This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Search@hand

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

I have a few problems with spyware and hijackers.
The most troublesome is search@hand, because I can't reach pages that I need for my work. Also, systemdoctror and stuff like that.
Here is the hijackthis log, so please haelp with a solution to clean up a little bit my PC

Logfile of HijackThis v1.99.1
Scan saved at 12:35:20, on 12.9.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctjvwdju.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\BPK\bpk.exe
C:\Program Files\SEC\MagicTune3.6_Client_pivot\GammaTray.exe
C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Siemens\Gigaset USB Adapter 108\OdHost.exe
C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\ICQ6\ICQ.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Flashget] C:\Program Files\FlashGet\flashget.exe /min
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\ljhulumy.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [bpk] C:\Program Files\BPK\bpk.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Color Calibration.lnk = ?
O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe
O4 - Global Startup: MagicTune3.6.lnk = ?
O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187218248996
O17 - HKLM\System\CCS\Services\Tcpip\..\{075E8904-E58A-443A-918F-EDA5722199A7}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{5589530C-5E34-4F99-B664-5D75E0CFFFDF}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{70F9FEC2-B21E-4D78-B626-AD0313A102EC}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{D62866E5-FAB6-4F36-97ED-F93032E29659}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.93 85.255.112.23
O17 - HKLM\System\CS2\Services\Tcpip\..\{075E8904-E58A-443A-918F-EDA5722199A7}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.93 85.255.112.23
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\ctjvwdju.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: hpdj - HP - C:\DOCUME~1\Cykke\LOCALS~1\Temp\hpdj.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Management Service - Unknown owner - C:\WINDOWS\system32\.exe (file missing)
O23 - Service: xp2 - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\yejwx.exe
Hi! Welcome to the WTT forums.
I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.

Rename HijackThis
There is a possibility an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Please rename hijackthis.exe to hello.exe

Now scan again and post a new log, please.
Thanks for help

ABBYY FineReader 8.0 Professional Edition
Ad-Aware 2007
Adobe Acrobat 5.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.0
Adobe Stock Photos 1.0
Adobe® Photoshop® Album Starter Edition 3.0
AGEIA PhysX v6.10.25
Alcatech BPM Studio Professional v4.9.1
Alcohol 120%
AnyDVD
ArcSoft PhotoStudio 5.5
Azureus
BlazingTools Perfect Keylogger
Broken Sword
Broken Sword - The Angel of Death Demo
BSPlayer
BSplayer Pro 2.15.943
Canon CanoScan Toolbox 4.9
Canon EOS Kiss REBEL 300D WIA Driver
Canon ScanGear Starter
Change Extension
CloneCD
CloneDVD2
Counter-Strike 1.6 NEW 2007 1.6 (public release 2) by IceMAN
Croatian language for ABBYY FineReader 8.0 Professional Edition
DC++ 0.698
DiRT Demo
DRIV3R
Easy CD-DA Extractor 10
Fallout2
Far Cry Demo
FastCapPro version 2.0.1
ffdshow [rev 1357] [2007-07-17]
Firebird 1.5.1.4481
FlashGet 1.8.2.1001
FLV Player
Ford Supercar Challenge from Ford (remove only)
Fraps (remove only)
Game Cam v1.4
Gigaset USB Adapter 108
GrabIt 1.7.1 Beta (build 960)
GT Interactive - Driver Demo
Hijackthis 1.99.1
HijackThis 1.99.1
hp deskjet 5100
ICQ6
Ipswitch WS_FTP Professional 2007
Java 2 Runtime Environment, SE v1.4.2_14
Java™ 6 Update 2
Java™ SE Runtime Environment 6
Java™ SE Runtime Environment 6 Update 1
Jewel Quest II
K-Lite Mega Codec Pack 1.25
Leisure Suit Larry - Magna Cum Laude Demo
LimeWire 4.12.11
Logitech Audio Echo Cancellation Component
Logitech QuickCam
Logitech Video Enumerator
Logitech® Camera Driver
Macromedia Extension Manager
Macromedia Flash 8
Magic ISO Maker v5.3 (build 0221)
MagicTune3.6_Client_pivot
Manual CanoScan LiDE 25
Microsoft Office FrontPage 2003
Mozilla Firefox (2.0.0.6)
Mozilla Thunderbird ([removed])
Mustek 1200 UB PLUS v1.2
MVision
Nancy Drew - Secret Of The Old Clock (remove only)
Need for Speed Underground 2
Need for Speed™ Carbon Demo
Nero 7
Nero 7 Premium
neroxml
NetLimiter 2 Pro (remove only)
NFS Underground
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia PC Suite
NVIDIA Drivers
Odyssey Client
OpenMG Limited Patch 4.7-07-14-05-01
OpenMG Secure Module 4.7.00
OpenOffice.org 2.2
Painkiller SP Demo
PC Connectivity Solution
PowerISO
Project Torque
RegSupreme Pro 1.4
Sam & Max - Culture Shock 1.0
SAM Broadcaster (remove only)
SEGA RALLY 2 DEMO
SILENT HILL 3(TRIAL)
Skype™ 3.5
SmartFTP Client
SonicStage 4.3
Sony Ericsson PC Suite 1.20.173
SoundMAX
Spybot - Search & Destroy
Spybot - Search & Destroy 1.4
Spyware Doctor 5.0
Static (Build 018.02)
SUPER © Version 2006.19 (FIX)
The Longest Journey Demo, Build 161
TrackMania Nations ESWC 1.7.9
TrackMania Sunrise Extreme 1.5.0
TrackMania United 0.2.0.0
TrackManiaDemo
Tuning Car Studio SK
VideoLAN VLC media player 0.8.6c
Winamp (remove only)
Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1)
Windows Driver Package - Nokia Modem (02/15/2007 3.1)
Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
WinRAR archiver
World Racing 2 Demo
Worms 4 Mayhem
XoftSpySE

New hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 23:42:26, on 12.9.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctjvwdju.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NetLimiter 2 Pro\NLClient.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SEC\MagicTune3.6_Client_pivot\GammaTray.exe
C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe
C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
C:\Program Files\Siemens\Gigaset USB Adapter 108\OdHost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthat\JackHi.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
O2 - BHO: (no name) - {02A47C3E-D2BB-40A4-AC3C-367ED42040E9} - C:\WINDOWS\system32\ddabc.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951A} - C:\Program Files\BPK\bpkwb.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {A6807262-1D7A-44AB-947B-23B71E97915C} - C:\WINDOWS\system32\byxvttt.dll
O2 - BHO: (no name) - {AA24D1EF-E4FF-41F9-A4C4-B8026DCF9123} - (no file)
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\pnlvktxj.dll
O2 - BHO: (no name) - {CDAAF2E6-294A-45DC-91DC-F96CF23D1ED7} - (no file)
O2 - BHO: (no name) - {F156768E-81EF-470C-9057-481BA8380DBA} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Flashget] C:\Program Files\FlashGet\flashget.exe /min
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\ljhulumy.dll",forkonce
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [bpk] C:\Program Files\BPK\bpk.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Color Calibration.lnk = ?
O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe
O4 - Global Startup: MagicTune3.6.lnk = ?
O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187218248996
O17 - HKLM\System\CCS\Services\Tcpip\..\{075E8904-E58A-443A-918F-EDA5722199A7}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{5589530C-5E34-4F99-B664-5D75E0CFFFDF}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{70F9FEC2-B21E-4D78-B626-AD0313A102EC}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\..\{D62866E5-FAB6-4F36-97ED-F93032E29659}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.93 85.255.112.23
O17 - HKLM\System\CS1\Services\Tcpip\..\{075E8904-E58A-443A-918F-EDA5722199A7}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.93 85.255.112.23
O17 - HKLM\System\CS2\Services\Tcpip\..\{075E8904-E58A-443A-918F-EDA5722199A7}: NameServer = 85.255.113.93,85.255.112.23
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.93 85.255.112.23
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: byxvttt - C:\WINDOWS\SYSTEM32\byxvttt.dll
O20 - Winlogon Notify: ddabc - C:\WINDOWS\system32\ddabc.dll (file missing)
O20 - Winlogon Notify: jkhhg - C:\WINDOWS\system32\jkhhg.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\ctjvwdju.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: hpdj - HP - C:\DOCUME~1\Cykke\LOCALS~1\Temp\hpdj.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Management Service - Unknown owner - C:\WINDOWS\system32\.exe (file missing)
O23 - Service: xp2 - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\yejwx.exe

BTW - Perfect Keylogger is not a problem, It's my monitoring/security solution
Hello

Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Download and Run FixWarout
Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

At the end of the fix, you may need to restart your computer again.

Remove bad HijackThis entries
  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):


  • Close all open windows and browsers/email, etc…
  • Click on the "Fix Checked" button
  • When completed, close the application.
Finally, please post a fresh HijackThis log, along with the contents of the logfile C:\fixwareout\report.txt

Now lets check some settings on your system.
(2000/XP) Only
In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable on some systems
Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)

Post back with the
  • Combofix log
  • Fixwareout report
  • new HijackThis log.
ComboFix log

ComboFix 07-09-13.1 - "Cykke" 2007-09-13 13:49:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.512 [GMT 2:00]
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\afxifxfg.ini
C:\WINDOWS\system32\apjvwpbr.ini
C:\WINDOWS\system32\auadhfkf.ini
C:\WINDOWS\system32\awemgdnu.dll
C:\WINDOWS\system32\bolkqvdy.dll
C:\WINDOWS\system32\byxvttt.dll
C:\WINDOWS\system32\cbadd.bak1
C:\WINDOWS\system32\cbadd.bak2
C:\WINDOWS\system32\cbadd.ini
C:\WINDOWS\system32\coyxmvpv.dll
C:\WINDOWS\system32\cscwlgry.dll
C:\WINDOWS\system32\ctjvwdju.exe
C:\WINDOWS\system32\ecvgylyu.exe
C:\WINDOWS\system32\ehghsxrb.exe
C:\WINDOWS\system32\fcdbrqnt.dll
C:\WINDOWS\system32\fjogxdwg.exe
C:\WINDOWS\system32\fkfhdaua.dll
C:\WINDOWS\system32\fkrctrtk.dll
C:\WINDOWS\system32\fulqgpxu.exe
C:\WINDOWS\system32\gfxfixfa.dll
C:\WINDOWS\system32\hcsgpjaa.exe
C:\WINDOWS\system32\hiqqowgk.exe
C:\WINDOWS\system32\hpkgivoc.exe
C:\WINDOWS\system32\hsilsiyy.exe
C:\WINDOWS\system32\hvsxgwpq.exe
C:\WINDOWS\system32\hxjpxiyd.dll
C:\WINDOWS\system32\icgnhkdo.ini
C:\WINDOWS\system32\ioefxnpq.exe
C:\WINDOWS\system32\ixueklef.exe
C:\WINDOWS\system32\jixrhnye.exe
C:\WINDOWS\system32\jlwrkoon.exe
C:\WINDOWS\system32\jpdcjbbv.exe
C:\WINDOWS\system32\jrmqpysy.exe
C:\WINDOWS\system32\kernel32.exe
C:\WINDOWS\system32\kibrhxjp.exe
C:\WINDOWS\system32\kissesld.exe
C:\WINDOWS\system32\lcqywrah.exe
C:\WINDOWS\system32\lhoapmcd.exe
C:\WINDOWS\system32\lmpujrcm.exe
C:\WINDOWS\system32\lpgftrqh.exe
C:\WINDOWS\system32\lrqlbmwx.exe
C:\WINDOWS\system32\lshgrhgy.exe
C:\WINDOWS\system32\lxocbxmp.exe
C:\WINDOWS\system32\ljhulumy.dll
C:\WINDOWS\system32\mfxleoke.dll
C:\WINDOWS\system32\mjyqptll.exe
C:\WINDOWS\system32\mpvewagq.exe
C:\WINDOWS\system32\ndhuqylo.exe
C:\WINDOWS\system32\nipjfjdu.dll
C:\WINDOWS\system32\odkhngci.dll
C:\WINDOWS\system32\oioayyid.exe
C:\WINDOWS\system32\opahvfhj.exe
C:\WINDOWS\system32\ossygids.dll
C:\WINDOWS\system32\owsnajyp.exe
C:\WINDOWS\system32\pnlvktxj.dll
C:\WINDOWS\system32\ppfwliom.exe
C:\WINDOWS\system32\ptkpqrlw.exe
C:\WINDOWS\system32\qageohsn.exe
C:\WINDOWS\system32\qfmcepit.dll
C:\WINDOWS\system32\qgflngpv.exe
C:\WINDOWS\system32\qiqyoynl.dll
C:\WINDOWS\system32\qlgjamas.dll
C:\WINDOWS\system32\qpffsscw.dll
C:\WINDOWS\system32\qupbwxhp.exe
C:\WINDOWS\system32\qvhufqot.exe
C:\WINDOWS\system32\rbldyiro.exe
C:\WINDOWS\system32\rbpwvjpa.dll
C:\WINDOWS\system32\rbvexgpl.exe
C:\WINDOWS\system32\riwlpmtt.exe
C:\WINDOWS\system32\smalubyq.exe
C:\WINDOWS\system32\ssadqlqv.exe
C:\WINDOWS\system32\sslwqlpk.exe
C:\WINDOWS\system32\ttoqevmh.exe
C:\WINDOWS\system32\txkonlrl.dll
C:\WINDOWS\system32\ubixglca.exe
C:\WINDOWS\system32\undgmewa.ini
C:\WINDOWS\system32\vdkfdkxg.exe
C:\WINDOWS\system32\vfvsykmg.exe
C:\WINDOWS\system32\vfysqrdj.exe
C:\WINDOWS\system32\vpvmxyoc.ini
C:\WINDOWS\system32\vrrigyer.exe
C:\WINDOWS\system32\wcssffpq.ini
C:\WINDOWS\system32\wegpdijg.exe
C:\WINDOWS\system32\xaqqyekv.exe
C:\WINDOWS\system32\yluobwyt.exe
C:\WINDOWS\system32\ymuluhjl.ini
C:\WINDOWS\system32\yrglwcsc.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_DOMAINSERVICE
——-\DomainService


((((((((((((((((((((((((( Files Created from 2007-08-13 to 2007-09-13 )))))))))))))))))))))))))))))))
.

2007-09-13 13:48 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-13 11:09 6,488 —hs—- C:\WINDOWS\system32\ghhkj.bak2
2007-09-12 23:38 d——– C:\Program Files\Hijackthat
2007-09-12 23:09 6,448 —hs—- C:\WINDOWS\system32\ghhkj.bak1
2007-09-12 23:08 369,248 –a—— C:\WINDOWS\system32\jkhhg.dll
2007-09-12 23:08 109,600 –a—— C:\WINDOWS\system32\sptll.dll
2007-09-12 13:30 d——– C:\Program Files\XoftSpySE
2007-09-12 12:55 82,248 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2007-09-12 12:55 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2007-09-12 12:55 57,672 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2007-09-12 12:55 40,264 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-09-12 12:55 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2007-09-12 12:55 d——– C:\Program Files\Spyware Doctor
2007-09-12 12:55 d——– C:\DOCUME~1\Cykke\APPLIC~1\PC Tools
2007-09-11 00:05 d——– C:\Program Files\GrabIt
2007-09-11 00:05 d——– C:\DOCUME~1\Cykke\APPLIC~1\GrabIt
2007-09-10 15:45 d——– C:\WINDOWS\system32\LogFiles
2007-09-07 19:08 d——– C:\Program Files\MegauploadToolbar
2007-09-02 23:26 d——– C:\Sword
2007-09-02 16:29 81,920 –a—— C:\WINDOWS\system32\PSCLK170.dll
2007-09-02 16:29 81,920 –a—— C:\WINDOWS\system32\CNDCK170.dll
2007-09-02 16:29 40,960 –a—— C:\WINDOWS\system32\CNDNDlg.exe
2007-09-02 16:29 159,744 –a—— C:\WINDOWS\system32\CNDUK170.dll
2007-09-02 11:39 12,062 –a—— C:\WINDOWS\system32\drivers\MTiCtwl.sys
2007-09-02 11:38 d——– C:\Program Files\SEC
2007-09-02 10:44 356,352 –a—— C:\WINDOWS\system32\nvudisp.exe
2007-09-02 10:44 d——– C:\WINDOWS\nview
2007-09-02 10:37 356,352 –a—— C:\WINDOWS\system32\NVUNINST.EXE
2007-09-01 14:09 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
2007-09-01 11:55 4,682 –a—— C:\WINDOWS\system32\npptNT2.sys
2007-09-01 11:50 d——– C:\Program Files\AeriaGames
2007-08-31 16:31 d——– C:\WINDOWS\FLV Player
2007-08-31 16:31 d——– C:\Program Files\FLV Player
2007-08-31 15:16 d——– C:\Program Files\THQ
2007-08-31 14:47 d——– C:\DOCUME~1\Cykke\APPLIC~1\SystemRequirementsLab
2007-08-30 14:40 d——– C:\DOCUME~1\Cykke\APPLIC~1\GetRightToGo
2007-08-30 14:35 d——– C:\Program Files\Nobilis
2007-08-30 13:10 d——– C:\NVIDIA
2007-08-20 14:40 d——– C:\Program Files\TrackMania Nations ESWC
2007-08-20 13:04 d——– C:\DOCUME~1\ALLUSE~1\SonicStage
2007-08-19 22:57 90,112 ——— C:\WINDOWS\snymsico.dll
2007-08-19 22:57 38,951 ——— C:\WINDOWS\system32\drivers\NETMDUSB.sys
2007-08-19 22:57 36,679 ——— C:\WINDOWS\system32\drivers\NETMD052.sys
2007-08-19 22:57 36,232 ——— C:\WINDOWS\system32\drivers\NETMD033.sys
2007-08-19 22:57 35,319 ——— C:\WINDOWS\system32\drivers\NETMD031.sys
2007-08-19 22:56 770,048 –a—— C:\WINDOWS\system32\CDDBUISony.dll
2007-08-19 22:56 73,728 –a—— C:\WINDOWS\system32\CddbLinkSony.dll
2007-08-19 22:56 655,360 –a—— C:\WINDOWS\system32\CDDBControlSony.dll
2007-08-19 22:56 589,824 –a—— C:\WINDOWS\system32\CddbMusicIDSony.dll
2007-08-19 22:56 532,480 –a—— C:\WINDOWS\system32\CddbPlaylist2Sony.dll
2007-08-19 22:56 116,472 ——— C:\WINDOWS\system32\pxcpyi64.exe
2007-08-19 22:55 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sony Corporation
2007-08-19 22:51 d——– C:\Program Files\Sony
2007-08-19 22:50 d——– C:\Program Files\Common Files\Sony Shared
2007-08-19 22:50 d——– C:\DOCUME~1\Cykke\APPLIC~1\Sony Corporation
2007-08-19 19:07 d——– C:\Program Files\Codemasters
2007-08-18 19:17 d——– C:\DOCUME~1\Cykke\APPLIC~1\fltk.org
2007-08-18 12:56 d——– C:\Program Files\ALCATech
2007-08-17 19:04 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Trymedia
2007-08-17 18:19 d——– C:\Program Files\Nancy Drew - Secret Of The Old Clock
2007-08-17 18:19 d——– C:\Program Files\BFG
2007-08-16 12:30 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\TrackMania United
2007-08-16 11:39 d——– C:\Program Files\Telltale Games
2007-08-16 11:21 d——– C:\DOCUME~1\Cykke\errorlogs
2007-08-16 02:24 d——– C:\DOCUME~1\Cykke\APPLIC~1\Skype
2007-08-16 02:23 d——– C:\Program Files\Skype
2007-08-16 02:23 d——– C:\Program Files\Common Files\Skype
2007-08-16 02:23 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
2007-08-16 01:48 17,024 –a–c— C:\WINDOWS\system32\dllcache\ccdecode.sys
2007-08-16 01:48 17,024 –a—— C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-08-16 01:47 53,760 –a–c— C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2007-08-16 01:47 53,760 –a—— C:\WINDOWS\system32\vfwwdm32.dll
2007-08-16 01:26 356,431 –a—— C:\WINDOWS\system32\GDS32.DLL
2007-08-16 01:26 d——– C:\Program Files\SpacialAudio
2007-08-16 01:26 d——– C:\Program Files\Firebird
2007-08-16 01:21 936,864 –a—— C:\WINDOWS\system32\drivers\LV302V32.SYS
2007-08-16 01:21 527,136 –a—— C:\WINDOWS\system32\LVUI2RC.dll
2007-08-16 01:21 41,248 –a—— C:\WINDOWS\system32\drivers\LVUSBSta.sys
2007-08-16 01:21 348,160 –a—— C:\WINDOWS\system\msvcr71.dll
2007-08-16 01:21 264,992 –a—— C:\WINDOWS\system32\lvcodec2.dll
2007-08-16 01:21 215,840 –a—— C:\WINDOWS\system32\LVUI2.dll
2007-08-16 01:21 14,240 –a—— C:\WINDOWS\system32\drivers\lv302af.sys
2007-08-16 01:21 133,920 –a—— C:\WINDOWS\system32\lvcoinst.dll
2007-08-16 01:21 13,092 –a—— C:\WINDOWS\system32\Repository.reg
2007-08-16 01:21 d——– C:\Program Files\Common Files\Logitech
2007-08-16 01:18 d——– C:\Program Files\Common Files\LogiShrd
2007-08-16 01:18 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
2007-08-16 00:51 43,352 –a—— C:\WINDOWS\system32\wups2.dll
2007-08-16 00:48 d—s—- C:\DOCUME~1\Cykke\UserData
2007-08-16 00:47 d——– C:\Program Files\Logitech
2007-08-16 00:30 d——– C:\Program Files\IceMAN
2007-08-16 00:15 d——– C:\Program Files\TrackMania United
2007-08-15 13:38 d——– C:\Program Files\VUGames
2007-08-14 23:15 d——– C:\Program Files\Webteh
2007-08-14 23:15 d——– C:\DOCUME~1\Cykke\APPLIC~1\BSplayer Pro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-13 13:57 ——— d——– C:\Program Files\FlashGet
2007-09-13 13:46 ——— d——– C:\Program Files\Mozilla Thunderbird
2007-09-13 10:51 ——— d——– C:\DOCUME~1\Cykke\APPLIC~1\Azureus
2007-09-12 13:02 ——— d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-07 16:50 ——— d——– C:\Program Files\Azureus
2007-09-02 16:29 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-09-02 16:29 ——— d——– C:\Program Files\Canon
2007-08-31 16:06 ——— d——– C:\DOCUME~1\Cykke\APPLIC~1\OpenOffice.org2
2007-08-28 13:55 ——— d——– C:\Program Files\ICQ6
2007-08-20 21:51 ——— d——– C:\Program Files\BPK
2007-08-10 13:59 87608 –a—— C:\DOCUME~1\Cykke\APPLIC~1\inst.exe
2007-08-10 13:59 47360 –a—— C:\DOCUME~1\Cykke\APPLIC~1\pcouffin.sys
2007-08-10 13:59 ——— d——– C:\Program Files\VSO
2007-08-10 13:59 ——— d——– C:\DOCUME~1\Cykke\APPLIC~1\Vso
2007-08-10 13:57 47360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2007-07-29 19:22 ——— d——– C:\DOCUME~1\Cykke\APPLIC~1\WinRAR
2007-07-26 01:16 126016 –a—— C:\WINDOWS\system32\onrwxuln.dll
2007-07-24 01:18 126016 –a—— C:\WINDOWS\system32\vyqfqtms.dll
2007-07-21 17:15 ——— d——– C:\DOCUME~1\Cykke\APPLIC~1\vlc
2007-07-21 17:11 ——— d——– C:\Program Files\VideoLAN
2007-07-19 13:45 ——— d——– C:\Program Files\EjoyStudio
2007-07-19 13:39 ——— d——– C:\Program Files\Game Cam v1.4
2007-07-10 20:24 7680 –a—— C:\WINDOWS\system32\ff_vfw.dll
2007-06-29 00:43 8466432 –a—— C:\WINDOWS\system32\nvcpl.dll
2007-06-29 00:43 81920 –a—— C:\WINDOWS\system32\nvwddi.dll
2007-06-29 00:43 81920 –a—— C:\WINDOWS\system32\nvmctray.dll
2007-06-29 00:43 753664 –a—— C:\WINDOWS\system32\nvcplui.exe
2007-06-29 00:43 6729728 –a—— C:\WINDOWS\system32\nvoglnt.dll
2007-06-29 00:43 6234112 –a—— C:\WINDOWS\system32\nvdisps.dll
2007-06-29 00:43 5690624 –a—— C:\WINDOWS\system32\nv4_disp.dll
2007-06-29 00:43 5455872 –a—— C:\WINDOWS\system32\nvdispsr.dll
2007-06-29 00:43 466944 –a—— C:\WINDOWS\system32\nvshell.dll
2007-06-29 00:43 458752 –a—— C:\WINDOWS\system32\nvmccssr.dll
2007-06-29 00:43 45056 –a—— C:\WINDOWS\system32\nvmccsrs.dll
2007-06-29 00:43 442368 –a—— C:\WINDOWS\system32\nvappbar.exe
2007-06-29 00:43 425984 –a—— C:\WINDOWS\system32\keystone.exe
2007-06-29 00:43 37376 –a—— C:\WINDOWS\system32\nvcodins.dll
2007-06-29 00:43 37376 –a—— C:\WINDOWS\system32\nvcod.dll
2007-06-29 00:43 360448 –a—— C:\WINDOWS\system32\nvapi.dll
2007-06-29 00:43 3600384 –a—— C:\WINDOWS\system32\nvvitvsr.dll
2007-06-29 00:43 3518464 –a—— C:\WINDOWS\system32\nvvitvs.dll
2007-06-29 00:43 3321856 –a—— C:\WINDOWS\system32\nvgames.dll
2007-06-29 00:43 3072000 –a—— C:\WINDOWS\system32\nvgamesr.dll
2007-06-29 00:43 307200 –a—— C:\WINDOWS\system32\nvexpbar.dll
2007-06-29 00:43 286720 –a—— C:\WINDOWS\system32\nvnt4cpl.dll
2007-06-29 00:43 2854912 –a—— C:\WINDOWS\system32\nvmoblsr.dll
2007-06-29 00:43 2416640 –a—— C:\WINDOWS\system32\nvwssr.dll
2007-06-29 00:43 2330624 –a—— C:\WINDOWS\system32\nvwss.dll
2007-06-29 00:43 229376 –a—— C:\WINDOWS\system32\nvmccs.dll
2007-06-29 00:43 188416 –a—— C:\WINDOWS\system32\nvmccss.dll
2007-06-29 00:43 1703936 –a—— C:\WINDOWS\system32\nvwdmcpl.dll
2007-06-29 00:43 1626112 –a—— C:\WINDOWS\system32\nwiz.exe
2007-06-29 00:43 155716 –a—— C:\WINDOWS\system32\nvsvc32.exe
2007-06-29 00:43 1474560 –a—— C:\WINDOWS\system32\nview.dll
2007-06-29 00:43 147456 –a—— C:\WINDOWS\system32\nvcolor.exe
2007-06-29 00:43 1339392 –a—— C:\WINDOWS\system32\nvdspsch.exe
2007-06-29 00:43 1142784 –a—— C:\WINDOWS\system32\nvmobls.dll
2007-06-29 00:43 1073152 –a—— C:\WINDOWS\system32\nvcpluir.dll
2007-06-29 00:43 1019904 –a—— C:\WINDOWS\system32\nvwimg.dll
2007-06-29 00:43 1018772 –a—— C:\WINDOWS\system32\nvucode.bin
2007-06-19 21:13 258048 –a—— C:\WINDOWS\system32\or_dx9font.dll
2005-05-13 15:12:00 217,073 –sha-r C:\WINDOWS\meta4.exe
2005-10-24 09:13:58 66,560 –sha-r C:\WINDOWS\MOTA113.exe
2005-10-13 19:27:00 422,400 –sha-r C:\WINDOWS\x2.64.exe
2005-10-07 17:14:52 308,224 –sha-r C:\WINDOWS\system32\avisynth.dll
2005-07-14 10:31:20 27,648 –sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 13:32:28 616,448 –sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-21 20:37:42 45,568 –sha-r C:\WINDOWS\system32\cygz.dll
2004-01-24 22:00:00 217,088 –sha-r C:\WINDOWS\system32\i420vfw.dll
2006-04-27 08:24:24 2,945,024 –sha-r C:\WINDOWS\system32\Smab.dll
2005-02-28 11:16:22 240,128 –sha-r C:\WINDOWS\system32\x.264.exe
2004-01-24 22:00:00 217,088 –sha-r C:\WINDOWS\system32\yv12vfw.dll
2007-03-31 17:18:58 299,008 –sh–w C:\WINDOWS\system32\_yejwx.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02A47C3E-D2BB-40A4-AC3C-367ED42040E9}]
C:\WINDOWS\system32\ddabc.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E1B2879-88FF-11D3-8D96-D7ACAC95951A}]
2006-06-30 16:36 40960 –a—— C:\Program Files\BPK\bpkwb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{79918589-3284-4DDC-B3A6-78F418D2B5A7}]
2007-09-12 23:08 369248 –a—— C:\WINDOWS\system32\jkhhg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A6807262-1D7A-44AB-947B-23B71E97915C}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA24D1EF-E4FF-41F9-A4C4-B8026DCF9123}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6039E6C-BDE9-4de5-BB40-768CAA584FDC}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CDAAF2E6-294A-45DC-91DC-F96CF23D1ED7}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-02-13 20:29]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 16:28]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2003-05-30 09:42]
"Flashget"="C:\Program Files\FlashGet\flashget.exe" [2007-03-20 12:40]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 19:51]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 13:20]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 C:\WINDOWS\system32\bthprops.cpl]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
"nwiz"="nwiz.exe" [2007-06-29 00:43 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 17:02]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-05-21 23:46]
"bpk"="C:\Program Files\BPK\bpk.exe" [2006-06-30 16:36]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Nokia.PCSync"=C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Color Calibration.lnk - C:\Program Files\SEC\MagicTune3.6_Client_pivot\GammaTray.exe [2007-09-02 11:38:39]
Gigaset WLAN Adapter Monitor.lnk - C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe [2007-03-28 17:45:10]
MagicTune3.6.lnk - C:\Program Files\SEC\MagicTune3.6_Client_pivot\MagicTuneTray.exe [2007-09-02 11:38:47]
Watch.lnk - C:\WINDOWS\twain_32\S6U12BX\WATCH.exe [2007-03-30 08:30:29]

C:\DOCUME~1\Cykke\STARTM~1\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxvttt]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddabc]
C:\WINDOWS\system32\ddabc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhg]
C:\WINDOWS\system32\jkhhg.dll 2007-09-12 23:08 369248 C:\WINDOWS\system32\jkhhg.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Cykke^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=C:\Documents and Settings\Cykke\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=C:\WINDOWS\pss\LimeWire On Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Cykke^Start Menu^Programs^Startup^start.exe]
path=C:\Documents and Settings\Cykke\Start Menu\Programs\Startup\start.exe
backup=C:\WINDOWS\pss\start.exeStartup


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
"C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
KHALMNPR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
"C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
"C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MemoryManager]
rundll32.exe "C:\WINDOWS\system32\onrwxuln.dll",forkonce

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\system32\ylshiynb.dll",forkonce

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vista Sidebar]
C:\Program Files\Vista Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VisualTooltip]
C:\Program Files\VisualTooltip\VisualToolTip.exe

R1 nltdi;nltdi;\??\C:\WINDOWS\system32\drivers\nltdi.sys
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe -s
R3 CBTNDIS5;CBTNDIS5 NDIS Protocol Driver;\??\C:\WINDOWS\system32\CBTNDIS5.SYS
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe -s
R3 OdysseyIM4;Odyssey Network Agent Miniport;C:\WINDOWS\system32\DRIVERS\odysseyIM4.sys
S2 Windows Management Service;Windows Management Service;C:\WINDOWS\system32\dmlaa.exe -service
S2 xp2;xp2;C:\Program Files\Common Files\Microsoft Shared\MSINFO\yejwx.exe
S3 AR5523;Gigaset USB Adapter 108;C:\WINDOWS\system32\DRIVERS\ar5523.sys
S3 ATHFMWDL;GigaSet USB Adapter 108 Bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys
S3 GT680x;Grand Tech GT680x NT;C:\WINDOWS\system32\DRIVERS\GT680x.SYS
S3 king002;king002;\??\C:\DOCUME~1\Cykke\LOCALS~1\Temp\xpa.sys


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40b48424-e8bf-11db-aa17-0001e3565461}]
AutoRun\command- I:\USBNB.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-09-13 11:58:51 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2007-09-12 11:30:07 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-13 13:59:53
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwEnumerateKey, ZwEnumerateValueKey, ZwQueryValueKey, ZwQueryDirectoryFile, ZwQuerySystemInformation

scanning hidden processes …

C:\WINDOWS\system32\svchost.exe [996] 0x8636EA98
C:\WINDOWS\system32\svchost.exe [2032] 0x85DF0020


scanning hidden autostart entries …

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System = csgkz.exe
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit = C:\WINDOWS\system32\userinit.exe,

scanning hidden files …

C:\WINDOWS\system32\csgkz.exe
C:\WINDOWS\system32\dmlaa.exe

scan completed successfully
hidden files: 2

**************************************************************************
.
Completion time: 2007-09-13 14:02:59 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-13 14:02
.
— E O F —

Fixwareout log
Username "Cykke" - 13.09.2007 14:08:47 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="csgkz.exe"
Service: "Windows Management Service" = C:\WINDOWS\System32\dmlaa.exe

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.113.93 85.255.112.23" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{075E8904-E58A-443A-918F-EDA5722199A7}
"nameserver"="85.255.113.93,85.255.112.23" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{5589530C-5E34-4F99-B664-5D75E0CFFFDF}
"nameserver"="85.255.113.93,85.255.112.23" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{70F9FEC2-B21E-4D78-B626-AD0313A102EC}
"nameserver"="85.255.113.93,85.255.112.23" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D62866E5-FAB6-4F36-97ED-F93032E29659}
"nameserver"="85.255.113.93,85.255.112.23" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{075E8904-E58A-443A-918F-EDA5722199A7}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{70F9FEC2-B21E-4D78-B626-AD0313A102EC}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D62866E5-FAB6-4F36-97ED-F93032E29659}
"DhcpNameServer"="[removed],[removed]"
Successfully flushed the DNS Resolver Cache.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}6EEDB36666A1-1EE8-26B4-432D-8B4909FC{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}9F20218D0C86-01C8-BED4-0AF6-B67C5423{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "dxwmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "}56F20E3B8FA0-963A-EEB4-6E16-5C7DCCC5{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\_r "aalmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion "zkgsc" Value deleted
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion "dmwxd.exe" Value deleted
HKCR\CLSID\{1FDC3FB3-77EF-44D4-ADF9-0198F93F3BE1}\_h\4 Deleted.
HKCR\CLSID\{46C6E9AB-1E6B-415B-8FBD-688460B3C48A}\_h\4 Deleted.
HKCR\CLSID\{51D8B96D-9905-4F87-80FC-7B1BABA9F88C}\_h\4 Deleted.
HKCR\CLSID\{6047B9DE-3B6C-4CA9-8E04-1DB7699C20A5}\_h\4 Deleted.
HKCR\CLSID\{82133F77-B9D7-46B2-B547-20CBC06D1060}\_h\4 Deleted.
HKCR\CLSID\{A01A2297-F143-4DBD-B74A-C88B4A177ACD}\_h\4 Deleted.
HKCR\CLSID\{BE87B07C-8913-48AA-ACBF-CB2CECA16D8D}\_h\4 Deleted.
HKCR\CLSID\{EC47D369-2F13-4FC2-AFDE-F0DBAA4AC122}\_h\4 Deleted.
HKCR\CLSID\{EE293710-8F5C-43D3-B5F6-8F59D303BB90}\_h\4 Deleted.
HKCR\CLSID\{F7F0E7B3-0787-4351-914A-840BEF6098C4}\_h\4 Deleted.
HKCR\CLSID\{F8788E49-D7C9-4421-901C-143C283F9A77}\_h\4 Deleted.
C:\WINDOWS\System32\gxipa.exe Deleted
C:\WINDOWS\System32\oosce.exe Deleted
C:\WINDOWS\System32\wrslq.exe Deleted
….
~~~~~ Misc files.
….
~~~~~ Checking for older varients.
….
~~~~~ Other
C:\WINDOWS\Temp\csgkz.ren 52759 12.09.2007
C:\WINDOWS\Temp\dmlaa.ren 63028 04.08.2004

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\jusched.exe\""
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe"
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"Flashget"="C:\\Program Files\\FlashGet\\flashget.exe /min"
"HP Software Update"="\"C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe\""
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"PCSuiteTrayApplication"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\LaunchApplication.exe -startup"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"Sony Ericsson PC Suite"="\"C:\\Program Files\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"SDTray"="\"C:\\Program Files\\Spyware Doctor\\SDTrayApp.exe\""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"AnyDVD"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"
"bpk"="C:\\Program Files\\BPK\\bpk.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
….
Hosts file was reset, If you use a custom hosts file please replace it…
~~~~~ End report ~~~~~

Hijackthis log
Logfile of HijackThis v1.99.1
Scan saved at 22:18:24, on 13.9.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
C:\WINDOWS\system32\calc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\BPK\bpk.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SEC\MagicTune3.6_Client_pivot\GammaTray.exe
C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe
C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
C:\Program Files\Siemens\Gigaset USB Adapter 108\OdHost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Hijackthat\JackHi.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
O2 - BHO: (no name) - {02A47C3E-D2BB-40A4-AC3C-367ED42040E9} - C:\WINDOWS\system32\ddabc.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: PK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951A} - C:\Program Files\BPK\bpkwb.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {8E5D4DCC-342A-4E86-93C2-BF6CF52327B6} - C:\WINDOWS\system32\jkhhg.dll
O2 - BHO: (no name) - {A6807262-1D7A-44AB-947B-23B71E97915C} - (no file)
O2 - BHO: (no name) - {AA24D1EF-E4FF-41F9-A4C4-B8026DCF9123} - (no file)
O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - (no file)
O2 - BHO: (no name) - {CDAAF2E6-294A-45DC-91DC-F96CF23D1ED7} - (no file)
O2 - BHO: (no name) - {F156768E-81EF-470C-9057-481BA8380DBA} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Flashget] C:\Program Files\FlashGet\flashget.exe /min
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [bpk] C:\Program Files\BPK\bpk.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Color Calibration.lnk = ?
O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Program Files\Siemens\Gigaset USB Adapter 108\Gcc.exe
O4 - Global Startup: MagicTune3.6.lnk = ?
O4 - Global Startup: Watch.lnk = C:\WINDOWS\twain_32\S6U12BX\WATCH.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1187218248996
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: byxvttt - C:\WINDOWS\
O20 - Winlogon Notify: ddabc - C:\WINDOWS\system32\ddabc.dll (file missing)
O20 - Winlogon Notify: jkhhg - C:\WINDOWS\system32\jkhhg.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Cykke\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: xp2 - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\MSINFO\yejwx.exe
Upload a File to Virustotal
Please visit Virustotal
  • Click the Browse… button
  • Navigate to the file C:\Program Files\Common Files\Microsoft Shared\MSINFO\yejwx.exe
  • Click the Open button
  • Click the Send button
  • Copy and paste the results back here please.
Hi
Could you follow the previous instruction again, but this time look for this file?
C:\WINDOWS\system32\_yejwx.exe

Im sorry if Im being a pain, but I really like to know what Im dealing with.
No problem… You are making me a favor ;) Nope, there is no file by that name in system32. I also used search to try to find it in /windows folder, but there is no file by this name (yejwx.exe)
Sorry, I forgot to add this, see if it helps.

To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon (or click Start, then select My Computer)
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
    Now your computer is configured to show all hidden files.
If that doesnt work, we will just move on.
Okay, lets press on.

First, a question. Did you knowingly install a keylogger program on your computer?

Please download and install IceSword

IceSword is in compressed RAR file format so you will need a utility like WinRar or the open source 7-Zip to extract it
Download and extract 7-Zip

The use 7-Zip to exract IceSword to C:\Program Files\IceSword

Once IceSword is extracted, with all browser and Explorer windows closed, run IceSword
  • Once IceSword is open, click the Win32 Service Function on the left Menu Bar
    If any red entries are found, click the blue Log Tab at the top of the screen and save the log to documents folder as service-list.txt.
  • Now, Click IceSword's Process Function on the left Menu Bar
    If any red entries are found, click the blue Log tab at the top of the screen and save the log to documents folder as processlist.txt.
Then post it in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI