This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan.Vundo and Trojan.Metajuan

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got these two viruses about 2 days ago. I could only block it with Norton Internet Security 2007, but I can never get rid of it. I even recovered my C drive and it still wouldn't go away. I need Help with this Trojan. Here is my HiJackThis report. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:44, on 2008-02-14 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe" O4 - HKLM\..\Run: [VAIOSurvey] "c:\program files\sony\vaio survey\surveysa.exe" O4 - HKLM\..\Run: [EXSHOW95.EXE] EXSHOW95.EXE O4 - HKLM\..\Run: [VAIO Recovery] "C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [b867984c] rundll32.exe "C:\WINDOWS\system32\minrtuou.dll",b O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople O17 - HKLM\System\CCS\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186 O17 - HKLM\System\CS1\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186 O17 - HKLM\System\CS2\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186 O20 - AppInit_DLLs: O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe – End of file - 8664 bytes Can you please help me get rid of these two trojans. Thanks in advance.
Hello SubaruWRXSTi and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 21:31, on 2008-02-15 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe C:\WINDOWS\system32\EXSHOW95.EXE C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\WINDOWS\system32\EXSHOW.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\imapi.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary O4 - HKLM\..\Run: [VAIOSurvey] "c:\program files\sony\vaio survey\surveysa.exe" O4 - HKLM\..\Run: [EXSHOW95.EXE] EXSHOW95.EXE O4 - HKLM\..\Run: [VAIO Recovery] "C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople O17 - HKLM\System\CCS\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186 O17 - HKLM\System\CS1\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186 O17 - HKLM\System\CS2\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe – End of file - 7114 bytes

Attachments:

A. Please copy/paste all your logs/reports in your repplies and not attach them. It makes it so much easier on us. Thanks.

B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\WINDOWS\system32\bilwpwdi.ini
C:\WINDOWS\system32\asykihkk.ini
C:\WINDOWS\system32\uoutrnim.ini
C:\WINDOWS\system32\duitgqoy.ini
C:\WINDOWS\system32\bpgwbrdk.ini
C:\install.dat
C:\WINDOWS\system32\llfmkbby.ini
C:\WINDOWS\system32\skdwkawy.ini
C:\WINDOWS\system32\ycdfsenb.ini
C:\WINDOWS\system32\hqdbwpkr.ini
C:\WINDOWS\system32\umqlkoxb.ini
C:\WINDOWS\TMP0001.TMP
J:\Autorun.exe

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


C. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
ComboFix 08-02-16.2 - Shoeb Rehman 2008-02-16 7:27:13.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.302 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Shoeb Rehman\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\install.dat
C:\WINDOWS\system32\asykihkk.ini
C:\WINDOWS\system32\bilwpwdi.ini
C:\WINDOWS\system32\bpgwbrdk.ini
C:\WINDOWS\system32\duitgqoy.ini
C:\WINDOWS\system32\hqdbwpkr.ini
C:\WINDOWS\system32\llfmkbby.ini
C:\WINDOWS\system32\skdwkawy.ini
C:\WINDOWS\system32\umqlkoxb.ini
C:\WINDOWS\system32\uoutrnim.ini
C:\WINDOWS\system32\ycdfsenb.ini
C:\WINDOWS\TMP0001.TMP
J:\Autorun.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.dat
C:\WINDOWS\system32\asykihkk.ini
C:\WINDOWS\system32\bilwpwdi.ini
C:\WINDOWS\system32\bpgwbrdk.ini
C:\WINDOWS\system32\duitgqoy.ini
C:\WINDOWS\system32\hqdbwpkr.ini
C:\WINDOWS\system32\llfmkbby.ini
C:\WINDOWS\system32\skdwkawy.ini
C:\WINDOWS\system32\umqlkoxb.ini
C:\WINDOWS\system32\uoutrnim.ini
C:\WINDOWS\system32\ycdfsenb.ini
C:\WINDOWS\TMP0001.TMP

.
((((((((((((((((((((((((( Files Created from 2008-01-16 to 2008-02-16 )))))))))))))))))))))))))))))))
.

2008-02-15 19:08 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-15 19:08 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-15 19:08 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-15 19:08 . 2008-02-15 19:08 130 –a—— C:\WINDOWS\ODBC.INI
2008-02-15 19:07 . 2008-02-15 19:07 d——– C:\Program Files\Alwil Software
2008-02-15 19:07 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-02-15 19:07 . 2004-01-09 05:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-02-15 19:07 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AVASTSS.scr
2008-02-15 19:07 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-15 19:07 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-15 18:13 . 2008-02-15 18:13 d——– C:\Program Files\BillP Studios
2008-02-15 18:13 . 2008-02-15 18:13 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\WinPatrol
2008-02-14 19:19 . 2008-02-14 19:19 d——– C:\Program Files\Trend Micro
2008-02-14 18:54 . 2008-02-15 16:13 d——– C:\VundoFix Backups
2008-02-14 18:32 . 2008-02-14 19:35 d——– C:\Program Files\Common Files\Webroot Shared
2008-02-14 18:21 . 2008-02-14 18:54 d——– C:\Program Files\Webroot
2008-02-14 17:36 . 2004-04-23 00:00 116,736 –a—— C:\WINDOWS\system32\CNMLM5y.DLL
2008-02-14 17:36 . 2004-03-11 11:06 86,016 -ra—— C:\WINDOWS\system32\CNMCP5y.exe
2008-02-14 17:36 . 2004-04-23 00:00 7,680 –a—— C:\WINDOWS\system32\CNMVS5y.DLL
2008-02-14 17:35 . 2004-08-03 23:01 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-14 17:35 . 2004-08-03 23:01 25,856 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-14 16:14 . 2008-02-14 17:25 d——– C:\Program Files\COMODO
2008-02-14 16:14 . 2008-02-14 17:25 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\Comodo
2008-02-14 16:14 . 2008-02-14 17:25 d——– C:\Documents and Settings\All Users\Application Data\comodo
2008-02-13 17:38 . 2008-02-13 17:38 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\gtk-2.0
2008-02-13 16:47 . 2008-02-13 16:47 d——– C:\Documents and Settings\Shoeb Rehman\.thumbnails
2008-02-13 16:46 . 2008-02-13 17:40 d——– C:\Documents and Settings\Shoeb Rehman\.gimp-2.4
2008-02-13 16:35 . 2008-02-13 16:35 d——– C:\Program Files\GIMP-2.0
2008-02-13 16:31 . 2001-08-17 22:36 87,040 –a—— C:\WINDOWS\system32\wiafbdrv.dll
2008-02-13 16:31 . 2001-08-17 22:36 87,040 –a–c— C:\WINDOWS\system32\dllcache\wiafbdrv.dll
2008-02-13 16:31 . 2004-08-03 22:58 15,104 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-13 16:31 . 2004-08-03 22:58 15,104 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2008-02-13 16:28 . 2008-02-13 16:31 d——– C:\Program Files\42 Bit Scanner
2008-02-12 17:32 . 2008-02-12 17:32 0 –ah—– C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf
2008-02-12 17:32 . 2008-02-12 17:32 0 –ah—– C:\WINDOWS\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2008-02-12 17:31 . 2008-02-12 17:31 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-02-12 17:31 . 2008-02-12 17:31 d——– C:\Program Files\Microsoft Xbox 360 Accessories
2008-02-12 17:31 . 2007-02-26 18:15 1,421,216 –a—— C:\WINDOWS\system32\WdfCoInstaller01001.dll
2008-02-12 17:31 . 2007-02-26 18:15 61,984 –a—— C:\WINDOWS\system32\drivers\xusb21.sys
2008-02-12 17:30 . 2006-09-28 16:04 68,888 –a—— C:\WINDOWS\system32\xinput1_3.dll
2008-02-12 16:21 . 2008-02-12 16:21 d——– C:\Program Files\EA SPORTS
2008-02-11 20:48 . 2008-02-11 20:48 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\TaxCut
2008-02-11 20:48 . 2008-02-11 20:48 d——– C:\Documents and Settings\All Users\Application Data\pdf995
2008-02-11 20:48 . 2008-02-11 20:48 249,856 –a—— C:\WINDOWS\system32\pdfmona.dll
2008-02-11 20:48 . 2008-02-11 20:48 51,716 –a—— C:\WINDOWS\system32\pdf995mon.dll
2008-02-11 20:48 . 2007-08-24 11:13 142 –a—— C:\WINDOWS\wpd99.drv
2008-02-11 20:46 . 2008-02-11 20:47 d——– C:\Program Files\TaxCut07
2008-02-11 20:46 . 2008-02-11 20:48 d——– C:\Program Files\PDF995
2008-02-11 20:43 . 2008-02-11 20:43 d–hs—- C:\WINDOWS\ftpcache
2008-02-11 20:43 . 2008-02-11 20:43 d——– C:\Documents and Settings\All Users\Application Data\TaxCut
2008-02-11 18:39 . 2006-10-04 09:06 1,197,294 —–c— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-02-11 18:36 . 2008-02-11 18:36 d——– C:\Program Files\Windows Media Connect 2
2008-02-11 18:27 . 2008-02-11 18:30 d——– C:\WINDOWS\system32\drivers\UMDF
2008-02-11 17:08 . 2008-02-11 17:48 147 –a—— C:\WINDOWS\wininit.ini
2008-02-11 16:31 . 2008-02-13 18:07 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-11 16:27 . 2008-02-11 17:17 1,870 –a—— C:\WINDOWS\system32\tmp.reg
2008-02-11 16:22 . 2008-02-11 16:23 d——– C:\Program Files\RogueRemover FREE
2008-02-11 15:58 . 2008-02-11 15:58 d——– C:\Program Files\MSXML 6.0
2008-02-11 15:25 . 2008-02-11 15:25 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\Corel
2008-02-10 21:54 . 2007-12-06 21:21 6,066,176 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-02-10 21:54 . 2007-06-30 22:31 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-02-10 21:54 . 2007-06-30 22:36 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-02-10 21:54 . 2007-12-06 21:21 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-02-10 21:54 . 2007-12-06 21:21 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-02-10 21:54 . 2007-12-06 21:21 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-10 21:54 . 2007-12-06 21:21 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-02-10 21:54 . 2007-12-06 21:21 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-02-10 21:54 . 2007-12-06 06:00 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-10 21:43 . 2008-02-10 21:43 d——– C:\Program Files\MSBuild
2008-02-10 21:39 . 2008-02-11 18:48 d——– C:\WINDOWS\system32\XPSViewer
2008-02-10 21:38 . 2008-02-10 21:38 d——– C:\Program Files\Reference Assemblies
2008-02-10 21:36 . 2006-06-29 13:07 14,048 –a—— C:\WINDOWS\system32\spmsg2.dll
2008-02-10 21:27 . 2006-08-21 04:14 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-02-10 21:27 . 2006-08-21 07:21 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2008-02-10 21:17 . 2001-09-07 16:17 376,832 –a—— C:\WINDOWS\system32\exshow.exe
2008-02-10 21:17 . 2001-09-07 16:22 122,880 –a—— C:\WINDOWS\system32\shw95dll.dll
2008-02-10 21:17 . 2001-09-07 16:18 45,056 –a—— C:\WINDOWS\system32\exshow95.exe
2008-02-10 21:17 . 2004-08-03 22:58 23,040 –a—— C:\WINDOWS\system32\mouclass.sys
2008-02-10 21:17 . 2001-08-17 13:48 12,160 –a—— C:\WINDOWS\system32\mouhid.sys
2008-02-10 21:13 . 2006-11-13 01:02 288,768 –a—— C:\WINDOWS\system32\rhttpaa.dll
2008-02-10 21:13 . 2006-11-13 01:02 116,736 –a—— C:\WINDOWS\system32\aaclient.dll
2008-02-10 21:13 . 2006-11-13 01:02 36,352 –a—— C:\WINDOWS\system32\tsgqec.dll
2008-02-10 21:06 . 2007-07-09 08:16 582,656 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-02-10 20:50 . 2008-02-10 20:50 d–hs—- C:\Documents and Settings\Shoeb Rehman\UserData
2008-02-10 20:49 . 2006-10-16 16:10 23,856 –a—— C:\WINDOWS\system32\spupdsvc.exe
2008-02-10 20:44 . 2008-02-10 20:44 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\Sonic
2008-02-10 20:44 . 2008-02-10 20:44 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\Leadertech
2008-02-10 20:00 . 2008-02-10 20:00 d——– C:\Program Files\Common Files\Adobe
2008-02-10 20:00 . 2008-02-10 20:00 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\AdobeUM
2008-02-10 19:22 . 2007-10-11 00:57 151,040 —–c— C:\WINDOWS\system32\dllcache\cdfview.dll
2008-02-10 19:02 . 2008-02-10 19:11 d——– C:\Documents and Settings\Shoeb Rehman\Application Data\Intuit
2008-02-10 19:01 . 2008-02-10 19:01 d——– C:\Program Files\Common Files\AnswerWorks 4.0
2008-02-10 18:55 . 2008-02-10 18:55 d——– C:\Program Files\Common Files\Intuit
2008-02-10 18:55 . 2007-10-22 18:58 1,721,712 –a—— C:\WINDOWS\system32\InetClnt.dll
2008-02-10 18:38 . 2008-02-10 18:38 d——– C:\Program Files\TurboTax
2008-02-10 13:23 . 2001-08-17 16:48 12,160 –a—— C:\WINDOWS\system32\drivers\mouhid.sys
2008-02-10 13:23 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2008-02-10 13:23 . 2001-08-17 14:02 9,600 –a–c— C:\WINDOWS\system32\dllcache\hidusb.sys
2008-02-10 12:53 . 2008-02-10 13:49 d——– C:\Program Files\Opera
2008-02-10 12:10 . 2008-02-11 18:27 d——– C:\WINDOWS\system32\LogFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-16 12:29 7,304 —-a-w C:\WINDOWS\TMP0001.TMP
2008-02-11 00:01 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-10 16:36 ——— d—–w C:\Program Files\Sony
2008-02-10 16:36 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sony Corporation
2008-02-10 16:33 ——— d—–w C:\Program Files\Common Files\Sony Shared
2008-02-10 15:32 ——— d—–w C:\Program Files\Google
2008-02-10 15:26 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-12-18 09:51 179,584 —-a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2001-08-22 18:15 245,760 —-a-w C:\WINDOWS\inf\i386\viceo.dll
2001-08-22 18:13 61,440 —-a-w C:\WINDOWS\inf\i386\gl.dll
2001-08-22 18:13 32,768 —-a-w C:\WINDOWS\inf\i386\Pmicro.dll
2001-08-03 23:29 13,824 —-a-w C:\WINDOWS\inf\i386\Usbscan.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-10 10:28 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2004-04-13 14:49 88363 C:\WINDOWS\AGRSMMSG.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-08 10:31 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-08 10:27 126976]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 18:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-10-21 17:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2004-10-21 20:44 2744832 C:\WINDOWS\ALCWZRD.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-10 00:10 344064]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2004-09-21 21:54 151552]
"EXSHOW95.EXE"="EXSHOW95.EXE" [2001-09-07 16:18 45056 C:\WINDOWS\system32\exshow95.exe]
"RegistryMechanic"="" []
"XboxStat"="c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 18:05 734264]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-08-02 11:59 292152]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CreateCD_Reminder]
–a—— 2004-07-16 14:17 53248 C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe

R3 KID_USB;Kensington Input Devices USB filter driver;C:\WINDOWS\system32\DRIVERS\KID_USB.sys [2001-09-05 11:42]
R3 KMW_SYS;Kensington MouseWorks Mouse filter driver;C:\WINDOWS\system32\DRIVERS\KMW_SYS.sys [2001-09-07 17:10]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\LaunchU3.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 07:30:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\EXSHOW.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2008-02-16 7:32:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-16 12:32:21
ComboFix2.txt 2008-02-16 02:29:10
.
2008-02-16 04:15:47 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:33:47 AM, on 2008-02-16
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\system32\EXSHOW95.EXE
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\EXSHOW.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [EXSHOW95.EXE] EXSHOW95.EXE
O4 - HKLM\..\Run: [XboxStat] "c:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O17 - HKLM\System\CCS\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186
O17 - HKLM\System\CS1\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186
O17 - HKLM\System\CS2\Services\Tcpip\..\{49142C50-9425-4F68-B0D1-AF0B54509FF1}: NameServer = 207.69.188.185,207.69.188.186
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

–
End of file - 7149 bytes
Sorry. I misread the instructions. Here is the report. ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT 2008-02-16 3:50:07 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 16/02/2008 Kaspersky Anti-Virus database records: 569372 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan Statistics: Total number of scanned objects: 52368 Number of viruses found: 4 Number of infected objects: 9 Number of suspicious objects: 0 Duration of the scan process: 00:27:38 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Sony Corporation\VAIO Entertainment Platform\1.0\VzCdb\MtData.ldb Object is locked skipped C:\Documents and Settings\All Users\Application Data\Sony Corporation\VAIO Entertainment Platform\1.0\VzCdb\MtData.mdb Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\cert8.db Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\formhistory.dat Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\history.dat Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\key3.db Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\parent.lock Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\search.sqlite Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Application Data\Mozilla\Firefox\Profiles\1gmlevre.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Temp\swg1.2.1128.5462080216-120344.dmp Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Shoeb Rehman\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Shoeb Rehman\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Shoeb Rehman\ntuser.dat.LOG Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped C:\Program Files\Mozilla Firefox\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ummhugtv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\catchme2008-02-15_212727.03.zip/mljgh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\QooBox\Quarantine\catchme2008-02-15_212727.03.zip/wvututt.dll Infected: Trojan-Downloader.Win32.Small.hsl skipped C:\QooBox\Quarantine\catchme2008-02-15_212727.03.zip ZIP: infected - 2 skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{3FB54717-8ED4-4CF6-8316-1C34E468C3C0}\RP2\A0000014.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{3FB54717-8ED4-4CF6-8316-1C34E468C3C0}\RP2\A0000021.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped C:\System Volume Information\_restore{3FB54717-8ED4-4CF6-8316-1C34E468C3C0}\RP2\A0000022.dll Infected: Trojan-Downloader.Win32.Small.hsl skipped C:\System Volume Information\_restore{3FB54717-8ED4-4CF6-8316-1C34E468C3C0}\RP6\change.log Object is locked skipped C:\VundoFix Backups\mljji.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.imh skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\JETDD21.tmp Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_5e4.dat Object is locked skipped C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
All remaining infected items are currently in quarantine. They will be deleted during the final cleanup procedures. If you are not aware of any more malware activity, just give me the OK and we will proceed with these final cleanup procedures and recommendations.
Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


  • [external image: Posted Image]



The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. FIREWALL
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

Do not install more than one firewall program because they will conflict with each other


4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

8. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
That sounds good.

Congratulations, your logs look CLEAN

There are a few things you must do once you system is completely clean:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


  • [external image: Posted Image]



The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.


Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Use and Update an Anti-Virus Software - I can not overemphasize the need for you to use and update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. FIREWALL
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. A tutorial on Firewalls and a listing of some available ones can be found here

Do not install more than one firewall program because they will conflict with each other


4. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

5. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

6. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

7. Install Spybot - Search and Destroy - Download and install Spybot - Search and Destroy with its TeaTimer option. This will provide real time spyware and hijacker protection on your computer alongside your virus protection. You should scan your computer with the program on a regular basis just as you would with your anti-virus software. A tutorial on installing and using this product can be found here:
Instructions for - Spybot S & D and Ad-aware

8. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI