This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis Log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Google searches get redirected: Spybot, Adware and Defender won't fix it - I am baffled.


Logfile of HijackThis v1.99.1
Scan saved at 22:41:10, on 25/05/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
H:\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\system32\taskswitch.exe
H:\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\guyb\Desktop\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=2333
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=2333
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: (no name) - {D60F6394-4DC4-0D0D-2AEB-DA017AFBD061} - typeconf.dll (file missing)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "H:\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [dmimg.exe] C:\WINDOWS\system32\dmimg.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [scanSYS] systemdll.exe
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144568701609
O17 - HKLM\System\CCS\Services\Tcpip\..\{280BFB0B-E596-46EB-8D77-E55BD80A2473}: Domain = mshome.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{280BFB0B-E596-46EB-8D77-E55BD80A2473}: NameServer = 85.255.113.116,85.255.112.80
O17 - HKLM\System\CCS\Services\Tcpip\..\{91DF2801-46AE-4373-800E-50471D06DF5D}: NameServer = 85.255.113.116 85.255.112.80
O17 - HKLM\System\CCS\Services\Tcpip\..\{B0EA8D78-EC7A-4C00-A72D-BC9CDEFD8BB4}: NameServer = 85.255.113.116,85.255.112.80
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - H:\PhotoshopElementsFileAgent.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
Welocme to the forum :wavey:

Your computer has been hijacked by people in the Ukraine. What you have is a Wareout infection.

85.255.112.0 - 85.255.127.255
Inhoster hosting company
OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine


Please download FixWareout from one of these sites:
Fixwareout.exe
Fixwareout.exe

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

* Save it to your desktop and run it.
* Click Next, then Install, make sure "Run fixit" is checked and click Finish.
* The fix will begin; follow the prompts.
* You will be asked to reboot your computer; please do so.
* Your system may take longer than usual to load; this is normal.
* Once the desktop loads a text will open (report.txt). We'll need that in a bit.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):
(Note: Fixwareout.exe may have already removed some of these)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R3 - URLSearchHook: (no name) - {D60F6394-4DC4-0D0D-2AEB-DA017AFBD061} - typeconf.dll (file missing)

O4 - HKLM\..\Run: [dmimg.exe] C:\WINDOWS\system32\dmimg.exe

O4 - HKCU\..\Run: [scanSYS] systemdll.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{280BFB0B-E596-46EB-8D77-E55BD80A2473}: NameServer = 85.255.113.116,85.255.112.80

O17 - HKLM\System\CCS\Services\Tcpip\..\{91DF2801-46AE-4373-800E-50471D06DF5D}: NameServer = 85.255.113.116 85.255.112.80

O17 - HKLM\System\CCS\Services\Tcpip\..\{B0EA8D78-EC7A-4C00-A72D-BC9CDEFD8BB4}: NameServer = 85.255.113.116,85.255.112.80

Then click "Fix checked" and close Hijack This!.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\windows\system32\dmimg.exe <— file

systemdll.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new HijackThis! log file into this thread.

Please open this file with Notepad:

C:\fixwareout\report.txt

And paste it's contents into your reply as well.

:)
Mission accomplished:

Logfile of HijackThis v1.99.1
Scan saved at 21:36:54, on 26/05/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
H:\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\system32\taskswitch.exe
H:\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\guyb\Desktop\Hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=2333
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "H:\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144568701609
O17 - HKLM\System\CCS\Services\Tcpip\..\{280BFB0B-E596-46EB-8D77-E55BD80A2473}: Domain = mshome.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{91DF2801-46AE-4373-800E-50471D06DF5D}: NameServer = 85.255.113.116 85.255.112.80
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - H:\PhotoshopElementsFileAgent.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)


Fixwareout ver 1.003
Last edited 04/26/2006
Post this report in the forums please

Reg Entries that were deleted
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Example ipsec6.exe is lagitamate

»»»»» Search by size and names…
C:\WINDOWS\SYSTEM32\DMOWJ.EXE
C:\WINDOWS\SYSTEM32\IPSEC6.EXE
* csr.exe C:\WINDOWS\System32\CSJWN.EXE
* csr.exe C:\WINDOWS\System32\CSPYA.EXE

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool

»»»»»
Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSJWN.EXE 51,293 2006-04-07
C:\WINDOWS\SYSTEM32\CSPYA.EXE 51,200 2006-01-05
C:\WINDOWS\SYSTEM32\DMAKB.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMEIB.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMFYR.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMGIC.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMGOC.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMJCZ.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMOWJ.EXE 44,032 2004-08-04
C:\WINDOWS\SYSTEM32\DMQAD.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMRAX.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMSMT.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMTFJ.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMUQS.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMVKJ.EXE 44,130 2004-08-04
C:\WINDOWS\SYSTEM32\DMXRG.EXE 44,130 2004-08-04
Fix this:

O17 - HKLM\System\CCS\Services\Tcpip\..\{91DF2801-46AE-4373-800E-50471D06DF5D}: NameServer = 85.255.113.116 85.255.112.80


Reboot and post a new HijackThis! log file.

Then, let's do as it suggests…

Go here:

VirusTotal

And submit these files for a virus scan:

C:\WINDOWS\SYSTEM32\CSJWN.EXE
C:\WINDOWS\SYSTEM32\CSPYA.EXE
C:\WINDOWS\SYSTEM32\DMAKB.EXE
C:\WINDOWS\SYSTEM32\DMEIB.EXE
C:\WINDOWS\SYSTEM32\DMFYR.EXE
C:\WINDOWS\SYSTEM32\DMGIC.EXE
C:\WINDOWS\SYSTEM32\DMGOC.EXE
C:\WINDOWS\SYSTEM32\DMJCZ.EXE
C:\WINDOWS\SYSTEM32\DMOWJ.EXE
C:\WINDOWS\SYSTEM32\DMQAD.EXE
C:\WINDOWS\SYSTEM32\DMRAX.EXE
C:\WINDOWS\SYSTEM32\DMSMT.EXE
C:\WINDOWS\SYSTEM32\DMTFJ.EXE
C:\WINDOWS\SYSTEM32\DMUQS.EXE
C:\WINDOWS\SYSTEM32\DMVKJ.EXE
C:\WINDOWS\SYSTEM32\DMXRG.EXE

Let me know the results.
:)
Second go:

New HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 22:36:55, on 27/05/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
H:\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\Explorer.EXE
C:\MadeSafe\Bin\Zanda.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\MadeSafe\Nvc\bin\nvcoas.exe
C:\MadeSafe\bin\NJEEVES.EXE
C:\MadeSafe\Nvc\BIN\NVCSCHED.EXE
C:\MadeSafe\Nvc\BIN\nipsvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\WINDOWS\system32\taskswitch.exe
H:\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\MadeSafe\bin\ZLH.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
C:\WINDOWS\System32\svchost.exe
C:\MadeSafe\Nvc\BIN\NIP.EXE
C:\MadeSafe\Nvc\bin\cclaw.exe
C:\MadeSafe\Nvc\BIN\NVCOD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\guyb\Desktop\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=2333
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=2333
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "H:\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Norman ZANDA] C:\MadeSafe\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: PC Alert 4.lnk = C:\Program Files\MSI\PC Alert 4\PCAlert4.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.microsoft.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1144568701609
O17 - HKLM\System\CCS\Services\Tcpip\..\{280BFB0B-E596-46EB-8D77-E55BD80A2473}: Domain = mshome.net
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - H:\PhotoshopElementsFileAgent.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\MadeSafe\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\MadeSafe\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\MadeSafe\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\MadeSafe\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\MadeSafe\Nvc\BIN\NVCSCHED.EXE




Results from TotalVirus:

C:\WINDOWS\SYSTEM32\CSJWN.EXE 51,293 2006-04-07


STATUS: FINISHEDComplete scanning result of "CSJWN.EXE___", received in VirusTotal at 05.27.2006, 22:32:20 (CET).

Antivirus Version Update Result
AntiVir 6.34.1.34 05.27.2006 TR/Dldr.FFZ.8
Authentium 4.93.8 05.26.2006 no virus found
Avast 4.6.695.0 05.26.2006 Win32:Agent-IU
AVG 386 05.26.2006 Downloader.Agent.13.AV
BitDefender 7.2 05.27.2006 Trojan.Downloader.FFZ
CAT-QuickHeal 8.00 05.27.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 05.27.2006 Trojan.Downloader.Agent-262
DrWeb 4.33 05.26.2006 no virus found
eTrust-InoculateIT 23.72.19 05.26.2006 no virus found
eTrust-Vet 12.6.2229 05.26.2006 Win32/Alureon!generic
Ewido 3.5 05.27.2006 Downloader.Agent.uj
Fortinet 2.77.0.0 05.27.2006 suspicious
F-Prot 3.16c 05.26.2006 no virus found
Ikarus 0.2.65.0 05.27.2006 no virus found
Kaspersky 4.0.2.24 05.27.2006 Trojan-Downloader.Win32.Agent.uj
McAfee 4771 05.26.2006 no virus found
Microsoft 1.1441 05.27.2006 no virus found
NOD32v2 1.1562 05.27.2006 a variant of Win32/Small.FB
Norman 5.90.17 05.26.2006 no virus found
Panda 9.0.0.4 05.27.2006 Adware/Trebuh
Sophos 4.05.0 05.27.2006 no virus found
Symantec 8.0 05.27.2006 no virus found
TheHacker 5.9.8.149 05.26.2006 no virus found
UNA 1.83 05.26.2006 no virus found
VBA32 3.11.0 05.26.2006 Trojan.DownLoader.4316

C:\WINDOWS\SYSTEM32\CSPYA.EXE 51,200 2006-01-05

STATUS: FINISHEDComplete scanning result of "CSPYA.EXE", received in VirusTotal at 05.27.2006, 22:30:48 (CET).

Antivirus Version Update Result
AntiVir 6.34.1.34 05.27.2006 TR/Dldr.Agent.UJ.161
Authentium 4.93.8 05.26.2006 no virus found
Avast 4.6.695.0 05.26.2006 Win32:Agent-IU
AVG 386 05.26.2006 Downloader.Agent.13.AV
BitDefender 7.2 05.27.2006 Trojan.Downloader.FFZ
CAT-QuickHeal 8.00 05.27.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 05.27.2006 Trojan.Downloader.Agent-262
DrWeb 4.33 05.26.2006 Trojan.DownLoader.9145
eTrust-InoculateIT 23.72.19 05.26.2006 no virus found
eTrust-Vet 12.6.2229 05.26.2006 no virus found
Ewido 3.5 05.27.2006 Downloader.Agent.uj
Fortinet 2.77.0.0 05.27.2006 suspicious
F-Prot 3.16c 05.26.2006 no virus found
Ikarus 0.2.65.0 05.27.2006 no virus found
Kaspersky 4.0.2.24 05.27.2006 Trojan-Downloader.Win32.Agent.uj
McAfee 4771 05.26.2006 no virus found
Microsoft 1.1441 05.27.2006 no virus found
NOD32v2 1.1562 05.27.2006 a variant of Win32/Small.FB
Norman 5.90.17 05.26.2006 no virus found
Panda 9.0.0.4 05.27.2006 Trj/Agent.BBG
Sophos 4.05.0 05.27.2006 no virus found
Symantec 8.0 05.27.2006 no virus found
TheHacker 5.9.8.149 05.26.2006 no virus found
UNA 1.83 05.26.2006 no virus found
VBA32 3.11.0 05.26.2006 Trojan.DownLoader.4316

C:\WINDOWS\SYSTEM32\DMAKB.EXE 44,130 2004-08-04 No Virus detected
C:\WINDOWS\SYSTEM32\DMEIB.EXE 44,130 2004-08-04No Virus detected
C:\WINDOWS\SYSTEM32\DMFYR.EXE 44,130 2004-08-04No Virus detected
C:\WINDOWS\SYSTEM32\DMGIC.EXE 44,130 2004-08-04No Virus detected
C:\WINDOWS\SYSTEM32\DMGOC.EXE 44,130 2004-08-04No Virus detected

C:\WINDOWS\SYSTEM32\DMJCZ.EXE 44,130 2004-08-04AntiVir 6.34.1.34 05.27.2006 Heuristic/Trojan.Downloader
Authentium 4.93.8 05.26.2006 no virus found
Avast 4.6.695.0 05.26.2006 Win32:Small-EK
AVG 386 05.26.2006 no virus found
BitDefender 7.2 05.27.2006 no virus found
CAT-QuickHeal 8.00 05.27.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 05.27.2006 no virus found
DrWeb 4.33 05.26.2006 Trojan.DownLoader.5401
eTrust-InoculateIT 23.72.19 05.26.2006 no virus found
eTrust-Vet 12.6.2229 05.26.2006 Win32/Alureon!generic
Ewido 3.5 05.27.2006 no virus found
Fortinet 2.77.0.0 05.27.2006 suspicious
F-Prot 3.16c 05.26.2006 no virus found
Ikarus 0.2.65.0 05.27.2006 no virus found
Kaspersky 4.0.2.24 05.27.2006 Trojan.Win32.Small.fb
McAfee 4771 05.26.2006 no virus found
Microsoft 1.1441 05.27.2006 no virus found
NOD32v2 1.1562 05.27.2006 Win32/Small.FB
Norman 5.90.17 05.26.2006 no virus found
Panda 9.0.0.4 05.27.2006 Trj/Downloader.HIB
Sophos 4.05.0 05.27.2006 no virus found
Symantec 8.0 05.27.2006 no virus found
TheHacker [removed] 05.26.2006 no virus found
UNA 1.83 05.26.2006 no virus found
VBA32 3.11.0 05.26.2006 Trojan.Win32.Pakes


C:\WINDOWS\SYSTEM32\DMOWJ.EXE

STATUS: FINISHEDComplete scanning result of "dmowj.exe", received in VirusTotal at 05.27.2006, 22:37:28 (CET).

Antivirus Version Update Result
AntiVir 6.34.1.34 05.27.2006 Heuristic/Trojan.Downloader
Authentium 4.93.8 05.26.2006 no virus found
Avast 4.6.695.0 05.26.2006 Win32:Small-EK
AVG 386 05.26.2006 no virus found
BitDefender 7.2 05.27.2006 no virus found
CAT-QuickHeal 8.00 05.27.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 05.27.2006 no virus found
DrWeb 4.33 05.26.2006 Trojan.DownLoader.5401
eTrust-InoculateIT 23.72.19 05.26.2006 no virus found
eTrust-Vet 12.6.2229 05.26.2006 Win32/Alureon!generic
Ewido 3.5 05.27.2006 no virus found
Fortinet 2.77.0.0 05.27.2006 suspicious
F-Prot 3.16c 05.26.2006 no virus found
Ikarus 0.2.65.0 05.27.2006 no virus found
Kaspersky 4.0.2.24 05.27.2006 Trojan.Win32.Small.fb
McAfee 4771 05.26.2006 no virus found
Microsoft 1.1441 05.27.2006 no virus found
NOD32v2 1.1562 05.27.2006 Win32/Small.FB
Norman 5.90.17 05.26.2006 no virus found
Panda 9.0.0.4 05.27.2006 Trj/Downloader.HIB
Sophos 4.05.0 05.27.2006 no virus found
Symantec 8.0 05.27.2006 no virus found
TheHacker [removed] 05.26.2006 no virus found
UNA 1.83 05.26.2006 no virus found
VBA32 3.11.0 05.26.2006 Trojan.Win32.Pakes


C:\WINDOWS\SYSTEM32\DMQAD.EXE 44,130 2004-08-04 No Virus found
C:\WINDOWS\SYSTEM32\DMRAX.EXE 44,130 2004-08-04 No Virus found
C:\WINDOWS\SYSTEM32\DMSMT.EXE 44,130 2004-08-04 No Virus found
C:\WINDOWS\SYSTEM32\DMTFJ.EXE 44,130 2004-08-04 No Virus found
C:\WINDOWS\SYSTEM32\DMUQS.EXE 44,130 2004-08-04 No Virus found
C:\WINDOWS\SYSTEM32\DMVKJ.EXE 44,130 2004-08-04 No Virus found
C:\WINDOWS\SYSTEM32\DMVKJ.EXE 44,130 2004-08-04 No Virus found
C:\WINDOWS\SYSTEM32\DMXRG.EXE No virus found
The log looks good. :thumbup:

Find and delete the following files:

C:\WINDOWS\SYSTEM32\CSJWN.EXE

C:\WINDOWS\SYSTEM32\CSPYA.EXE

C:\WINDOWS\SYSTEM32\DMJCZ.EXE

C:\WINDOWS\SYSTEM32\DMOWJ.EXE

If you're not experiencing any problems, then I'd say you're "good to go".

Thank you for using the forum.

M68 :)

Post Infection Items To Ponder
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI