My Computer is all messed up...please help!!!

  1. #1

    Unhappy My Computer is all messed up...please help!!!

    Ive done scans with AVAST, Spybot, CCleaner, Malwarebytes, and numerous others...Problem is still here though...Just to name a few- Redirecting when a link is clicked on google, random numer .exes popping up, Computer is a lot slower than it used to be...What do i need to do to fix it??? Please help...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:16:54 AM, on 4/21/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Common Files\AOL\1148417991\ee\AOLSoftware.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    C:\Program Files\Tiny Utilities\Vitrite\Vitrite.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = AOL.com - Welcome to AOL
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = AOL.com - Welcome to AOL
    O2 - BHO: C:\WINDOWS\system32\jh9fgo4ksdgf.dll - {d7bf4552-94f1-42bd-f434-3604812c856d} - C:\WINDOWS\system32\jh9fgo4ksdgf.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1148417991\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\jxbml43.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Windows Resurections] C:\WINDOWS\TEMP\jxbml43.exe (User 'Default user')
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    O4 - Startup: Vitrite.lnk = C:\Program Files\Tiny Utilities\Vitrite\Vitrite.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presar io&pf=laptop
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O22 - SharedTaskScheduler: sfdawtawgreage4tregrgae34 - {D7BF4552-94F1-42BD-F434-3604812C856D} - C:\WINDOWS\system32\jh9fgo4ksdgf.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\
    O24 - Desktop Component 0: (no name) - file:///C:/Documents%20and%20Settings/Greg/My%20Documents/My%20Pictures/9uh7yh%20117.JPG

    --
    End of file - 8170 bytes


  2. #2
    broni is offline Senior Member
    Your computer is still infected.

    Please download ComboFix from Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
      • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      • Close any open browsers.
      • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

  3. #3
    Thank you very much for the help...I did exactly what you said and here is the new Hijackthis log and the Combofix log.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:20:01 PM, on 4/21/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\Common Files\AOL\1148417991\ee\AOLSoftware.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    C:\Program Files\Tiny Utilities\Vitrite\Vitrite.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\HPZinw12.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = AOL.com - Welcome to AOL
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1148417991\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
    O4 - Startup: Vitrite.lnk = C:\Program Files\Tiny Utilities\Vitrite\Vitrite.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presar io&pf=laptop
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...1/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...26/mcgdmgr.cab
    O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\
    O24 - Desktop Component 0: (no name) - file:///C:/Documents%20and%20Settings/Greg/My%20Documents/My%20Pictures/9uh7yh%20117.JPG

    --
    End of file - 7860 bytes

    __________________________________________________ _____________________________

    ComboFix 09-04-22.02 - Greg 04/21/2009 18:06.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.382.88 [GMT -5:00]
    Running from: c:\documents and settings\Greg\Desktop\ComboFix.exe
    AV: avast! antivirus 4.8.1335 [VPS 090421-0] *On-access scanning disabled* (Updated)
    FW: Norton Internet Worm Protection *disabled*
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
    c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
    c:\windows\system32\_000007_.tmp.dll
    c:\windows\system32\dahovifo.dll
    c:\windows\system32\drivers\gxvxcroyuhypithxfmloak fraqjuubntomyqx.sys
    c:\windows\system32\drivers\ovfsthydgftcrmqcbaoers inctskjlhlicygnw.sys
    c:\windows\system32\gxvxccounter
    c:\windows\system32\gxvxcewqxaektbuekkmtooiotxdpsb ppfbrru.dll
    c:\windows\system32\hivibisu.dll
    c:\windows\system32\jh9fgo4ksdgf.dll
    c:\windows\system32\ovfsthekvnwyrjaqpnihktesibwfdj opxttnkl.dll
    c:\windows\system32\ovfsthjtrwvreedkvitbcavpecjefa djdgrphp.dat
    c:\windows\system32\ovfsthmodiayllxtvdnppaumewuoel rmrxwqep.dll
    c:\windows\system32\ovfsthnveqkhsorjarfjmmakmlqtok vvcgfhlm.dll
    c:\windows\system32\ovfsthxplpegmfdfobsmqjqidlykdo phaffjfx.dat
    c:\windows\system32\p2hhr.bat
    c:\windows\system32\sakadadu.dll
    D:\Autorun.inf
    F:\Autorun.inf

    ----- BITS: Possible infected sites -----

    hxxp://porntube67.com
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_ovfsthemmqbihbtkmnkskxhdduhopqfvisfqmu
    -------\Service_GXVXCSERV.SYS
    -------\Legacy_oreans32
    -------\Service_oreans32


    ((((((((((((((((((((((((( Files Created from 2009-03-21 to 2009-04-21 )))))))))))))))))))))))))))))))
    .

    2009-04-21 18:06 . 2009-04-21 18:07 -------- d-----w c:\program files\QuickTime
    2009-04-21 18:06 . 2009-04-21 18:06 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
    2009-04-21 18:05 . 2009-04-21 18:05 -------- d-----w c:\documents and settings\Greg\Local Settings\Application Data\Apple
    2009-04-21 18:05 . 2009-04-21 18:05 -------- d-----w c:\program files\Apple Software Update
    2009-04-21 18:05 . 2009-04-21 18:05 -------- d-----w c:\documents and settings\All Users\Application Data\Apple
    2009-04-21 18:04 . 2009-04-21 18:04 -------- d-----w c:\documents and settings\Greg\Local Settings\Application Data\Apple Computer
    2009-04-21 16:16 . 2009-04-21 16:16 -------- d-----w c:\program files\Trend Micro
    2009-04-19 01:53 . 2009-04-19 01:59 -------- d-----w c:\documents and settings\Greg\Application Data\Mp3tag
    2009-04-19 01:53 . 2009-04-19 01:53 -------- d-----w c:\program files\Mp3tag
    2009-04-19 00:15 . 2009-04-19 00:15 -------- d-----w c:\documents and settings\Greg\Application Data\Smith Micro
    2009-04-18 01:59 . 2009-04-20 01:01 664 ----a-w c:\windows\system32\d3d9caps.dat
    2009-04-16 20:40 . 2009-04-16 20:38 9256 ----a-w c:\windows\system32\drivers\sscdwhnt.sys
    2009-04-16 20:40 . 2009-04-16 20:38 9256 ----a-w c:\windows\system32\drivers\sscdwh.sys
    2009-04-16 20:40 . 2009-04-16 20:38 9256 ----a-w c:\windows\system32\drivers\sscdcmnt.sys
    2009-04-16 20:40 . 2009-04-16 20:38 9256 ----a-w c:\windows\system32\drivers\sscdcm.sys
    2009-04-16 20:40 . 2009-04-16 20:38 86824 ----a-w c:\windows\system32\drivers\sscdserd.sys
    2009-04-16 20:40 . 2009-04-16 20:38 80552 ----a-w c:\windows\system32\drivers\sscdbus.sys
    2009-04-16 20:40 . 2009-04-16 20:38 11944 ----a-w c:\windows\system32\drivers\sscdmdfl.sys
    2009-04-16 20:40 . 2009-04-16 20:38 106792 ----a-w c:\windows\system32\drivers\sscdmdm.sys
    2009-04-16 20:40 . 2009-04-16 20:40 -------- d-----w c:\program files\Samsung
    2009-04-16 20:39 . 2008-06-05 07:59 222552 ------w c:\windows\RM.exe
    2009-04-16 20:14 . 2009-04-16 20:14 33824 ----a-w c:\windows\system32\drivers\oreans32.sys
    2009-04-16 20:07 . 2009-04-20 21:46 21504 ----a-w c:\windows\system32\ak1.exe
    2009-04-16 20:01 . 2009-04-16 20:02 -------- d-----w c:\program files\QPST
    2009-04-15 18:41 . 2009-04-15 18:41 -------- d-----w c:\documents and settings\Greg\Application Data\Malwarebytes
    2009-04-15 18:35 . 2009-04-06 20:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
    2009-04-15 18:35 . 2009-04-06 20:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-15 18:35 . 2009-04-15 18:35 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
    2009-04-15 18:35 . 2009-04-15 18:35 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-04-13 21:00 . 2009-04-13 21:00 -------- d-----w c:\program files\Alwil Software
    2009-04-13 20:49 . 2009-04-13 20:49 -------- d-----w c:\program files\CCleaner
    2009-04-13 15:26 . 2004-10-01 00:01 139345 ----a-w c:\windows\system32\hpzlnt12.dll
    2009-04-13 15:25 . 2004-09-30 23:45 229376 ----a-r c:\windows\system32\hpovst08.dll
    2009-04-13 15:25 . 2004-09-30 23:44 581632 ----a-r c:\windows\system32\hpotscl.dll
    2009-04-13 15:24 . 2009-04-13 15:24 696 ----a-w c:\windows\hpntwksetup.ini
    2009-04-13 15:18 . 2009-04-13 15:54 68951 ----a-w c:\windows\hpoins05.dat
    2009-04-13 15:18 . 2004-12-14 15:39 19696 ------w c:\windows\hpomdl05.dat
    2009-04-12 01:47 . 2009-04-12 01:47 -------- d-----w c:\program files\AVG
    2009-04-11 23:59 . 2009-04-11 23:59 155 ----a-w c:\windows\system32\SelfDel.bat
    2009-04-11 23:44 . 2009-04-21 23:15 109010 ----a-w c:\windows\system32\drivers\504c987b.sys
    2009-04-11 22:43 . 2009-04-11 22:43 24576 ----a-w c:\documents and settings\Greg\Local Settings\Application Data\cp_setup_assist.exe
    2009-04-11 21:50 . 2009-04-11 21:50 -------- d-----w c:\program files\Alcohol Soft
    2009-04-11 19:14 . 2009-04-21 18:13 -------- d-----w c:\documents and settings\Greg\Local Settings\Application Data\MediaMonkey
    2009-04-11 19:14 . 2009-04-11 19:14 -------- d-----w c:\program files\MediaMonkey
    2009-04-08 18:24 . 2009-04-08 18:24 1409 ----a-w c:\windows\system32\tmp8DBE6.FOT
    2009-04-08 18:24 . 2009-04-08 18:24 1409 ----a-w c:\windows\system32\tmp71CE6.FOT
    2009-04-08 18:24 . 2009-04-08 18:24 1409 ----a-w c:\windows\system32\tmp63CE6.FOT
    2009-04-08 18:24 . 2009-04-08 18:24 1409 ----a-w c:\windows\system32\tmp55CE6.FOT
    2009-04-08 17:49 . 2009-04-08 17:49 717296 ----a-w c:\windows\system32\drivers\sptd.sys
    2009-04-08 17:36 . 2009-04-08 17:36 -------- d-----w c:\program files\Kap.SATr

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
    .
    2009-04-21 23:13 . 2006-02-16 10:43 297 ----a-w C:\hpqp.ini
    2009-04-21 23:13 . 2006-02-16 10:43 39 ----a-w C:\XP_TV.ini
    2009-04-21 22:44 . 2009-01-24 05:29 -------- d-----w c:\documents and settings\Greg\Application Data\uTorrent
    2009-04-20 22:16 . 2009-01-24 05:29 -------- d-----w c:\program files\uTorrent
    2009-04-16 20:01 . 2006-02-16 09:51 -------- d--h--w c:\program files\InstallShield Installation Information
    2009-04-13 20:52 . 2009-01-24 04:10 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-04-13 15:42 . 2006-02-16 10:02 -------- d-----w c:\program files\HP
    2009-04-13 15:41 . 2006-02-16 10:04 -------- d-----w c:\program files\Hewlett-Packard
    2009-04-10 22:37 . 2006-05-23 22:48 -------- d-----w c:\program files\Common Files\Adobe
    2009-04-09 20:34 . 2009-01-24 04:10 -------- d-----w c:\program files\Spybot - Search & Destroy
    2009-04-09 20:34 . 2006-02-16 10:35 -------- d-----w c:\program files\Google
    2009-02-15 06:14 . 2008-10-17 12:46 81 ----a-w C:\DVDPATH.TXT
    2009-02-09 10:19 . 2007-03-08 13:47 1846272 ------w c:\windows\system32\dllcache\win32k.sys
    2009-02-09 10:19 . 2004-08-04 08:00 1846272 ----a-w c:\windows\system32\win32k.sys
    2009-01-25 01:55 . 2009-01-25 01:55 11047052 ----a-w c:\windows\system32\Doom 3 Screensaver.scr
    2009-01-24 03:16 . 2009-01-24 03:11 6112 ----a-w c:\windows\BricoPackFoldersDelete.cmd
    2009-01-24 03:16 . 2009-01-24 03:16 54459 ----a-w c:\windows\BricoPackUninst.cmd
    2009-01-24 03:16 . 2004-08-04 08:00 218624 ----a-w c:\windows\system32\uxtheme.dll
    2009-01-23 01:48 . 2009-01-23 01:48 98304 ----a-w c:\windows\system32\CmdLineExt.dll
    2008-02-17 22:40 . 2006-05-23 09:42 69040 ----a-w c:\documents and settings\Greg\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2007-12-04 00:20 . 2007-12-04 00:20 64632 ----a-w c:\documents and settings\Greg\Application Data\GDIPFONTCACHEV1.DAT
    2006-05-23 09:44 . 2006-05-23 09:42 127 ----a-w c:\documents and settings\Greg\Local Settings\Application Data\fusioncache.dat
    2007-07-21 21:23 . 2007-07-21 21:23 159 --sha-r c:\windows\Regbak.dat
    2007-01-28 22:48 . 2007-01-28 22:48 22 --sha-w c:\windows\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe" [2009-01-24 68856]
    "AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2009-04-02 203928]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
    "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-11 344064]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
    "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
    "QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
    "eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-07 409600]
    "Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
    "RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
    "hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
    "HostManager"="c:\program files\Common Files\AOL\1148417991\ee\AOLSoftware.exe" [2006-03-08 48280]
    "RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-05-23 26112]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
    "IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-03-27 126104]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp. exe" [2009-02-05 81000]

    c:\documents and settings\Greg\Start Menu\Programs\Startup\
    RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-3-18 630784]
    Vitrite.lnk - c:\program files\Tiny Utilities\Vitrite\Vitrite.exe [2002-5-21 26624]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
    HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\America Online 9.0\\waol.exe"=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
    "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
    "c:\\Program Files\\Common Files\\AOL\\1148417991\\EE\\AOLServiceHost.exe"=
    "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
    "c:\\Program Files\\America Online 9.0a\\waol.exe"=
    "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
    "c:\\Program Files\\uTorrent\\uTorrent.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

    S1 aswsp;avast! Self Protection; [x]
    S2 aswfsblk;aswfsblk;c:\windows\system32\DRIVERS\aswF sBlk.sys [2009-02-05 20560]
    S3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFH WATI.sys [2005-08-22 231424]


    --- Other Services/Drivers In Memory ---

    *Deregistered* - BootScreen

    [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\D]
    \Shell\AutoRun\command - D:\setupSNK.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\F]
    \Shell\AutoRun\command - wd_windows_tools\WDSetup.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{eac19af5-e5e4-11dd-8c91-0014a57b398e}]
    \Shell\AutoRun\command - G:\WDSetup.exe
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{d7bf4552-94f1-42bd-f434-3604812c856d} - c:\windows\system32\jh9fgo4ksdgf.dll
    HKU-Default-Run-Windows Resurections - c:\windows\TEMP\jxbml43.exe
    SharedTaskScheduler-{D7BF4552-94F1-42BD-F434-3604812C856D} - c:\windows\system32\jh9fgo4ksdgf.dll


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com/
    uSearch Page = hxxp://www.google.com
    uSearch Bar =
    uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presar io&pf=laptop
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\Greg\Application Data\Mozilla\Firefox\Profiles\zcgm9we7.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    .

    ************************************************** ************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-04-21 18:15
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
    Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe??????????p????|?????? ???B?????????????hLC? ??????

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    ************************************************** ************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\5 04c987b]
    "ImagePath"="\SystemRoot\System32\drivers\504c987b .sys"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\s-1-5-21-2947147797-864919052-3012701610-1006\Software\Microsoft\SystemCertificates\Address Book*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(804)
    c:\windows\system32\Ati2evxx.dll

    - - - - - - - > 'explorer.exe'(2324)
    c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
    c:\progra~1\WINDOW~1\wmpband.dll
    c:\windows\system32\ntshrui.dll
    c:\windows\system32\NETSHELL.dll
    c:\windows\system32\credui.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\program files\Common Files\aolshare\aolshcpy.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\ati2evxx.exe
    c:\program files\Alwil Software\Avast4\aswUpdSv.exe
    c:\program files\Alwil Software\Avast4\ashServ.exe
    c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    c:\program files\Common Files\LightScribe\LSSrvc.exe
    c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
    c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
    c:\windows\system32\ati2evxx.exe
    c:\progra~1\HPQ\shared\HPQTOA~1.EXE
    c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
    c:\windows\system32\HPZipm12.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\system32\HPZinw12.exe
    .
    ************************************************** ************************
    .
    Completion time: 2009-04-21 18:19 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-04-21 23:19

    Pre-Run: 30,564,790,272 bytes free
    Post-Run: 30,711,742,464 bytes free

    WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect

    256 --- E O F --- 2009-03-24 14:21

  4. #4
    broni is offline Senior Member
    Save 20% on AVG Internet Security 2012 Suite!
    It looks pretty good

    *** You need to update Java:
    Download Free Java Software - Sun Microsystems
    JRE 6 Update 13
    Uninstall all previous versions of Java through Add\Remove ("Programs and Features" in Vista).

    Note
    1. The Java Quick Starter (JQS.exe) adds unnecessary startup service. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
    Click OK and reboot your computer.
    2. Make sure to uncheck Yahoo!Toolbar box during installation process.

    Your computer is clean

    1. Download, and install CCleaner: CCleaner - Builds. Get "Slim" version.
    Read CCleaner instruction here: CCleaner Manual.
    Run CCleaner.

    2. Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    3. Restart computer.

    4. Turn System Restore on.

    5. Make sure, Windows Updates are current.

    6. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    7. Download, and install WOT (Web OF Trust): Internet Security | WOT Web of Trust. It'll warn you (in most cases) about dangerous web sites.

    8. Read How did I get infected?, With steps so it does not happen again!: How did I get infected?

    9. Let me know, how your computer is doing.

+ Reply to Thread