Spyware / Malware / Virus Removal
Popups
12 min read
LDTate
Did you get any errors from Killbox?
Run combofix again please.
jennyg
no i didnt get any errors
"chad1" - 07-04-25 20:35:27 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\chad1\Desktop\"
((((((((((((((((((((((((((((((( Files Created from 2007-03-25 to 2007-04-25 ))))))))))))))))))))))))))))))))))
2007-04-25 14:06 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-04-25 08:31 119,808 –a—— C:\WINDOWS\system32\__c00F049E.dat
2007-04-24 21:32 1,220 –a—— C:\WINDOWS\system32\tmp.reg
2007-04-24 21:27 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-24 03:04 1,390,605 —hs—- C:\WINDOWS\system32\qttss.bak2
2007-04-24 00:31 d——– C:\Program Files\Jackpot Matchup
2007-04-23 23:55 119,808 –a—— C:\WINDOWS\system32\__c003BE4E.dat
2007-04-23 23:54 36,352 –a—— C:\WINDOWS\system32\__c0030A4A.dat
2007-04-22 19:09 1,372,070 —hs—- C:\WINDOWS\system32\qttss.bak1
2007-04-22 19:08 281,172 –ahs—- C:\WINDOWS\system32\ssttq.dll.vir
2007-04-19 19:54 d–hs—- C:\WINDOWS\ftpcache
2007-04-19 19:53 d——– C:\Program Files\A Pirates Legend
2007-04-19 08:16 d——– C:\Program Files\Rack Em Up Roadtrip
2007-04-16 22:55 d——– C:\Program Files\Mad Magic
2007-04-16 18:20 d——– C:\Program Files\Sony Setup
2007-04-16 18:04 d——– C:\Program Files\Red Kawa
2007-04-12 21:31 d——– C:\Program Files\Little Shop Of Treasures
2007-04-11 20:38 d——– C:\Program Files\Candy Can
2007-04-09 13:10 d——– C:\DOCUME~1\chad1\APPLIC~1\MysteryStudio
2007-04-08 16:22 d——– C:\Program Files\SNES
2007-04-06 17:41 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-04-05 19:55 d——– C:\Program Files\Burger Rush
2007-04-05 18:33 94,552 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-04-05 18:33 90,112 –a—— C:\WINDOWS\system32\AVASTSS.scr
2007-04-05 18:33 85,952 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-04-05 18:33 733,824 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-04-05 18:33 499,712 –a—— C:\WINDOWS\system32\MSVCP71.dll
2007-04-05 18:33 43,176 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-04-05 18:33 348,160 –a—— C:\WINDOWS\system32\MSVCR71.dll
2007-04-05 18:33 26,888 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-05 18:33 23,416 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-04-05 18:33 1,060,864 –a—— C:\WINDOWS\system32\MFC71.dll
2007-04-05 18:33 d——– C:\Program Files\Alwil Software
2007-04-04 12:54 d——– C:\Program Files\Magic Academy
2007-04-04 12:54 d——– C:\DOCUME~1\chad1\APPLIC~1\Magic Academy
2007-04-03 22:45 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-04-03 22:45 8,234 –a—— C:\clean.bat
2007-04-03 22:45 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-04-03 17:52 d——– C:\DOCUME~1\chad1\APPLIC~1\Lavasoft
2007-04-03 17:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-04-02 18:01 d——– C:\DOCUME~1\chad1\APPLIC~1\Alawar
2007-04-02 17:59 d——– C:\Program Files\Roboball
2007-04-01 11:52 d——– C:\Program Files\Super Collapse Puzzle Gallery
2007-04-01 11:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InterAction studios
2007-03-31 18:46 4 –a—— C:\WINDOWS\system32\pepwqdir.dll
2007-03-31 18:41 4 –a—— C:\WINDOWS\system32\servifg3.dll
2007-03-31 18:41 2,483 –a—— C:\WINDOWS\system32\comcxi7.dll
2007-03-31 18:36 6 –a—— C:\WINDOWS\system32\fidhidus.dll
2007-03-31 18:34 36 –a—— C:\WINDOWS\system32\ligfinaw.dll
2007-03-31 18:34 286 –a—— C:\WINDOWS\system32\comcsi7.dll
2007-03-27 23:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-03-26 20:55 dr-h—– C:\DOCUME~1\chad1\APPLIC~1\yahoo!
2007-03-26 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-03-26 20:53 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\yahoo!
2007-03-26 20:50 d——– C:\Program Files\Yahoo!
2007-03-25 21:49 d——– C:\WINDOWS\Downloaded Installations
2007-03-25 18:26 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-25 08:31 119808 –a—— C:\WINDOWS\system32\__c00f049e.dat
2007-04-25 00:17 36352 –a—— C:\WINDOWS\system32\__c0030a4a.dat
2007-04-24 20:44 ——– d——– C:\Program Files\mirc
2007-04-24 08:14 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\dvdcss
2007-04-23 23:55 119808 –a—— C:\WINDOWS\system32\__c003be4e.dat
2007-04-23 15:57 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\azureus
2007-04-06 20:06 ——– d——– C:\Program Files\messenger
2007-03-23 20:12 ——– d——– C:\Program Files\azureus
2007-03-22 23:24 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\google
2007-03-22 15:50 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\vlc
2007-03-22 15:48 ——– d——– C:\Program Files\videolan
2007-03-22 15:48 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\help
2007-03-21 20:31 ——– d——– C:\Program Files\reflexivearcade
2007-03-21 20:31 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\playfirst
2007-03-21 20:15 ——– d——– C:\Program Files\belkin
2007-03-21 20:06 ——– d——– C:\Program Files\online services
2007-03-21 20:06 ——– d——– C:\Program Files\netropa
2007-03-21 19:52 ——– d——– C:\Program Files\via technologies, inc
2007-03-21 19:51 ——– d——– C:\Program Files\gigabyte
2007-03-21 19:40 0 -rahs—- C:\MSDOS.SYS
2007-03-21 19:40 0 -rahs—- C:\IO.SYS
2007-03-21 19:40 0 –a—— C:\CONFIG.SYS
2007-03-21 19:40 0 –a—— C:\AUTOEXEC.BAT
2007-03-21 19:40 ——– d——– C:\Program Files\microsoft frontpage
2007-03-21 19:38 ——– d–h—– C:\Program Files\windowsupdate
2007-03-21 19:38 ——– d——– C:\Program Files\movie maker
2007-03-21 19:38 ——– d——– C:\Program Files\Common Files\mssoap
2007-03-21 19:37 21640 –a—— C:\WINDOWS\system32\emptyregdb.dat
2007-03-21 19:36 ——– d——– C:\Program Files\windows nt
2007-03-21 19:36 ——– d——– C:\Program Files\msn gaming zone
2007-03-21 19:29 ——– d——– C:\Program Files\nero
2007-03-21 19:28 4212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-03-21 19:25 ——– d——– C:\Program Files\alcohol soft
2007-03-21 19:24 ——– d——– C:\Program Files\xvid
2007-03-21 19:23 ——– d–h—– C:\Program Files\installshield installation information
2007-03-21 19:23 ——– d——– C:\Program Files\lead technologies, inc
2007-03-21 14:30 62 –ahs—- C:\DOCUME~1\chad1\APPLIC~1\desktop.ini
2007-03-21 14:30 ——– d——– C:\Program Files\Common Files\speechengines
2007-03-21 14:30 ——– d——– C:\Program Files\Common Files\odbc
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} C:\Program Files\Yahoo!\Common\yiesrvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"MULTIMEDIA KEYBOARD"="C:\\Program Files\\Netropa\\Multimedia Keyboard\\MMKeybd.exe"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0030A4A
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-04-25 20:37:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-25 20:37:04
C:\ComboFix-quarantined-files.txt … 07-04-25 20:37
C:\ComboFix2.txt … 07-04-25 14:06
"chad1" - 07-04-25 20:35:27 Service Pack 2
ComboFix 07-04-25.4V - Running from: "C:\Documents and Settings\chad1\Desktop\"
((((((((((((((((((((((((((((((( Files Created from 2007-03-25 to 2007-04-25 ))))))))))))))))))))))))))))))))))
2007-04-25 14:06 49,152 –a—— C:\WINDOWS\nircmd.exe
2007-04-25 08:31 119,808 –a—— C:\WINDOWS\system32\__c00F049E.dat
2007-04-24 21:32 1,220 –a—— C:\WINDOWS\system32\tmp.reg
2007-04-24 21:27 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-04-24 03:04 1,390,605 —hs—- C:\WINDOWS\system32\qttss.bak2
2007-04-24 00:31 d——– C:\Program Files\Jackpot Matchup
2007-04-23 23:55 119,808 –a—— C:\WINDOWS\system32\__c003BE4E.dat
2007-04-23 23:54 36,352 –a—— C:\WINDOWS\system32\__c0030A4A.dat
2007-04-22 19:09 1,372,070 —hs—- C:\WINDOWS\system32\qttss.bak1
2007-04-22 19:08 281,172 –ahs—- C:\WINDOWS\system32\ssttq.dll.vir
2007-04-19 19:54 d–hs—- C:\WINDOWS\ftpcache
2007-04-19 19:53 d——– C:\Program Files\A Pirates Legend
2007-04-19 08:16 d——– C:\Program Files\Rack Em Up Roadtrip
2007-04-16 22:55 d——– C:\Program Files\Mad Magic
2007-04-16 18:20 d——– C:\Program Files\Sony Setup
2007-04-16 18:04 d——– C:\Program Files\Red Kawa
2007-04-12 21:31 d——– C:\Program Files\Little Shop Of Treasures
2007-04-11 20:38 d——– C:\Program Files\Candy Can
2007-04-09 13:10 d——– C:\DOCUME~1\chad1\APPLIC~1\MysteryStudio
2007-04-08 16:22 d——– C:\Program Files\SNES
2007-04-06 17:41 155,648 –a—— C:\WINDOWS\system32\NeroCheck.exe
2007-04-05 19:55 d——– C:\Program Files\Burger Rush
2007-04-05 18:33 94,552 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2007-04-05 18:33 90,112 –a—— C:\WINDOWS\system32\AVASTSS.scr
2007-04-05 18:33 85,952 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2007-04-05 18:33 733,824 –a—— C:\WINDOWS\system32\aswBoot.exe
2007-04-05 18:33 499,712 –a—— C:\WINDOWS\system32\MSVCP71.dll
2007-04-05 18:33 43,176 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2007-04-05 18:33 348,160 –a—— C:\WINDOWS\system32\MSVCR71.dll
2007-04-05 18:33 26,888 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-05 18:33 23,416 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2007-04-05 18:33 1,060,864 –a—— C:\WINDOWS\system32\MFC71.dll
2007-04-05 18:33 d——– C:\Program Files\Alwil Software
2007-04-04 12:54 d——– C:\Program Files\Magic Academy
2007-04-04 12:54 d——– C:\DOCUME~1\chad1\APPLIC~1\Magic Academy
2007-04-03 22:45 90,112 –a—— C:\WINDOWS\system32\RegDACL.exe
2007-04-03 22:45 8,234 –a—— C:\clean.bat
2007-04-03 22:45 4,096 –a—— C:\WINDOWS\system32\reboot.exe
2007-04-03 17:52 d——– C:\DOCUME~1\chad1\APPLIC~1\Lavasoft
2007-04-03 17:31 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-04-02 18:01 d——– C:\DOCUME~1\chad1\APPLIC~1\Alawar
2007-04-02 17:59 d——– C:\Program Files\Roboball
2007-04-01 11:52 d——– C:\Program Files\Super Collapse Puzzle Gallery
2007-04-01 11:52 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InterAction studios
2007-03-31 18:46 4 –a—— C:\WINDOWS\system32\pepwqdir.dll
2007-03-31 18:41 4 –a—— C:\WINDOWS\system32\servifg3.dll
2007-03-31 18:41 2,483 –a—— C:\WINDOWS\system32\comcxi7.dll
2007-03-31 18:36 6 –a—— C:\WINDOWS\system32\fidhidus.dll
2007-03-31 18:34 36 –a—— C:\WINDOWS\system32\ligfinaw.dll
2007-03-31 18:34 286 –a—— C:\WINDOWS\system32\comcsi7.dll
2007-03-27 23:07 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-03-26 20:55 dr-h—– C:\DOCUME~1\chad1\APPLIC~1\yahoo!
2007-03-26 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion
2007-03-26 20:53 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\yahoo!
2007-03-26 20:50 d——– C:\Program Files\Yahoo!
2007-03-25 21:49 d——– C:\WINDOWS\Downloaded Installations
2007-03-25 18:26 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-25 08:31 119808 –a—— C:\WINDOWS\system32\__c00f049e.dat
2007-04-25 00:17 36352 –a—— C:\WINDOWS\system32\__c0030a4a.dat
2007-04-24 20:44 ——– d——– C:\Program Files\mirc
2007-04-24 08:14 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\dvdcss
2007-04-23 23:55 119808 –a—— C:\WINDOWS\system32\__c003be4e.dat
2007-04-23 15:57 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\azureus
2007-04-06 20:06 ——– d——– C:\Program Files\messenger
2007-03-23 20:12 ——– d——– C:\Program Files\azureus
2007-03-22 23:24 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\google
2007-03-22 15:50 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\vlc
2007-03-22 15:48 ——– d——– C:\Program Files\videolan
2007-03-22 15:48 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\help
2007-03-21 20:31 ——– d——– C:\Program Files\reflexivearcade
2007-03-21 20:31 ——– d——– C:\DOCUME~1\chad1\APPLIC~1\playfirst
2007-03-21 20:15 ——– d——– C:\Program Files\belkin
2007-03-21 20:06 ——– d——– C:\Program Files\online services
2007-03-21 20:06 ——– d——– C:\Program Files\netropa
2007-03-21 19:52 ——– d——– C:\Program Files\via technologies, inc
2007-03-21 19:51 ——– d——– C:\Program Files\gigabyte
2007-03-21 19:40 0 -rahs—- C:\MSDOS.SYS
2007-03-21 19:40 0 -rahs—- C:\IO.SYS
2007-03-21 19:40 0 –a—— C:\CONFIG.SYS
2007-03-21 19:40 0 –a—— C:\AUTOEXEC.BAT
2007-03-21 19:40 ——– d——– C:\Program Files\microsoft frontpage
2007-03-21 19:38 ——– d–h—– C:\Program Files\windowsupdate
2007-03-21 19:38 ——– d——– C:\Program Files\movie maker
2007-03-21 19:38 ——– d——– C:\Program Files\Common Files\mssoap
2007-03-21 19:37 21640 –a—— C:\WINDOWS\system32\emptyregdb.dat
2007-03-21 19:36 ——– d——– C:\Program Files\windows nt
2007-03-21 19:36 ——– d——– C:\Program Files\msn gaming zone
2007-03-21 19:29 ——– d——– C:\Program Files\nero
2007-03-21 19:28 4212 —h—– C:\WINDOWS\system32\zllictbl.dat
2007-03-21 19:25 ——– d——– C:\Program Files\alcohol soft
2007-03-21 19:24 ——– d——– C:\Program Files\xvid
2007-03-21 19:23 ——– d–h—– C:\Program Files\installshield installation information
2007-03-21 19:23 ——– d——– C:\Program Files\lead technologies, inc
2007-03-21 14:30 62 –ahs—- C:\DOCUME~1\chad1\APPLIC~1\desktop.ini
2007-03-21 14:30 ——– d——– C:\Program Files\Common Files\speechengines
2007-03-21 14:30 ——– d——– C:\Program Files\Common Files\odbc
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670} C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
{53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} C:\Program Files\Yahoo!\Common\yiesrvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"MULTIMEDIA KEYBOARD"="C:\\Program Files\\Netropa\\Multimedia Keyboard\\MMKeybd.exe"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0030A4A
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\
Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\
Notification Packages REG_MULTI_SZ scecli\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\
LocalService REG_MULTI_SZ AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService REG_MULTI_SZ DnsCache\
DcomLaunch REG_MULTI_SZ DcomLaunchTermService\
rpcss REG_MULTI_SZ RpcSs\
imgsvc REG_MULTI_SZ StiSvc\
termsvcs REG_MULTI_SZ TermService\
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-04-25 20:37:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden services …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-04-25 20:37:04
C:\ComboFix-quarantined-files.txt … 07-04-25 20:37
C:\ComboFix2.txt … 07-04-25 14:06
LDTate
Download Avenger by Swandog, and unzip it to your desktop or somewhere you can find it. (Do not run it yet).
http://swandog46.geekstogo.com/avenger.zip
Note: The Avenger must be run from a user account with administrator privileges,
and ONLY works on Windows 2000 and XP,.
Open a Notepad file by clicking Start > Run and typing Notepad.exe in the box, click OK.
Click Format, and ensure Word Wrap is unchecked.
Copy and Paste all the text inside the box below into Notepad.
Now save the file as RemoveFiles.txt in a location where you can find it.
Check Load script from file:
Click on the folder symbol below and to the right, and browse to RemoveFiles.txt.
Double click it to enter it into Avenger.
Click the green traffic light symbol.
You will be asked if you want to execute the script, answer Yes.
At this point you may get prompts from your protection systems, allow them please.
Avenger will set itself up to run the next time you re-boot, and will prompt you to re-start immediately.
Answer Yes, and allow your computer to re-boot.
Upon re-boot a command window will briefly appear on screen (this is normal).
A Notepad text file will be created C:\avenger.txt.
Copy and Paste it into your next post please, along with a new HJT log.
http://swandog46.geekstogo.com/avenger.zip
Note: The Avenger must be run from a user account with administrator privileges,
and ONLY works on Windows 2000 and XP,.
Open a Notepad file by clicking Start > Run and typing Notepad.exe in the box, click OK.
Click Format, and ensure Word Wrap is unchecked.
Copy and Paste all the text inside the box below into Notepad.
Now save the file as RemoveFiles.txt in a location where you can find it.
Start Avenger by double clicking on Avenger.exe.Files to delete:
C:\WINDOWS\system32\__c00F049E.dat
C:\WINDOWS\system32\qttss.bak2
C:\WINDOWS\system32\__c003BE4E.dat
C:\WINDOWS\system32\__c0030A4A.dat
C:\WINDOWS\system32\qttss.bak1
C:\WINDOWS\system32\ssttq.dll.vir
C:\WINDOWS\system32\ssttq.dll
C:\WINDOWS\system32\reboot.exe
C:\WINDOWS\system32\pepwqdir.dll
C:\WINDOWS\system32\servifg3.dll
C:\WINDOWS\system32\comcxi7.dll
C:\WINDOWS\system32\fidhidus.dll
C:\WINDOWS\system32\ligfinaw.dll
C:\WINDOWS\system32\comcsi7.dll
Check Load script from file:
Click on the folder symbol below and to the right, and browse to RemoveFiles.txt.
Double click it to enter it into Avenger.
Click the green traffic light symbol.
You will be asked if you want to execute the script, answer Yes.
At this point you may get prompts from your protection systems, allow them please.
Avenger will set itself up to run the next time you re-boot, and will prompt you to re-start immediately.
Answer Yes, and allow your computer to re-boot.
Upon re-boot a command window will briefly appear on screen (this is normal).
A Notepad text file will be created C:\avenger.txt.
Copy and Paste it into your next post please, along with a new HJT log.
jennyg
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\xwghmtep
*******************
Script file located at: \??\C:\Documents and Settings\dvnipdcu.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\__c00F049E.dat deleted successfully.
File C:\WINDOWS\system32\qttss.bak2 deleted successfully.
File C:\WINDOWS\system32\__c003BE4E.dat deleted successfully.
File C:\WINDOWS\system32\__c0030A4A.dat deleted successfully.
File C:\WINDOWS\system32\qttss.bak1 deleted successfully.
File C:\WINDOWS\system32\ssttq.dll.vir deleted successfully.
File C:\WINDOWS\system32\ssttq.dll not found!
Deletion of file C:\WINDOWS\system32\ssttq.dll failed!
Could not process line:
C:\WINDOWS\system32\ssttq.dll
Status: 0xc0000034
File C:\WINDOWS\system32\reboot.exe deleted successfully.
File C:\WINDOWS\system32\pepwqdir.dll deleted successfully.
File C:\WINDOWS\system32\servifg3.dll deleted successfully.
File C:\WINDOWS\system32\comcxi7.dll deleted successfully.
File C:\WINDOWS\system32\fidhidus.dll deleted successfully.
File C:\WINDOWS\system32\ligfinaw.dll deleted successfully.
File C:\WINDOWS\system32\comcsi7.dll deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Logfile of HijackThis v1.99.1
Scan saved at 9:08:05 PM, on 4/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\Spyware.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: __c0030A4A - C:\WINDOWS\system32\__c0030A4A.dat (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\xwghmtep
*******************
Script file located at: \??\C:\Documents and Settings\dvnipdcu.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\__c00F049E.dat deleted successfully.
File C:\WINDOWS\system32\qttss.bak2 deleted successfully.
File C:\WINDOWS\system32\__c003BE4E.dat deleted successfully.
File C:\WINDOWS\system32\__c0030A4A.dat deleted successfully.
File C:\WINDOWS\system32\qttss.bak1 deleted successfully.
File C:\WINDOWS\system32\ssttq.dll.vir deleted successfully.
File C:\WINDOWS\system32\ssttq.dll not found!
Deletion of file C:\WINDOWS\system32\ssttq.dll failed!
Could not process line:
C:\WINDOWS\system32\ssttq.dll
Status: 0xc0000034
File C:\WINDOWS\system32\reboot.exe deleted successfully.
File C:\WINDOWS\system32\pepwqdir.dll deleted successfully.
File C:\WINDOWS\system32\servifg3.dll deleted successfully.
File C:\WINDOWS\system32\comcxi7.dll deleted successfully.
File C:\WINDOWS\system32\fidhidus.dll deleted successfully.
File C:\WINDOWS\system32\ligfinaw.dll deleted successfully.
File C:\WINDOWS\system32\comcsi7.dll deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
Logfile of HijackThis v1.99.1
Scan saved at 9:08:05 PM, on 4/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\chad1\Desktop\hijackthis\Spyware.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: __c0030A4A - C:\WINDOWS\system32\__c0030A4A.dat (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
LDTate
That killed em
Run HJT and check this one.
O20 - Winlogon Notify: __c0030A4A - C:\WINDOWS\system32\__c0030A4A.dat (file missing)
Are the pop-ups gone now?
jennyg
no more popups! thanx so much!
can i delete and uninstall all that other stuff i used to fix this? like that deldomains and fixme.reg?
LDTate
You can remove any programs I had you install. Use Add/Remove Programs to remove if listed there: Make sure you delete all the backup folders as well.
Log looks good
You need to create a new Clean restore point.
Note: This will remove all previous Restore Points
Turn off System Restore:
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer, turn it back on.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.
If you dont have any programs like these, I would recommend that you get them.
Spywareblaster,
Spywareguard.
Also get a FREE FIREWALL and FREE ANTI VIRUS if you need one.
Only run one Anti-Virus and Firewall program.
It is critical to have both a firewall and anti virus to protect your system.
Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.
Do not use Ad-aware if you have McAfee's VirusScan and AntiSpyware
Safe Surfing.
I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Log looks good
You need to create a new Clean restore point.
Note: This will remove all previous Restore Points
Turn off System Restore:
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer, turn it back on.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.
If you dont have any programs like these, I would recommend that you get them.
Spywareblaster,
Spywareguard.
Also get a FREE FIREWALL and FREE ANTI VIRUS if you need one.
Only run one Anti-Virus and Firewall program.
It is critical to have both a firewall and anti virus to protect your system.
Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.
Do not use Ad-aware if you have McAfee's VirusScan and AntiSpyware
Safe Surfing.
I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
LDTate
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Coyote's Installed programs for prevention:
http://forums.tomcoyote.org/index.php?showtopic=31418
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Coyote's Installed programs for prevention:
http://forums.tomcoyote.org/index.php?showtopic=31418
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI