This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Casalemedia Again And.... Maybe Others

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, folks…

Since several days I'm having extrange behaviour in my home PC, popups, slow boot, etc. etc. :huh:

I downloaded last version of AD-Aware and last version of defs. file. This gave to me some hundreds of found cookies and trojans and…..

But the Casalemedia still remains and the boot is still somehow strange (it takes much time and desktop appears once a long time is passed) and slow….

So, I run HijackThis and put here the log asking for your very valuable help.

Thanks and best regards.

Javier

***** HijackThis Log: *******

Logfile of HijackThis v1.97.7
Scan saved at 16:29:07, on 03/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Archivos de programa\NavNT\defwatch.exe
C:\Archivos de programa\IBM\Desktop On-Call\dtocsrvc.exe
C:\WINNT\System32\svchost.exe
C:\Archivos de programa\IBM\Desktop On-Call\logon.exe
C:\Archivos de programa\Ahead\InCD\InCDsrv.exe
C:\Archivos de programa\IBM\Desktop On-Call\httpd.exe
C:\Archivos de programa\IBM\Desktop On-Call\slaved.exe
C:\Archivos de programa\IBM\Desktop On-Call\automap.exe
C:\Archivos de programa\IBM\Desktop On-Call\dtocftpd.exe
C:\Archivos de programa\IBM\Desktop On-Call\chat.exe
c:\sdwork\issimsvc.exe
C:\Notes\ntmulti.exe
C:\ARCHIV~1\AT&TNE~2\NetCfgSv.EXE
C:\Archivos de programa\Symantec_Desktop_Firewall\NISSERV.EXE
C:\Archivos de programa\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\drivers\trcboot.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Archivos de programa\UltraVNC\WinVNC.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\Archivos de programa\Personal Communications\PCS_AGNT.EXE
C:\Archivos de programa\Symantec_Desktop_Firewall\NISUM.EXE
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\desk95.exe
C:\WINNT\system32\carpserv.exe
C:\Archivos de programa\Symantec_Desktop_Firewall\IAMAPP.EXE
C:\Archivos de programa\NavNT\vptray.exe
C:\Archivos de programa\Real\RealPlayer\RealPlay.exe
C:\Archivos de programa\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\Archivos de programa\Logitech\ImageStudio\LogiTray.exe
C:\WINNT\tppaldr.exe
C:\WINNT\system32\UMonit2k.exe
C:\Archivos de programa\Java\j2re1.4.2_03\bin\jusched.exe
C:\Archivos de programa\Ahead\InCD\InCD.exe
C:\WINNT\system32\LVCOMSX.EXE
C:\Archivos de programa\Logitech\Video\LogiTray.exe
C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINNT\system32\internat.exe
C:\Archivos de programa\Logitech\MouseWare\system\em_exec.exe
C:\Archivos de programa\ATI Multimedia\main\launchpd.exe
C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Lotus\organize\EasyClip.exe
C:\Lotus\smartctr\suitest.exe
C:\Archivos de programa\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Archivos de programa\Logitech\Video\FxSvr2.exe
C:\Archivos de programa\Plextor\PlexTool.exe
C:\psm\ipnotif.exe
C:\Archivos de programa\ArGo Software Design\Mail Server\MailServer.exe
C:\Archivos de programa\Caere\OmniPagePro90\EREG\REMIND32.EXE
D:\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: 172.26.0.1 router-multi-local
O1 - Hosts: 213.98.17.196 router-multi-remoto
O1 - Hosts: 213.98.17.193 router-mono-local
O1 - Hosts: 172.26.0.2 desktop-casa
O1 - Hosts: 172.26.0.3 portatil-casa #Thinkpad 600E en casa
O1 - Hosts: 172.26.0.4 imagenes
O1 - Hosts: 172.26.0.5 invitado
O1 - Hosts: 172.26.0.6 TP23
O1 - Hosts: 213.98.17.196 router-casa
O1 - Hosts: 213.186.37.169 www.911cd.net Forums de Bootable CD
O1 - Hosts: 9.139.234.1 proxy-mad-a
O1 - Hosts: 9.139.234.2 proxy-mad-b
O1 - Hosts: 9.139.234.4 proxy-mad
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {702AD576-FDDB-4d0f-9811-A43252064684} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HydarVisionDesktopManager] desk95.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [DNSRestore] "C:\ARCHIV~1\AT&TNE~2\DNSRestore.exe" -R
O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [iamapp] "C:\Archivos de programa\Symantec_Desktop_Firewall\IAMAPP.EXE"
O4 - HKLM\..\Run: [vptray] C:\Archivos de programa\NavNT\vptray.exe
O4 - HKLM\..\Run: [RealTray] C:\Archivos de programa\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCTVRemote] C:\Archivos de programa\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Archivos de programa\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Archivos de programa\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINNT\tppaldr.exe
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINNT\system32\UMonit2k.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Archivos de programa\Archivos comunes\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [service] C:\WINNT\services.exe -serv
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Archivos de programa\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [InCD] C:\Archivos de programa\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Archivos de programa\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Archivos de programa\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AtiPTA] C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Archivos de programa\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [LDM] C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Archivos de programa\Logitech\Video\ManifestEngine.exe" boot
O4 - Startup: MailServer.lnk = C:\Archivos de programa\ArGo Software Design\Mail Server\MailServer.exe
O4 - Startup: reminder-Registro del producto ScanSoft.lnk = C:\Archivos de programa\Caere\OmniPagePro90\EREG\REMIND32.EXE
O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\Lotus\organize\EasyClip.exe
O4 - Global Startup: Lotus QuickStart.lnk = C:\Lotus\wordpro\ltsstart.exe
O4 - Global Startup: Lotus SuiteStart.lnk = C:\Lotus\smartctr\suitest.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Pinnacle Scheduler.lnk = C:\Archivos de programa\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
O4 - Global Startup: PlexTools Professional.lnk = C:\Archivos de programa\Plextor\PlexTool.exe
O4 - Global Startup: PSM Notification.lnk = C:\psm\ipnotif.exe
O9 - Extra 'Tools' menuitem: Consola de Sun Java (HKLM)
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\asnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O12 - Plugin for .spop: C:\Archivos de programa\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.8.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…7667.6189351852
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/shock…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A97B7CD-7106-4309-AFE2-D991B2AA1885}: Domain = ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A97B7CD-7106-4309-AFE2-D991B2AA1885}: NameServer = 194.179.1.100,194.179.1.101
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com

**********************************************
Greetings and welcome to TomCoyote.org!

Please download the latest version of Hijack This!

Links to Hijack This! v 1.98.2:

http://tools.radiosplace.com/HijackThis.exe
http://spywarewarrior.com/files/HijackThis.exe
http://tomcoyote.org/hjt/HijackThis.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

Only fix any of the "O1 - Hosts" that you do not recognize as useful and friendly

O1 - Hosts: 172.26.0.1 router-multi-local

O1 - Hosts: 213.98.17.196 router-multi-remoto

O1 - Hosts: 213.98.17.193 router-mono-local

O1 - Hosts: 172.26.0.2 desktop-casa

O1 - Hosts: 172.26.0.3 portatil-casa #Thinkpad 600E en casa

O1 - Hosts: 172.26.0.4 imagenes

O1 - Hosts: 172.26.0.5 invitado

O1 - Hosts: 172.26.0.6 TP23

O1 - Hosts: 213.98.17.196 router-casa

O1 - Hosts: 213.186.37.169 www.911cd.net Forums de Bootable CD

O1 - Hosts: 9.139.234.1 proxy-mad-a

O1 - Hosts: 9.139.234.2 proxy-mad-b

O1 - Hosts: 9.139.234.4 proxy-mad

O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)

O3 - Toolbar: (no name) - {702AD576-FDDB-4d0f-9811-A43252064684} - (no file)

O4 - HKLM\..\Run: [service] C:\WINNT\services.exe -serv

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebpr…etup1.0.0.8.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/get/shock…ash/swflash.cab

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

c:\winnt\services.exe <— file
(Probably added on your machine by the Netsky virus!)

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode.

Because one entry was probably viral related. Please try some online virus removing tools.

Please try these free online virus scans of your system:

Trend-Micro Housecall

Panda Activescan

Etrust Security Advisor

Choose "fix" or "clean".

Let them remove any infections found. Reboot after each scan.

Then and "copy/paste" a new log file into this thread. :)
Thanks..

I did all of it and it seems that Casalemedia popup went out….

But I was not able to find "services.exe" in WINNT folder. It is in several of the subfolders:

C:\WINNT>dir services.exe /s /p

Directorio de C:\WINNT\$NtServicePackUninstall$

19/07/2002 09:34 88.848 services.exe
1 archivos 88.848 bytes

Directorio de C:\WINNT\ServicePackFiles\i386

19/06/2003 12:05 89.360 services.exe
1 archivos 89.360 bytes

Directorio de C:\WINNT\system32

19/06/2003 12:05 89.360 SERVICES.EXE
1 archivos 89.360 bytes

and it shouldn't be a problem of hidden files because:

C:\WINNT>attrib services.exe /s
C:\WINNT\$NtServicePackUninstall$\services.exe
C:\WINNT\ServicePackFiles\i386\services.exe
A C:\WINNT\system32\SERVICES.EXE

should I delete any of those particular ones or are those ones "good files" of the system?

Boot is still slowly, is there any other thing in the system I can look for ?

I'm pasting the new Hijak This log (btw, I downloaded the lastest version in tomcoyote.org and it is always v1.97.7, not 1.98.2 as you posted… refresh problems ?)

All the 01 Hosts are known and useful.

**** Hijak This new log ****

Logfile of HijackThis v1.97.7
Scan saved at 0:54:21, on 04/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Archivos de programa\NavNT\defwatch.exe
C:\Archivos de programa\IBM\Desktop On-Call\dtocsrvc.exe
C:\WINNT\System32\svchost.exe
C:\Archivos de programa\Ahead\InCD\InCDsrv.exe
C:\Archivos de programa\IBM\Desktop On-Call\logon.exe
C:\Archivos de programa\IBM\Desktop On-Call\httpd.exe
C:\Archivos de programa\IBM\Desktop On-Call\slaved.exe
C:\Archivos de programa\IBM\Desktop On-Call\automap.exe
C:\Archivos de programa\IBM\Desktop On-Call\dtocftpd.exe
C:\Archivos de programa\IBM\Desktop On-Call\chat.exe
c:\sdwork\issimsvc.exe
C:\Notes\ntmulti.exe
C:\ARCHIV~1\AT&TNE~2\NetCfgSv.EXE
C:\Archivos de programa\Symantec_Desktop_Firewall\NISSERV.EXE
C:\Archivos de programa\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\drivers\trcboot.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Archivos de programa\Personal Communications\PCS_AGNT.EXE
C:\Archivos de programa\UltraVNC\WinVNC.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\Archivos de programa\Symantec_Desktop_Firewall\NISUM.EXE
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\system32\desk95.exe
C:\WINNT\system32\carpserv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Archivos de programa\Symantec_Desktop_Firewall\IAMAPP.EXE
C:\Archivos de programa\NavNT\vptray.exe
C:\Archivos de programa\Real\RealPlayer\RealPlay.exe
C:\Archivos de programa\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\Archivos de programa\Logitech\ImageStudio\LogiTray.exe
C:\WINNT\tppaldr.exe
C:\WINNT\system32\UMonit2k.exe
C:\Archivos de programa\Java\j2re1.4.2_03\bin\jusched.exe
C:\Archivos de programa\Ahead\InCD\InCD.exe
C:\WINNT\system32\LVCOMSX.EXE
C:\Archivos de programa\Logitech\Video\LogiTray.exe
C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Archivos de programa\Logitech\MouseWare\system\em_exec.exe
D:\edonkeybasic\edonkey2000.exe
G:\SB\sb.exe
C:\WINNT\system32\internat.exe
C:\Archivos de programa\ATI Multimedia\main\launchpd.exe
C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Archivos de programa\MyServer.org\DynamicDNS.exe
C:\Lotus\organize\EasyClip.exe
C:\Lotus\smartctr\suitest.exe
C:\Archivos de programa\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Archivos de programa\Logitech\Video\FxSvr2.exe
C:\Archivos de programa\Plextor\PlexTool.exe
C:\psm\ipnotif.exe
C:\Archivos de programa\ArGo Software Design\Mail Server\MailServer.exe
C:\Archivos de programa\Caere\OmniPagePro90\EREG\REMIND32.EXE
D:\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: 172.26.0.1 router-multi-local
O1 - Hosts: 213.98.17.196 router-multi-remoto
O1 - Hosts: 213.98.17.193 router-mono-local
O1 - Hosts: 172.26.0.2 desktop-casa
O1 - Hosts: 172.26.0.3 portatil-casa #Thinkpad 600E en casa
O1 - Hosts: 172.26.0.4 imagenes
O1 - Hosts: 172.26.0.5 invitado
O1 - Hosts: 172.26.0.6 TP23
O1 - Hosts: 213.98.17.196 router-casa
O1 - Hosts: 213.186.37.169 www.911cd.net Forums de Bootable CD
O1 - Hosts: 9.139.234.1 proxy-mad-a
O1 - Hosts: 9.139.234.2 proxy-mad-b
O1 - Hosts: 9.139.234.4 proxy-mad
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HydarVisionDesktopManager] desk95.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [DNSRestore] "C:\ARCHIV~1\AT&TNE~2\DNSRestore.exe" -R
O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [iamapp] "C:\Archivos de programa\Symantec_Desktop_Firewall\IAMAPP.EXE"
O4 - HKLM\..\Run: [vptray] C:\Archivos de programa\NavNT\vptray.exe
O4 - HKLM\..\Run: [RealTray] C:\Archivos de programa\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCTVRemote] C:\Archivos de programa\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Archivos de programa\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Archivos de programa\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINNT\tppaldr.exe
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINNT\system32\UMonit2k.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Archivos de programa\Archivos comunes\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Archivos de programa\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [InCD] C:\Archivos de programa\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Archivos de programa\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Archivos de programa\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AtiPTA] C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [eDonkey2000] "D:\edonkeybasic\edonkey2000.exe" -t
O4 - HKLM\..\Run: [System32] System32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Archivos de programa\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [LDM] C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Archivos de programa\Logitech\Video\ManifestEngine.exe" boot
O4 - Startup: MailServer.lnk = C:\Archivos de programa\ArGo Software Design\Mail Server\MailServer.exe
O4 - Startup: reminder-Registro del producto ScanSoft.lnk = C:\Archivos de programa\Caere\OmniPagePro90\EREG\REMIND32.EXE
O4 - Global Startup: Acceso directo a Conexión ADSL IBM Externa.lnk = ?
O4 - Global Startup: Dynamic DNS App.LNK = C:\Archivos de programa\MyServer.org\DynamicDNS.exe
O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\Lotus\organize\EasyClip.exe
O4 - Global Startup: Lotus QuickStart.lnk = C:\Lotus\wordpro\ltsstart.exe
O4 - Global Startup: Lotus SuiteStart.lnk = C:\Lotus\smartctr\suitest.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Pinnacle Scheduler.lnk = C:\Archivos de programa\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
O4 - Global Startup: PlexTools Professional.lnk = C:\Archivos de programa\Plextor\PlexTool.exe
O4 - Global Startup: PSM Notification.lnk = C:\psm\ipnotif.exe
O9 - Extra 'Tools' menuitem: Consola de Sun Java (HKLM)
O9 - Extra button: Juegos On Line (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\asnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O12 - Plugin for .spop: C:\Archivos de programa\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…7667.6189351852
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{077FFA96-7BF6-4F38-9022-96A39E00F5E8}: NameServer = 213.0.184.85 213.0.184.88
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A97B7CD-7106-4309-AFE2-D991B2AA1885}: Domain = ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A97B7CD-7106-4309-AFE2-D991B2AA1885}: NameServer = 194.179.1.100,194.179.1.101
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com

*****


Thanks again. Javier
Leave all the "services.exe" files you mentioned alone.

This new entry:

O4 - HKLM\..\Run: [System32] System32.exe

Means you are infected with this virus.

Please download the latest version of Hijack This!

Links to Hijack This! v 1.98.2:

http://tools.radiosplace.com/HijackThis.exe
http://spywarewarrior.com/files/HijackThis.exe
http://tomcoyote.org/hjt/HijackThis.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [System32] System32.exe

Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

system32.exe <— file
(should be in the C:\WINNT\System32 folder)

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)

If you have the time and patience, it wouldn't hurt to re-run the online virus scans one more time.
Thanks again !

I looked for that entry for fixing it… but some strange things seems to be happening,

1.- the "system32.exe" file seems not to exist in my PC:


C:\>dir system32*.* /s /p
El volumen de la unidad C es Win2kDiscoC
El número de serie del volumen es: 78B1-442C

Directorio de C:\WINNT

04/10/2004 00:41 system32
0 archivos 0 bytes

Total de archivos en la lista:
0 archivos 0 bytes
1 dirs 3.808.882.688 bytes libres

C:\>attrib system32*.* /s
File not found: system32*.*

And the 04 entry doesn't seem to exist either. Here is the current HijackThis log:

****
Logfile of HijackThis v1.98.2
Scan saved at 9:17:42, on 04/10/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Archivos de programa\NavNT\defwatch.exe
C:\Archivos de programa\IBM\Desktop On-Call\dtocsrvc.exe
C:\WINNT\System32\svchost.exe
C:\Archivos de programa\Ahead\InCD\InCDsrv.exe
C:\Archivos de programa\IBM\Desktop On-Call\logon.exe
C:\Archivos de programa\IBM\Desktop On-Call\httpd.exe
C:\Archivos de programa\IBM\Desktop On-Call\slaved.exe
C:\Archivos de programa\IBM\Desktop On-Call\automap.exe
C:\Archivos de programa\IBM\Desktop On-Call\dtocftpd.exe
C:\Archivos de programa\IBM\Desktop On-Call\chat.exe
c:\sdwork\issimsvc.exe
C:\Notes\ntmulti.exe
C:\ARCHIV~1\AT&TNE~2\NetCfgSv.EXE
C:\Archivos de programa\Symantec_Desktop_Firewall\NISSERV.EXE
C:\Archivos de programa\NavNT\rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\drivers\trcboot.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Archivos de programa\Personal Communications\PCS_AGNT.EXE
C:\Archivos de programa\UltraVNC\WinVNC.exe
C:\WINNT\system32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\Archivos de programa\Symantec_Desktop_Firewall\NISUM.EXE
C:\WINNT\system32\MsgSys.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\system32\desk95.exe
C:\WINNT\system32\carpserv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\Archivos de programa\Symantec_Desktop_Firewall\IAMAPP.EXE
C:\Archivos de programa\NavNT\vptray.exe
C:\Archivos de programa\Real\RealPlayer\RealPlay.exe
C:\Archivos de programa\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\Archivos de programa\Logitech\ImageStudio\LogiTray.exe
C:\WINNT\tppaldr.exe
C:\WINNT\system32\UMonit2k.exe
C:\Archivos de programa\Java\j2re1.4.2_03\bin\jusched.exe
C:\Archivos de programa\Ahead\InCD\InCD.exe
C:\WINNT\system32\LVCOMSX.EXE
C:\Archivos de programa\Logitech\Video\LogiTray.exe
C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Archivos de programa\Logitech\MouseWare\system\em_exec.exe
D:\edonkeybasic\edonkey2000.exe
G:\SB\sb.exe
C:\WINNT\system32\internat.exe
C:\Archivos de programa\ATI Multimedia\main\launchpd.exe
C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Archivos de programa\MyServer.org\DynamicDNS.exe
C:\Lotus\organize\EasyClip.exe
C:\Lotus\smartctr\suitest.exe
C:\Archivos de programa\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Archivos de programa\Logitech\Video\FxSvr2.exe
C:\Archivos de programa\Plextor\PlexTool.exe
C:\psm\ipnotif.exe
C:\Archivos de programa\ArGo Software Design\Mail Server\MailServer.exe
C:\Archivos de programa\Caere\OmniPagePro90\EREG\REMIND32.EXE
C:\WINNT\tppnttry.exe
C:\WINNT\System32\svchost.exe
D:\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: 172.26.0.1 router-multi-local
O1 - Hosts: 213.98.17.196 router-multi-remoto
O1 - Hosts: 213.98.17.193 router-mono-local
O1 - Hosts: 172.26.0.2 desktop-casa
O1 - Hosts: 172.26.0.3 portatil-casa #Thinkpad 600E en casa
O1 - Hosts: 172.26.0.4 imagenes
O1 - Hosts: 172.26.0.5 invitado
O1 - Hosts: 172.26.0.6 TP23
O1 - Hosts: 213.98.17.196 router-casa
O1 - Hosts: 213.186.37.169 www.911cd.net Forums de Bootable CD
O1 - Hosts: 9.139.234.1 proxy-mad-a
O1 - Hosts: 9.139.234.2 proxy-mad-b
O1 - Hosts: 9.139.234.4 proxy-mad
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HydarVisionDesktopManager] desk95.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [DNSRestore] "C:\ARCHIV~1\AT&TNE~2\DNSRestore.exe" -R
O4 - HKLM\..\Run: [stgclean] c:\sdwork\w32main2.exe /cleanup
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\NTFSCLUP.EXE
O4 - HKLM\..\Run: [CSScheduleCheck] C:\CFGSAFE\SCHWIZEX.EXE -CHECK
O4 - HKLM\..\Run: [iamapp] "C:\Archivos de programa\Symantec_Desktop_Firewall\IAMAPP.EXE"
O4 - HKLM\..\Run: [vptray] C:\Archivos de programa\NavNT\vptray.exe
O4 - HKLM\..\Run: [RealTray] C:\Archivos de programa\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PCTVRemote] C:\Archivos de programa\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Archivos de programa\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Archivos de programa\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [ISSI EZUpdate Service] "c:\sdwork\issimsvc.exe"
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINNT\tppaldr.exe
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINNT\system32\UMonit2k.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Archivos de programa\Archivos comunes\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Archivos de programa\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [InCD] C:\Archivos de programa\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINNT\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Archivos de programa\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Archivos de programa\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [AtiPTA] C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [eDonkey2000] "D:\edonkeybasic\edonkey2000.exe" -t
O4 - HKLM\..\Run: [Trunk32] Trunk32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Archivos de programa\ATI Multimedia\main\launchpd.exe"
O4 - HKCU\..\Run: [LDM] C:\Archivos de programa\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Archivos de programa\Logitech\Video\ManifestEngine.exe" boot
O4 - Startup: MailServer.lnk = C:\Archivos de programa\ArGo Software Design\Mail Server\MailServer.exe
O4 - Startup: reminder-Registro del producto ScanSoft.lnk = C:\Archivos de programa\Caere\OmniPagePro90\EREG\REMIND32.EXE
O4 - Global Startup: Acceso directo a Conexión ADSL IBM Externa.lnk = ?
O4 - Global Startup: Dynamic DNS App.LNK = C:\Archivos de programa\MyServer.org\DynamicDNS.exe
O4 - Global Startup: Lotus Organizer EasyClip.lnk = C:\Lotus\organize\EasyClip.exe
O4 - Global Startup: Lotus QuickStart.lnk = C:\Lotus\wordpro\ltsstart.exe
O4 - Global Startup: Lotus SuiteStart.lnk = C:\Lotus\smartctr\suitest.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Pinnacle Scheduler.lnk = C:\Archivos de programa\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
O4 - Global Startup: PlexTools Professional.lnk = C:\Archivos de programa\Plextor\PlexTool.exe
O4 - Global Startup: PSM Notification.lnk = C:\psm\ipnotif.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Juegos On Line - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\mrc-buscadorfacil3\local.htm (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARCHIV~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARCHIV~1\Yahoo!\MESSEN~1\YPager.exe
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\asnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\aventail\connect\aslsp.dll
O12 - Plugin for .spop: C:\Archivos de programa\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9519B2A2-6592-4E41-8290-D0298459270C} (LNWebAssist Class) - http://w3.ibm.com/bluepages/scripts/lnwebassist.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{077FFA96-7BF6-4F38-9022-96A39E00F5E8}: NameServer = 213.0.184.85 213.0.184.88
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A97B7CD-7106-4309-AFE2-D991B2AA1885}: Domain = ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A97B7CD-7106-4309-AFE2-D991B2AA1885}: NameServer = 194.179.1.100,194.179.1.101
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mad.es.ibm.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = watson.ibm.com ibm.com

****

Rgds. Javier
Well… there's still one piece of "undefined" software on your machine.

I'd like you to go here:

Kaspersky Online Scanner

And submit this file:

O4 - HKLM\..\Run: [Trunk32] Trunk32.exe

(Can't tell from the log what folder it is in)

For an online virus check.

Let me know the results. :)
Dear Sam: Trunk32.exe doesn't exist as a file. I then looked into the registry and it seems to be an "intemediate" pointer to another one. In the registry "trunk" points to "trun32exe", and "trun32.exe" is again defined in the "App Paths" Key and points to another execution file that I know and control and anyway I submitted to the Kaspersky website with result: - OK Thanks for your help Javier
If you trust that last file (or pointer), then you're clean!!!

GOD bless!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.
(Personally I'm NOT recommending SP2 for XP at this time)

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI