This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Money stolen from bank via internet [Solved]

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few days back I had money taken from my bank account, I used only to transfer funds via the internet from one bank to the other.
Have since changed passwords etc. I since discovered avast had run out and required re registering.
I am now having trouble with eg this site as it usually denies access at first attempt, its similar with other websites. My laptop is running slow.
I tried downloading some of the self help programmes but on one I can only get a shortcut to the `attach` file but cant find the file (tried search) I have therefore attched the only logs I have managed to save. I hope this is ok.

Hijack

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:06:33, on 23/03/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\NETGEAR\WNDA3200\WNDA3200WPSMgr.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\HiJackThis.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NETGEAR\WNDA3200\WifiDevChkSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVAST Software\Avast\setup\avast.setup

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OneNote Table Of Contents.onetoc2
O4 - Global Startup: NETGEAR WNDA3200 Smart Wizard.lnk = C:\Program Files\NETGEAR\WNDA3200\WNDA3200WPSMgr.exe
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: JumpStart Wi-Fi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\NETGEAR\WNDA3200\jswpsapi.exe
O23 - Service: NETGEAR WNDA3200 Device Checking Service (WDCS_WNDA3200) - Unknown owner - C:\Program Files\NETGEAR\WNDA3200\WifiDevChkSvc.exe

–
End of file - 8214 bytes

……………
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 8:10:59 on 2012-03-23
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7227.1100\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Eee Docking] c:\program files\asus\eee docking\Eee Docking.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [SynAsusAcpi] %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [LiveUpdate] c:\program files\asus\liveupdate\LiveUpdate.exe auto
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{208B9C75-7A35-4F5A-B36C-D57590287C88} : DhcpNameServer = [removed] [removed]
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
R? Ambfilt;Ambfilt
R? AR9271;Atheros AR9271 Wireless Network Adapter Service
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? JmUsbCcgp;JMicron USB Composite Device Lower Filter Driver
R? JmUsbVideo;JMicron 31x Upper Filter Driver
R? JmUsbVideo2;JMicron 31x Lower Filter Driver
R? jswpsapi;JumpStart Wi-Fi Protected Setup
R? massfilter;MBB Mass Storage Filter Driver
R? rtsuvc;Realtek USB2.0 PC Camera
R? ZTEusbnet;ZTE USB-NDIS miniport
R? ZTEusbvoice;ZTE VoUSB Port
S? AsUpIO;AsUpIO
S? aswFsBlk;aswFsBlk
S? aswSnx;aswSnx
S? aswSP;aswSP
S? avast! Antivirus;avast! Antivirus
S? JSWSCIMD;jswscimd Service
S? L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller
S? usbsmi;USB2.0 UVC WebCam
S? vodafone_K380x-z_dc_enum;vodafone_K380x-z_dc_enum
S? WDCS_WNDA3200;NETGEAR WNDA3200 Device Checking Service
.
=============== Created Last 30 ================
.
2012-03-17 19:15:38 ——– d—–w- c:\windows\system32\wbem\repository\FS
2012-03-17 19:15:38 ——– d—–w- c:\windows\system32\wbem\Repository
2012-03-17 19:14:50 ——– d—–w- c:\program files\Atheros
2012-03-17 19:14:20 ——– d—–w- c:\program files\JMicron
2012-03-17 19:14:18 ——– d—–w- c:\windows\smFile
2012-03-17 19:14:17 ——– d—–w- c:\program files\Azurewave, SMI371L
2012-03-17 19:14:11 ——– d—–w- c:\program files\Free YouTube Downloader
2012-03-17 19:13:54 ——– d—–w- c:\program files\Windows Media Connect 2
2012-03-17 19:13:54 ——– d—–w- c:\program files\Sony Media Go Install(2)
2012-03-17 19:13:54 ——– d—–w- c:\program files\Sony Media Go Install
2012-03-17 19:13:54 ——– d—–w- c:\program files\OpenOffice.org 3
2012-03-17 19:13:54 ——– d—–w- c:\program files\Online Services
2012-03-17 19:13:54 ——– d—–w- c:\program files\Oberon Media
2012-03-17 19:13:54 ——– d—–w- c:\program files\MWSnap(2)
2012-03-17 19:13:41 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2012-03-01 21:15:07 ——– d—–w- c:\program files\common files\Sony Shared
2012-03-01 21:09:55 ——– d—–w- c:\documents and settings\lynda-lou\local settings\application data\Apple
2012-03-01 21:08:55 ——– d—–w- c:\documents and settings\lynda-lou\local settings\application data\Apple Computer
2012-03-01 21:00:37 ——– d—–w- c:\documents and settings\lynda-lou\local settings\application data\Downloaded Installations
.
==================== Find3M ====================
.
2012-02-27 21:56:49 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-03 09:22:18 1860096 —-a-w- c:\windows\system32\win32k.sys
2012-01-11 19:06:47 3072 ——w- c:\windows\system32\iacenc.dll
2012-01-09 16:20:25 139784 —-a-w- c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 8:19:09.57 ===============
Hi, and welcome to our malware removal forum!

My name is Richard and I'll be happy to help you with your computer problems.

Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies.

Please note the following:
  • The cleaning process is not instant as logs can take time to research. Sit tight and please be patient.
  • I will be working on your malware issues. This may or may not solve other issues you may have with your system.
  • While we are fixing your problems, do NOT install/re-install any programs or run any fixes or scanners unless told to do so.
  • Ensure that your anti-virus definitions are up-to-date.
  • I would advise backing up all your important documents, personal data files and photos to a CD or DVD drive.
  • Do not back up any Applications (programs). These should be re-installed from the original source CD(s) or website(s).
  • During the course of our cleanup, please do not do any additional online work or surfing until we have verified that your system is clean.
  • I suggest printing out each set of instructions and reading the entire post before proceeding. It will make following them easier.
  • Be sure to follow the directions and run tools/scans in the order listed.
  • If you do not reply to your topic, it will be closed after 3 days.
I will return as soon as possible with more instructions.



Regards,

Richard :wavey:
Could you please check whether or not Attach.txt is on your Desktop? :)

Please post the contents of the log in your next reply, if present.

Next

GMER Rootkit Scanner
—————
Download GMER Rootkit Scanner from here to to your Desktop. It will be a randomly named executable.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
  • In the right panel, you will see several boxes that have been checked. uncheck the following:
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your Desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


In your next reply, please provide the following:
  • attach.txt
  • GMER log.



Regards,

Richard :wavey:
Thanks for the information :thumbup:

OTL
————-
  • Download OTL to your Desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post both logs with your next reply. You may need two posts to fit them both in.
In your next reply, please provide the following:
  • OTL log.



Regards,

Richard :wavey:
It is only openeing one file as per posted cannot find the extras log, checked c drive.

OTL logfile created on: 27/03/2012 08:47:24 - Run 3
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Documents and Settings\Lynda-Lou\My Documents\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1014.11 Mb Total Physical Memory | 447.71 Mb Available Physical Memory | 44.15% Memory free
2.38 Gb Paging File | 1.96 Gb Available in Paging File | 82.06% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 80.01 Gb Total Space | 53.46 Gb Free Space | 66.82% Space Free | Partition Type: NTFS
Drive D: | 62.16 Gb Total Space | 61.98 Gb Free Space | 99.72% Space Free | Partition Type: NTFS

Computer Name: LYNDA | User Name: Lynda-Lou | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\NETGEAR\WNDA3200\WNDA3200WPSMgr.exe (NETGEAR)
PRC - C:\Program Files\NETGEAR\WNDA3200\WifiDevChkSvc.exe ()
PRC - C:\Program Files\ASUS\LiveUpdate\LiveUpdate.exe ()
PRC - C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\ASUS\Eee Docking\Eee Docking.exe ()
PRC - C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVAST Software\Avast\defs\12032602\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\12032601\algo.dll ()
MOD - C:\Program Files\NETGEAR\WNDA3200\WPSLib.dll ()
MOD - C:\Program Files\NETGEAR\WNDA3200\WifiDevChkSvc.exe ()
MOD - C:\Program Files\ASUS\LiveUpdate\Enumeration.dll ()
MOD - C:\Program Files\ASUS\LiveUpdate\LiveUpdate.exe ()
MOD - C:\Program Files\ASUS\LiveUpdate\ClientSocket.dll ()
MOD - C:\Program Files\ASUS\Eee Docking\Eee Docking.exe ()
MOD - C:\Program Files\ASUS\LiveUpdate\Parser.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AppMgmt) – %SystemRoot%\System32\appmgmts.dll File not found
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (WDCS_WNDA3200) – C:\Program Files\NETGEAR\WNDA3200\WifiDevChkSvc.exe ()
SRV - (jswpsapi) – C:\Program Files\NETGEAR\WNDA3200\jswpsapi.exe (Atheros Communications, Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (uxtdapob) – C:\DOCUME~1\LYNDA-~1\LOCALS~1\Temp\uxtdapob.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (PCASp50) – System32\Drivers\PCASp50.sys File not found
DRV - (mbr) – C:\DOCUME~1\LYNDA-~1\LOCALS~1\Temp\mbr.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (hwdatacard) – system32\DRIVERS\ewusbmdm.sys File not found
DRV - (Changer) – File not found
DRV - (BTWUSB) – System32\Drivers\btwusb.sys File not found
DRV - (btwhid) – system32\DRIVERS\btwhid.sys File not found
DRV - (BTWDNDIS) – system32\DRIVERS\btwdndis.sys File not found
DRV - (BTDriver) – system32\DRIVERS\btport.sys File not found
DRV - (btaudio) – system32\drivers\btaudio.sys File not found
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (AR9271) – C:\WINDOWS\system32\drivers\athuw.sys (Atheros Communications, Inc.)
DRV - (ZTEusbnet) – C:\WINDOWS\system32\drivers\ZTEusbnet.sys (ZTE Corporation)
DRV - (ZTEusbvoice) – C:\WINDOWS\system32\drivers\zteusbvoice.sys (ZTE Incorporated)
DRV - (ZTEusbser6k) – C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\WINDOWS\system32\drivers\massfilter.sys (MBB Incorporated)
DRV - (vodafone_K380x-z_dc_enum) – C:\WINDOWS\system32\drivers\vodafone_K380x-z_dc_enum.sys (Vodafone)
DRV - (rtsuvc) – C:\WINDOWS\system32\drivers\rtsuvc.sys (Realtek Semiconductor Corp.)
DRV - (usbsmi) – C:\WINDOWS\system32\drivers\SMIksdrv.sys (SMI)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (JmUsbVideo) – C:\WINDOWS\system32\drivers\jmcam.sys (JMicron Technology Corp.)
DRV - (JmUsbVideo2) – C:\WINDOWS\system32\drivers\jmcam_lo.sys (JMicron Technology Corp.)
DRV - (JmUsbCcgp) – C:\WINDOWS\system32\drivers\jmccgp.sys (JMicron Technology Corp.)
DRV - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\WINDOWS\system32\drivers\snp2uvc.sys ()
DRV - (AR5416) – C:\WINDOWS\system32\drivers\athw.sys (Atheros Communications, Inc.)
DRV - (L1c) – C:\WINDOWS\system32\drivers\l1c51x86.sys (Atheros Communications, Inc.)
DRV - (AsUpIO) – C:\WINDOWS\system32\drivers\AsUpIO.sys ()
DRV - (kbfiltr) – C:\WINDOWS\system32\drivers\kbfiltr.sys ( )
DRV - (ZDPSp50) – C:\WINDOWS\system32\drivers\ZDPSp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (JSWSCIMD) – C:\WINDOWS\system32\drivers\jswscimd.sys (Atheros Communications, Inc.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (AsusACPI) – C:\WINDOWS\system32\drivers\ASUSACPI.SYS (ASUSTeK Computer Inc.)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {F89A1867-F9AB-4AA0-989A-DA8B11F76F03}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{F89A1867-F9AB-4AA0-989A-DA8B11F76F03}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-993901069-943735995-3242418095-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\S-1-5-21-993901069-943735995-3242418095-1006\..\SearchScopes,DefaultScope = {F89A1867-F9AB-4AA0-989A-DA8B11F76F03}
IE - HKU\S-1-5-21-993901069-943735995-3242418095-1006\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKU\S-1-5-21-993901069-943735995-3242418095-1006\..\SearchScopes\{F89A1867-F9AB-4AA0-989A-DA8B11F76F03}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7ADFA_en
IE - HKU\S-1-5-21-993901069-943735995-3242418095-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)



O1 HOSTS File: ([2008/04/14 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-993901069-943735995-3242418095-1006\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-993901069-943735995-3242418095-1006\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LiveUpdate] C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe ()
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (Synaptics Incorporated)
O4 - HKU\S-1-5-21-993901069-943735995-3242418095-1006..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WNDA3200 Smart Wizard.lnk = C:\Program Files\NETGEAR\WNDA3200\WNDA3200WPSMgr.exe (NETGEAR)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SuperHybridEngine.lnk = C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe (ASUSTeK Computer Inc.)
O4 - Startup: C:\Documents and Settings\Lynda-Lou\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2 ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-993901069-943735995-3242418095-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm File not found
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{208B9C75-7A35-4F5A-B36C-D57590287C88}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Lynda-Lou\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Lynda-Lou\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/27 11:11:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1b0c30aa-8d5c-11e0-9647-485b391bafd6}\Shell - "" = AutoRun
O33 - MountPoints2\{1b0c30aa-8d5c-11e0-9647-485b391bafd6}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{1b0c30aa-8d5c-11e0-9647-485b391bafd6}\Shell\AutoRun\command - "" = E:\setup_vmb_lite.exe /checkApplicationPresence
O33 - MountPoints2\{84cbb0ec-9455-11e0-9658-1c4bd684be5e}\Shell - "" = AutoRun
O33 - MountPoints2\{84cbb0ec-9455-11e0-9658-1c4bd684be5e}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{84cbb0ec-9455-11e0-9658-1c4bd684be5e}\Shell\AutoRun\command - "" = E:\AutoInst.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/03/27 08:26:09 | 000,593,920 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\OTL.exe
[2012/03/26 16:52:50 | 000,000,000 | R–D | C] – C:\Documents and Settings\Lynda-Lou\Start Menu\Programs\Administrative Tools
[2012/03/26 16:52:11 | 000,607,260 | R— | C] (Swearware) – C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\dds.scr
[2012/03/26 13:49:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\help
[2012/03/23 13:19:37 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2012/03/23 13:19:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/03/23 13:16:03 | 000,000,000 | —D | C] – C:\Program Files\Java
[2012/03/17 22:07:44 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Lynda-Lou\Recent
[2012/03/17 20:14:50 | 000,000,000 | —D | C] – C:\Program Files\Atheros
[2012/03/17 20:14:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Google Earth
[2012/03/17 20:14:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WALKMAN Guide
[2012/03/17 20:14:20 | 000,000,000 | —D | C] – C:\Program Files\JMicron
[2012/03/17 20:14:18 | 000,000,000 | —D | C] – C:\WINDOWS\smFile
[2012/03/17 20:14:17 | 000,000,000 | —D | C] – C:\Program Files\Azurewave, SMI371L
[2012/03/17 20:14:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\NETGEAR WNDA3200 Smart Wizard
[2012/03/17 20:14:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Lynda-Lou\Start Menu\Programs\MWSnap
[2012/03/17 20:14:13 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.1
[2012/03/17 20:14:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Visual Studio 2005
[2012/03/17 20:14:11 | 000,000,000 | —D | C] – C:\Program Files\Free YouTube Downloader
[2012/03/17 20:14:11 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2012/03/17 20:13:54 | 000,000,000 | —D | C] – C:\Program Files\Windows Media Connect 2
[2012/03/17 20:13:54 | 000,000,000 | —D | C] – C:\Program Files\Sony Media Go Install(2)
[2012/03/17 20:13:54 | 000,000,000 | —D | C] – C:\Program Files\Sony Media Go Install
[2012/03/17 20:13:54 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2012/03/17 20:13:54 | 000,000,000 | —D | C] – C:\Program Files\Online Services
[2012/03/17 20:13:54 | 000,000,000 | —D | C] – C:\Program Files\Oberon Media
[2012/03/17 20:13:54 | 000,000,000 | —D | C] – C:\Program Files\MWSnap(2)
[2012/03/17 20:13:54 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2012/03/17 20:13:53 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2012/03/17 20:13:41 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2012/03/17 20:13:41 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2012/03/16 17:22:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Lynda-Lou\My Documents\My Videos
[2012/03/16 17:22:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Lynda-Lou\My Documents\My Office
[2012/03/16 17:22:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Lynda-Lou\My Documents\My Ebooks
[2012/03/01 22:15:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Sony
[2012/03/01 22:15:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Sony Shared
[2012/03/01 22:10:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2012/03/01 22:09:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Lynda-Lou\Local Settings\Application Data\Apple
[2012/03/01 22:09:47 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2012/03/01 22:08:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Lynda-Lou\Local Settings\Application Data\Apple Computer
[2012/03/01 22:00:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Lynda-Lou\Local Settings\Application Data\Downloaded Installations
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/03/27 08:35:44 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{1904F2E7-AA13-497A-BB41-1C359D2FE41B}.job
[2012/03/27 08:26:25 | 000,593,920 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\OTL.exe
[2012/03/26 17:03:44 | 000,003,844 | —- | M] () – C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\attach.zip
[2012/03/26 17:01:04 | 000,000,892 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/26 16:52:23 | 000,607,260 | R— | M] (Swearware) – C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\dds.scr
[2012/03/26 13:01:01 | 000,000,888 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/26 11:24:55 | 000,475,996 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012/03/26 11:24:55 | 000,085,476 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012/03/26 11:20:41 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012/03/26 11:19:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/03/17 22:19:48 | 000,359,344 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/17 22:12:44 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012/03/01 22:09:57 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/03/01 22:01:29 | 000,001,841 | —- | M] () – C:\Documents and Settings\All Users\Desktop\NWZ-E460 WALKMAN Guide.lnk
[2012/03/01 21:57:35 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012/03/01 21:40:17 | 000,048,640 | —- | M] () – C:\Documents and Settings\Lynda-Lou\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/03/26 17:03:44 | 000,003,844 | —- | C] () – C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\attach.zip
[2012/03/17 22:12:31 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012/03/01 22:09:56 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/03/01 22:09:50 | 000,001,830 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Apple Software Update.lnk
[2012/03/01 22:01:29 | 000,001,841 | —- | C] () – C:\Documents and Settings\All Users\Desktop\NWZ-E460 WALKMAN Guide.lnk
[2012/02/18 10:23:56 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/04/07 19:48:51 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/07/18 12:51:41 | 000,048,640 | —- | C] () – C:\Documents and Settings\Lynda-Lou\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/17 09:47:18 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS

========== LOP Check ==========

[2011/04/07 20:04:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2010/01/07 20:40:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EBI
[2011/05/29 12:47:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QueryExplorer
[2009/12/11 21:13:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ralink Driver
[2010/01/07 20:40:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RSMR
[2011/06/02 22:37:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vodafone
[2012/01/30 08:34:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Lynda-Lou\Application Data\BitTorrent
[2010/08/27 23:37:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Lynda-Lou\Application Data\OpenOffice.org
[2011/07/28 22:45:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Lynda-Lou\Application Data\RegistryKeys
[2011/12/25 23:30:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Lynda-Lou\Application Data\Sony
[2011/04/16 18:02:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Lynda-Lou\Application Data\Vodafone
[2012/03/27 08:35:44 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{1904F2E7-AA13-497A-BB41-1C359D2FE41B}.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/04/14 13:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 13:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 13:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\dllcache\svchost.exe
[2008/04/14 13:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/04/14 13:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\dllcache\userinit.exe
[2008/04/14 13:00:00 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2008/04/14 13:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\dllcache\winlogon.exe
[2008/04/14 13:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed\thard disk media
Interface type: IDE
Media Type: Fixed\thard disk media
Model: WDC WD1600BEVT-80A23T0
Partitions: 4
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 80.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 62.00GB
Starting Offset: 85904824320
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 7.00GB
Starting Offset: 152644746240
Hidden sectors: 0


DeviceID: Disk #0, Partition #3
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 159989921280
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790 -> Junction
[C:\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a] -> C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e -> Junction

< End of report >
P2P Programs Warning!

IMPORTANT
I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.
  • BitTorrent
Please read these short reports on the dangers of peer-2-peer programs and file sharing:
I would recommend that you go to Control Panel > Add/Remove Programs and uninstall the P2P programs listed above, however that choice is up to you.
Note: you must NOT use any P2P whilst we are cleaning your machine.

Next
  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.

Next

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O3 - HKU\S-1-5-21-993901069-943735995-3242418095-1006\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O33 - MountPoints2\{1b0c30aa-8d5c-11e0-9647-485b391bafd6}\Shell - "" = AutoRun
    O33 - MountPoints2\{1b0c30aa-8d5c-11e0-9647-485b391bafd6}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{1b0c30aa-8d5c-11e0-9647-485b391bafd6}\Shell\AutoRun\command - "" = E:\setup_vmb_lite.exe /checkApplicationPresence
    O33 - MountPoints2\{84cbb0ec-9455-11e0-9658-1c4bd684be5e}\Shell - "" = AutoRun
    O33 - MountPoints2\{84cbb0ec-9455-11e0-9658-1c4bd684be5e}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{84cbb0ec-9455-11e0-9658-1c4bd684be5e}\Shell\AutoRun\command - "" = E:\AutoInst.exe
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done.
  • When the computer has rebooted, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date/time of the tool run.
  • Copy and paste the contents of that report in your next reply.

In your next reply, please provide the following:
  • aswMBR log.
  • OTL log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
📎MBR.zipI got as far as "Run OTL.exe" but it was still running after an hour and a half so decided to abort and retry, when rebooting the boot up looped from the 28 sec countdown and just kept countingdown and going back to 28 sec and so on. I rebooted and eventually got my desktop but then all icons re the internet have disappeared (so using another PC at the moment) I tried system restore but that isnt working, I get the message "system restore cannot protect your computer please restart your computer and try again" which doesnt work. I need to try and get the internet connection back. I will (tomorrow) use a memory stick (for the copy/paste) and try and run OTL again. When I run OTL it did not ask to download Avasts definitions just in case that is relevent. Hopefully I can post and update tomorrow, Thurs. Thurs… OTL is saying it has an error and wouldnt run, I downloaded another on seperate PC and transferred with memory stick and having the same issue `error` So cant run OTL. I did run OTL on another PC so I dont think the exe programme is corrupt. Tried system restore in safe mode, "system restore cannot protect your computer please restart your computer and try again" I got this for diagnostic check for internet….. "warn HTTP: Error 12007 connecting to www.microsoft.com: The server name or address could not be resolved warn HTTPS: Error 12007 connecting to www.microsoft.com: The server name or address could not be resolved warn FTP (Passive): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved warn HTTP: Error 12007 connecting to www.hotmail.com: The server name or address could not be resolved warn HTTPS: Error 12007 connecting to www.passport.net: The server name or address could not be resolved warn FTP (Active): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved error Could not make an HTTP connection. error Could not make an HTTPS connection. error Could not make an FTP connection." Still cannot retrieve the internet icons. Before the laptop stopped working I managed to get the MBR scans done… aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-28 22:39:30 —————————– 22:39:30.375 OS Version: Windows 5.1.2600 Service Pack 3 22:39:30.375 Number of processors: 2 586 0x1C0A 22:39:30.375 ComputerName: LYNDA UserName: 22:39:31.937 Initialize success 22:39:32.265 AVAST engine defs: 12032802 22:40:13.265 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 22:40:13.281 Disk 0 Vendor: WDC_WD16 01.0 Size: 152627MB BusType: 3 22:40:13.328 Disk 0 MBR read successfully 22:40:13.328 Disk 0 MBR scan 22:40:13.343 Disk 0 Windows XP default MBR code 22:40:13.343 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 81925 MB offset 63 22:40:13.390 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 63648 MB offset 167782860 22:40:13.421 Disk 0 Partition 3 00 1C Hidd FAT32 LBA MSDOS5.0 7004 MB offset 298134270 22:40:13.437 Disk 0 Partition 4 00 EF EFI FAT 47 MB offset 312480315 22:40:13.453 Disk 0 scanning sectors +312576705 22:40:13.515 Disk 0 scanning C:\WINDOWS\system32\drivers 22:40:24.593 Service scanning 22:40:40.781 Modules scanning 22:41:10.609 Disk 0 trace - called modules: 22:41:10.656 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys 22:41:10.671 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86b59030] 22:41:10.687 3 CLASSPNP.SYS[f763efd7] -> nt!IofCallDriver -> \Device\0000006c[0x86b38848] 22:41:10.703 5 ACPI.sys[f74d5620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x86b75028] 22:41:11.640 AVAST engine scan C:\WINDOWS 22:41:18.296 AVAST engine scan C:\WINDOWS\system32 22:45:01.062 AVAST engine scan C:\WINDOWS\system32\drivers 22:45:17.453 AVAST engine scan C:\Documents and Settings\Lynda-Lou 22:47:52.203 AVAST engine scan C:\Documents and Settings\All Users 22:48:15.015 Scan finished successfully 22:57:55.812 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\MBR.dat" 22:57:55.828 The log file has been saved successfully to "C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\aswMBR.txt" LyndaLou
Please follow these steps in normal mode:
  • Remove the Vodafone Mobile Broadband USB Stick.
  • Restart your computer.
  • Re-insert the USB Stick.
Next

Please do not run the OTL fix, but did you see what the OTL error said?

You should find some logs in the following location:

C:\_OTL\MovedFiles

The logs will be named MMDDYYYY_HHMMSS.log where MDYHMS are numbers indicating the date and time the log was created.

Please post the last one created, which could be from the fix you've just run.

Next

OTL
————-
  • Double click on the OTL icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users.
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post both logs with your next reply. You may need two posts to fit them both in.

In your next reply, please provide the following:
  • OTL log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
Ok I will try and find the logs. In the meantime "•Remove the Vodafone Mobile Broadband USB Stick." I dont have this, this was a temp solution about 9 months ago when moving house I am using virgin broadband. Added….. The C:\OTL folder is empty, no logs. When I try and run OTL it states "OTL has encountered a problem" and the usual do you want to send a report to …. Errror signature. AppName otl exe App Ver [removed] Mod name kernal 32dll Mod Vers 5.1.2600.5781 Offset 00012afb To check if other programmes were running I run the aswMBR scan and it came up with… Module C:\Windows\Ststem32\drivers\dxgTHK.sys **suspicious** I still cant run OTL.
Please post the full aswMBR log :)

Next

Do you use a router?

Next

Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.

In your next reply, please provide the following:
  • aswMBR log
  • MiniToolBox log.
  • Update on how your PC is running.



Regards,

Richard :wavey:
📎MBR.zipPC appears to run ok other than no internet connection. aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-30 15:49:22 —————————– 15:49:22.390 OS Version: Windows 5.1.2600 Service Pack 3 15:49:22.390 Number of processors: 2 586 0x1C0A 15:49:22.390 ComputerName: LYNDA UserName: 15:49:23.812 Initialize success 15:49:24.093 AVAST engine defs: 12032802 15:49:47.078 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 15:49:47.078 Disk 0 Vendor: WDC_WD16 01.0 Size: 152627MB BusType: 3 15:49:47.109 Disk 0 MBR read successfully 15:49:47.125 Disk 0 MBR scan 15:49:47.125 Disk 0 Windows XP default MBR code 15:49:47.140 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 81925 MB offset 63 15:49:47.171 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 63648 MB offset 167782860 15:49:47.203 Disk 0 Partition 3 00 1C Hidd FAT32 LBA MSDOS5.0 7004 MB offset 298134270 15:49:47.234 Disk 0 Partition 4 00 EF EFI FAT 47 MB offset 312480315 15:49:47.250 Disk 0 scanning sectors +312576705 15:49:47.421 Disk 0 scanning C:\WINDOWS\system32\drivers 15:50:02.875 Service scanning 15:50:22.765 Modules scanning 15:50:28.015 Module: C:\WINDOWS\System32\drivers\dxgthk.sys **SUSPICIOUS** 15:50:29.562 Module: C:\WINDOWS\system32\ntdll.dll **SUSPICIOUS** 15:50:29.578 Disk 0 trace - called modules: 15:50:29.640 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys 15:50:29.656 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d679c0] 15:50:29.671 3 CLASSPNP.SYS[f763efd7] -> nt!IofCallDriver -> \Device\0000006c[0x86d4f5e0] 15:50:29.687 5 ACPI.sys[f74d5620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x867cc028] 15:50:30.484 AVAST engine scan C:\WINDOWS 15:50:38.859 AVAST engine scan C:\WINDOWS\system32 15:53:08.546 AVAST engine scan C:\WINDOWS\system32\drivers 15:53:24.234 AVAST engine scan C:\Documents and Settings\Lynda-Lou 15:56:20.718 AVAST engine scan C:\Documents and Settings\All Users 15:56:43.750 Scan finished successfully 15:58:59.281 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\MBR.dat" 15:58:59.312 The log file has been saved successfully to "C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\aswMBR.txt" 16:02:45.968 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\MBR.dat" 16:02:46.000 The log file has been saved successfully to "C:\Documents and Settings\Lynda-Lou\My Documents\Desktop\aswMBR.txt" ############################################ MiniToolBox by Farbar Version: 18-01-2012 Ran by [removed] (administrator) on 30-03-2012 at 15:36:53 Microsoft Windows XP Service Pack 3 (X86) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= Hosts content: ================================= 127.0.0.1 localhost ========================= IP Configuration: ================================ WARNING: Could not obtain host information from machine: [LYNDA]. Some commands may not be available. The service did not respond to the start or control request in a timely fashion. # ———————————- # Interface IP Configuration # ———————————- pushd interface ip # Interface IP Configuration for "Local Area Connection" set address name="Local Area Connection" source=dhcp set dns name="Local Area Connection" source=dhcp register=PRIMARY set wins name="Local Area Connection" source=dhcp # Interface IP Configuration for "Wireless Network Connection" set address name="Wireless Network Connection" source=dhcp set dns name="Wireless Network Connection" source=dhcp register=PRIMARY set wins name="Wireless Network Connection" source=dhcp popd # End of interface IP configuration Windows IP Configuration Host Name . . . . . . . . . . . . : Lynda Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No Ethernet adapter Local Area Connection: Media State . . . . . . . . . . . : Media disconnected Description . . . . . . . . . . . : Atheros AR8132 PCI-E Fast Ethernet Controller Physical Address. . . . . . . . . : 48-5B-39-1B-AF-D6 Ethernet adapter Wireless Network Connection: Media State . . . . . . . . . . . : Media disconnected Description . . . . . . . . . . . : Atheros AR2427 Wireless Network Adapter Physical Address. . . . . . . . . : 1C-4B-D6-84-BE-5E Server: UnKnown Address: 127.0.0.1 Ping request could not find host google.com. Please check the name and try again. Server: UnKnown Address: 127.0.0.1 Ping request could not find host yahoo.com. Please check the name and try again. Server: UnKnown Address: 127.0.0.1 Ping request could not find host bleepingcomputer.com. Please check the name and try again. Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 0x1 ……………………… MS TCP Loopback interface 0x2 …48 5b 39 1b af d6 …… Atheros AR8132 PCI-E Fast Ethernet Controller - Packet Scheduler Miniport 0x3 …1c 4b d6 84 be 5e …… Atheros AR2427 Wireless Network Adapter - Packet Scheduler Miniport =========================================================================== =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1 255.255.255.255 255.255.255.255 255.255.255.255 3 1 255.255.255.255 255.255.255.255 255.255.255.255 2 1 =========================================================================== Persistent Routes: None ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation) Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation) Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 04 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation) Catalog9 05 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation) Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 16 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 17 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 18 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) Catalog9 19 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (03/30/2012 10:11:31 AM) (Source: Application Error) (User: ) Description: Faulting application explorer.exe, version 6.0.2900.5512, faulting module shell32.dll, version 6.0.2900.6072, fault address 0x000969aa. Processing media-specific event for [explorer.exe!ws!] Error: (03/30/2012 08:04:24 AM) (Source: EventSystem) (User: ) Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007041D from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error. Error: (03/29/2012 07:15:44 PM) (Source: Application Error) (User: ) Description: Faulting application otl.exe, version 3.2.39.2, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb. Processing media-specific event for [otl.exe!ws!] Error: (03/29/2012 07:11:34 PM) (Source: Application Error) (User: ) Description: Faulting application otl.exe, version 3.2.39.2, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb. Processing media-specific event for [otl.exe!ws!] Error: (03/29/2012 07:10:06 PM) (Source: EventSystem) (User: ) Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007041D from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error. Error: (03/29/2012 05:31:35 PM) (Source: Application Error) (User: ) Description: Faulting application otl.exe, version 3.2.39.2, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb. Processing media-specific event for [otl.exe!ws!] Error: (03/29/2012 00:46:50 PM) (Source: EventSystem) (User: ) Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007041D from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error. Error: (03/29/2012 08:58:55 AM) (Source: EventSystem) (User: ) Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007041D from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error. Error: (03/29/2012 08:54:53 AM) (Source: EventSystem) (User: ) Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 8007041D from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error. Error: (03/29/2012 08:32:49 AM) (Source: Application Error) (User: ) Description: Faulting application otl.exe, version 3.2.39.2, faulting module kernel32.dll, version 5.1.2600.5781, fault address 0x00012afb. Processing media-specific event for [otl.exe!ws!] System errors: ============= Error: (03/30/2012 03:36:59 PM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Error: (03/30/2012 03:36:58 PM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Error: (03/30/2012 00:58:13 PM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Error: (03/30/2012 00:54:48 PM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error: (03/30/2012 00:54:48 PM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error: (03/30/2012 10:13:46 AM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error: (03/30/2012 10:13:45 AM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error: (03/30/2012 10:13:16 AM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Error: (03/30/2012 10:12:39 AM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} Error: (03/30/2012 10:11:46 AM) (Source: DCOM) (User: Lynda-Lou) Description: DCOM got error "%%1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} Microsoft Office Sessions: ========================= =========================== Installed Programs ============================ Adobe AIR (Version: 1.5.0.7220) Adobe Flash Player 11 ActiveX (Version: 11.1.102.62) Adobe Reader 9.1 MUI (Version: 9.1.0) Apple Application Support (Version: 1.4.1) Apple Software Update (Version: 2.1.1.116) Asus ACPI Driver (Version: 6.1.1.1034) ASUS USB2.0 UVC VGA WebCam ASUS VIBE (Version: 1.0.187) ASUSUpdate for Eee PC (Version: 1.03.06) Atheros Client Installation Program (Version: 7.0) Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (Version: 1.0.0.23) avast! Free Antivirus (Version: 6.0.1367.0) BitTorrent (Version: 7.2.0) CCleaner (Version: 2.33) Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000) Data Sync (Version: 1.0.2) Eee Docking 1.3.10.0 (Version: 1.3.10.0) EzMessenger (Version: 1.0.2) FontResizer (Version: 1.01.0011) Google Earth (Version: 6.1.0.5001) Google Toolbar for Internet Explorer (Version: 1.0.0) Google Toolbar for Internet Explorer (Version: 7.3.2710.138) Google Update Helper (Version: 1.3.21.111) Intel® Graphics Media Accelerator Driver (Version: 0.0.0.0000) Java Auto Updater (Version: 2.0.7.1) Java™ 6 Update 31 (Version: 6.0.310) Junk Mail filter update (Version: 14.0.8089.726) LiveUpdate (Version: 1.21) Media Go (Version: 1.7.254) Microsoft .NET Framework 1.1 (Version: 1.1.4322) Microsoft .NET Framework 1.1 Security Update (KB2656353) Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729) Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft Application Error Reporting (Version: 12.0.6012.5000) Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1) Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000) Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (Version: 14.0.5130.5003) Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000) Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000) Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000) Microsoft Software Update for Web Folders (English) 12 (Version: 12.0.6612.1000) Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000) Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0) MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0) NETGEAR WNDA3200 wireless adapter Setup (Version: 1.0.0.11) NWZ-E460 WALKMAN Guide (Version: 2.0.2.04130) PlayStation®Network Downloader (Version: 2.07.00849) PlayStation®Store (Version: 4.1.8.11883) Ralink RT2860 Wireless LAN Card (Version: 1.0.7.0) Realtek High Definition Audio Driver (Version: 5.10.0.5983) Skype™ 5.5 (Version: 5.5.124) Super Hybrid Engine (Version: 1.19) Synaptics Pointing Device Driver (Version: 13.2.6.1) Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2597970) 32-Bit Edition Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition Update for Windows Internet Explorer 8 (KB971930) (Version: 1) Update for Windows Internet Explorer 8 (KB975364) (Version: 1) Update for Windows Internet Explorer 8 (KB976662) (Version: 1) Update for Windows Internet Explorer 8 (KB976749) (Version: 1) Update for Windows XP (KB2141007) (Version: 1) Update for Windows XP (KB2345886) (Version: 1) Update for Windows XP (KB2467659) (Version: 1) Update for Windows XP (KB2541763) (Version: 1) Update for Windows XP (KB2607712) (Version: 1) Update for Windows XP (KB2616676) (Version: 1) Update for Windows XP (KB2641690) (Version: 1) Update for Windows XP (KB898461) (Version: 1) Update for Windows XP (KB942763) (Version: 1) Update for Windows XP (KB951072-v2) (Version: 2) Update for Windows XP (KB951618-v2) (Version: 2) Update for Windows XP (KB951978) (Version: 1) Update for Windows XP (KB953356) (Version: 1) Update for Windows XP (KB955759) (Version: 1) Update for Windows XP (KB955839) (Version: 1) Update for Windows XP (KB961503) (Version: 1) Update for Windows XP (KB967715) (Version: 1) Update for Windows XP (KB968389) (Version: 1) Update for Windows XP (KB971029) (Version: 1) Update for Windows XP (KB971737) (Version: 1) Update for Windows XP (KB973687) (Version: 1) Update for Windows XP (KB973815) (Version: 1) USB2.0 UVC VGA WebCam (Version: 1.0.5.1) USB2.0 UVC VGA WebCam (Version: 6.1.7601.0023) USB2.0 UVC WebCam (Version: 5.58.0.1) VLC media player 1.1.0 (Version: 1.1.0) WebFldrs XP (Version: 9.50.7523) Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0) Windows Internet Explorer 8 (Version: 20090308.140743) Windows Live Sync (Version: 14.0.8089.726) Windows Media Format 11 runtime ========================= Memory info: =================================== Percentage of memory in use: 38% Total physical RAM: 1014.11 MB Available physical RAM: 625.8 MB Total Pagefile: 2440.5 MB Available Pagefile: 2140.58 MB Total Virtual: 2047.88 MB Available Virtual: 1975.35 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:80.01 GB) (Free:54.19 GB) NTFS 2 Drive d: () (Fixed) (Total:62.16 GB) (Free:61.98 GB) NTFS 3 Drive e: () (Removable) (Total:0.06 GB) (Free:0.06 GB) FAT ========================= Users: ======================================== User accounts for \\ Administrator ASPNET Guest HelpAssistant Lynda-Lou SUPPORT_388945a0 ========================= Minidump Files ================================== No minidump file found **** End of log ****
Make sure the computer is set to obtain an IP address automatically.

1. Go Start > Settings > Control Panel
2. Double click Network Connections
  • For a wired network connection, right-click Local Area Connection, and then select Properties.
  • For a wireless network connection, right-click Wireless Network Connection, and then select Properties.
3. From the General tab, click Internet Protocol (TCP/IP), make sure it is checked, and then click Properties.
4. Click Obtain an IP Address Automatically, and then click OK.

Restart the computer and test internet connection.
If that doesn't work:

Turn off the computer. Disconnect the router and modem from their power source for 1 minute. At the same time disconnect the Ethernet cable as well.

Reconnect everything.

Restart the computer and test internet connection.

If that doesn't work, connect the computer straight to the modem.

If that doesn't work…

Go to Start > Run, type in:
cmd
Click OK

In the Command Prompt window, type in the following commands, and hit Enter after each one:
ipconfig /registerdns
ipconfig /release
ipconfig /renew
net stop "dns client"
net start "dns client"

Restart the computer and test internet connection.

Report any errors :thumbup:

Next

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
  • Double-click the SystemLook and copy/paste the following into the box:
    :filefind 
    dxgthk.*
    ntdll.*
  • Click the Look button. Let it finish the scan.
  • When finished, a notepad window will open with the results of the scan. Post the content of the log here in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

In your next reply, please provide the following:
  • SystemLook log.
  • Update on how your PC is running.



Regards,

Richard :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI