This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

sound problem...

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hit here, im running windows 7 and am having a couple problems.

1. my sound won't play in internet exporer, or google chrome, but it will play all the system sounds that my comp makes and i can play videos and music on wmp, itunes etc… when im on facebook and try to watch a video thats posted from youtube it plays with no sound for two seconds then stops.

2. while i'm looking something up in google when i've clicked on the link to the page that i want, something redirects me almost every time to some sort of spam page. If i right click and open in new tab/browser it's fine.

Maybe the ad problem is somehow linked to the sound problem? i think i've checked almost all my settings, in control panel, my sound card, internet explorer > multemedia options etc and nothing.

i updated my flash adobe and all that jazz ….

also, when i updated my shockwave , when it was done it had some free demo games i could try online and just to check i tried one and the sound worked on that so i donno.

there's another website i go to for music called the hypemachine hype.com and the music doesn't play in there either when it normally would.

please help :)


during my hijack this log this error came up… (there was more to it) but this is all i remember
"system denied acces to hosts files"

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:36:07 AM, on 30/06/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\EgisTec IPS\PmmUpdate.exe
C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
C:\Program Files\EgisTec IPS\EgisUpdate.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\prevhost.exe
C:\Program Files\Windows Media Player\wmprph.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Users\Monta\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.msn.com/?ocid=OIE9HP
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.msn.com/?ocid=OIE9HP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…34ww65w4712u741
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer, optimized for Bing and MSN
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: PlayBryte BHO - {61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd} - mscoree.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: PlayBryte Toolbar - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [WatcherHelper] "C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [iBryte playbryte Desktop] C:\Program Files\iBryte\playbryte\ibrytedesktop.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Users\Monta\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [InstallIQUpdater] "C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos-beta/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files\Launch Manager\dsiwmis.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files\Acer\Registration\GREGsvc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 8922 bytes
:welcome:

We dont use Hijackthis much anymore, lets do this

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.

[external image: Posted Image]
Thank You Atribune





Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please






OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
malware log Malwarebytes' Anti-Malware 1.51.0.1200 www.malwarebytes.org Database version: 7008 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 02/07/2011 10:38:12 PM mbam-log-2011-07-02 (22-38-11).txt Scan type: Quick scan Objects scanned: 155220 Time elapsed: 11 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
otl scan:

OTL logfile created on: 7/2/2011 10:50:40 PM - Run 2
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Monta\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1013.10 Mb Total Physical Memory | 303.66 Mb Available Physical Memory | 29.97% Memory free
1.99 Gb Paging File | 0.67 Gb Available in Paging File | 33.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 219.79 Gb Total Space | 29.30 Gb Free Space | 13.33% Space Free | Partition Type: NTFS

Computer Name: MONTA-PC | User Name: Monta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Monta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\prevhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Acer Incorporated)
PRC - C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe (Sierra Wireless Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Monta\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Acer\Acer ePower Management\SysHook.dll (Acer Incorporated)


========== Win32 Services (SafeList) ==========

SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) – C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (GameConsoleService) – C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (RS_Service) – C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV - (GREGService) – C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (EUCR) – C:\Windows\System32\drivers\EUCR6SK.sys (ENE Technology Inc.)
DRV - (L1C) – C:\Windows\System32\drivers\L1C62x86.sys (Atheros Communications, Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (mwlPSDVDisk) – C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV - (mwlPSDNServ) – C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV - (mwlPSDFilter) – C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (SWMX00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…34ww65w4712u741


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3581049348-171761381-3618842985-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.msn.com/?ocid=OIE9HP
IE - HKU\S-1-5-21-3581049348-171761381-3618842985-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3581049348-171761381-3618842985-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ca.msn.com/?ocid=OIE9HP
IE - HKU\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2011/06/13 23:35:54 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [iBryte playbryte Desktop] File not found
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [SuiteTray] C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [WatcherHelper] C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe (Sierra Wireless Inc.)
O4 - HKU\S-1-5-21-3581049348-171761381-3618842985-1000..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group)
O4 - HKU\S-1-5-21-3581049348-171761381-3618842985-1000..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-3581049348-171761381-3618842985-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} http://download.macromedia.com/pub/shockwa…are/awswaxf.cab (Macromedia Authorware Web Player Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab (IWinAmpActiveX Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/02 02:49:20 | 000,000,000 | —D | C] – C:\DFU
[2011/07/02 02:33:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/07/02 02:31:45 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/07/02 02:31:28 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/07/02 02:30:28 | 000,000,000 | —D | C] – C:\Windows\LastGood
[2011/07/01 01:58:41 | 000,000,000 | —D | C] – C:\Users\Monta\Desktop\SilentWeaponsQuietWar-TripHopCollectionV1
[2011/06/30 12:45:23 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{838C7696-47FF-406A-BCF1-70625E9856AC}
[2011/06/30 00:24:35 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{C00E4C12-60EC-4E51-A7F8-645BD3B324FB}
[2011/06/29 23:31:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/06/29 23:31:50 | 000,232,448 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\mp3fhg.acm
[2011/06/29 23:31:49 | 000,237,568 | —- | C] (www.helixcommunity.org) – C:\Windows\System32\yv12vfw.dll
[2011/06/29 23:31:49 | 000,151,552 | —- | C] (fccHandler) – C:\Windows\System32\ac3acm.acm
[2011/06/29 23:31:44 | 000,000,000 | —D | C] – C:\Program Files\K-Lite Codec Pack
[2011/06/29 23:20:07 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_43.dll
[2011/06/29 23:20:07 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_7.dll
[2011/06/29 23:20:07 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_7.dll
[2011/06/29 23:20:07 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_5.dll
[2011/06/29 23:20:06 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_43.dll
[2011/06/29 23:20:06 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_43.dll
[2011/06/29 23:20:06 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_43.dll
[2011/06/29 23:20:05 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_43.dll
[2011/06/29 23:20:05 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_6.dll
[2011/06/29 23:20:05 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_6.dll
[2011/06/29 23:20:05 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_4.dll
[2011/06/29 23:20:05 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_7.dll
[2011/06/29 23:20:04 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_42.dll
[2011/06/29 23:20:04 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_42.dll
[2011/06/29 23:20:04 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_5.dll
[2011/06/29 23:20:03 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_42.dll
[2011/06/29 23:20:03 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_42.dll
[2011/06/29 23:20:02 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_41.dll
[2011/06/29 23:20:02 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_4.dll
[2011/06/29 23:20:02 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_4.dll
[2011/06/29 23:20:01 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_40.dll
[2011/06/29 23:20:01 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_40.dll
[2011/06/29 23:20:01 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_40.dll
[2011/06/29 23:20:01 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_6.dll
[2011/06/29 23:20:00 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_3.dll
[2011/06/29 23:20:00 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_3.dll
[2011/06/29 23:20:00 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_2.dll
[2011/06/29 23:20:00 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_5.dll
[2011/06/29 23:19:59 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2011/06/29 23:19:59 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_2.dll
[2011/06/29 23:19:59 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2011/06/29 23:19:59 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_2.dll
[2011/06/29 23:19:59 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_1.dll
[2011/06/29 23:19:58 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2011/06/29 23:19:57 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_1.dll
[2011/06/29 23:19:57 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_1.dll
[2011/06/29 23:19:57 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_0.dll
[2011/06/29 23:19:56 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_38.dll
[2011/06/29 23:19:56 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_0.dll
[2011/06/29 23:19:56 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_38.dll
[2011/06/29 23:19:56 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_0.dll
[2011/06/29 23:19:56 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_4.dll
[2011/06/29 23:19:55 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_37.dll
[2011/06/29 23:19:55 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_37.dll
[2011/06/29 23:19:55 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_37.dll
[2011/06/29 23:19:55 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_3.dll
[2011/06/29 23:19:54 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_36.dll
[2011/06/29 23:19:54 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_36.dll
[2011/06/29 23:19:54 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_10.dll
[2011/06/29 23:19:53 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_36.dll
[2011/06/29 23:19:52 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2011/06/29 23:19:52 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_35.dll
[2011/06/29 23:19:52 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_35.dll
[2011/06/29 23:19:52 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_9.dll
[2011/06/29 23:19:50 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_34.dll
[2011/06/29 23:19:50 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_34.dll
[2011/06/29 23:19:50 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_34.dll
[2011/06/29 23:19:50 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_8.dll
[2011/06/29 23:19:50 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_2.dll
[2011/06/29 23:19:44 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_33.dll
[2011/06/29 23:19:44 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_33.dll
[2011/06/29 23:19:44 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_7.dll
[2011/06/29 23:19:44 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_3.dll
[2011/06/29 23:19:43 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_33.dll
[2011/06/29 23:19:42 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10.dll
[2011/06/29 23:19:42 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_6.dll
[2011/06/29 23:19:42 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_5.dll
[2011/06/29 23:19:42 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_4.dll
[2011/06/29 23:19:42 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_1.dll
[2011/06/29 23:19:41 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_31.dll
[2011/06/29 23:19:40 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_3.dll
[2011/06/29 23:19:40 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_2.dll
[2011/06/29 23:19:40 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_1.dll
[2011/06/29 23:19:40 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_2.dll
[2011/06/29 23:19:40 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_1.dll
[2011/06/29 23:19:36 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_30.dll
[2011/06/29 23:19:35 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_29.dll
[2011/06/29 23:19:35 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_28.dll
[2011/06/29 23:19:35 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_27.dll
[2011/06/29 23:19:35 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_26.dll
[2011/06/29 23:19:35 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_0.dll
[2011/06/29 23:19:35 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_0.dll
[2011/06/29 23:19:34 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_25.dll
[2011/06/29 23:19:33 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_24.dll
[2011/06/29 23:17:04 | 000,000,000 | —D | C] – C:\Windows\System32\directx
[2011/06/29 23:15:59 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Roaming\Nullsoft
[2011/06/29 22:34:10 | 000,000,000 | —D | C] – C:\Windows\System32\Adobe
[2011/06/28 16:45:24 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2011/06/28 16:45:24 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2011/06/28 16:45:23 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2011/06/28 16:45:23 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2011/06/28 16:45:23 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2011/06/28 16:45:22 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2011/06/27 19:49:57 | 000,000,000 | —D | C] – C:\Users\Monta\Desktop\Little Hell
[2011/06/27 19:24:48 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{BF153F72-0A84-4B32-A5DD-1090FE9D891B}
[2011/06/27 18:42:08 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/06/27 01:40:06 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{9FAB7B89-5835-4CD8-A38E-F2C09B42C63C}
[2011/06/26 23:26:46 | 000,000,000 | —D | C] – C:\Users\Monta\Desktop\The Big Lebowski(1998).720p.BRRip.H264.ResourceRG by Dusty
[2011/06/26 14:47:21 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{9E3EE5CD-6C23-4D4F-A913-8D99E5EFF865}
[2011/06/26 04:14:52 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{8276F5F5-0825-4FF8-95E5-D49EB1B48049}
[2011/06/25 00:06:57 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{5EAB32D6-F4B6-47EE-9DF2-3A149F99BE16}
[2011/06/23 21:05:41 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{56BEDEC6-9944-44CA-B544-D13E34D779FD}
[2011/06/22 18:45:55 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{FECA4387-1C3E-4E2A-B543-5794A5F1181F}
[2011/06/21 21:44:11 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{5B2B6F56-AE79-4A13-96FB-1E0710746225}
[2011/06/20 18:57:30 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/06/19 17:56:31 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{087EB8E3-5E3E-421F-9183-280DC78DB0F4}
[2011/06/17 17:11:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2011/06/17 16:59:31 | 000,000,000 | -HSD | C] – C:\Windows\System32\%APPDATA%
[2011/06/17 16:58:19 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/06/17 16:58:15 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/06/17 16:58:15 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/06/17 16:58:15 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/06/16 18:04:36 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/06/14 00:44:18 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/06/14 00:44:18 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/06/14 00:44:18 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/06/14 00:44:18 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/06/14 00:44:18 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/06/14 00:44:18 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/06/14 00:44:18 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/06/14 00:44:18 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/06/14 00:44:18 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/06/14 00:44:18 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/06/14 00:44:18 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/06/14 00:44:17 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/06/14 00:44:17 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/06/14 00:44:16 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/06/14 00:44:16 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/06/14 00:44:15 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/06/14 00:44:15 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/06/14 00:44:15 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/06/14 00:44:15 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/06/14 00:44:15 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/06/14 00:44:15 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/06/14 00:44:15 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/06/14 00:44:15 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/06/14 00:44:15 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/06/14 00:44:14 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/06/14 00:44:14 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/06/14 00:44:14 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/06/14 00:44:14 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/06/14 00:44:13 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/06/14 00:44:13 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/06/14 00:44:13 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/06/14 00:44:12 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/06/14 00:44:12 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/06/14 00:44:11 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/06/14 00:44:11 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/06/14 00:43:44 | 000,000,000 | -HSD | C] – C:\Windows\System32\AI_RecycleBin
[2011/06/14 00:43:41 | 000,000,000 | —D | C] – C:\Program Files\W3i
[2011/06/14 00:43:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstallIQ Updater
[2011/06/14 00:43:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/06/14 00:42:15 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/06/14 00:42:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/06/14 00:42:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/06/13 23:56:06 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/06/13 23:34:05 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/06/13 23:01:57 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{1B6EA47D-20F1-4637-9EFC-B9DDB11322C1}
[2011/06/13 22:57:04 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\temp
[2011/06/10 19:27:20 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/06/10 17:39:00 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/06/10 17:39:00 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/06/10 17:39:00 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/06/10 17:38:49 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/06/10 17:38:43 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/10 17:35:46 | 004,121,168 | R— | C] (Swearware) – C:\Users\Monta\Desktop\ComboFix.exe
[2011/06/10 17:19:49 | 000,589,632 | —- | C] (AVAST Software) – C:\aswMBR.exe
[2011/06/10 17:06:25 | 000,000,000 | —D | C] – C:\_OTL
[2011/06/08 21:49:43 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Monta\Desktop\HiJackThis.exe
[2011/06/08 21:45:20 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\Monta\Desktop\OTL.exe
[2011/06/07 22:57:32 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{18F19DC1-96F1-4044-AAE1-FACCE83E8D17}
[2011/06/02 22:56:31 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{647447FF-A3F8-42D9-9829-BE6B992101D7}
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/07/02 22:26:41 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000Core.job
[2011/07/02 22:18:46 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000UA.job
[2011/07/02 22:18:23 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/02 02:33:26 | 000,001,757 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/30 12:51:39 | 000,009,696 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/30 12:51:39 | 000,009,696 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/30 12:50:45 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/06/30 12:50:45 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/06/30 12:44:12 | 796,733,440 | -HS- | M] () – C:\hiberfil.sys
[2011/06/29 23:12:49 | 000,001,819 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/06/29 22:32:36 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/29 22:23:01 | 000,002,363 | —- | M] () – C:\Users\Monta\Desktop\Google Chrome.lnk
[2011/06/29 12:48:38 | 000,257,736 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/06/27 18:42:03 | 148,525,464 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/06/17 17:11:34 | 000,001,993 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/16 01:00:00 | 000,000,038 | —- | M] () – C:\Windows\avisplitter.ini
[2011/06/14 00:49:53 | 000,001,411 | —- | M] () – C:\Users\Monta\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/14 00:44:18 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/06/14 00:44:18 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/06/14 00:44:18 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/06/14 00:44:18 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/06/14 00:44:18 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/06/14 00:44:18 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/06/14 00:44:18 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/06/14 00:44:18 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/06/14 00:44:18 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/06/14 00:44:18 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/06/14 00:44:18 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/06/14 00:44:17 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/06/14 00:44:17 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/06/14 00:44:17 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/06/14 00:44:16 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/06/14 00:44:16 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/06/14 00:44:15 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/06/14 00:44:15 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/06/14 00:44:15 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/06/14 00:44:15 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/06/14 00:44:15 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/06/14 00:44:15 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/06/14 00:44:15 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/06/14 00:44:15 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/06/14 00:44:15 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/06/14 00:44:15 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/06/14 00:44:14 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/06/14 00:44:14 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/06/14 00:44:14 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/06/14 00:44:13 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/06/14 00:44:13 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/06/14 00:44:13 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/06/14 00:44:13 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/06/14 00:44:12 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/06/14 00:44:11 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/06/14 00:44:11 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/06/13 23:35:54 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2011/06/13 22:44:32 | 004,121,168 | R— | M] (Swearware) – C:\Users\Monta\Desktop\ComboFix.exe
[2011/06/10 23:15:03 | 000,017,771 | —- | M] () – C:\Users\Monta\Desktop\110609191800.jpg
[2011/06/10 17:24:44 | 000,000,550 | —- | M] () – C:\MBR.rar
[2011/06/10 17:22:01 | 000,000,512 | —- | M] () – C:\MBR.dat
[2011/06/10 17:19:54 | 000,589,632 | —- | M] (AVAST Software) – C:\aswMBR.exe
[2011/06/08 22:13:55 | 000,625,664 | —- | M] () – C:\dds.scr
[2011/06/08 21:49:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Monta\Desktop\HiJackThis.exe
[2011/06/08 21:45:22 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Monta\Desktop\OTL.exe
[1 C:\Windows\System32\drivers\*.tmp files -> C:\Windows\System32\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/07/02 02:33:26 | 000,001,757 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/29 23:31:52 | 000,175,616 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/06/29 23:31:51 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/06/29 23:31:49 | 000,644,608 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/06/29 23:31:47 | 000,243,200 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/06/29 23:12:49 | 000,001,819 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/06/27 18:42:03 | 148,525,464 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/06/20 18:57:36 | 000,002,363 | —- | C] () – C:\Users\Monta\Desktop\Google Chrome.lnk
[2011/06/20 18:56:32 | 000,000,908 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000UA.job
[2011/06/20 18:56:29 | 000,000,856 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000Core.job
[2011/06/17 17:11:34 | 000,001,993 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/17 17:11:33 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/14 00:44:15 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/06/10 23:15:46 | 000,017,771 | —- | C] () – C:\Users\Monta\Desktop\110609191800.jpg
[2011/06/10 17:39:00 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/06/10 17:39:00 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/06/10 17:39:00 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/06/10 17:39:00 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/06/10 17:39:00 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/06/10 17:24:44 | 000,000,550 | —- | C] () – C:\MBR.rar
[2011/06/10 17:22:01 | 000,000,512 | —- | C] () – C:\MBR.dat
[2011/06/08 22:13:53 | 000,625,664 | —- | C] () – C:\dds.scr
[2011/05/31 14:51:06 | 001,402,880 | —- | C] () – C:\Program Files\HijackThis.msi
[2011/05/10 21:20:58 | 000,003,584 | —- | C] () – C:\Users\Monta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/09 17:56:11 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2010/12/26 04:20:02 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/08/15 16:15:43 | 000,206,208 | —- | C] () – C:\Windows\PLFSetI.exe
[2010/08/15 16:15:42 | 000,113,264 | —- | C] () – C:\Windows\FixUVC.exe
[2010/08/15 16:15:42 | 000,000,302 | —- | C] () – C:\Windows\PidList_C.ini
[2010/07/06 08:09:56 | 000,361,808 | —- | C] () – C:\Windows\EMCRI_E.dll
[2010/07/06 08:01:36 | 000,247,560 | —- | C] () – C:\Windows\System32\drivers\RTConvEQ.dat
[2010/07/06 08:01:36 | 000,037,468 | —- | C] () – C:\Windows\System32\drivers\RtPCEE3.DAT
[2010/07/06 08:01:36 | 000,001,448 | —- | C] () – C:\Windows\System32\drivers\RtHdatEx.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX3.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX2.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX1.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX0.dat
[2010/07/06 08:01:36 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ1.dat
[2010/07/06 08:01:36 | 000,000,024 | —- | C] () – C:\Windows\System32\drivers\rtkhdaud.dat
[2010/01/13 19:41:00 | 000,309,248 | —- | C] () – C:\Windows\System32\sqlite36_engine.dll
[2010/01/13 19:38:00 | 000,023,552 | —- | C] () – C:\Windows\System32\DirectCOM.dll
[2009/07/13 21:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:33:53 | 000,257,736 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 19:05:48 | 000,628,460 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 19:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 19:05:48 | 000,110,612 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 19:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 19:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 19:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 16:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/02/29 18:08:08 | 000,024,840 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys

========== LOP Check ==========

[2011/07/02 22:48:13 | 000,000,000 | —D | M] – C:\Users\Monta\AppData\Roaming\BitTorrent
[2011/02/20 14:10:19 | 000,000,000 | —D | M] – C:\Users\Monta\AppData\Roaming\Hardcore
[2011/02/19 21:30:29 | 000,000,000 | —D | M] – C:\Users\Monta\AppData\Roaming\Ludia
[2011/06/29 23:15:59 | 000,000,000 | —D | M] – C:\Users\Monta\AppData\Roaming\Nullsoft
[2011/02/19 20:50:16 | 000,000,000 | —D | M] – C:\Users\Monta\AppData\Roaming\PlayFirst
[2011/02/14 13:31:58 | 000,000,000 | —D | M] – C:\Users\Monta\AppData\Roaming\Sierra Wireless
[2011/02/19 20:48:49 | 000,000,000 | —D | M] – C:\Users\Monta\AppData\Roaming\WildTangent
[2011/04/03 00:11:37 | 000,000,000 | —D | M] – C:\Users\Monta\AppData\Roaming\Windows Live Writer
[2009/07/13 21:53:46 | 000,022,268 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
im sorry i couldnt find the extras file, it didnt pop up, nor in the place you told me to look. there's one in cdrive but it's from a earlier date
Thats fine, no to worry about the extras. Nothing bad jumping out at me but lets check those redirects

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
aswMBR version 0.9.7.675 Copyright© 2011 AVAST Software Run date: 2011-07-03 14:19:12 —————————– 14:19:12.440 OS Version: Windows 6.1.7601 Service Pack 1 14:19:12.441 Number of processors: 2 586 0x1C0A 14:19:12.444 ComputerName: MONTA-PC UserName: Monta 14:19:26.507 Initialize success 14:20:01.921 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 14:20:01.933 Disk 0 Vendor: WDC_WD25 01.0 Size: 238475MB BusType: 3 14:20:01.973 Disk 0 MBR read successfully 14:20:02.013 Disk 0 MBR scan 14:20:02.038 Disk 0 Windows 7 default MBR code 14:20:02.054 Disk 0 scanning sectors +488394752 14:20:02.105 Disk 0 scanning C:\Windows\system32\drivers 14:20:12.091 Service scanning 14:20:13.207 Disk 0 trace - called modules: 14:20:13.259 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll 14:20:13.269 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x850542e0] 14:20:13.279 3 CLASSPNP.SYS[86da459e] -> nt!IofCallDriver -> [0x8466b700] 14:20:13.289 Scan finished successfully 14:22:05.026 Disk 0 MBR has been saved successfully to "C:\Users\Monta\Desktop\MBR.dat" 14:22:05.078 The log file has been saved successfully to "C:\Users\Monta\Desktop\aswMBR.txt"
Not looking at a rootkit :)

Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /release /c
    ipconfig /renew /c
    ipconfig /flushdns /c
    
    
    
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )




Post the log from the fix and a new OTL log and let me know if the redirects have stopped
All processes killed
========== PROCESSES ==========
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /release /c >
Windows IP Configuration
No operation can be performed on Local Area Connection while it has its media disconnected.
Wireless LAN adapter Wireless Network Connection:
Connection-specific DNS Suffix . :
Link-local IPv6 Address . . . . . : fe80::e909:6b77:60ed:df21%11
Default Gateway . . . . . . . . . :
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{7F78B4CB-6491-4426-96DA-F0F77E6C8437}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.domain.invalid:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
C:\Users\Monta\Desktop\cmd.bat deleted successfully.
C:\Users\Monta\Desktop\cmd.txt deleted successfully.
< ipconfig /renew /c >
Windows IP Configuration
No operation can be performed on Local Area Connection while it has its media disconnected.
Wireless LAN adapter Wireless Network Connection:
Connection-specific DNS Suffix . : domain.invalid
Link-local IPv6 Address . . . . . : fe80::e909:6b77:60ed:df21%11
IPv4 Address. . . . . . . . . . . : 192.168.1.79
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.254
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.{7F78B4CB-6491-4426-96DA-F0F77E6C8437}:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter isatap.domain.invalid:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Tunnel adapter Teredo Tunneling Pseudo-Interface:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
C:\Users\Monta\Desktop\cmd.bat deleted successfully.
C:\Users\Monta\Desktop\cmd.txt deleted successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Monta\Desktop\cmd.bat deleted successfully.
C:\Users\Monta\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56468 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Monta
->Temp folder emptied: 212992 bytes
->Temporary Internet Files folder emptied: 132628318 bytes
->Java cache emptied: 1 bytes
->Google Chrome cache emptied: 1905008 bytes
->Flash cache emptied: 9883 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 42496 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 129.00 mb


OTL by OldTimer - Version 3.2.23.0 log created on 07032011_144317

Files\Folders moved on Reboot…
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZA2OPC9X\ai[2].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZA2OPC9X\like[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZA2OPC9X\search[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S3FOH1I2\like[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S3FOH1I2\lpc[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L4TCRZT8\iframe3[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L4TCRZT8\index[2].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GU6JRYQ9\ai[2].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIMTCVZX\ai[3].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FC3ZYWBU\localpages_com[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FC3ZYWBU\search[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FC3ZYWBU\search[4].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\11[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\button[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\like[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\login_status[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\pixel[1].gif moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\st[1] moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\st[2] moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\tweet_button[2].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DKNYY0SK\_;ord=1309729375164564[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AKKF1LW\ai[5].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AKKF1LW\ai[6].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AKKF1LW\feed[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AKKF1LW\iframe[2].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AKKF1LW\proxy[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86O5HU9M\115188489535[1].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86O5HU9M\ai[4].htm moved successfully.
C:\Users\Monta\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\86O5HU9M\search[2].htm moved successfully.
File move failed. C:\Windows\temp\dsiwmis.log scheduled to be moved on reboot.

Registry entries deleted on Reboot…
i thought i posted the fix one and now i cant find it…

here's the new otl one tho … and rthe redirects have not stopped :S

also.. one more thing i noticed i went to a webpage that has a music player on it, and something popped up saying there was a jscript run time error and asked me if i wanted to debug it. i clicked yes once and it took me to some weird html editor box and said there was a problem with line 1 or something i didnt understand and when i click no, nothing happens.


OTL logfile created on: 7/4/2011 2:30:50 PM - Run 3
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Monta\Desktop
Starter Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

1013.10 Mb Total Physical Memory | 214.52 Mb Available Physical Memory | 21.17% Memory free
1.99 Gb Paging File | 0.83 Gb Available in Paging File | 41.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 219.79 Gb Total Space | 28.92 Gb Free Space | 13.16% Space Free | Partition Type: NTFS

Computer Name: MONTA-PC | User Name: Monta | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Monta\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\prevhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\PLFSetI.exe ()
PRC - C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files\Launch Manager\LMworker.exe (Dritek System Inc.)
PRC - C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Acer Incorporated)
PRC - C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
PRC - C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
PRC - C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
PRC - C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe (Sierra Wireless Inc.)


========== Modules (SafeList) ==========

MOD - C:\Users\Monta\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Acer\Acer ePower Management\SysHook.dll (Acer Incorporated)


========== Win32 Services (SafeList) ==========

SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (DsiWMIService) – C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (ePowerSvc) – C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
SRV - (MWLService) – C:\Program Files\EgisTec MyWinLocker\x86\MWLService.exe (Egis Technology Inc.)
SRV - (GameConsoleService) – C:\Program Files\Acer Games\Acer Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (RS_Service) – C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer Incorporated)
SRV - (Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Group)
SRV - (GREGService) – C:\Program Files\Acer\Registration\GREGsvc.exe (Acer Incorporated)
SRV - (IAANTMON) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (EUCR) – C:\Windows\System32\drivers\EUCR6SK.sys (ENE Technology Inc.)
DRV - (L1C) – C:\Windows\System32\drivers\L1C62x86.sys (Atheros Communications, Inc.)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (mwlPSDVDisk) – C:\Windows\System32\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV - (mwlPSDNServ) – C:\Windows\System32\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV - (mwlPSDFilter) – C:\Windows\System32\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV - (swmsflt) – C:\Windows\System32\drivers\swmsflt.sys ()
DRV - (SWMX00) Sierra Wireless USB MUX Driver (#00) – C:\Windows\System32\drivers\swmx00.sys (Sierra Wireless Inc.)
DRV - (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00) – C:\Windows\System32\drivers\SWNC5E00.sys (Sierra Wireless Inc.)
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…34ww65w4712u741

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.msn.com/?ocid=OIE9HP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ca.msn.com/?ocid=OIE9HP
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: ([2011/07/03 14:43:35 | 000,000,098 | —- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [iBryte playbryte Desktop] File not found
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mwlDaemon] C:\Program Files\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [PLFSetI] C:\Windows\PLFSetI.exe ()
O4 - HKLM..\Run: [SuiteTray] C:\Program Files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [WatcherHelper] C:\Program Files\Sierra Wireless Inc\Watcher\WaHelper.exe (Sierra Wireless Inc.)
O4 - HKCU..\Run: [ares] C:\Program Files\Ares\Ares.exe (Ares Development Group)
O4 - HKCU..\Run: [InstallIQUpdater] C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} http://download.macromedia.com/pub/shockwa…are/awswaxf.cab (Macromedia Authorware Web Player Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/pub/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab (IWinAmpActiveX Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/07/03 14:52:19 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{238FA81E-A3C4-4B79-B24C-6281948B4809}
[2011/07/03 14:19:00 | 001,904,128 | —- | C] (AVAST Software) – C:\Users\Monta\Desktop\aswMBR.exe
[2011/07/03 14:09:44 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\Apple Computer
[2011/07/02 02:49:20 | 000,000,000 | —D | C] – C:\DFU
[2011/07/02 02:33:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/07/02 02:31:45 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/07/02 02:31:28 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/07/01 01:58:41 | 000,000,000 | —D | C] – C:\Users\Monta\Desktop\SilentWeaponsQuietWar-TripHopCollectionV1
[2011/06/30 12:45:23 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{838C7696-47FF-406A-BCF1-70625E9856AC}
[2011/06/30 00:24:35 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{C00E4C12-60EC-4E51-A7F8-645BD3B324FB}
[2011/06/29 23:31:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2011/06/29 23:31:50 | 000,232,448 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\mp3fhg.acm
[2011/06/29 23:31:49 | 000,237,568 | —- | C] (www.helixcommunity.org) – C:\Windows\System32\yv12vfw.dll
[2011/06/29 23:31:49 | 000,151,552 | —- | C] (fccHandler) – C:\Windows\System32\ac3acm.acm
[2011/06/29 23:31:44 | 000,000,000 | —D | C] – C:\Program Files\K-Lite Codec Pack
[2011/06/29 23:20:07 | 002,106,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_43.dll
[2011/06/29 23:20:07 | 000,527,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_7.dll
[2011/06/29 23:20:07 | 000,239,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_7.dll
[2011/06/29 23:20:07 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_5.dll
[2011/06/29 23:20:06 | 001,868,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_43.dll
[2011/06/29 23:20:06 | 000,470,880 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_43.dll
[2011/06/29 23:20:06 | 000,248,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_43.dll
[2011/06/29 23:20:05 | 001,998,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_43.dll
[2011/06/29 23:20:05 | 000,528,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_6.dll
[2011/06/29 23:20:05 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_6.dll
[2011/06/29 23:20:05 | 000,074,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_4.dll
[2011/06/29 23:20:05 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_7.dll
[2011/06/29 23:20:04 | 005,501,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dcsx_42.dll
[2011/06/29 23:20:04 | 001,974,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_42.dll
[2011/06/29 23:20:04 | 000,238,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_5.dll
[2011/06/29 23:20:03 | 001,892,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_42.dll
[2011/06/29 23:20:03 | 000,235,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx11_42.dll
[2011/06/29 23:20:02 | 004,178,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_41.dll
[2011/06/29 23:20:02 | 000,517,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_4.dll
[2011/06/29 23:20:02 | 000,235,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_4.dll
[2011/06/29 23:20:01 | 004,379,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_40.dll
[2011/06/29 23:20:01 | 002,036,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_40.dll
[2011/06/29 23:20:01 | 000,452,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_40.dll
[2011/06/29 23:20:01 | 000,022,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_6.dll
[2011/06/29 23:20:00 | 000,514,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_3.dll
[2011/06/29 23:20:00 | 000,235,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_3.dll
[2011/06/29 23:20:00 | 000,070,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_2.dll
[2011/06/29 23:20:00 | 000,023,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_5.dll
[2011/06/29 23:19:59 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_39.dll
[2011/06/29 23:19:59 | 000,509,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_2.dll
[2011/06/29 23:19:59 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_39.dll
[2011/06/29 23:19:59 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_2.dll
[2011/06/29 23:19:59 | 000,068,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_1.dll
[2011/06/29 23:19:58 | 003,851,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_39.dll
[2011/06/29 23:19:57 | 000,507,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_1.dll
[2011/06/29 23:19:57 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_1.dll
[2011/06/29 23:19:57 | 000,065,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAPOFX1_0.dll
[2011/06/29 23:19:56 | 001,491,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_38.dll
[2011/06/29 23:19:56 | 000,479,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XAudio2_0.dll
[2011/06/29 23:19:56 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_38.dll
[2011/06/29 23:19:56 | 000,238,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine3_0.dll
[2011/06/29 23:19:56 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_4.dll
[2011/06/29 23:19:55 | 003,786,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DX9_37.dll
[2011/06/29 23:19:55 | 001,420,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_37.dll
[2011/06/29 23:19:55 | 000,462,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_37.dll
[2011/06/29 23:19:55 | 000,025,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_3.dll
[2011/06/29 23:19:54 | 001,374,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_36.dll
[2011/06/29 23:19:54 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_36.dll
[2011/06/29 23:19:54 | 000,267,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_10.dll
[2011/06/29 23:19:53 | 003,734,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_36.dll
[2011/06/29 23:19:52 | 003,727,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_35.dll
[2011/06/29 23:19:52 | 001,358,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_35.dll
[2011/06/29 23:19:52 | 000,444,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_35.dll
[2011/06/29 23:19:52 | 000,267,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_9.dll
[2011/06/29 23:19:50 | 003,497,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_34.dll
[2011/06/29 23:19:50 | 001,124,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_34.dll
[2011/06/29 23:19:50 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_34.dll
[2011/06/29 23:19:50 | 000,266,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_8.dll
[2011/06/29 23:19:50 | 000,017,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\X3DAudio1_2.dll
[2011/06/29 23:19:44 | 001,123,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\D3DCompiler_33.dll
[2011/06/29 23:19:44 | 000,443,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10_33.dll
[2011/06/29 23:19:44 | 000,261,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_7.dll
[2011/06/29 23:19:44 | 000,081,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_3.dll
[2011/06/29 23:19:43 | 003,495,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_33.dll
[2011/06/29 23:19:42 | 000,440,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx10.dll
[2011/06/29 23:19:42 | 000,255,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_6.dll
[2011/06/29 23:19:42 | 000,251,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_5.dll
[2011/06/29 23:19:42 | 000,237,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_4.dll
[2011/06/29 23:19:42 | 000,015,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_1.dll
[2011/06/29 23:19:41 | 002,414,360 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_31.dll
[2011/06/29 23:19:40 | 000,236,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_3.dll
[2011/06/29 23:19:40 | 000,230,168 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_2.dll
[2011/06/29 23:19:40 | 000,229,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_1.dll
[2011/06/29 23:19:40 | 000,062,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_2.dll
[2011/06/29 23:19:40 | 000,062,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xinput1_1.dll
[2011/06/29 23:19:36 | 002,388,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_30.dll
[2011/06/29 23:19:35 | 002,332,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_29.dll
[2011/06/29 23:19:35 | 002,323,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_28.dll
[2011/06/29 23:19:35 | 002,319,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_27.dll
[2011/06/29 23:19:35 | 002,297,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_26.dll
[2011/06/29 23:19:35 | 000,230,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xactengine2_0.dll
[2011/06/29 23:19:35 | 000,014,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\x3daudio1_0.dll
[2011/06/29 23:19:34 | 002,337,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_25.dll
[2011/06/29 23:19:33 | 002,222,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_24.dll
[2011/06/29 23:17:04 | 000,000,000 | —D | C] – C:\Windows\System32\directx
[2011/06/29 23:15:59 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Roaming\Nullsoft
[2011/06/29 22:34:10 | 000,000,000 | —D | C] – C:\Windows\System32\Adobe
[2011/06/28 16:45:24 | 001,549,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tquery.dll
[2011/06/28 16:45:24 | 001,401,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssrch.dll
[2011/06/28 16:45:23 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssvp.dll
[2011/06/28 16:45:23 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssph.dll
[2011/06/28 16:45:23 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mssphtb.dll
[2011/06/28 16:45:22 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msscntrs.dll
[2011/06/27 19:49:57 | 000,000,000 | —D | C] – C:\Users\Monta\Desktop\Little Hell
[2011/06/27 19:24:48 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{BF153F72-0A84-4B32-A5DD-1090FE9D891B}
[2011/06/27 18:42:08 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2011/06/27 01:40:06 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{9FAB7B89-5835-4CD8-A38E-F2C09B42C63C}
[2011/06/26 23:26:46 | 000,000,000 | —D | C] – C:\Users\Monta\Desktop\The Big Lebowski(1998).720p.BRRip.H264.ResourceRG by Dusty
[2011/06/26 14:47:21 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{9E3EE5CD-6C23-4D4F-A913-8D99E5EFF865}
[2011/06/26 04:14:52 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{8276F5F5-0825-4FF8-95E5-D49EB1B48049}
[2011/06/25 00:06:57 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{5EAB32D6-F4B6-47EE-9DF2-3A149F99BE16}
[2011/06/23 21:05:41 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{56BEDEC6-9944-44CA-B544-D13E34D779FD}
[2011/06/22 18:45:55 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{FECA4387-1C3E-4E2A-B543-5794A5F1181F}
[2011/06/21 21:44:11 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{5B2B6F56-AE79-4A13-96FB-1E0710746225}
[2011/06/20 18:57:30 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/06/19 17:56:31 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{087EB8E3-5E3E-421F-9183-280DC78DB0F4}
[2011/06/17 17:11:16 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2011/06/17 16:59:31 | 000,000,000 | -HSD | C] – C:\Windows\System32\%APPDATA%
[2011/06/17 16:58:19 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2011/06/17 16:58:15 | 001,797,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2011/06/17 16:58:15 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2011/06/17 16:58:15 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2011/06/16 18:04:36 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3d10_1.dll
[2011/06/14 00:44:18 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/06/14 00:44:18 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/06/14 00:44:18 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/06/14 00:44:18 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/06/14 00:44:18 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/06/14 00:44:18 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/06/14 00:44:18 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/06/14 00:44:18 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/06/14 00:44:18 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/06/14 00:44:18 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/06/14 00:44:18 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/06/14 00:44:17 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/06/14 00:44:17 | 000,223,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/06/14 00:44:16 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/06/14 00:44:16 | 000,353,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/06/14 00:44:15 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/06/14 00:44:15 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/06/14 00:44:15 | 000,353,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/06/14 00:44:15 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/06/14 00:44:15 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/06/14 00:44:15 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/06/14 00:44:15 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/06/14 00:44:15 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/06/14 00:44:15 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/06/14 00:44:14 | 000,580,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/06/14 00:44:14 | 000,420,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/06/14 00:44:14 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/06/14 00:44:14 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/06/14 00:44:13 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/06/14 00:44:13 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/06/14 00:44:13 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/06/14 00:44:12 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/06/14 00:44:12 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/06/14 00:44:11 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/06/14 00:44:11 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/06/14 00:43:44 | 000,000,000 | -HSD | C] – C:\Windows\System32\AI_RecycleBin
[2011/06/14 00:43:41 | 000,000,000 | —D | C] – C:\Program Files\W3i
[2011/06/14 00:43:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstallIQ Updater
[2011/06/14 00:43:20 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/06/14 00:42:15 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2011/06/14 00:42:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2011/06/14 00:42:15 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2011/06/13 23:56:06 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/06/13 23:34:05 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/06/13 23:01:57 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{1B6EA47D-20F1-4637-9EFC-B9DDB11322C1}
[2011/06/13 22:57:04 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\temp
[2011/06/10 19:27:20 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/06/10 17:39:00 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/06/10 17:39:00 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/06/10 17:39:00 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/06/10 17:38:49 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/06/10 17:38:43 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/10 17:35:46 | 004,121,168 | R— | C] (Swearware) – C:\Users\Monta\Desktop\ComboFix.exe
[2011/06/10 17:19:49 | 000,589,632 | —- | C] (AVAST Software) – C:\aswMBR.exe
[2011/06/10 17:06:25 | 000,000,000 | —D | C] – C:\_OTL
[2011/06/08 21:49:43 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Monta\Desktop\HiJackThis.exe
[2011/06/08 21:45:20 | 000,580,096 | —- | C] (OldTimer Tools) – C:\Users\Monta\Desktop\OTL.exe
[2011/06/07 22:57:32 | 000,000,000 | —D | C] – C:\Users\Monta\AppData\Local\{18F19DC1-96F1-4044-AAE1-FACCE83E8D17}

========== Files - Modified Within 30 Days ==========

[2011/07/04 14:22:49 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000UA.job
[2011/07/04 14:22:41 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/03 21:18:49 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000Core.job
[2011/07/03 14:58:20 | 000,009,696 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/03 14:58:20 | 000,009,696 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/03 14:55:42 | 000,628,460 | —- | M] () – C:\Windows\System32\perfh009.dat
[2011/07/03 14:55:42 | 000,110,612 | —- | M] () – C:\Windows\System32\perfc009.dat
[2011/07/03 14:50:50 | 796,733,440 | -HS- | M] () – C:\hiberfil.sys
[2011/07/03 14:43:35 | 000,000,098 | —- | M] () – C:\Windows\System32\drivers\etc\Hosts
[2011/07/03 14:22:05 | 000,000,512 | —- | M] () – C:\Users\Monta\Desktop\MBR.dat
[2011/07/03 14:18:58 | 001,904,128 | —- | M] (AVAST Software) – C:\Users\Monta\Desktop\aswMBR.exe
[2011/07/03 00:00:32 | 000,035,841 | —- | M] () – C:\Users\Monta\Desktop\n562350639_5910464_9851.jpg
[2011/07/02 23:56:15 | 000,021,786 | —- | M] () – C:\Users\Monta\Desktop\254303_10150625869080640_562350639_18837414_1064970_n.jpg
[2011/07/02 02:33:26 | 000,001,757 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/29 23:12:49 | 000,001,819 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/06/29 22:32:36 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/06/29 22:23:01 | 000,002,363 | —- | M] () – C:\Users\Monta\Desktop\Google Chrome.lnk
[2011/06/29 12:48:38 | 000,257,736 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2011/06/27 18:42:03 | 148,525,464 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/06/17 17:11:34 | 000,001,993 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/16 01:00:00 | 000,000,038 | —- | M] () – C:\Windows\avisplitter.ini
[2011/06/14 00:49:53 | 000,001,411 | —- | M] () – C:\Users\Monta\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/06/14 00:44:18 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msrating.dll
[2011/06/14 00:44:18 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msls31.dll
[2011/06/14 00:44:18 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakeng.dll
[2011/06/14 00:44:18 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\System32\IEAdvpack.dll
[2011/06/14 00:44:18 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2011/06/14 00:44:18 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\System32\SetIEInstalledDate.exe
[2011/06/14 00:44:18 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\RegisterIEPKEYs.exe
[2011/06/14 00:44:18 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2011/06/14 00:44:18 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2011/06/14 00:44:18 | 000,041,472 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2011/06/14 00:44:18 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2011/06/14 00:44:17 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2011/06/14 00:44:17 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2011/06/14 00:44:17 | 000,223,232 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2011/06/14 00:44:16 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2011/06/14 00:44:16 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2011/06/14 00:44:15 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2011/06/14 00:44:15 | 000,353,584 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2011/06/14 00:44:15 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2011/06/14 00:44:15 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wextract.exe
[2011/06/14 00:44:15 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\inseng.dll
[2011/06/14 00:44:15 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2011/06/14 00:44:15 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2011/06/14 00:44:15 | 000,072,822 | —- | M] () – C:\Windows\System32\ieuinit.inf
[2011/06/14 00:44:15 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2011/06/14 00:44:15 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2011/06/14 00:44:14 | 000,580,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2011/06/14 00:44:14 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2011/06/14 00:44:14 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iexpress.exe
[2011/06/14 00:44:13 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2011/06/14 00:44:13 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2011/06/14 00:44:13 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2011/06/14 00:44:13 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2011/06/14 00:44:12 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2011/06/14 00:44:11 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2011/06/14 00:44:11 | 000,035,840 | —- | M] (Microsoft Corporation) – C:\Windows\System32\imgutil.dll
[2011/06/13 22:44:32 | 004,121,168 | R— | M] (Swearware) – C:\Users\Monta\Desktop\ComboFix.exe
[2011/06/10 23:15:03 | 000,017,771 | —- | M] () – C:\Users\Monta\Desktop\110609191800.jpg
[2011/06/10 17:24:44 | 000,000,550 | —- | M] () – C:\MBR.rar
[2011/06/10 17:22:01 | 000,000,512 | —- | M] () – C:\MBR.dat
[2011/06/10 17:19:54 | 000,589,632 | —- | M] (AVAST Software) – C:\aswMBR.exe
[2011/06/08 22:13:55 | 000,625,664 | —- | M] () – C:\dds.scr
[2011/06/08 21:49:45 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Monta\Desktop\HiJackThis.exe
[2011/06/08 21:45:22 | 000,580,096 | —- | M] (OldTimer Tools) – C:\Users\Monta\Desktop\OTL.exe

========== Files Created - No Company Name ==========

[2011/07/03 14:22:05 | 000,000,512 | —- | C] () – C:\Users\Monta\Desktop\MBR.dat
[2011/07/03 00:00:42 | 000,035,841 | —- | C] () – C:\Users\Monta\Desktop\n562350639_5910464_9851.jpg
[2011/07/02 23:56:24 | 000,021,786 | —- | C] () – C:\Users\Monta\Desktop\254303_10150625869080640_562350639_18837414_1064970_n.jpg
[2011/07/02 02:33:26 | 000,001,757 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/06/29 23:31:52 | 000,175,616 | —- | C] () – C:\Windows\System32\unrar.dll
[2011/06/29 23:31:51 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2011/06/29 23:31:49 | 000,644,608 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2011/06/29 23:31:47 | 000,243,200 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2011/06/29 23:12:49 | 000,001,819 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/06/27 18:42:03 | 148,525,464 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/06/20 18:57:36 | 000,002,363 | —- | C] () – C:\Users\Monta\Desktop\Google Chrome.lnk
[2011/06/20 18:56:32 | 000,000,908 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000UA.job
[2011/06/20 18:56:29 | 000,000,856 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000Core.job
[2011/06/17 17:11:34 | 000,001,993 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/06/17 17:11:33 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/06/14 00:44:15 | 000,072,822 | —- | C] () – C:\Windows\System32\ieuinit.inf
[2011/06/10 23:15:46 | 000,017,771 | —- | C] () – C:\Users\Monta\Desktop\110609191800.jpg
[2011/06/10 17:39:00 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/06/10 17:39:00 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/06/10 17:39:00 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/06/10 17:39:00 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/06/10 17:39:00 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/06/10 17:24:44 | 000,000,550 | —- | C] () – C:\MBR.rar
[2011/06/10 17:22:01 | 000,000,512 | —- | C] () – C:\MBR.dat
[2011/06/08 22:13:53 | 000,625,664 | —- | C] () – C:\dds.scr
[2011/05/31 14:51:06 | 001,402,880 | —- | C] () – C:\Program Files\HijackThis.msi
[2011/05/10 21:20:58 | 000,003,584 | —- | C] () – C:\Users\Monta\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/09 17:56:11 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2010/12/26 04:20:02 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2010/08/15 16:15:43 | 000,206,208 | —- | C] () – C:\Windows\PLFSetI.exe
[2010/08/15 16:15:42 | 000,113,264 | —- | C] () – C:\Windows\FixUVC.exe
[2010/08/15 16:15:42 | 000,000,302 | —- | C] () – C:\Windows\PidList_C.ini
[2010/07/06 08:09:56 | 000,361,808 | —- | C] () – C:\Windows\EMCRI_E.dll
[2010/07/06 08:01:36 | 000,247,560 | —- | C] () – C:\Windows\System32\drivers\RTConvEQ.dat
[2010/07/06 08:01:36 | 000,037,468 | —- | C] () – C:\Windows\System32\drivers\RtPCEE3.DAT
[2010/07/06 08:01:36 | 000,001,448 | —- | C] () – C:\Windows\System32\drivers\RtHdatEx.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX3.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX2.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX1.dat
[2010/07/06 08:01:36 | 000,000,520 | —- | C] () – C:\Windows\System32\drivers\RTEQEX0.dat
[2010/07/06 08:01:36 | 000,000,176 | —- | C] () – C:\Windows\System32\drivers\RTHDAEQ1.dat
[2010/07/06 08:01:36 | 000,000,024 | —- | C] () – C:\Windows\System32\drivers\rtkhdaud.dat
[2010/01/13 19:41:00 | 000,309,248 | —- | C] () – C:\Windows\System32\sqlite36_engine.dll
[2010/01/13 19:38:00 | 000,023,552 | —- | C] () – C:\Windows\System32\DirectCOM.dll
[2009/07/13 21:57:37 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:33:53 | 000,257,736 | —- | C] () – C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 19:05:48 | 000,628,460 | —- | C] () – C:\Windows\System32\perfh009.dat
[2009/07/13 19:05:48 | 000,291,294 | —- | C] () – C:\Windows\System32\perfi009.dat
[2009/07/13 19:05:48 | 000,110,612 | —- | C] () – C:\Windows\System32\perfc009.dat
[2009/07/13 19:05:48 | 000,031,548 | —- | C] () – C:\Windows\System32\perfd009.dat
[2009/07/13 19:05:05 | 000,000,741 | —- | C] () – C:\Windows\System32\NOISE.DAT
[2009/07/13 19:04:11 | 000,215,943 | —- | C] () – C:\Windows\System32\dssec.dat
[2009/07/13 16:55:01 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\System32\mlang.dat
[2008/02/29 18:08:08 | 000,024,840 | —- | C] () – C:\Windows\System32\drivers\swmsflt.sys

< End of report >
Lets do this


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
aComboFix 11-07-03.04 - Monta 04/07/2011 15:34:35.4.2 - x86 Microsoft Windows 7 Starter 6.1.7601.1.1252.2.1033.18.1013.368 [GMT -7:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2011-06-04 to 2011-07-04 ))))))))))))))))))))))))))))))) . . 2011-07-04 22:48 . 2011-07-04 22:48 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-07-04 22:28 . 2011-07-04 22:28 ——– d—–w- c:\users\Monta\AppData\Local\{D6FA6441-5A13-4902-88FA-D4B985FDBE3B} 2011-07-03 21:52 . 2011-07-03 21:52 ——– d—–w- c:\users\Monta\AppData\Local\{238FA81E-A3C4-4B79-B24C-6281948B4809} 2011-07-03 21:09 . 2011-07-04 07:46 ——– d—–w- c:\users\Monta\AppData\Local\Apple Computer 2011-07-02 09:49 . 2011-07-02 09:49 ——– d—–w- C:\DFU 2011-07-02 09:31 . 2011-07-02 09:31 ——– d—–w- c:\program files\iPod 2011-07-02 09:31 . 2011-07-02 09:33 ——– d—–w- c:\program files\iTunes 2011-06-30 19:45 . 2011-07-02 21:05 ——– d—–w- c:\users\Monta\AppData\Local\{838C7696-47FF-406A-BCF1-70625E9856AC} 2011-06-30 07:24 . 2011-06-30 07:24 ——– d—–w- c:\users\Monta\AppData\Local\{C00E4C12-60EC-4E51-A7F8-645BD3B324FB} 2011-06-30 06:31 . 2011-03-02 10:43 175616 —-a-w- c:\windows\system32\unrar.dll 2011-06-30 06:31 . 2006-10-18 18:05 232448 —-a-w- c:\windows\system32\mp3fhg.acm 2011-06-30 06:31 . 2011-06-02 00:10 644608 —-a-w- c:\windows\system32\xvidcore.dll 2011-06-30 06:31 . 2011-03-19 19:00 151552 —-a-w- c:\windows\system32\ac3acm.acm 2011-06-30 06:31 . 2010-11-03 18:08 237568 —-a-w- c:\windows\system32\yv12vfw.dll 2011-06-30 06:31 . 2011-06-02 00:15 243200 —-a-w- c:\windows\system32\xvidvfw.dll 2011-06-30 06:31 . 2011-06-30 06:32 ——– d—–w- c:\program files\K-Lite Codec Pack 2011-06-30 06:19 . 2008-07-31 17:41 238088 —-a-w- c:\windows\system32\xactengine3_2.dll 2011-06-30 06:15 . 2011-06-30 06:15 ——– d—–w- c:\users\Monta\AppData\Roaming\Nullsoft 2011-06-30 05:34 . 2011-06-30 05:35 ——– d—–w- c:\windows\system32\Adobe 2011-06-28 23:45 . 2011-05-04 04:34 1549312 —-a-w- c:\windows\system32\tquery.dll 2011-06-28 23:45 . 2011-05-04 04:32 1401344 —-a-w- c:\windows\system32\mssrch.dll 2011-06-28 23:45 . 2011-05-04 04:32 666624 —-a-w- c:\windows\system32\mssvp.dll 2011-06-28 23:45 . 2011-05-04 04:32 337408 —-a-w- c:\windows\system32\mssph.dll 2011-06-28 23:45 . 2011-05-04 04:32 197120 —-a-w- c:\windows\system32\mssphtb.dll 2011-06-28 23:45 . 2011-05-04 04:28 86528 —-a-w- c:\windows\system32\SearchFilterHost.exe 2011-06-28 23:45 . 2011-05-04 04:28 427520 —-a-w- c:\windows\system32\SearchIndexer.exe 2011-06-28 23:45 . 2011-05-04 04:28 164352 —-a-w- c:\windows\system32\SearchProtocolHost.exe 2011-06-28 23:45 . 2011-05-04 04:32 59392 —-a-w- c:\windows\system32\msscntrs.dll 2011-06-28 22:47 . 2011-05-24 10:44 293376 —-a-w- c:\windows\system32\umpnpmgr.dll 2011-06-28 02:24 . 2011-06-29 19:24 ——– d—–w- c:\users\Monta\AppData\Local\{BF153F72-0A84-4B32-A5DD-1090FE9D891B} 2011-06-27 08:40 . 2011-06-27 08:40 ——– d—–w- c:\users\Monta\AppData\Local\{9FAB7B89-5835-4CD8-A38E-F2C09B42C63C} 2011-06-26 21:47 . 2011-06-26 21:47 ——– d—–w- c:\users\Monta\AppData\Local\{9E3EE5CD-6C23-4D4F-A913-8D99E5EFF865} 2011-06-26 11:14 . 2011-06-26 11:14 ——– d—–w- c:\users\Monta\AppData\Local\{8276F5F5-0825-4FF8-95E5-D49EB1B48049} 2011-06-25 07:06 . 2011-06-25 07:07 ——– d—–w- c:\users\Monta\AppData\Local\{5EAB32D6-F4B6-47EE-9DF2-3A149F99BE16} 2011-06-24 04:05 . 2011-06-24 04:06 ——– d—–w- c:\users\Monta\AppData\Local\{56BEDEC6-9944-44CA-B544-D13E34D779FD} 2011-06-23 01:45 . 2011-06-23 01:46 ——– d—–w- c:\users\Monta\AppData\Local\{FECA4387-1C3E-4E2A-B543-5794A5F1181F} 2011-06-22 04:44 . 2011-06-22 04:44 ——– d—–w- c:\users\Monta\AppData\Local\{5B2B6F56-AE79-4A13-96FB-1E0710746225} 2011-06-20 00:56 . 2011-06-20 18:40 ——– d—–w- c:\users\Monta\AppData\Local\{087EB8E3-5E3E-421F-9183-280DC78DB0F4} 2011-06-18 00:11 . 2011-06-18 00:11 ——– d—–w- c:\program files\Common Files\Adobe 2011-06-17 23:59 . 2011-06-17 23:59 ——– d-sh–w- c:\windows\system32\%APPDATA% 2011-06-17 23:58 . 2011-04-22 23:25 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-06-17 23:58 . 2011-04-25 15:29 141104 —-a-w- c:\program files\Internet Explorer\sqmapi.dll 2011-06-17 23:58 . 2011-04-22 23:35 1797632 —-a-w- c:\windows\system32\jscript9.dll 2011-06-17 01:04 . 2011-04-29 02:46 311808 —-a-w- c:\windows\system32\drivers\srv.sys 2011-06-17 01:04 . 2011-04-29 02:46 310272 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-06-17 01:04 . 2011-04-29 02:46 114688 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-17 01:04 . 2011-04-25 04:31 1290624 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-06-17 01:04 . 2011-04-25 02:18 338944 —-a-w- c:\windows\system32\drivers\afd.sys 2011-06-17 01:04 . 2011-02-25 05:34 571904 —-a-w- c:\windows\system32\oleaut32.dll 2011-06-17 01:04 . 2011-05-03 04:30 741376 —-a-w- c:\windows\system32\inetcomm.dll 2011-06-17 01:04 . 2011-01-17 05:47 161792 —-a-w- c:\windows\system32\d3d10_1.dll 2011-06-17 01:04 . 2011-04-27 02:17 223744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-17 01:04 . 2011-04-27 02:17 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-17 01:04 . 2011-04-27 02:17 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-14 07:43 . 2011-06-14 07:43 ——– d-sh–w- c:\windows\system32\AI_RecycleBin 2011-06-14 07:43 . 2011-06-14 07:43 ——– d—–w- c:\program files\W3i 2011-06-14 07:43 . 2011-06-14 07:43 ——– d—–w- c:\program files\Common Files\Java 2011-06-14 06:01 . 2011-06-14 06:02 ——– d—–w- c:\users\Monta\AppData\Local\{1B6EA47D-20F1-4637-9EFC-B9DDB11322C1} 2011-06-14 05:57 . 2011-07-04 22:48 ——– d—–w- c:\users\Monta\AppData\Local\temp 2011-06-11 02:27 . 2011-06-11 02:27 ——– d—–w- c:\program files\ESET 2011-06-11 00:19 . 2011-06-11 00:19 589632 —-a-w- C:\aswMBR.exe 2011-06-11 00:06 . 2011-06-11 00:06 ——– d—–w- C:\_OTL 2011-06-09 05:13 . 2011-06-09 05:13 625664 —-a-w- C:\dds.scr 2011-06-08 05:57 . 2011-06-08 05:57 ——– d—–w- c:\users\Monta\AppData\Local\{18F19DC1-96F1-4044-AAE1-FACCE83E8D17} 2011-06-06 19:55 . 2011-06-06 19:55 183696 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-06-30 05:32 . 2011-05-27 08:15 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-05-31 21:51 . 2011-05-31 21:51 1402880 —-a-w- c:\program files\HijackThis.msi 2011-05-29 16:11 . 2011-05-03 05:11 39984 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-27 07:50 . 2009-07-14 02:05 152576 —-a-w- c:\windows\system32\msclmd.dll 2011-05-10 15:06 . 2011-05-10 15:06 4517664 —-a-w- c:\windows\system32\usbaaplrc.dll 2011-05-04 11:52 . 2011-01-22 10:00 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-04-22 19:14 . 2011-05-25 00:40 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys 2011-04-09 06:02 . 2011-05-10 20:26 3967872 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-04-09 06:02 . 2011-05-10 20:26 3912576 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-04-09 05:56 . 2011-05-19 03:29 123904 —-a-w- c:\windows\system32\poqexec.exe 2011-04-06 23:20 . 2011-04-06 23:20 91424 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 23:20 . 2011-04-06 23:20 75040 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 23:20 . 2011-04-06 23:20 197920 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 23:20 . 2011-04-06 23:20 107808 —-a-w- c:\windows\system32\dns-sd.exe 2011-04-02 23:41 242413 –sha-w- c:\windows\System32\sysprep\CRYPTBASE.DLL . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}] 2010-11-05 01:58 297808 —-a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{b278d9f8-0fa9-465e-9938-0c392605d8e3}"= "mscoree.dll" [2010-11-05 297808] . [HKEY_CLASSES_ROOT\clsid\{b278d9f8-0fa9-465e-9938-0c392605d8e3}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-05-27 02:40 120176 —-a-w- c:\program files\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ares"="c:\program files\Ares\Ares.exe" [2010-10-27 1015808] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336] "InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-05-10 1205760] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-10-13 186904] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-06-22 9292392] "SuiteTray"="c:\program files\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264] "EgisUpdate"="c:\program files\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584] "EgisTecPMMUpdate"="c:\program files\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920] "mwlDaemon"="c:\program files\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-06-16 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-06-16 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-06-16 150552] "LManager"="c:\program files\Launch Manager\LManager.exe" [2010-06-22 968272] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-02-05 1692968] "PLFSetI"="c:\windows\PLFSetI.exe" [2010-08-15 206208] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-06-11 715296] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888] "WatcherHelper"="c:\program files\Sierra Wireless Inc\Watcher\WaHelper.exe" [2008-05-28 114688] "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-05-29 1047656] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-08 421160] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux3"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640] R3 EUCR;EUCR;c:\windows\system32\DRIVERS\EUCR6SK.SYS [2010-06-17 82768] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] R3 MWLService;MyWinLocker Service;c:\program files\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [2009-06-03 18992] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [2009-06-03 16432] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [2009-06-03 60976] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 DsiWMIService;Dritek WMI Service;c:\program files\Launch Manager\dsiwmis.exe [2010-06-22 321104] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 735776] S2 GREGService;GREGService;c:\program files\Acer\Registration\GREGsvc.exe [2010-01-08 23584] S2 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [2010-01-29 260640] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x86.sys [2010-05-20 68208] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc . Contents of the 'Scheduled Tasks' folder . 2011-07-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000Core.job - c:\users\Monta\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-21 01:56] . 2011-07-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3581049348-171761381-3618842985-1000UA.job - c:\users\Monta\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-21 01:56] . . ——- Supplementary Scan ——- . mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=1009&m=aod255&r=27b51210w555l0434ww65w4712u741 uInternet Settings,ProxyOverride = *.local IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html TCP: DhcpNameServer = 192.168.1.254 192.168.1.254 . - - - - ORPHANS REMOVED - - - - . HKLM-Run-iBryte playbryte Desktop - c:\program files\iBryte\playbryte\ibrytedesktop.exe AddRemove-iBryte_playbryte - c:\program files\iBryte\playbryte\uninstall.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_USERS\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-3581049348-171761381-3618842985-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ——————— DLLs Loaded Under Running Processes ——————— . - - - - - - - > 'Explorer.exe'(4208) c:\program files\EgisTec MyWinLocker\x86\psdprotect.dll c:\program files\EgisTec MyWinLocker\x86\sysenv.dll c:\program files\Acer\Acer ePower Management\SysHook.dll . Completion time: 2011-07-04 15:54:45 ComboFix-quarantined-files.txt 2011-07-04 22:54 ComboFix2.txt 2011-06-14 06:59 ComboFix3.txt 2011-06-14 06:10 ComboFix4.txt 2011-06-11 00:58 . Pre-Run: 35,019,628,544 bytes free Post-Run: 34,828,775,424 bytes free . - - End Of File - - 2768D87DD23CA983F2D07F89B7AA58D1
Looks ok, nothing removed.

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI