This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack log

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got a serious problem with my Windows computer. Yesterday the internet of the computer shut down totally and I checked my settings, as the my connection worked for my other computers. In the information-tab of my connection my ip was wrong (I have a router that distributes static ip-adresses) and my default gateway was blank. My antivirus program found viruses in my memory even though I bootscanned it. So I figured that I could just reinstall my windows xp and wipe the harddrive since I wasn't happy with my partitions anyway and everything was getting slower. But no, the boot-installer-from-cd said that it couldn't find my harddrive and it was probably caused by a virus or permanent damage to the harddrive. But I could still boot my computer so aparantly it could find it. So I'm unable to wipe my harddrive until I've removed the virus. So you could say that I could use some instructions/advice on how to cure my computer. Here is my Hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 12:57:51, on 2006-06-15
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program\AirPlus XtremeG\AirPlusCFG.exe
C:\DOCUME~1\THRSE~1\MINADO~1\MCROSO~1.NET\csrss.exe
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\Program\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program\Alwil Software\Avast4\ashMaiSv.exe
C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program\Hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = L‰nkar
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: (no name) - {6D526BDC-DE1F-F59D-4EB2-A0BFD28985C8} - C:\WINDOWS\system32\xin.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] C:\Program\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [fe481b4.exe] C:\WINDOWS\system32\fe481b4.exe
O4 - HKLM\..\Run: [SpywareQuake.com] C:\Program\SpywareQuake.com\Spyware-Quake.exe /h
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [keyboard] C:\\keyboard25.exe
O4 - HKLM\..\Run: [defender] C:\\defender26.exe
O4 - HKLM\..\Run: [newname] C:\\newname25.exe
O4 - HKLM\..\Run: [webHancer Agent] C:\Program\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program\webHancer\Programs\whsurvey.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Utopia Angel] "F:\Spel\Angel\Angel.exe"
O4 - HKCU\..\Run: [fe481b4.exe] C:\Documents and Settings\ThÈrËse\Lokala inst‰llningar\Application Data\fe481b4.exe
O4 - HKCU\..\Run: [Uehs] "C:\DOCUME~1\THRSE~1\MINADO~1\MCROSO~1.NET\csrss.exe" -vt yax
O4 - HKCU\..\Run: [Rfbsphq] C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BINGOOO - {87F2CA68-5130-49A3-8E5B-73E61F67BB0B} - C:\Program\BINGOOO\BINGOOO.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'c:\program\webhancer\programs\webhdll.dll' missing
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0990D180-4226-4530-9777-AB82315505B9} (Installer Class) - http://www.foreningssparbanken.se/betala/e…iscomsigned.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149201934968
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {785EA525-5066-495F-ADF6-3B8316515DEF} (Collapse Control) - http://mirror.worldwinner.com/games/v46/co…se/collapse.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\winlogon.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\vzdx16.dll (file missing)
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Lg\command.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
Hello bredbite, welcome to the forum


Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

Please print out or copy these instructions\tutorials to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.



Download SmitRem.exe © noahdfear from one of these sites to your Desktop.
http://www.downloads.subratam.org/smitRem.exe
http://noahdfear.geekstogo.com/click%20cou....php?id=1"

[external image: Posted Image]


Double-click the smitRem.exe and it will extract the files to a smitRem folder on your Desktop. Don't Run Yet.

[external image: Posted Image]

Please download the trial version of ewido anti-malware 3.5. Install ewido anti-malware 3.5 and start the program from the icon on your desktop, then check for and download updates. Don't Run Yet.


Reboot to safe mode

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


logon to your user account.
Open the smitfraud folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. When the tool completes:

[external image: Posted Image]


Open Ewido Security Suite
  • Then please run Ewido, click on the Scanner run a full scan and let
  • it clean everything it finds.
  • Once the scan has completed, there will be a button located on the bottom
  • of the screen named
  • Click Save report
  • Save the report to your desktop
In the Control Panel click Display > Desktop > Customize desktop > Website > Uncheck "Security Info" if present.

Empty recycle bin.


Reboot

Download this file from the link to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection


"copy/paste" the contents of the log C:\smitfiles.txt a new HijackThis log and the Ewido log.
Also please describe how your computer behaves at the moment.
Thanks for answering!

Ok, I've followed your instructions. The problem is that I couldn't update ewido, since I (as I said in my first post) cant get an internet connection on the "infected computer".

After the reboot from safemode, I got an popup from ewindo saying that I got malware on my computer, even though I cleaned it in safemode (yes, full scan). I still can't get an IP or gateway from my router so no internet connection. I can however set a static ip from the "infected computer" and access the local network. This is how I copy the logs and download the software that you require. The computer I write from now is a Mac.

Edit: I can't seem to post the ewindo log? It just disapheres when I copy paste it to the log?

Here comes the smitfiles.txt:


smitRem © log file
version 3.0

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
"IE"="6.0000"

Running from
C:\Documents and Settings\ThÇräse\Skrivbord\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{9ae613a2-a13b-4379-8d0e-86a1a78476ec}"="corindon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{9ae613a2-a13b-4379-8d0e-86a1a78476ec}\InProcServer32]
@="C:\WINDOWS\system32\rmzdzx.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!


checking for drsmartload2 key

drsmartload2 key present!



Running drsmartload2 fix!



drsmartload2 key was successfully removed! :)

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
AlfaCleaner uninstaller NOT present
SpyFalcon uninstaller NOT present
SpywareQuake uninstaller NOT present
SpywareSheriff uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~

Antivirus Test Online.url


~~~ system32 folder ~~~

regperf.exe
simpole.tlb
stdole3.tlb
dcomcfg.exe
amcompat.tlb
nscompat.tlb
atmtd.dll
atmtd.dll._
1024 dir
ld****.tmp
perfcii.ini
logfiles


~~~ Icons in System32 ~~~

ts.ico
ot.ico


~~~ Windows directory ~~~

sites.ini


~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 828 'explorer.exe'
Killing PID 828 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{9ae613a2-a13b-4379-8d0e-86a1a78476ec}"="corindon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{9ae613a2-a13b-4379-8d0e-86a1a78476ec}\InProcServer32]
@="C:\WINDOWS\system32\rmzdzx.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


~~~ Wininet.dll ~~~

CLEAN! :)

Here comes the new hijacklog:

Logfile of HijackThis v1.99.1
Scan saved at 01:21:31, on 2006-06-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program\AirPlus XtremeG\AirPlusCFG.exe
C:\WINDOWS\system32\fe481b4.exe
C:\Program\ALWILS~1\Avast4\ashDisp.exe
C:\Program\ewido anti-spyware 4.0\ewido.exe
C:\DOCUME~1\THRSE~1\MINADO~1\MCROSO~1.NET\csrss.exe
C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\Program\Alwil Software\Avast4\ashServ.exe
C:\Program\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program\Alwil Software\Avast4\ashMaiSv.exe
C:\Program\Hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = L‰nkar
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: (no name) - {6D526BDC-DE1F-F59D-4EB2-A0BFD28985C8} - C:\WINDOWS\system32\xin.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] C:\Program\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [fe481b4.exe] C:\WINDOWS\system32\fe481b4.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [webHancer Agent] C:\Program\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program\webHancer\Programs\whsurvey.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Utopia Angel] "F:\Spel\Angel\Angel.exe"
O4 - HKCU\..\Run: [fe481b4.exe] C:\Documents and Settings\ThÈrËse\Lokala inst‰llningar\Application Data\fe481b4.exe
O4 - HKCU\..\Run: [Uehs] "C:\DOCUME~1\THRSE~1\MINADO~1\MCROSO~1.NET\csrss.exe" -vt yax
O4 - HKCU\..\Run: [Rfbsphq] C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE
O8 - Extra context menu item: E&xportera; till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BINGOOO - {87F2CA68-5130-49A3-8E5B-73E61F67BB0B} - C:\Program\BINGOOO\BINGOOO.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'c:\program\webhancer\programs\webhdll.dll' missing
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0990D180-4226-4530-9777-AB82315505B9} (Installer Class) - http://www.foreningssparbanken.se/betala/e…iscomsigned.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149201934968
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {785EA525-5066-495F-ADF6-3B8316515DEF} (Collapse Control) - http://mirror.worldwinner.com/games/v46/co…se/collapse.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\winlogon.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\vzdx16.dll (file missing)
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

-
Yes, now I can access the internet again!

Edit #1: There seems to be something that ewindo cant quarantine or delete: Adware.SearchMaid. And when I copy paste the log in this post, it disapheres after I complete the post? After the startup from safemode, where I did an another ewindo scan, I get a notification that ewindo found a malware: Adware.Agent, Location: C:\program\outlook express\wabimp.exe. And my antivirus finds a trojan: Win32:Purityscan-Q, Location: C:\Docume~1\thrse~1\Lokala~1\Temp\!update.exe\[UPSX].

Here is my new HijackLog:

Logfile of HijackThis v1.99.1
Scan saved at 09:45:32, on 2006-06-21
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program\AirPlus XtremeG\AirPlusCFG.exe
C:\Program\ALWILS~1\Avast4\ashDisp.exe
C:\Program\ewido anti-spyware 4.0\ewido.exe
C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\Program\Alwil Software\Avast4\ashServ.exe
C:\Program\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program\Alwil Software\Avast4\ashMaiSv.exe
C:\Program\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\Hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = L‰nkar
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: (no name) - {6D526BDC-DE1F-F59D-4EB2-A0BFD28985C8} - C:\WINDOWS\system32\xin.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] C:\Program\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [webHancer Agent] C:\Program\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program\webHancer\Programs\whsurvey.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Utopia Angel] "F:\Spel\Angel\Angel.exe"
O4 - HKCU\..\Run: [fe481b4.exe] C:\Documents and Settings\ThÈrËse\Lokala inst‰llningar\Application Data\fe481b4.exe
O4 - HKCU\..\Run: [Rfbsphq] C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BINGOOO - {87F2CA68-5130-49A3-8E5B-73E61F67BB0B} - C:\Program\BINGOOO\BINGOOO.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0990D180-4226-4530-9777-AB82315505B9} (Installer Class) - http://www.foreningssparbanken.se/betala/e…iscomsigned.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149201934968
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {785EA525-5066-495F-ADF6-3B8316515DEF} (Collapse Control) - http://mirror.worldwinner.com/games/v46/co…se/collapse.cab
O20 - AppInit_DLLs: winlogon.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\vzdx16.dll (file missing)
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

Here is the new ewindo log:

ewido anti-spyware - Scan Report



+ Created at: 09:35:33 2006-06-21



+ Scan result:







HKLM\SOFTWARE\Classes\CLSID\{77B2F8DE-CB3F-4b6b-839B-807DD1ADBA1C} -> Adware.SearchMaid : Error during cleaning.





::Report end
Here is the first ewindo log that I tried to post earlier but failed, seems like this forum don't like lines of "——".

e\w\i\d\o\ \a\n\t\i\-\s\p\y\w\a\r\e\ \-\ \S\c\a\n\ \R\e\p\o\r\t\
\
\ \+\ \C\r\e\a\t\e\d\ \a\t\:\ \0\1\:\1\5\:\2\6\ \2\0\0\6\-\0\6\-\2\1\
\
\ \+\ \S\c\a\n\ \r\e\s\u\l\t\:\ \
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\1\0\0\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\1\0\0\\\L\o\c\t\_\4\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\3\2\9\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\3\2\9\\\L\o\c\t\_\0\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\3\2\9\\\L\o\c\t\_\1\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\3\2\9\\\L\o\c\t\_\2\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\3\2\9\\\L\o\c\t\_\3\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\3\2\9\\\S\e\r\v\i\c\e\s\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\U\\\S\-\1\-\5\-\2\1\-\6\0\6\7\4\7\1\4\5\-\5\1\5\9\6\7\8\9\9\-\8\3\9\5\2\2\1\1\5\-\1\0\0\5\\\S\o\f\t\w\a\r\e\\\K\a\z\a\a\\\P\r\o\m\o\t\i\o\n\s\\\C\y\d\o\o\r\\\A\d\w\r\_\3\2\9\\\S\e\r\v\i\c\e\s\\\Q\u\e\u\e\ \-\>\ \A\d\w\a\r\e\.\C\y\d\o\o\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\W\I\N\D\O\W\S\\\i\L\o\o\k\u\p\ \-\>\ \A\d\w\a\r\e\.\e\Z\u\l\a\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\P\e\r\f\e\c\t\N\a\v\ \-\>\ \A\d\w\a\r\e\.\K\e\e\n\V\a\l\u\e\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\C\l\a\s\s\e\s\\\C\L\S\I\D\\\{\7\7\B\2\F\8\D\E\-\C\B\3\F\-\4\b\6\b\-\8\3\9\B\-\8\0\7\D\D\1\A\D\B\A\1\C\}\ \-\>\ \A\d\w\a\r\e\.\S\e\a\r\c\h\M\a\i\d\ \:\ \E\r\r\o\r\ \d\u\r\i\n\g\ \c\l\e\a\n\i\n\g\.\
\
\C\:\\\P\r\o\g\r\a\m\\\w\h\I\n\s\t\a\l\l\ \-\>\ \A\d\w\a\r\e\.\W\e\b\h\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\P\r\o\g\r\a\m\\\w\h\I\n\s\t\a\l\l\\\l\i\c\e\n\s\e\.\t\x\t\ \-\>\ \A\d\w\a\r\e\.\W\e\b\h\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\P\r\o\g\r\a\m\\\w\h\I\n\s\t\a\l\l\\\r\e\a\d\m\e\.\t\x\t\ \-\>\ \A\d\w\a\r\e\.\W\e\b\h\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\P\r\o\g\r\a\m\\\w\h\I\n\s\t\a\l\l\\\w\h\A\g\e\n\t\.\i\n\i\ \-\>\ \A\d\w\a\r\e\.\W\e\b\h\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\W\H\C\C\2\.\e\x\e\/\w\h\A\g\e\n\t\.\e\x\e\ \-\>\ \A\d\w\a\r\e\.\W\e\b\H\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\C\l\a\s\s\e\s\\\W\h\I\e\H\e\l\p\e\r\O\b\j\.\W\h\I\e\H\e\l\p\e\r\O\b\j\ \-\>\ \A\d\w\a\r\e\.\W\e\b\H\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\C\l\a\s\s\e\s\\\W\h\I\e\H\e\l\p\e\r\O\b\j\.\W\h\I\e\H\e\l\p\e\r\O\b\j\.\1\ \-\>\ \A\d\w\a\r\e\.\W\e\b\H\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\C\l\a\s\s\e\s\\\W\h\I\e\H\e\l\p\e\r\O\b\j\.\W\h\I\e\H\e\l\p\e\r\O\b\j\\\C\u\r\V\e\r\ \-\>\ \A\d\w\a\r\e\.\W\e\b\H\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\w\e\b\h\a\n\c\e\r\ \-\>\ \A\d\w\a\r\e\.\W\e\b\H\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\w\e\b\h\a\n\c\e\r\\\C\C\ \-\>\ \A\d\w\a\r\e\.\W\e\b\H\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\w\e\b\h\a\n\c\e\r\\\E\S\O\ \-\>\ \A\d\w\a\r\e\.\W\e\b\H\a\n\c\e\r\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\H\K\L\M\\\S\O\F\T\W\A\R\E\\\C\l\a\s\s\e\s\\\P\R\O\T\O\C\O\L\S\\\N\a\m\e\-\S\p\a\c\e\ \H\a\n\d\l\e\r\\\r\e\s\ \-\>\ \A\d\w\a\r\e\.\W\e\b\S\e\a\r\c\h\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\d\r\s\m\a\r\t\l\o\a\d\4\5\a\.\e\x\e\ \-\>\ \D\o\w\n\l\o\a\d\e\r\.\A\d\l\o\a\d\.\b\o\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\d\r\s\m\a\r\t\l\o\a\d\4\6\a\.\e\x\e\ \-\>\ \D\o\w\n\l\o\a\d\e\r\.\A\d\l\o\a\d\.\b\o\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\d\r\s\m\a\r\t\l\o\a\d\8\4\9\a\.\e\x\e\ \-\>\ \D\o\w\n\l\o\a\d\e\r\.\A\d\l\o\a\d\.\b\o\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\n\e\w\n\a\m\e\2\5\.\e\x\e\ \-\>\ \D\o\w\n\l\o\a\d\e\r\.\V\B\.\a\b\m\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\q\.\e\x\e\ \-\>\ \D\r\o\p\p\e\r\.\D\e\l\f\.\l\j\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\C\:\\\k\e\y\b\o\a\r\d\2\5\.\e\x\e\ \-\>\ \H\i\j\a\c\k\e\r\.\S\t\a\r\t\P\a\g\e\.\a\j\u\ \:\ \C\l\e\a\n\e\d\ \w\i\t\h\ \b\a\c\k\u\p\ \(\q\u\a\r\a\n\t\i\n\e\d\)\.\
\
\:\m\o\z\i\l\l\a\.\1\4\:\C\:\\\D\o\c\u\m\e\n\t\s\ \a\n\d\ \S\e\t\t\i\n\g\s\\\T\h\È\r\Ë\s\e\\\A\p\p\l\i\c\a\t\i\o\n\ \D\a\t\a\\\P\h\o\e\n\i\x\\\P\r\o\f\i\l\e\s\\\d\e\f\a\u\l\t\\\5\3\f\o\4\c\x\o\.\s\l\t\\\c\o\o\k\i\e\s\.\t\x\t\ \-\>\ \T\r\a\c\k\i\n\g\C\o\o\k\i\e\.\A\t\d\m\t\ \:\ \C\l\e\a\n\e\d\.\
\
\:\m\o\z\i\l\l\a\.\2\7\:\C\:\\\D\o\c\u\m\e\n\t\s\ \a\n\d\ \S\e\t\t\i\n\g\s\\\T\h\È\r\Ë\s\e\\\A\p\p\l\i\c\a\t\i\o\n\ \D\a\t\a\\\P\h\o\e\n\i\x\\\P\r\o\f\i\l\e\s\\\d\e\f\a\u\l\t\\\5\3\f\o\4\c\x\o\.\s\l\t\\\c\o\o\k\i\e\s\.\t\x\t\ \-\>\ \T\r\a\c\k\i\n\g\C\o\o\k\i\e\.\D\o\u\b\l\e\c\l\i\c\k\ \:\ \C\l\e\a\n\e\d\.\
\
\:\m\o\z\i\l\l\a\.\2\0\:\C\:\\\D\o\c\u\m\e\n\t\s\ \a\n\d\ \S\e\t\t\i\n\g\s\\\T\h\È\r\Ë\s\e\\\A\p\p\l\i\c\a\t\i\o\n\ \D\a\t\a\\\P\h\o\e\n\i\x\\\P\r\o\f\i\l\e\s\\\d\e\f\a\u\l\t\\\5\3\f\o\4\c\x\o\.\s\l\t\\\c\o\o\k\i\e\s\.\t\x\t\ \-\>\ \T\r\a\c\k\i\n\g\C\o\o\k\i\e\.\H\i\t\s\l\i\n\k\ \:\ \C\l\e\a\n\e\d\.\
\
\:\m\o\z\i\l\l\a\.\2\1\:\C\:\\\D\o\c\u\m\e\n\t\s\ \a\n\d\ \S\e\t\t\i\n\g\s\\\T\h\È\r\Ë\s\e\\\A\p\p\l\i\c\a\t\i\o\n\ \D\a\t\a\\\P\h\o\e\n\i\x\\\P\r\o\f\i\l\e\s\\\d\e\f\a\u\l\t\\\5\3\f\o\4\c\x\o\.\s\l\t\\\c\o\o\k\i\e\s\.\t\x\t\ \-\>\ \T\r\a\c\k\i\n\g\C\o\o\k\i\e\.\H\i\t\s\l\i\n\k\ \:\ \C\l\e\a\n\e\d\.\
\
\:\m\o\z\i\l\l\a\.\2\2\:\C\:\\\D\o\c\u\m\e\n\t\s\ \a\n\d\ \S\e\t\t\i\n\g\s\\\T\h\È\r\Ë\s\e\\\A\p\p\l\i\c\a\t\i\o\n\ \D\a\t\a\\\P\h\o\e\n\i\x\\\P\r\o\f\i\l\e\s\\\d\e\f\a\u\l\t\\\5\3\f\o\4\c\x\o\.\s\l\t\\\c\o\o\k\i\e\s\.\t\x\t\ \-\>\ \T\r\a\c\k\i\n\g\C\o\o\k\i\e\.\H\i\t\s\l\i\n\k\ \:\ \C\l\e\a\n\e\d\.\
\
\:\m\o\z\i\l\l\a\.\2\3\:\C\:\\\D\o\c\u\m\e\n\t\s\ \a\n\d\ \S\e\t\t\i\n\g\s\\\T\h\È\r\Ë\s\e\\\A\p\p\l\i\c\a\t\i\o\n\ \D\a\t\a\\\P\h\o\e\n\i\x\\\P\r\o\f\i\l\e\s\\\d\e\f\a\u\l\t\\\5\3\f\o\4\c\x\o\.\s\l\t\\\c\o\o\k\i\e\s\.\t\x\t\ \-\>\ \T\r\a\c\k\i\n\g\C\o\o\k\i\e\.\H\i\t\s\l\i\n\k\ \:\ \C\l\e\a\n\e\d\.\
\
\:\m\o\z\i\l\l\a\.\3\1\:\C\:\\\D\o\c\u\m\e\n\t\s\ \a\n\d\ \S\e\t\t\i\n\g\s\\\T\h\È\r\Ë\s\e\\\A\p\p\l\i\c\a\t\i\o\n\ \D\a\t\a\\\P\h\o\e\n\i\x\\\P\r\o\f\i\l\e\s\\\d\e\f\a\u\l\t\\\5\3\f\o\4\c\x\o\.\s\l\t\\\c\o\o\k\i\e\s\.\t\x\t\ \-\>\ \T\r\a\c\k\i\n\g\C\o\o\k\i\e\.\M\e\d\i\a\p\l\e\x\ \:\ \C\l\e\a\n\e\d\.\
\
\:\m\o\z\i\l\l\a\.\3\3\:\C\:\\\D\o\c\u\m\e\n\t\s\ \a\n\d\ \S\e\t\t\i\n\g\s\\\T\h\È\r\Ë\s\e\\\A\p\p\l\i\c\a\t\i\o\n\ \D\a\t\a\\\P\h\o\e\n\i\x\\\P\r\o\f\i\l\e\s\\\d\e\f\a\u\l\t\\\5\3\f\o\4\c\x\o\.\s\l\t\\\c\o\o\k\i\e\s\.\t\x\t\ \-\>\ \T\r\a\c\k\i\n\g\C\o\o\k\i\e\.\V\a\l\u\e\a\d\ \:\ \C\l\e\a\n\e\d\.\
\
\
\
\
\
\:\:\R\e\p\o\r\t\ \e\n\d
Only for Windows XP and Windows 2000

Lets try this one.

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________

Please download the trial version of Ewido anti-malware 3.5 from here:
http://www.ewido.net/en/download/
  • Install Ewido anti-malware.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
  • When you run Ewido for the first time, you could get a warning "Database could not be found!". Click Ok.
  • The program will prompt you to update. Click the Ok button.
  • The program will now go to the main screen.
You will need to update Ewido to the latest definition files.
  • On the left-hand side of the main screen click the Update Button.
  • Click on Start.
The update will start and a progress bar will show the updates being installed.
Once finished updating, close Ewido. Don't Run It Yet.

If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates. Make sure to close Ewido before installing the update.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named:
c:\rapport.txt
Ewido is currently 4.0 and those options are not avaliable when installing.
Here is the log from smitfraud.cmd:

SmitFraudFix v2.63

Scan done at 9:10:53,00, 2006-06-22
Run from C:\Documents and Settings\Th‚rŠse\Skrivbord\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\date.ico FOUND !
C:\WINDOWS\system32\network.ico FOUND !
C:\WINDOWS\system32\pharm.ico FOUND !
C:\WINDOWS\system32\spam.ico FOUND !
C:\WINDOWS\system32\spyware.ico FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Th‚rŠse\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\THRSE~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Min aktuella startsida"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{9ae613a2-a13b-4379-8d0e-86a1a78476ec}"="corindon"

[HKEY_CLASSES_ROOT\CLSID\{9ae613a2-a13b-4379-8d0e-86a1a78476ec}\InProcServer32]
@="C:\WINDOWS\system32\rmzdzx.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{9ae613a2-a13b-4379-8d0e-86a1a78476ec}\InProcServer32]
@="C:\WINDOWS\system32\rmzdzx.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
Sorry about the Ewido change.

Running the Clean

Warning: running option #2 on a non infected computer will remove your Desktop background.


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • Click on Scanner
  • Click on Settings
    • Under How to scan all boxes should be checked
    • Under Unwanted Software all boxes should be checked
    • Under What to scan select Scan every file
    • Click on Ok
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put a checkmark in the box next to Create encrypted backup, then choose clean and click Ok.

Once the scan has completed, there will be a button located on the bottom of the screen named Save Report.
  • Click Save Report button
  • Save the report to your Desktop
Close Ewido and Reboot in Normal Mode.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer Yes to the question "Restore Trusted Zone ?" by typing
Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________

Please post:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
"Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok."

There were no such entry

"If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put a checkmark in the box next to Create encrypted backup, then choose clean and click Ok."

It didn't popup a notification. It just listed all the infections in a list with a suggested "fix" next to it. Then afterwards I could choose to "apply all actions" or "save log file". The only file it found was Adware.Searchmaid, wich it failed to quarantine (and delete).

The rapport.txt file:

SmitFraudFix v2.63

Scan done at 1:17:05,56, 2006-06-23
Run from C:\Documents and Settings\Th‚rŠse\Skrivbord\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{9ae613a2-a13b-4379-8d0e-86a1a78476ec}"="corindon"

[HKEY_CLASSES_ROOT\CLSID\{9ae613a2-a13b-4379-8d0e-86a1a78476ec}\InProcServer32]
@="C:\WINDOWS\system32\rmzdzx.dll"

[HKEY_CURRENT_USER\Software\Classes\CLSID\{9ae613a2-a13b-4379-8d0e-86a1a78476ec}\InProcServer32]
@="C:\WINDOWS\system32\rmzdzx.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\rmzdzx.dll -> Missing File


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\date.ico Deleted
C:\WINDOWS\system32\network.ico Deleted
C:\WINDOWS\system32\pharm.ico Deleted
C:\WINDOWS\system32\spam.ico Deleted
C:\WINDOWS\system32\spyware.ico Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
The ewido log:

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 01:39:53 2006-06-23

+ Scan result:



HKLM\SOFTWARE\Classes\CLSID\{77B2F8DE-CB3F-4b6b-839B-807DD1ADBA1C} -> Adware.SearchMaid : Error during cleaning.


::Report end

The Hijack Log:

Logfile of HijackThis v1.99.1
Scan saved at 01:51:04, on 2006-06-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program\AirPlus XtremeG\AirPlusCFG.exe
C:\Program\ALWILS~1\Avast4\ashDisp.exe
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\Program\Alwil Software\Avast4\ashServ.exe
C:\Program\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program\Alwil Software\Avast4\ashMaiSv.exe
C:\Program\Alwil Software\Avast4\ashWebSv.exe
C:\Program\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: (no name) - {6D526BDC-DE1F-F59D-4EB2-A0BFD28985C8} - C:\WINDOWS\system32\xin.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] C:\Program\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program\webHancer\Programs\whsurvey.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Utopia Angel] "F:\Spel\Angel\Angel.exe"
O4 - HKCU\..\Run: [fe481b4.exe] C:\Documents and Settings\Thérèse\Lokala inställningar\Application Data\fe481b4.exe
O4 - HKCU\..\Run: [Rfbsphq] C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BINGOOO - {87F2CA68-5130-49A3-8E5B-73E61F67BB0B} - C:\Program\BINGOOO\BINGOOO.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0990D180-4226-4530-9777-AB82315505B9} (Installer Class) - http://www.foreningssparbanken.se/betala/e…iscomsigned.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149201934968
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {785EA525-5066-495F-ADF6-3B8316515DEF} (Collapse Control) - http://mirror.worldwinner.com/games/v46/co…se/collapse.cab
O20 - AppInit_DLLs: winlogon.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\vzdx16.dll (file missing)
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL




Click "Start"> "Run"> type in Regedit tap Enter Key

Make sure "My Computer" is highlighted

Click "Edit"> "Find"
Type in SearchMaid tap Enter Key.
Right Click on the file if found and select "Delete"

Tap the "F3" Key to find the next entry of the file. Continue using the "F3" Key until it's finished searching.

Close Regedit.


Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Nothing found

Hijacklog after reboot:

Logfile of HijackThis v1.99.1
Scan saved at 02:04:04, on 2006-06-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program\AirPlus XtremeG\AirPlusCFG.exe
C:\Program\ALWILS~1\Avast4\ashDisp.exe
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\Program\Alwil Software\Avast4\ashServ.exe
C:\Program\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program\Alwil Software\Avast4\ashMaiSv.exe
C:\Program\Alwil Software\Avast4\ashWebSv.exe
C:\Program\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
R3 - URLSearchHook: (no name) - {6D526BDC-DE1F-F59D-4EB2-A0BFD28985C8} - C:\WINDOWS\system32\xin.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] C:\Program\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program\webHancer\Programs\whsurvey.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Utopia Angel] "F:\Spel\Angel\Angel.exe"
O4 - HKCU\..\Run: [fe481b4.exe] C:\Documents and Settings\Thérèse\Lokala inställningar\Application Data\fe481b4.exe
O4 - HKCU\..\Run: [Rfbsphq] C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BINGOOO - {87F2CA68-5130-49A3-8E5B-73E61F67BB0B} - C:\Program\BINGOOO\BINGOOO.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0990D180-4226-4530-9777-AB82315505B9} (Installer Class) - http://www.foreningssparbanken.se/betala/e…iscomsigned.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149201934968
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {785EA525-5066-495F-ADF6-3B8316515DEF} (Collapse Control) - http://mirror.worldwinner.com/games/v46/co…se/collapse.cab
O20 - AppInit_DLLs: winlogon.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\vzdx16.dll (file missing)
O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)

R3 - URLSearchHook: (no name) - {6D526BDC-DE1F-F59D-4EB2-A0BFD28985C8} - C:\WINDOWS\system32\xin.dll (file missing)

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O4 - HKCU\..\Run: [fe481b4.exe] C:\Documents and Settings\Thérèse\Lokala inställningar\Application Data\fe481b4.exe

O4 - HKCU\..\Run: [Rfbsphq] C:\Program\COMMON~1\RACLE~1\ERINIT~1.EXE

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -

O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123

O20 - AppInit_DLLs: winlogon.dll

O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\vzdx16.dll (file missing)

O20 - Winlogon Notify: winopn32 - winopn32.dll (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"




Delete these Files if listed:
C:\Documents and Settings\Thérèse\Lokala inställningar\Application Data\fe481b4.exe
C:\WINDOWS\system32\vzdx16.dll
C:\WINDOWS\system32\winlogon.dll <== don't try to delete winlogon.exe !!!!


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Well, I got internet access, but Ive had that since you fixed it with WinsockxpFix.exe.

Since the main issue was that I cant reinstall Windows XP, I guess I have to try that to explain how my system behaves. Otherwise it feels normal.

I got an error message when I tried to do the fix in HiJack:

An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: winlogon.dll)
Error #5 - Invalid procedure call or argument

Please email me at [removed], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.2180
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.

Here is the new HiJack log:
Logfile of HijackThis v1.99.1
Scan saved at 02:32:16, on 2006-06-23
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program\AirPlus XtremeG\AirPlusCFG.exe
C:\Program\ALWILS~1\Avast4\ashDisp.exe
C:\Program\Alwil Software\Avast4\aswUpdSv.exe
C:\Program\Alwil Software\Avast4\ashServ.exe
C:\Program\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program\Alwil Software\Avast4\ashMaiSv.exe
C:\Program\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] C:\Program\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [avast!] C:\Program\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program\webHancer\Programs\whsurvey.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Utopia Angel] "F:\Spel\Angel\Angel.exe"
O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BINGOOO - {87F2CA68-5130-49A3-8E5B-73E61F67BB0B} - C:\Program\BINGOOO\BINGOOO.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\Program\Agnitum\OUTPOS~1.0\trash.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0990D180-4226-4530-9777-AB82315505B9} (Installer Class) - http://www.foreningssparbanken.se/betala/e…iscomsigned.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1149201934968
O16 - DPF: {785EA525-5066-495F-ADF6-3B8316515DEF} (Collapse Control) - http://mirror.worldwinner.com/games/v46/co…se/collapse.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program\Delade filer\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program\iPod\bin\iPodService.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program\Network Monitor\netmon.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI