This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I had to uninstalled my AV(symantec corprate 10.1) and now I can get it reinstalled. Please help!!!!



Logfile of HijackThis v1.99.1
Scan saved at 9:09:21 AM, on 4/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Chat\Chat.EXE
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {b8e2ced3-3af2-4748-b42d-e3ba9c42446e} - C:\WINDOWS\system32\kbd863.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - Startup: Chat.lnk = vbapps\Chat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647240770
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647233560
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\Software\..\Telephony: DomainName = brownhelicopter.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O20 - Winlogon Notify: kbd863 - C:\WINDOWS\SYSTEM32\kbd863.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Commander Service - Seagull Scientific, Inc - C:\Program Files\Seagull\BarTender\7.75\CmdrSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Danny Haggard :D

Welcome back, it looks like you are getting yourself infected as fast as we clean you up <_<


We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.



You have this installed already, just set it up this way

Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop. It's very important that I see the report so make sure you follow the instructions and save the log.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

O2 - BHO: (no name) - {b8e2ced3-3af2-4748-b42d-e3ba9c42446e} - C:\WINDOWS\system32\kbd863.dll

O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe

If you or an administrator set this then leave it otherwise fix it
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O20 - Winlogon Notify: kbd863 - C:\WINDOWS\SYSTEM32\kbd863.dll




Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5
Still in safemode, delete these files.

C:\WINDOWS\system32\kbd863.dll
C:\WINDOWS\system32\lsasss.exe



Reboot and run this system cleaner.


If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner



Its important that I see the AVG log as it will show me what and was not removed along with an extensive report that may lead to other infections, so make sure you have it set to Delete or Quarantine what it finds and to save the Log file . Post a new HJT log also please.
Ok I did the scans and ccCleaner.

I could not find either of the 2 dll's

I can no longer go to any web site. I can get to the internal network and I can ping web sites. I just get the standard page not found when I try to browse.


Here are the logs.

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 16:20 4/17/2007

+ Scan result:



C:\QooBox\Quarantine7-04-10\Program Files\Web Buying\v1.6.8\webbuying.exe.vir -> Adware.Agent : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp124.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp3.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp43.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp460.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp53F.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp543.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp546.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp6F0.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp752.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp7C.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp80.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmpDE.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmpEC6.tmp.exe -> Adware.Virtumonde : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp129.tmp.exe -> Downloader.Agent.bjk : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmpC5.tmp.exe -> Downloader.Agent.bjk : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmpE1.tmp.exe -> Downloader.Agent.bjk : No action taken.
C:\WINDOWS\system32\kbd863.dll -> Downloader.ConHook : No action taken.
C:\hijackthis\backups\backup-20070411-101716-727.dll -> Downloader.ConHook : No action taken.
C:\hijackthis\backups\backup-20070411-104424-819.dll -> Downloader.ConHook : No action taken.
C:\hijackthis\backups\backup-20070412-081118-775.dll -> Downloader.ConHook : No action taken.
C:\hijackthis\backups\backup-20070412-150459-336.dll -> Downloader.ConHook : No action taken.
C:\hijackthis\backups\backup-20070417-080059-784.dll -> Downloader.ConHook : No action taken.
C:\hijackthis\backups\backup-20070417-142857-981.dll -> Downloader.ConHook : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\ICD5.tmp\UDC6_0001_D21M0303NetInstaller.exe -> Downloader.Small : No action taken.
C:\WINDOWS\Downloaded Program Files\UDC6_0001_D21M0303NetInstaller.exe -> Downloader.Small : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\ICD7.tmp\UDC6_0001_D19M1908NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : No action taken.
C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\ICD6.tmp\UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\QooBox\Quarantine7-04-16\WINDOWS\system32\vexga4me1.exe.vir -> Proxy.Xorpix.ar : No action taken.
C:\Documents and Settings\danny\Cookies\danny@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\danny\Cookies\danny@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\danny\Cookies\danny@oyaka.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\danny\Cookies\danny@aavalue[1].txt -> TrackingCookie.Aavalue : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : No action taken.
C:\Documents and Settings\danny\Cookies\danny@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\danny\Cookies\danny@adrevolver[3].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\danny\Cookies\danny@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\danny\Cookies\danny@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\danny\Cookies\danny@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\danny\Cookies\danny@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\danny\Cookies\danny@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\danny\Cookies\danny@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\danny\Cookies\danny@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\danny\Cookies\danny@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\danny\Cookies\danny@fortunecity[1].txt -> TrackingCookie.Fortunecity : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\danny\Cookies\danny@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\danny\Cookies\danny@linksynergy[2].txt -> TrackingCookie.Linksynergy : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\danny\Cookies\danny@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\danny\Cookies\danny@overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\danny\Cookies\danny@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\danny\Cookies\danny@realmedia[2].txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\danny\Cookies\[removed]-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\danny\Cookies\danny@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\danny\Cookies\danny@specificclick[2].txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\danny\Cookies\danny@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\danny\Cookies\danny@targetnet[1].txt -> TrackingCookie.Targetnet : No action taken.
C:\Documents and Settings\danny\Cookies\danny@trafficmp[1].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\danny\Cookies\danny@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][1].txt -> TrackingCookie.Valuead : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\danny\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\danny\Cookies\danny@zedo[1].txt -> TrackingCookie.Zedo : No action taken.
C:\WINDOWS\awuurp.dll -> Trojan.Agent.agv : No action taken.
C:\WINDOWS\fcyvvw.dll -> Trojan.Agent.agv : No action taken.
C:\WINDOWS\pmnllm.dll -> Trojan.Agent.agv : No action taken.
C:\WINDOWS\ssrpmn.dll -> Trojan.Agent.agv : No action taken.
C:\WINDOWS\sstutu.dll -> Trojan.Agent.agv : No action taken.
C:\WINDOWS\tuttut.dll -> Trojan.Agent.agv : No action taken.
C:\WINDOWS\wvtqrq.dll -> Trojan.Agent.agv : No action taken.
C:\WINDOWS\yaxxya.dll -> Trojan.Agent.agv : No action taken.
C:\WINDOWS\system32\micro1\b9.exe -> Trojan.Bantool : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp125.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp1F0.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp45.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp461.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp5.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp540.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp544.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp547.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp6F1.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp753.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmp82.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmpE0.tmp.exe -> Trojan.BHO.o : No action taken.
C:\Documents and Settings\danny\Local Settings\Temp\tmpF4D.tmp.exe -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-10\WINDOWS\system32\tmp4B1.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-10\WINDOWS\system32\tmpA2.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-12\WINDOWS\system32\tmp461.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-12\WINDOWS\system32\tmp5.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-16\WINDOWS\system32\tmp1F0.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-16\WINDOWS\system32\tmp6F1.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-16\WINDOWS\system32\tmp753.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-16\WINDOWS\system32\tmpF4D.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-17\WINDOWS\system32\tmpE0.tmp.dll.vir -> Trojan.BHO.o : No action taken.
C:\hijackthis\backups\backup-20070417-080059-835.dll -> Trojan.BHO.o : No action taken.
C:\QooBox\Quarantine7-04-10\WINDOWS\system32\kernels32.exe.vir -> Trojan.Tibs.p : No action taken.


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 4:37:46 PM, on 4/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Chat\Chat.EXE
C:\hijackthis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {b8e2ced3-3af2-4748-b42d-e3ba9c42446e} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - Startup: Chat.lnk = vbapps\Chat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647240770
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647233560
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\Software\..\Telephony: DomainName = brownhelicopter.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O20 - Winlogon Notify: kbd863 - kbd863.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Commander Service - Seagull Scientific, Inc - C:\Program Files\Seagull\BarTender\7.75\CmdrSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
I just noticed that the AGV log says "no action taken" I saved the log before I "applied all actions" It deleted all of the items and seemed not to have a problem. Thanks for the support Danny
Hi Danny,

Go ahead and run this program for Vundo


Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

If there is a file VundoFix doesn't find we need it submitted. Please submit
the files to upload malware http://www.uploadmalware.com




1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to Delete:
C:\WINDOWS\system32\kbd863.dll
C:\WINDOWS\system32\lsasss.exe

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply


Post the Avenger, Vundofix and a New HJt log please
Danny,

There is nothing that we have done to not load web pages. Keep in mind that I am looking at some serious infections on your system, Vundo, possible Smitfraud and maybe another one.


Close any instance of Internet Explorer and Windows Explorer.
  • Go to Start> Control Panel> Internet Options . You shoud be on the General Tab
  • Delete Cookies
  • Delete Files > and offline content as well
  • Then go to the Programs Tab and Reset Web Settings

Brownhelicopter <– Is this something you use??
I have friends fly out of Tamiami in Miami.
Vondo Not found.



Logfile of HijackThis v1.99.1
Scan saved at 5:29:57 PM, on 4/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Chat\Chat.EXE
C:\hijackthis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {b8e2ced3-3af2-4748-b42d-e3ba9c42446e} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - Startup: Chat.lnk = vbapps\Chat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647240770
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647233560
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\Software\..\Telephony: DomainName = brownhelicopter.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O20 - Winlogon Notify: kbd863 - kbd863.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Commander Service - Seagull Scientific, Inc - C:\Program Files\Seagull\BarTender\7.75\CmdrSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\lkuxjioc

*******************

Script file located at: \??\C:\Program Files\vrshqwps.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\kbd863.dll not found!
Deletion of file C:\WINDOWS\system32\kbd863.dll failed!

Could not process line:
C:\WINDOWS\system32\kbd863.dll
Status: 0xc0000034



File C:\WINDOWS\system32\lsasss.exe not found!
Deletion of file C:\WINDOWS\system32\lsasss.exe failed!

Could not process line:
C:\WINDOWS\system32\lsasss.exe
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.



Going to the gym pick this up first thing in the am

thanks again

Danny
Hello Danny,

Your AVG log has Vundo and Smitfraud written all over it. Lets do a few things.

Please start by downloading VirtumondoBegone to your desktop.
  • Reboot your computer into Safemode
  • Go to START/ SHUT OF YOUR COMPUTER/ RESTART
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
  • Then press the ENTER KEY ON YOUR KEYBOARD
  • Doubleclick on VirtumundoBeGone.exe and follow the instructions.
  • Do not worry if you see a BLUE SCREEN "Fatal Error" Message, it is normal and expected.
  • When it has finished, reboot and post the log that is created on your desktop called VBG.TXT in your next reply.

Before you reboot, fix these entries with HJT.



O2 - BHO: (no name) - {b8e2ced3-3af2-4748-b42d-e3ba9c42446e} - (no file)

O4 - Startup: Chat.lnk = vbapps\Chat.exe

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab

O20 - Winlogon Notify: kbd863 - kbd863.dll (file missing)




Still in Safemode, delete this folder.

C:\Program Files\Chat



Reboot normally



Please download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.



I need you to rename HJT, just go to the folder that HJT resides in, right click on the HJT icon ( looks like a stick of dynamite with a plunger ) and click on Rename and rename it to Scanner.exe




Let me see the Vundobegone log, the Smitfraud log and a New HJT log with it renamed to Scanner.exe
Ken

Here are the logs

Chat.exe is a in house program that I wrote in VB6. I went ahead and deleted it but the network reinstalls it on login.

This did make me think about something, when I loging in normaly I use user Danny on the domain. When I login in safe mode I can only login as administrator, of the local computer. This may not make a diffrence but I thought you should know.

also the link to smitfraud was bad but I had a copy from last month that I used.


[04/18/2007, 8:07:51] - VirtumundoBeGone v1.5 ( "C:\hijackthis\VirtumundoBeGone.exe" )
[04/18/2007, 8:07:57] - Detected System Information:
[04/18/2007, 8:07:57] - Windows Version: 5.1.2600, Service Pack 2
[04/18/2007, 8:07:57] - Current Username: Administrator (Admin)
[04/18/2007, 8:07:57] - Windows is in SAFE mode with Networking.
[04/18/2007, 8:07:57] - Searching for Browser Helper Objects:
[04/18/2007, 8:07:57] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (&Yahoo! Toolbar Helper)
[04/18/2007, 8:07:57] - BHO 2: {b8e2ced3-3af2-4748-b42d-e3ba9c42446e} ()
[04/18/2007, 8:07:57] - WARNING: BHO has no default name. Checking for Winlogon reference.
[04/18/2007, 8:07:57] - No filename found. Continuing.
[04/18/2007, 8:07:57] - Finished Searching Browser Helper Objects
[04/18/2007, 8:07:57] - Finishing up…
[04/18/2007, 8:07:58] - Nothing found! Exiting…


SmitFraudFix v2.148

Scan done at 8:28:03.32, Wed 04/18/2007
Run from C:\hijackthis\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\danny


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\danny\Application Data

C:\Documents and Settings\danny\Application Data\Install.dat FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\danny\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


Logfile of HijackThis v1.99.1
Scan saved at 8:30:19 AM, on 4/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Chat\Chat.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\notepad.exe
C:\hijackthis\scanner.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - Startup: Chat.lnk = vbapps\Chat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647240770
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647233560
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\Software\..\Telephony: DomainName = brownhelicopter.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Commander Service - Seagull Scientific, Inc - C:\Program Files\Seagull\BarTender\7.75\CmdrSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Ken I am still having the IE6 problem, what is strange is that I can go to web sites if I use the "Webbrowser Control" in vb6. Is it ok if I reinstall XP sp2 so that it can repair IE6? Thanks Danny
Danny,

Chat.exe was flagged as a virus but if its something you wrote or use than leave it be.

It looks like you have all or parts of Smitfraud. Lets continue with the fix using Option #2.


Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode

  • Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
  • Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
  • You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
  • The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart into normal Windows.
  • A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt





Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start> Control Panel and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete Offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button.
  • Click Apply then OK.


Reboot normally.

  • Open the SmitfraudFix folder and double-click smitfraudfix.cmd
  • Select option #3 - Delete Trusted zone by typing 3 and press Enter
  • Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.
Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.



After you run the fix for Smitfraud, try doing this.

Depending on how your manufacturer set up your system you may or may not need your Windows XP CD.
  • Click Start>Run
  • Type in sfc /scannow, hit Enter.
  • Note: there is a space between sfc and /scannow
  • This should replace any corrupted/missing system files and will hopefully fix things.
    You may need your XP disc in your CD drive for this.


Close any instance of Internet Explorer and Windows Explorer.
  • Go to Start> Control Panel> Internet Options . You shoud be on the General Tab
  • Delete Cookies
  • Delete Files > and offline content as well
  • Then go to the Programs Tab and Reset Web Settings


  • Go to My Computer/ C: Drive/ Documents and Settings/ Every User on this Computer /Local Settings and delete all the contents of the Temp Folder and the Temporary Internet Files Folder <–Just the contents, not the folder itself.
  • Go to My Computer/ C:/ Windows/ Temp and delete all the contents of the Temp Folder <– But not the temp folder itself.
  • Go to My Computer/ C:/ Windows/ Prefetch and remove all the contents of the Prefetch Folder. <–But not the Prefetch folder itself.

You can try installing the Firefox Browser and see if you still have problems access websites. I have been using this one for years and only use IE when I absolutely have to. It won't interfere with IE in anyway, you can use them both and its your call if you want to make it your default browser.
http://www.mozilla.com/en-US/firefox/


Let me see the Smitfraud log and a New HJT log please and let me know if the above fix for IE has helped.
Nope that didn't fix the IE problem. The problem I have with moving over to FF is that I control IE thru VB6. I don't know if this would be posible with FF at the least it would take a lot of rewriting of code.



SmitFraudFix v2.148

Scan done at 11:53:43.37, Wed 04/18/2007
Run from C:\hijackthis\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End



Logfile of HijackThis v1.99.1
Scan saved at 12:22:07 PM, on 4/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - Startup: Chat.lnk = vbapps\Chat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647240770
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157647233560
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\Software\..\Telephony: DomainName = brownhelicopter.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = brownhelicopter.local
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Commander Service - Seagull Scientific, Inc - C:\Program Files\Seagull\BarTender\7.75\CmdrSrv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Danny,

You have a clean log now, it looks like its free of malware. Any problems your having not accessing certain websites does not appear to be malware related. If you want to write scripts to do all this for you then I don't know what to tell you as I am not a programmer. The only thing I can suggest is to post in a windows support forum for help, be sure to tell them you posted here and we cleaned you up.


Windows Tech Support Forums


It's Not Always MalwareSpeedup Windows Windows Tips

How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.

Danny, this forum is for the removal of malware and viruses only and since you look clean, this is where I leave you.

Thanks for using Tom Coyote
I got IE fixed had to regsvr32 urlmon.dll BTW Thank You Thank You Thank You Thank You Thank You Thank You Thank You Thank You Thank You Thank You Thank You Thank You Danny

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI