This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hijack log, looking for analysis

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have recently been given a PC which was running very slow, I have taken out what I consider to be a lot of rubbish and then run ccleaner, spybot then defragmented, the speed has improved a lot but please would someone cast an eye over my log to make sure nothing else is lurking.
thank you.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:34:41, on 09/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Apps\ActivBoard\OSD.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Packard Bell - {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - C:\Apps\IECustom\script.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe

–
End of file - 5266 bytes
Well looks clean :thumbup:

Click HERE to run Panda's ActiveScan

* You need to use IE to run this scan
* Once you are on the Panda site click the Scan your PC button
* A new window will open…click the Check Now button
* Enter your Country
* Enter your State/Province
* Enter your e-mail address and click send
* Select either Home User or Company
* Click the big Scan Now button
* If it wants to install an ActiveX component allow it
* It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
* When download is complete, click on My Computer to start the scan
* When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
That took about 3 hours to scan but here is the log….. ;******************************************************************************* ********************************************************************************* ******************* ANALYSIS: 2008-11-09 20:36:34 PROTECTIONS: 1 MALWARE: 41 SUSPECTS: 5 ;******************************************************************************* ********************************************************************************* ******************* PROTECTIONS Description Version Active Updated ;=============================================================================== ================================================================================= =================== AVG 7.5.549 7.5.549 Yes Yes ;=============================================================================== ================================================================================= =================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=============================================================================== ================================================================================= =================== 00035722 adware/comet Adware No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1678F7E1-C422-11D0-AD7D-00400515CAAA} 00039703 Application/Pskill.A HackTools No 0 Yes No C:\WINDOWS\system\RESTORE.INS[C:/OEMCUST/TOOLS/WIN32/PSKILL.EXE] 00039703 Application/Pskill.A HackTools No 0 Yes No C:\WINDOWS\RESTORE.INS[C:/OEMCUST/TOOLS/WIN32/PSKILL.EXE] 00046774 Joke/Chospe Jokes No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\My Documents\house Info\Free Cup Holder.exe 00046774 Joke/Chospe Jokes No 0 Yes No C:\Documents and Settings\TOM\My Documents\house Info\Free Cup Holder.exe 00046774 Joke/Chospe Jokes No 0 Yes No D:\Documents and Settings\Stan\My Documents\house Info\Free Cup Holder.exe 00046774 Joke/Chospe Jokes No 0 Yes No D:\System Volume Information\_restore{9AB2AC02-A367-4E03-9604-92C631BB214E}\RP29\A0003772.exe 00046774 Joke/Chospe Jokes No 0 Yes No D:\System Volume Information\_restore{9AB2AC02-A367-4E03-9604-92C631BB214E}\RP29\A0003775.exe 00103551 adware/windowenhancer Adware No 0 Yes No c:\windows\system32\sbutils 00110259 dialer.py Dialers No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8522F9B3-38C5-4AA4-AE40-7401F1BBC851} 00132710 dialer.xd Dialers No 0 Yes No HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FF3F0F03-0F01-131A-A3F9-08F02B23E0CC} 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@casalemedia[2].txt 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@doubleclick[1].txt 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No D:\Documents and Settings\Stan\Cookies\stan@doubleclick[1].txt 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@doubleclick[2].txt 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No D:\Documents and Settings\Stan\Cookies\stan@atdmt[2].txt 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@atdmt[2].txt 00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@tradedoubler[1].txt 00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@tradedoubler[1].txt 00145457 Cookie/FastClick TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@fastclick[1].txt 00145457 Cookie/FastClick TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@fastclick[1].txt 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@tribalfusion[1].txt 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@tribalfusion[2].txt 00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@mediaplex[2].txt 00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@mediaplex[1].txt 00145881 Cookie/NewMedia TrackingCookie No 0 Yes No C:\Documents and Settings\TOM\Cookies\[removed][2].txt 00147824 Cookie/Clickbank TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@clickbank[2].txt 00167642 Cookie/Com.com TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@com[1].txt 00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\TOM\Cookies\tom@com[2].txt 00167704 Cookie/Xiti TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@xiti[1].txt 00167753 Cookie/Statcounter TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@statcounter[1].txt 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\[removed][2].txt 00168061 Cookie/Apmebf TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@apmebf[1].txt 00168061 Cookie/Apmebf TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@apmebf[1].txt 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@serving-sys[1].txt 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@serving-sys[1].txt 00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\[removed]-sys[1].txt 00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\[removed]-sys[2].txt 00168109 Cookie/Adtech TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@adtech[1].txt 00168109 Cookie/Adtech TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@adtech[1].txt 00169190 Cookie/Advertising TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt 00169190 Cookie/Advertising TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@advertising[1].txt 00169190 Cookie/Advertising TrackingCookie No 0 Yes No D:\Documents and Settings\Stan\Cookies\stan@advertising[1].txt 00169287 Cookie/Adrevolver TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@adrevolver[1].txt 00169287 Cookie/Adrevolver TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@adrevolver[1].txt 00170554 Cookie/Overture TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@overture[1].txt 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@realmedia[1].txt 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@questionmarket[1].txt 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@questionmarket[2].txt 00172221 Cookie/Zedo TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@zedo[1].txt 00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@adrevolver[2].txt 00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@adrevolver[2].txt 00187950 Cookie/bravenetA TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@bravenet[1].txt 00187950 Cookie/bravenetA TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@bravenet[1].txt 00207936 Cookie/Adviva TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\administrator@adviva[2].txt 00207936 Cookie/Adviva TrackingCookie No 0 Yes No D:\Documents and Settings\Guest\Cookies\guest@adviva[2].txt 00293517 Cookie/AdDynamix TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\[removed][1].txt 00339246 Adware/VirusBurst Adware No 0 Yes No C:\RECYCLER\S-1-5-21-1659004503-1454471165-839522115-500\Dc250.tmp 00506672 Trj/Spammer.ZX Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{61F7EA25-4D2F-45A9-A7E7-6B2873809074}\RP2\A0003015.exe 01606636 Cookie/Adserver TrackingCookie No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Cookies\[removed][1].txt 02161252 Generic Trojan Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{61F7EA25-4D2F-45A9-A7E7-6B2873809074}\RP1\A0000002.exe 02555303 Trj/Cimuz.CI Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{61F7EA25-4D2F-45A9-A7E7-6B2873809074}\RP2\A0003001.dll 02555303 Trj/Cimuz.CI Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{61F7EA25-4D2F-45A9-A7E7-6B2873809074}\RP2\A0002001.dll 02555303 Trj/Cimuz.CI Virus/Trojan No 0 Yes No D:\System Volume Information\_restore{61F7EA25-4D2F-45A9-A7E7-6B2873809074}\RP2\A0001001.dll 02916589 Application/PassRock HackTools No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Desktop\kf151.zip[keyfinder.exe] 02916589 Application/PassRock HackTools No 0 Yes No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Desktop\kf151\keyfinder.exe 02919763 Trj/Downloader.MDW Virus/Trojan No 0 Yes No C:\APPS\HOMEPAGE\HOMEPGUI.EXE 03074964 Trj/CI.A Virus/Trojan No 0 No No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Desktop\kf151\keyfinder.exe[D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Desktop\kf151\keyfinder.exe][officekey.exe] 03074964 Trj/CI.A Virus/Trojan No 0 No No D:\Documents and Settings\Administrator.RENT-M407LWRWHD\Desktop\kf151.zip[keyfinder.exe][keyfinder.exe][officekey.exe] ;=============================================================================== ================================================================================= =================== SUSPECTS Sent Location ;=============================================================================== ================================================================================= =================== No C:\WINDOWS\system32\suppdll.dll No C:\WINDOWS\System88\Folder Lock 5.2.6 With [Serial]\Folder Lock 5.2.6 With [Serial]\Folder Lock 5.2.6.exe No D:\Program Files\Folder Lock\Locked\³▒À░ʳ\Folder Lock 5.2.6 With [Serial]\Folder Lock 5.2.6 With [Serial]\Folder Lock 5.2.6.exe No D:\System Volume Information\_restore{61F7EA25-4D2F-45A9-A7E7-6B2873809074}\RP2\A0002002.dll No D:\WINDOWS\system32\suppdll.dll ;=============================================================================== ================================================================================= =================== VULNERABILITIES Id Severity Description ;=============================================================================== ================================================================================= =================== 182048 HIGH MS07-069 176382 HIGH MS07-057 170906 HIGH MS07-045 170904 HIGH MS07-043 164913 HIGH MS07-033 160623 HIGH MS07-027 150253 HIGH MS07-016 141030 HIGH MS06-072 ;=============================================================================== ================================================================================= ===================
Run - ATF Cleaner instructions here.

—————-


Then download Malwarebytes' Anti-Malware to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform FULL SCAN, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location and post it here. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Malwarebytes' Anti-Malware 1.30 Database version: 1378 Windows 5.1.2600 Service Pack 2 10/11/2008 09:19:40 mbam-log-2008-11-10 (09-19-40).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 235009 Time elapsed: 3 hour(s), 15 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1678f7e1-c422-11d0-ad7d-00400515caaa} (Spyware.Comet.Cursor) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8} (Adware.180Solutions) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: D:\WINDOWS\system32\fdeployt.dll (Trojan.Zapchast) -> Quarantined and deleted successfully. D:\WINDOWS\system32\FwsVpno.dll (Trojan.Zapchast) -> Quarantined and deleted successfully. D:\WINDOWS\system32\confmspb.dll (Trojan.Zapchast) -> Quarantined and deleted successfully. D:\WINDOWS\system32\dgsetupd.dll (Trojan.Zapchast) -> Quarantined and deleted successfully.
Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.



1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net


2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Combofix log, followed by Hijack this log…..

ComboFix 08-11-09.04 - TOM 2008-11-10 21:15:53.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.414 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\dao350.dll
c:\windows\system32\MabryObj.dll

.
((((((((((((((((((((((((( Files Created from 2008-10-10 to 2008-11-10 )))))))))))))))))))))))))))))))
.

2008-11-09 21:37 . 2008-11-09 21:37 d——– c:\documents and settings\TOM\Application Data\Malwarebytes
2008-11-09 21:37 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-09 21:36 . 2008-11-09 21:37 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-09 21:36 . 2008-11-09 21:36 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-09 21:36 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-09 16:41 . 2008-11-09 16:41 d——– c:\program files\Panda Security
2008-11-09 16:41 . 2008-06-19 17:24 28,544 –a—— c:\windows\system32\drivers\pavboot.sys
2008-11-09 13:29 . 2008-11-09 13:29 d——– c:\program files\eBay
2008-11-09 13:29 . 2008-11-09 13:29 d——– c:\documents and settings\All Users\eBay
2008-11-09 12:34 . 2008-11-09 12:34 d——– c:\program files\Trend Micro
2008-11-07 12:24 . 2004-08-04 07:56 159,232 –a—— c:\windows\system32\ptpusd.dll
2008-11-07 12:24 . 2004-08-04 05:58 15,104 –a—— c:\windows\system32\drivers\usbscan.sys
2008-11-07 12:24 . 2004-08-04 05:58 15,104 –a—— c:\windows\system32\dllcache\usbscan.sys
2008-11-07 12:24 . 2001-08-17 22:36 5,632 –a—— c:\windows\system32\ptpusb.dll
2008-11-06 23:36 . 2008-11-06 23:39 d——– c:\documents and settings\TOM\Application Data\vlc
2008-11-06 23:26 . 2008-11-06 23:26 d——– c:\program files\VideoLAN
2008-11-06 21:13 . 2008-11-07 07:59 d——– c:\windows\system32\CatRoot_bak
2008-11-05 12:23 . 2008-11-05 12:23 1,044,480 -ra—— c:\windows\system32\roboex32.dll
2008-11-05 12:23 . 2008-11-05 12:23 49,152 -ra—— c:\windows\system32\inetwh32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-09 13:30 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-08 22:36 ——— d—–w c:\program files\Folder Lock
2008-10-15 16:57 332,800 ——w c:\windows\system32\dllcache\netapi32.dll
2008-09-15 11:57 1,846,016 —-a-w c:\windows\system32\win32k.sys
2008-09-15 11:57 1,846,016 ——w c:\windows\system32\dllcache\win32k.sys
2008-08-28 10:04 333,056 —-a-w c:\windows\system32\dllcache\srv.sys
2008-08-19 09:30 18,432 —-a-w c:\windows\system32\dllcache\iedw.exe
2008-08-14 10:00 2,180,352 —-a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 10:00 2,180,352 —-a-w c:\windows\system32\dllcache\ntoskrnl.exe
2008-08-14 09:58 2,136,064 ——w c:\windows\system32\dllcache\ntkrnlmp.exe
2008-08-14 09:51 138,368 —-a-w c:\windows\system32\dllcache\afd.sys
2008-08-14 09:22 2,057,728 —-a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 09:22 2,057,728 —-a-w c:\windows\system32\dllcache\ntkrnlpa.exe
2008-08-14 09:22 2,015,744 ——w c:\windows\system32\dllcache\ntkrpamp.exe
2005-06-18 14:52 164 -c-ha-w c:\documents and settings\All Users\hpothb07.dat
2005-03-29 18:23 72,272 -c–a-w c:\documents and settings\TOM\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-09-01 376912]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EM_EXEC"="c:\progra~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-01-28 35328]
"ACTIVBOARD"="c:\apps\ActivBoard\MMKeybd.exe" [2001-05-03 159744]
"VCSPlayer"="c:\program files\Virtual CD v4 SDK\system\vcsplay.exe" [2002-06-07 299008]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"SmcService"="c:\progra~1\Sygate\SPF\smc.exe" [2004-10-15 2577632]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-11-06 590848]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-03-24 219136]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-04-24 113664]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= IR41_32.DLL
"MSACM.CEGSM"= mobilev.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ActivSurf]
–a–c— 2002-08-12 15:15 16384 c:\apps\ActivSurf\4448364\Program\backWeb-4448364.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"nhksrv"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
R1 mchInjDrv;madCodeHook DLL injection driver;c:\windows\system32\Drivers\mchInjDrv.sys [2008-03-22 2560]
R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\DRIVERS\msikbd2k.sys [2000-10-03 6942]
R1 vcsmpdrv;vcsmpdrv;c:\windows\system32\DRIVERS\vcsmpdrv.sys [2002-06-07 49232]
R2 VCSSecS;Virtual CD v4 Security service (SDK - Version);c:\program files\Virtual CD v4 SDK\system\vcssecs.exe [2002-05-16 139264]
R3 STAC97NA;SigmaTel 3D Environmental Audio;c:\windows\system32\drivers\stac97na.sys [2002-06-05 296179]
R3 STAC97NH;STAC97NH;c:\windows\system32\drivers\stac97nh.sys [2002-06-05 231855]
S3 V90drv;v90drv;c:\windows\system32\DRIVERS\v90drv.sys [2001-11-29 1432836]
S4 nhksrv;Netropa NHK Server;c:\apps\ActivBoard\nhksrv.exe [2000-09-13 28672]

*Newly Created Service* - PAVBOOT
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
MSConfigStartUp-Microsoft Works Portfolio - c:\program files\Microsoft Works\WksSb.exe
MSConfigStartUp-Microsoft Works Update Detection - c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
MSConfigStartUp-MoneyAgent - c:\program files\Microsoft Money\System\Money Express.exe
MSConfigStartUp-MoneyStartUp10 - c:\program files\Microsoft Money\System\Activation.exe
MSConfigStartUp-PestTrap - c:\program files\PestTrap\PestTrap.exe
MSConfigStartUp-Spyware Begone - c:\spywarebegone\SpywareBeGone.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
MSConfigStartUp-WorksFUD - c:\program files\Microsoft Works\wkfud.exe


.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = about:blank
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-Internet Settings,ProxyOverride = 127.0.0.1
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 -: {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - c:\apps\IECustom\script.htm
O9 -: {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - c:\apps\IECustom\script.htm -
O18 -: WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\Microsoft ActiveSync\CENetFlt.dll
O18 -: WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\Microsoft ActiveSync\CENetFlt.dll
O18 -: WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\Microsoft ActiveSync\CENetFlt.dll
O18 -: WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\Microsoft ActiveSync\CENetFlt.dll
O18 -: WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\Microsoft ActiveSync\CENetFlt.dll
O18 -: WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\Microsoft ActiveSync\CENetFlt.dll

O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 21:18:19
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Completion time: 2008-11-10 21:19:14
ComboFix-quarantined-files.txt 2008-11-10 21:19:11

Pre-Run: 5,694,033,920 bytes free
Post-Run: 5,681,340,416 bytes free

152 — E O F — 2008-11-07 08:26:01

HiJack this log….

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:21:27, on 10/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Apps\ActivBoard\MMKeybd.exe
C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Apps\ActivBoard\TrayMon.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Apps\ActivBoard\OSD.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\imapi.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\DOCUME~1\TOM\LOCALS~1\Temp\Temporary Directory 1 for HiJackThis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\apps\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [ACTIVBOARD] C:\Apps\ActivBoard\MMKeybd.exe
O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Packard Bell - {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - C:\Apps\IECustom\script.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe

–
End of file - 5694 bytes
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI