sorry i didnt follow your instructions to the letter but i could nt see any other way to get it to you , it looks like somethings trying to block me sending text ??? im just going to do the gamer thing now , i may have to post to you in the same way regards phil c
Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
hi mow man , sorry ive taken a while to get back to you , but when a reply is given on here an e-mail usually come to my in box as like your past two replys, this time no e-mail came through informing me youd replied, most strange . here is the rquired log THANK YOU OH HAPPY NEW YEAR 2011/01/01 17:37:56.0640 TDSS rootkit removing tool 2.4.12.0 Dec 16 2010 09:46:46 2011/01/01 17:37:56.0640 ================================================================================ 2011/01/01 17:37:56.0640 SystemInfo: 2011/01/01 17:37:56.0640 2011/01/01 17:37:56.0640 OS Version: 5.1.2600 ServicePack: 3.0 2011/01/01 17:37:56.0640 Product type: Workstation 2011/01/01 17:37:56.0640 ComputerName: EDITMACHINE 2011/01/01 17:37:56.0640 UserName: P Compton 2011/01/01 17:37:56.0640 Windows directory: C:\WINDOWS 2011/01/01 17:37:56.0640 System windows directory: C:\WINDOWS 2011/01/01 17:37:56.0640 Processor architecture: Intel x86 2011/01/01 17:37:56.0640 Number of processors: 2 2011/01/01 17:37:56.0640 Page size: 0x1000 2011/01/01 17:37:56.0640 Boot type: Normal boot 2011/01/01 17:37:56.0640 ================================================================================ 2011/01/01 17:37:56.0968 Initialize success 2011/01/01 17:38:56.0140 ================================================================================ 2011/01/01 17:38:56.0140 Scan started 2011/01/01 17:38:56.0140 Mode: Manual; 2011/01/01 17:38:56.0140 ================================================================================ 2011/01/01 17:38:58.0406 61883 (914a9709fc3bf419ad2f85547f2a4832) C:\WINDOWS\system32\DRIVERS\61883.sys 2011/01/01 17:38:59.0078 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2011/01/01 17:38:59.0312 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 2011/01/01 17:38:59.0796 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 2011/01/01 17:39:00.0031 Afc (a7b8a3a79d35215d798a300df49ed23f) C:\WINDOWS\system32\drivers\Afc.sys 2011/01/01 17:39:00.0281 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 2011/01/01 17:39:01.0156 aksfridge (45f65f2f7ae28e5e56ab64e3ac61bd52) C:\WINDOWS\system32\DRIVERS\aksfridge.sys 2011/01/01 17:39:01.0390 akshasp (64fc197d24a2b240598f29ce0a6660c0) C:\WINDOWS\system32\DRIVERS\akshasp.sys 2011/01/01 17:39:01.0640 akshhl (147b61b81be1ffc38939ea47e5cfb51f) C:\WINDOWS\system32\DRIVERS\akshhl.sys 2011/01/01 17:39:01.0890 aksusb (cce6c56f18d214de8d66f3f2a774cd5b) C:\WINDOWS\system32\DRIVERS\aksusb.sys 2011/01/01 17:39:02.0546 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2011/01/01 17:39:03.0453 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2011/01/01 17:39:03.0687 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 2011/01/01 17:39:04.0250 ati2mtag (6733656c24f4c6a29317c3dd9ac5980a) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 2011/01/01 17:39:04.0500 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2011/01/01 17:39:04.0734 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2011/01/01 17:39:04.0968 Avc (f8e6956a614f15a0860474c5e2a7de6b) C:\WINDOWS\system32\DRIVERS\avc.sys 2011/01/01 17:39:05.0218 AVCSTRM (e625773d7b950842d582f713656859c0) C:\WINDOWS\system32\DRIVERS\avcstrm.sys 2011/01/01 17:39:05.0515 AvgLdx86 (9c0a7e6d3cb9a8a7ad4e4575d9a42e94) C:\WINDOWS\system32\Drivers\avgldx86.sys 2011/01/01 17:39:05.0828 AvgMfx86 (f9caeec3ff1545991f490264429724c5) C:\WINDOWS\system32\Drivers\avgmfx86.sys 2011/01/01 17:39:06.0109 AvgTdiX (cf9ac576490bb6c547cd16ef0b782358) C:\WINDOWS\system32\Drivers\avgtdix.sys 2011/01/01 17:39:06.0343 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2011/01/01 17:39:06.0593 BlueletAudio (0744aa40fe6fa9c471fa59ccb5ca1f73) C:\WINDOWS\system32\DRIVERS\blueletaudio.sys 2011/01/01 17:39:06.0843 BlueletSCOAudio (01d1832f2b13dfaf7384884f7c3e0124) C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys 2011/01/01 17:39:07.0093 Bridge (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 2011/01/01 17:39:07.0109 BridgeMP (f934d1b230f84e1d19dd00ac5a7a83ed) C:\WINDOWS\system32\DRIVERS\bridge.sys 2011/01/01 17:39:07.0359 BT (51eff72092088948933298c12ed23fd1) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys 2011/01/01 17:39:07.0593 Btcsrusb (3efdd3cc9118f6290398d94a72458b00) C:\WINDOWS\system32\Drivers\btcusb.sys 2011/01/01 17:39:07.0812 BthEnum (b279426e3c0c344893ed78a613a73bde) C:\WINDOWS\system32\DRIVERS\BthEnum.sys 2011/01/01 17:39:08.0078 BTHidEnum (e69d9e7854095a9c81acee40d766fe2d) C:\WINDOWS\system32\DRIVERS\vbtenum.sys 2011/01/01 17:39:08.0312 BTHidMgr (a9164c2a39bd917b9f42ae087560ac3d) C:\WINDOWS\system32\Drivers\BTHidMgr.sys 2011/01/01 17:39:08.0562 BthPan (80602b8746d3738f5886ce3d67ef06b6) C:\WINDOWS\system32\DRIVERS\bthpan.sys 2011/01/01 17:39:08.0812 BTHPORT (662bfd909447dd9cc15b1a1c366583b4) C:\WINDOWS\system32\Drivers\BTHport.sys 2011/01/01 17:39:09.0062 BTHUSB (61364cd71ef63b0f038b7e9df00f1efa) C:\WINDOWS\system32\Drivers\BTHUSB.sys 2011/01/01 17:39:09.0328 Cam5603D (53aef6e6f113ffc28f765d34ee70ebd0) C:\WINDOWS\system32\Drivers\BisonCam.sys 2011/01/01 17:39:09.0578 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2011/01/01 17:39:09.0796 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 2011/01/01 17:39:10.0234 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2011/01/01 17:39:10.0437 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 2011/01/01 17:39:10.0640 cdrblock (39af0375c683546d057ff8be5f630d75) C:\WINDOWS\system32\DRIVERS\cdrblock.sys 2011/01/01 17:39:10.0859 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2011/01/01 17:39:11.0218 cdrport (0d116214017a394b08897c3e4bde0607) C:\WINDOWS\system32\DRIVERS\cdrport.sys 2011/01/01 17:39:11.0765 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 2011/01/01 17:39:12.0203 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 2011/01/01 17:39:13.0343 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 2011/01/01 17:39:13.0625 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 2011/01/01 17:39:13.0953 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\DRIVERS\dmio.sys 2011/01/01 17:39:14.0234 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2011/01/01 17:39:14.0468 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 2011/01/01 17:39:15.0484 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 2011/01/01 17:39:15.0750 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 2011/01/01 17:39:16.0000 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 2011/01/01 17:39:16.0250 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 2011/01/01 17:39:16.0515 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 2011/01/01 17:39:16.0796 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 2011/01/01 17:39:17.0140 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2011/01/01 17:39:17.0421 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2011/01/01 17:39:17.0671 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys 2011/01/01 17:39:17.0984 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2011/01/01 17:39:18.0250 Hardlock (995178a443b07fa9eeaea041d7b4b5ca) C:\WINDOWS\system32\drivers\hardlock.sys 2011/01/01 17:39:18.0484 Haspnt (2dd25f060dc9f79b5cdf33d90ed93669) C:\WINDOWS\system32\drivers\Haspnt.sys 2011/01/01 17:39:18.0750 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 2011/01/01 17:39:19.0062 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2011/01/01 17:39:19.0531 HSFHWAZL (14d33812459b114cdc9d13c7000ef4ba) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 2011/01/01 17:39:19.0812 HSF_DPV (60d45b3c61099f3814c9577d91b70b18) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 2011/01/01 17:39:20.0125 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 2011/01/01 17:39:20.0812 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2011/01/01 17:39:21.0171 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 2011/01/01 17:39:21.0765 IntcAzAudAddService (c464cf7a58c011a70188602b55c64e99) C:\WINDOWS\system32\drivers\RtkHDAud.sys 2011/01/01 17:39:22.0468 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2011/01/01 17:39:22.0718 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 2011/01/01 17:39:22.0984 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2011/01/01 17:39:23.0218 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2011/01/01 17:39:23.0500 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2011/01/01 17:39:24.0078 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2011/01/01 17:39:24.0343 irda (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys 2011/01/01 17:39:24.0593 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 2011/01/01 17:39:24.0843 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2011/01/01 17:39:25.0187 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2011/01/01 17:39:25.0437 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 2011/01/01 17:39:25.0656 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 2011/01/01 17:39:25.0984 Ktp (2fa0ba441e92cacddef9514f0dc0e978) C:\WINDOWS\system32\DRIVERS\Ktp.sys 2011/01/01 17:39:26.0828 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 2011/01/01 17:39:27.0156 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2011/01/01 17:39:27.0421 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 2011/01/01 17:39:27.0671 MotDev (20ff89c59b0a50f53822303064988e00) C:\WINDOWS\system32\DRIVERS\motodrv.sys 2011/01/01 17:39:28.0031 motmodem (fe80c18ba448ddd76b7bead9eb203d37) C:\WINDOWS\system32\DRIVERS\motmodem.sys 2011/01/01 17:39:28.0281 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2011/01/01 17:39:28.0531 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2011/01/01 17:39:28.0781 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 2011/01/01 17:39:29.0625 MpFilter (7e34bfa1a7b60bba1da03d677f16cd63) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 2011/01/01 17:39:30.0093 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2011/01/01 17:39:30.0375 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2011/01/01 17:39:30.0625 MSDV (1477849772712bac69c144dcf2c9ce81) C:\WINDOWS\system32\DRIVERS\msdv.sys 2011/01/01 17:39:30.0859 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 2011/01/01 17:39:31.0093 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2011/01/01 17:39:31.0328 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2011/01/01 17:39:31.0578 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 2011/01/01 17:39:31.0812 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2011/01/01 17:39:32.0062 MSTAPE (5c3f9bdf4db23b75306388fc26a0a8e5) C:\WINDOWS\system32\DRIVERS\mstape.sys 2011/01/01 17:39:32.0281 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 2011/01/01 17:39:32.0593 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 2011/01/01 17:39:32.0843 n558 (88705dc61b9275b82e48904d53031f5b) C:\WINDOWS\system32\Drivers\n558.sys 2011/01/01 17:39:33.0125 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2011/01/01 17:39:33.0359 NCHSSVAD (e78ce4b8e70ccc1a6e63008c3660867c) C:\WINDOWS\system32\drivers\nchssvad.sys 2011/01/01 17:39:33.0671 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 2011/01/01 17:39:34.0000 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2011/01/01 17:39:34.0234 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2011/01/01 17:39:34.0484 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2011/01/01 17:39:34.0734 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2011/01/01 17:39:35.0062 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 2011/01/01 17:39:35.0312 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 2011/01/01 17:39:35.0593 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2011/01/01 17:39:35.0859 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 2011/01/01 17:39:36.0078 NSCIRDA (2adc0ca9945c65284b3d19bc18765974) C:\WINDOWS\system32\DRIVERS\nscirda.sys 2011/01/01 17:39:36.0375 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 2011/01/01 17:39:36.0640 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2011/01/01 17:39:36.0906 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2011/01/01 17:39:38.0156 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2011/01/01 17:39:38.0546 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2011/01/01 17:39:38.0796 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 2011/01/01 17:39:39.0031 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 2011/01/01 17:39:39.0296 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2011/01/01 17:39:39.0562 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 2011/01/01 17:39:40.0000 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2011/01/01 17:39:40.0234 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 2011/01/01 17:39:41.0750 PhilCam8116 (a3a4d50051ddbcf390e5918c43c167ef) C:\WINDOWS\system32\DRIVERS\CamDrL21.sys 2011/01/01 17:39:42.0156 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2011/01/01 17:39:42.0406 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 2011/01/01 17:39:42.0656 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2011/01/01 17:39:44.0046 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2011/01/01 17:39:44.0296 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys 2011/01/01 17:39:44.0515 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2011/01/01 17:39:44.0765 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2011/01/01 17:39:45.0062 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2011/01/01 17:39:45.0328 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2011/01/01 17:39:45.0578 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2011/01/01 17:39:45.0828 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2011/01/01 17:39:46.0109 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 2011/01/01 17:39:46.0359 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 2011/01/01 17:39:46.0609 RFCOMM (851c30df2807fcfa21e4c681a7d6440e) C:\WINDOWS\system32\DRIVERS\rfcomm.sys 2011/01/01 17:39:46.0843 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 2011/01/01 17:39:47.0109 RTL8023xp (eacd871fdbe85393d112782896c2d7dd) C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys 2011/01/01 17:39:47.0671 sbp2port (b244960e5a1db8e9d5d17086de37c1e4) C:\WINDOWS\system32\DRIVERS\sbp2port.sys 2011/01/01 17:39:47.0953 sdbus (8d04819a3ce51b9eb47e5689b44d43c4) C:\WINDOWS\system32\DRIVERS\sdbus.sys 2011/01/01 17:39:48.0187 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2011/01/01 17:39:48.0421 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 2011/01/01 17:39:48.0687 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 2011/01/01 17:39:48.0937 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 2011/01/01 17:39:49.0187 SI3132 (0b9b5c6df6226497ef4819b6e1b2efd5) C:\WINDOWS\system32\DRIVERS\SI3132.sys 2011/01/01 17:39:49.0453 SiFilter (ad29a80543c63e5b3588d118fb327e22) C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys 2011/01/01 17:39:50.0000 SiRemFil (b19efe5e45ae31f3c3e4c4f0f9da3c49) C:\WINDOWS\system32\DRIVERS\SiRemFil.sys 2011/01/01 17:39:50.0218 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2011/01/01 17:39:50.0656 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 2011/01/01 17:39:50.0953 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 2011/01/01 17:39:51.0187 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys 2011/01/01 17:39:51.0437 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys 2011/01/01 17:39:51.0671 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2011/01/01 17:39:52.0031 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 2011/01/01 17:39:52.0312 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 2011/01/01 17:39:53.0437 SynTP (69bf2dd9b1099d1aa3e7cf14b4b842cd) C:\WINDOWS\system32\DRIVERS\SynTP.sys 2011/01/01 17:39:53.0687 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 2011/01/01 17:39:54.0046 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2011/01/01 17:39:54.0281 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 2011/01/01 17:39:54.0531 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 2011/01/01 17:39:54.0781 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 2011/01/01 17:39:55.0218 tifm21 (f779ba4cd37963ab4600c9871b7752a3) C:\WINDOWS\system32\drivers\tifm21.sys 2011/01/01 17:39:55.0671 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 2011/01/01 17:39:56.0156 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 2011/01/01 17:39:56.0406 USBAAPL (5c2bdc152bbab34f36473deaf7713f22) C:\WINDOWS\system32\Drivers\usbaapl.sys 2011/01/01 17:39:56.0656 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys 2011/01/01 17:39:56.0906 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2011/01/01 17:39:57.0156 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2011/01/01 17:39:57.0390 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2011/01/01 17:39:57.0656 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2011/01/01 17:39:58.0015 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 2011/01/01 17:39:58.0281 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2011/01/01 17:39:58.0531 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2011/01/01 17:39:58.0796 VComm (9ebee4a060c5364a31aeaa04eac2af1e) C:\WINDOWS\system32\DRIVERS\VComm.sys 2011/01/01 17:39:59.0156 VcommMgr (d1ddff84dc3060456c8bc0c47af8cbb2) C:\WINDOWS\system32\Drivers\VcommMgr.sys 2011/01/01 17:39:59.0421 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 2011/01/01 17:40:00.0015 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 2011/01/01 17:40:00.0281 w39n51 (b1f126e7e28877106d60e6ff3998d033) C:\WINDOWS\system32\DRIVERS\w39n51.sys 2011/01/01 17:40:00.0531 w810bus (5e8b60606fc4173b69cdecd964f22d28) C:\WINDOWS\system32\DRIVERS\w810bus.sys 2011/01/01 17:40:00.0765 w810mdfl (c0cc4f5a3c58b4c07ec4a82a5ae24714) C:\WINDOWS\system32\DRIVERS\w810mdfl.sys 2011/01/01 17:40:01.0156 w810mdm (2aafeedc3bfe14419cbce7ceea59dd05) C:\WINDOWS\system32\DRIVERS\w810mdm.sys 2011/01/01 17:40:01.0390 w810mgmt (b0037db3f890d0ffcf7e35f356a435ec) C:\WINDOWS\system32\DRIVERS\w810mgmt.sys 2011/01/01 17:40:01.0625 w810obex (bf609636068f17246f94b490c5812483) C:\WINDOWS\system32\DRIVERS\w810obex.sys 2011/01/01 17:40:01.0953 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2011/01/01 17:40:02.0250 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys 2011/01/01 17:40:02.0718 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 2011/01/01 17:40:03.0078 winachsf (97fa8f7f2e9168e3a4f02dee76709a29) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 2011/01/01 17:40:03.0359 WpdUsb (c60dc16d4e406810fad54b98dc92d5ec) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 2011/01/01 17:40:03.0609 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2011/01/01 17:40:03.0859 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 2011/01/01 17:40:04.0109 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 2011/01/01 17:40:04.0171 \HardDisk0 - detected Rootkit.Win32.TDSS.tdl4 (0) 2011/01/01 17:40:04.0171 ================================================================================ 2011/01/01 17:40:04.0171 Scan finished 2011/01/01 17:40:04.0171 ================================================================================ 2011/01/01 17:40:04.0171 Detected object count: 1 2011/01/01 17:41:09.0343 \HardDisk0 - will be cured after reboot 2011/01/01 17:41:09.0343 Rootkit.Win32.TDSS.tdl4(\HardDisk0) - User select action: Cure 2011/01/01 17:41:19.0125 Deinitialize success
HI MOWMAN my computer now wants to do updates finally, ive stopped it from doing so should i or not until we finish ?? regards phil c
Leave the updates until we are finished.



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.






Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5443 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 02/01/2011 15:57:38 mbam-log-2011-01-02 (15-57-38).txt Scan type: Quick scan Objects scanned: 158243 Time elapsed: 7 minute(s), 11 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 6 Files Infected: 8 Memory Processes Infected: c:\WINDOWS\Temp\laby\setup.exe (Spyware.Passwords.XGen) -> 1976 -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AMService (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUP.EXE (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: c:\documents and settings\networkservice\application data\sky-banners (Adware.Adrotator) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\sky-banners\skb (Adware.Adrotator) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\street-ads (Adware.Adrotator) -> Quarantined and deleted successfully. c:\documents and settings\networkservice\application data\street-ads\sta (Adware.Adrotator) -> Quarantined and deleted successfully. c:\documents and settings\p compton\application data\whitesmoke (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\WINDOWS\$ntuninstallmtf197$ (Adware.Adrotator) -> Quarantined and deleted successfully. Files Infected: c:\WINDOWS\Temp\laby\setup.exe (Spyware.Passwords.XGen) -> Quarantined and deleted successfully. c:\documents and settings\p compton\local settings\temp\~nsu.tmp\mosquito.exe (Trojan.Dropper) -> Quarantined and deleted successfully. c:\WINDOWS\catmstma.dll (Trojan.Hiloti) -> Quarantined and deleted successfully. c:\documents and settings\p compton\application data\Adobe\plugs\kb4166984.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\p compton\application data\Adobe\plugs\kb4208328.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\p compton\application data\whitesmoke\stat.log (PUP.WhiteSmoke) -> Quarantined and deleted successfully. c:\WINDOWS\$ntuninstallmtf197$\apuninstall.exe (Adware.Adrotator) -> Quarantined and deleted successfully. c:\WINDOWS\$ntuninstallmtf197$\zrpt.xml (Adware.Adrotator) -> Quarantined and deleted successfully.
hi mowman canot get the eset scan to run , it comes up with " cannot update , is proxy configured " i have no clue ??? regards phil c
hi mowman , i have now got the scan to run , i by passed my wireless connection and used a cable to my laptop, i shall post the log when scan is finished
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=1 esets_scanner_update returned -1 esets_gle=41217 esets_scanner_update returned -1 esets_gle=41217 esets_scanner_update returned -1 esets_gle=41217 esets_scanner_update returned -1 esets_gle=1 # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=6a322a6aaf3de846b42ff7234fe769ce # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-01-02 05:17:01 # local_time=2011-01-02 05:17:01 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777191 100 0 0 0 0 0 # compatibility_mode=5891 16776869 42 87 84604 6029934 0 0 # compatibility_mode=8192 67108863 100 0 4742 4742 0 0 # scanned=146853 # found=0 # cleaned=0 # scan_time=3149
hi mowman,
OTL logfile created on: 02/01/2011 19:14:00 - Run 2
OTL by OldTimer - Version 3.2.18.1 Folder = C:\Documents and Settings\P Compton\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 40.00 Gb Total Space | 6.10 Gb Free Space | 15.26% Space Free | Partition Type: NTFS
Drive D: | 146.31 Gb Total Space | 113.81 Gb Free Space | 77.79% Space Free | Partition Type: NTFS

Computer Name: EDITMACHINE | User Name: P Compton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\P Compton\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\hasplms.exe (SafeNet Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\P Compton\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (SNMPTRAP) – C:\WINDOWS\System32\snmptrap.exe File not found
SRV - (SNMP) – C:\WINDOWS\System32\snmp.exe File not found
SRV - (NBService) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (gusvc) – File not found
SRV - (Fun4IM Coordinator) – C:\PROGRA~1\Fun4IM\Bandoo.exe File not found
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe File not found
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe File not found
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (hasplms) – C:\WINDOWS\System32\hasplms.exe (SafeNet Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (BlueSoleil Hid Service) – C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()
SRV - (AutoExNT) – C:\WINDOWS\system32\Autoexnt.exe ()


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys File not found
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS File not found
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS File not found
DRV - (Lbd) – C:\WINDOWS\System32\DRIVERS\Lbd.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\PCOMPT~1\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NCHSSVAD) SoundTap Recorder (32 Bit) – C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)
DRV - (aksfridge) – C:\WINDOWS\system32\drivers\aksfridge.sys (Aladdin Knowledge Systems Ltd.)
DRV - (akshasp) – C:\WINDOWS\system32\drivers\akshasp.sys (Aladdin Knowledge Systems Ltd.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (SafeNet Inc.)
DRV - (aksusb) – C:\WINDOWS\system32\drivers\aksusb.sys (Aladdin Knowledge Systems Ltd.)
DRV - (akshhl) – C:\WINDOWS\system32\drivers\akshhl.sys (Aladdin Knowledge Systems Ltd.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (NSCIRDA) – C:\WINDOWS\system32\drivers\nscirda.sys (National Semiconductor Corporation)
DRV - (61883) – C:\WINDOWS\system32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\WINDOWS\system32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\WINDOWS\system32\drivers\msdv.sys (Microsoft Corporation)
DRV - (MSTAPE) – C:\WINDOWS\system32\drivers\mstape.sys (Microsoft Corporation)
DRV - (AVCSTRM) – C:\WINDOWS\system32\drivers\avcstrm.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (cdrblock) – C:\WINDOWS\system32\drivers\cdrblock.sys (Canopus Co,. Ltd.)
DRV - (Haspnt) – C:\WINDOWS\system32\drivers\Haspnt.sys (Aladdin Knowledge Systems)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SiFilter) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc)
DRV - (SiRemFil) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc)
DRV - (SI3132) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc)
DRV - (n558) – C:\WINDOWS\system32\drivers\n558.sys ()
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (MotDev) – C:\WINDOWS\system32\drivers\motodrv.sys (Motorola Inc)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation)
DRV - (BlueletAudio) – C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\BtNetDrv.sys (IVT Corporation)
DRV - (Cam5603D) – C:\WINDOWS\system32\drivers\BisonCam.sys (Bison Electronics. Inc. )
DRV - (Ktp) – C:\WINDOWS\system32\drivers\Ktp.sys (ELANTECH Devices Corp.)
DRV - (w810obex) – C:\WINDOWS\system32\drivers\w810obex.sys (MCCI)
DRV - (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\w810mgmt.sys (MCCI)
DRV - (w810mdm) – C:\WINDOWS\system32\drivers\w810mdm.sys (MCCI)
DRV - (w810mdfl) – C:\WINDOWS\system32\drivers\w810mdfl.sys (MCCI)
DRV - (w810bus) Sony Ericsson W810 Driver driver (WDM) – C:\WINDOWS\system32\drivers\w810bus.sys (MCCI)
DRV - (BlueletSCOAudio) – C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation)
DRV - (BTHidEnum) – C:\WINDOWS\system32\drivers\vbtenum.sys ()
DRV - (BTHidMgr) – C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation)
DRV - (cdrport) – C:\WINDOWS\system32\drivers\cdrport.sys (Canopus Co,. Ltd.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation)
DRV - (PhilCam8116) Logitech QuickCam Pro 3000(PID_08B0) – C:\WINDOWS\system32\drivers\CamDrL21.sys (Philips Semiconductors)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://uk.yahoo.com"
FF - prefs.js..keyword.URL: "http://uk.search.yahoo.com/search?fr=ffds1&p="
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://uk.search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.16.0


[2009/04/25 12:12:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Extensions
[2009/01/19 13:07:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Extensions\[removed]
[2010/04/13 11:35:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Firefox\Profiles\jorb9q2r.default\extensions
[2010/04/13 11:35:55 | 000,000,000 | —D | M] (Vuze Remote Toolbar) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Firefox\Profiles\jorb9q2r.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
File not found (No name found) – C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX

O1 HOSTS File: ([2010/05/24 18:55:47 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe File not found
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [KTPWare] C:\Program Files\Elantech\Ktp.exe (ELANTECH Devices Corp.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe File not found
O4 - Startup: C:\Documents and Settings\P Compton\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1263498871678 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} http://download.sopcast.com/download/SOPCORE.CAB (SopCore Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll File not found
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\P Compton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\P Compton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/20 15:39:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/05/01 21:08:11 | 000,000,000 | R–D | M] - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2009/05/01 21:08:11 | 000,000,000 | R–D | M] - D:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2011/01/02 16:05:30 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/02 15:42:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/01/02 15:42:33 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/01/02 15:42:33 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/29 12:24:50 | 000,601,600 | —- | C] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2010/12/28 23:58:20 | 000,014,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2010/12/28 23:42:30 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\Bandoo
[2010/12/28 23:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\searchqutb
[2010/12/28 23:42:14 | 000,000,000 | —D | C] – C:\Program Files\Windows Searchqu Toolbar
[2010/12/28 23:42:13 | 000,000,000 | —D | C] – C:\Program Files\Fun4IM
[2010/12/28 18:02:15 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2010/12/28 17:51:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/12/28 17:51:45 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/28 17:51:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/28 17:51:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/28 17:04:25 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Conduit
[2010/12/28 17:04:22 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Vuze_Remote
[2010/12/28 15:37:20 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/12/28 15:37:20 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/12/28 14:25:11 | 000,000,000 | RH-D | C] – C:\Documents and Settings\P Compton\Recent
[2010/12/28 13:40:12 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Local Settings\Application Data\{033964CD-4C22-4505-A7A9-BD9546940F05}
[2010/12/28 13:18:28 | 000,000,000 | —D | C] – C:\Program Files\WOT
[2010/12/27 19:43:31 | 000,000,000 | —D | C] – C:\Program Files\Veetle
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/01/02 19:12:08 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job
[2011/01/02 19:01:00 | 000,000,242 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/01/02 17:08:22 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/01/02 16:00:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/02 15:42:38 | 000,000,754 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/01 17:38:46 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/01 17:37:44 | 001,232,020 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\tdsskiller.zip
[2010/12/31 17:32:12 | 000,001,252 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/30 18:38:48 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/12/30 18:38:24 | 000,000,840 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\Windows Media Player.lnk
[2010/12/29 12:44:13 | 000,288,107 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\gmer.zip
[2010/12/29 12:25:04 | 000,601,600 | —- | M] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2010/12/28 23:58:04 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2010/12/28 23:58:04 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2010/12/28 23:42:02 | 000,001,730 | —- | M] () – C:\Documents and Settings\P Compton\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch WhiteSmoke.lnk
[2010/12/28 18:03:15 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2010/12/28 17:55:25 | 007,864,320 | —- | M] () – C:\Documents and Settings\P Compton\ntuser.bak
[2010/12/28 17:49:02 | 000,464,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/12/28 17:49:02 | 000,079,562 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/12/28 17:38:54 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/12/28 13:40:14 | 000,000,120 | —- | M] () – C:\WINDOWS\Yvagejivuluyet.dat
[2010/12/28 13:40:14 | 000,000,000 | —- | M] () – C:\WINDOWS\Pkacovoxadosex.bin
[2010/12/27 20:01:20 | 000,000,724 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\SopCast.lnk
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/19 14:30:30 | 002,207,840 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/18 17:23:00 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/01/02 15:42:38 | 000,000,754 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/01 17:37:28 | 001,232,020 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\tdsskiller.zip
[2010/12/29 13:16:18 | 000,026,762 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\gmer.text
[2010/12/29 12:44:12 | 000,288,107 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\gmer.zip
[2010/12/28 23:42:02 | 000,001,730 | —- | C] () – C:\Documents and Settings\P Compton\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch WhiteSmoke.lnk
[2010/12/28 18:07:47 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/12/28 17:59:39 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2010/12/28 13:40:14 | 000,000,120 | —- | C] () – C:\WINDOWS\Yvagejivuluyet.dat
[2010/12/28 13:40:14 | 000,000,000 | —- | C] () – C:\WINDOWS\Pkacovoxadosex.bin
[2010/06/03 11:37:47 | 000,000,576 | —- | C] () – C:\Documents and Settings\All Users\Application Data\afl.log
[2010/05/19 09:08:13 | 000,000,132 | —- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\fusioncache.dat
[2010/04/10 17:21:31 | 000,002,320 | —- | C] () – C:\WINDOWS\System32\Servmess.dll
[2010/04/09 01:09:00 | 000,017,182 | -HS- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\8O3lJ
[2010/04/09 01:09:00 | 000,017,182 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\8O3lJ
[2010/04/08 23:07:35 | 000,001,690 | -HS- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\1474v
[2010/04/08 23:07:35 | 000,001,690 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1474v
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/02 12:21:43 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/02 12:21:43 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/07/23 10:52:45 | 000,000,241 | —- | C] () – C:\WINDOWS\QSync.INI
[2009/07/23 10:51:06 | 000,000,544 | —- | C] () – C:\WINDOWS\_delis32.ini
[2009/07/23 10:50:51 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\MimicICM.dll
[2009/07/23 10:38:15 | 000,005,187 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/04/24 22:34:25 | 001,122,304 | —- | C] () – C:\WINDOWS\System32\Boris TTK Renderer.dll
[2009/04/24 22:34:25 | 000,813,056 | —- | C] () – C:\WINDOWS\System32\Boris TTK Scene.dll
[2009/04/24 22:34:25 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\Boris TTK Utilities.dll
[2009/04/24 22:34:25 | 000,094,720 | —- | C] () – C:\WINDOWS\System32\Boris TTK Render Node.dll
[2009/04/24 22:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptTO6.0.ini
[2009/04/24 22:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptLD6.0.ini
[2009/04/24 22:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptET6.0.ini
[2009/04/24 22:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptES6.0.ini
[2009/04/24 22:34:17 | 018,619,392 | —- | C] () – C:\WINDOWS\System32\BCC6_AE_16Bit.dll
[2009/04/24 22:33:59 | 018,531,840 | —- | C] () – C:\WINDOWS\System32\BCC6_AE_8Bit.dll
[2009/04/24 22:22:18 | 000,000,000 | —- | C] () – C:\WINDOWS\BorisFX BCC6.ini
[2009/04/17 20:10:52 | 000,000,302 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/09/05 23:30:42 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\WgaLogon.dll
[2008/07/21 16:14:10 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/06/21 19:01:02 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2008/05/16 09:11:23 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/01/23 11:53:38 | 000,237,568 | R— | C] () – C:\WINDOWS\System32\qtmlClient.dll
[2007/12/30 18:03:45 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/12/01 22:25:20 | 000,117,248 | —- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/01 17:17:13 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/30 17:39:17 | 000,000,383 | —- | C] () – C:\WINDOWS\System32\haspdos.sys
[2007/11/30 17:38:37 | 000,002,098 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/11/30 17:06:41 | 000,000,034 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/29 23:33:06 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/11/27 14:12:18 | 000,000,103 | —- | C] () – C:\WINDOWS\canopus.ini
[2007/11/21 11:42:51 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\pavedius4db.dll
[2007/11/21 11:42:51 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\pavedius.dll
[2007/11/21 11:07:21 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2007/11/21 11:05:52 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2007/11/21 11:05:52 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2007/11/21 10:41:36 | 000,015,190 | —- | C] () – C:\WINDOWS\M2000Twn.ini
[2007/11/20 15:28:35 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/15 07:27:18 | 000,009,600 | —- | C] () – C:\WINDOWS\System32\drivers\n558.sys
[2006/04/14 09:14:12 | 000,014,312 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2005/08/12 21:57:09 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/07/30 07:21:32 | 000,011,988 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[1999/01/27 12:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 06:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll

========== LOP Check ==========

[2010/05/29 22:58:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/02/03 21:59:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2007/11/29 23:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2009/08/04 19:25:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canopus
[2009/08/04 19:25:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2007/11/30 17:45:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grass Valley
[2009/10/06 08:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juicer3
[2010/11/15 14:09:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/04/08 18:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/10/06 12:05:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\proDAD
[2010/02/21 23:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/01/22 13:32:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/06/28 09:54:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/04/11 19:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/29 14:20:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/28 13:09:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/02/13 18:47:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2010/05/20 22:13:47 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\AVG9
[2010/12/19 21:44:46 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Azureus
[2010/12/28 23:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Bandoo
[2007/11/29 23:36:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Canopus
[2010/10/03 17:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\FileZilla
[2007/12/23 15:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Grass Valley
[2009/01/21 22:38:28 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Inscriber
[2008/10/10 11:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\LimeWire
[2008/06/21 18:45:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Motorola
[2010/11/15 14:16:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\NCH Swift Sound
[2009/05/22 19:12:47 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\OpenCandy
[2010/02/05 16:53:31 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Recordpad
[2010/03/22 19:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Red Kawa
[2010/12/30 19:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\searchqutb
[2008/06/21 18:48:00 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Teleca
[2009/01/19 13:07:24 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\TomTom
[2009/08/04 19:25:35 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Uniblue
[2008/11/06 11:17:45 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Windows Desktop Search
[2008/11/07 15:54:16 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Windows Search
[2007/12/04 18:00:20 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\WinPatrol
[2010/11/28 09:40:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/11/15 14:07:38 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\expressripDowngrade.job
[2010/11/21 14:07:00 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/01/02 17:08:22 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/01/02 19:01:00 | 000,000,242 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/01/02 19:12:08 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
the computer is running ok now , no redirects at all so far

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI