HJTL- Programs deleted on boot?

vroom_skies

VIP Member
Hey John,
In short this computer was/ is a mess. I've spent the better part of a day trying to finish it up, yet it seems I've been missing something large.

Any type of "security" program gets deleted on boot. You can install them fine, yet after you restart and try to launch it, it's a no go. The error you get is this "Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item" or "application not found". So I'm not sure what's up. Granted this is on Vista 32bit and I don't have much experience on those feilds yet, so maybe it's something really simple I'm over looking.

Thanks in advance.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:57:30 AM, on 1/20/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18865)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\Owner\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp32&d=0109&m=aspire_4730z
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {03402f96-3dc7-4285-bc50-9e81fefafe43} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [MSSE] "C:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: ImageMixer 3 SE Camera Monitor for SD.lnk = C:\Program Files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: PremierOpinion - Unknown owner - C:\Program Files\PremierOpinion\pmservice.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe

--
End of file - 5842 bytes
 
Have you ran combofix yet? If not,

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply please post:
  • The ComboFix log
  • A fresh HiJackThis log
  • An update on how your computer is running
 
Yeah, I've ran combofix and everything else practically lol.
Actually twice, once within the computer and then again with the hdd out and hooked up to a test machine, in which it found more errors. What log would you like? Either of the previous ones or a fresh one?

BTW- Other then this one issue I'm having the computer is running quite nice. So maybe I'm overlooking something and it might be in the realm of user privileges or something, even though the account is an admin account. Maybe Vista is different in these ways.
 
Alright here we go:

CF Log 1:

ComboFix 10-01-19.03 - Owner 01/19/2010 19:58:57.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1977.1168 [GMT -5:00]
Running from: c:\users\Owner\Desktop\Security\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-2124122394-3785959010-2140080963-500

.
((((((((((((((((((((((((( Files Created from 2009-12-20 to 2010-01-20 )))))))))))))))))))))))))))))))
.

2010-01-20 01:07 . 2010-01-20 01:08 -------- d-----w- c:\users\Owner\AppData\Local\temp
2010-01-20 01:07 . 2010-01-20 01:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-19 23:34 . 2010-01-19 23:34 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-01-19 19:37 . 2010-01-14 16:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-19 19:33 . 2010-01-19 19:33 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-01-19 19:31 . 2010-01-19 19:31 -------- d-----w- c:\users\Owner\AppData\Roaming\Malwarebytes
2010-01-19 19:31 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-19 19:31 . 2010-01-19 19:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-19 19:31 . 2010-01-19 19:31 -------- d-----w- c:\programdata\Malwarebytes
2010-01-19 19:31 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-19 18:59 . 2010-01-19 18:59 -------- d-----w- c:\program files\iPod
2010-01-19 18:59 . 2010-01-19 19:01 -------- d-----w- c:\program files\iTunes
2010-01-19 18:28 . 2010-01-19 18:28 -------- d-----w- c:\program files\CCleaner
2010-01-19 18:06 . 2010-01-19 18:08 -------- d-----w- c:\windows\system32\ca-ES
2010-01-19 18:06 . 2010-01-19 18:07 -------- d-----w- c:\windows\system32\eu-ES
2010-01-19 18:06 . 2010-01-19 18:07 -------- d-----w- c:\windows\system32\vi-VN
2010-01-19 17:39 . 2010-01-19 17:39 -------- d-----w- c:\windows\system32\EventProviders
2010-01-14 03:23 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-14 03:23 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-02 16:34 . 2010-01-02 16:34 -------- d-----w- c:\users\Owner\AppData\Roaming\eSobi
2009-12-29 22:03 . 2009-12-29 22:03 -------- d-----w- c:\users\Owner\AppData\Local\CyberLink
2009-12-29 22:03 . 2009-12-29 22:03 -------- d-----w- c:\users\Owner\AppData\Local\PlayMovie
2009-12-29 22:03 . 2009-12-29 22:03 -------- d-----w- c:\users\Owner\AppData\Local\SoftDMA
2009-12-29 22:03 . 2009-12-29 22:03 -------- d-----w- c:\users\Owner\AppData\Local\Acer Arcade Deluxe
2009-12-29 22:03 . 2009-12-29 22:04 -------- d-----w- c:\users\Owner\AppData\Roaming\CyberLink
2009-12-29 20:47 . 2009-12-29 20:47 -------- d-----w- c:\program files\PIXELA
2009-12-26 22:47 . 2009-12-26 22:47 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-20 03:32 . 2008-08-19 02:31 -------- d-----w- c:\program files\Microsoft Works
2010-01-20 03:32 . 2008-08-19 02:29 -------- d-----w- c:\programdata\Microsoft Help
2010-01-19 19:27 . 2008-08-19 02:07 -------- d-----w- c:\programdata\McAfee
2010-01-19 18:59 . 2009-03-25 02:19 -------- d-----w- c:\program files\Common Files\Apple
2010-01-19 18:29 . 2009-03-25 03:26 -------- d-----w- c:\programdata\Viewpoint
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-01-19 18:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-01-19 18:06 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-01-02 16:36 . 2009-01-14 20:56 -------- d-----w- c:\programdata\CyberLink
2009-12-29 23:22 . 2009-12-29 23:22 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-29 20:47 . 2008-08-19 01:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-25 23:15 . 2009-01-14 20:51 -------- d-----w- c:\program files\Google
2009-12-25 17:33 . 2008-08-19 02:11 -------- d-----w- c:\program files\Acer GameZone
2009-12-12 22:37 . 2009-04-01 02:39 -------- d-----w- c:\users\Owner\AppData\Roaming\LimeWire
2009-12-12 22:18 . 2009-04-01 02:36 -------- d-----w- c:\program files\LimeWire
2009-12-09 16:04 . 2009-12-09 16:03 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-09 15:58 . 2009-12-09 15:57 -------- d-----w- c:\program files\QuickTime
2009-12-09 15:50 . 2009-03-25 02:19 -------- d-----w- c:\programdata\Apple
2009-12-09 15:46 . 2009-03-25 03:26 -------- d-----w- c:\program files\Common Files\AOL
2009-12-09 15:14 . 2009-03-25 02:23 -------- d-----w- c:\users\Owner\AppData\Roaming\Apple Computer
2009-12-05 03:05 . 2009-12-05 03:05 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbAAA2.tmp.exe
2009-11-21 06:40 . 2010-01-19 17:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2010-01-19 17:21 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2010-01-19 17:21 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2010-01-19 17:21 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-12 22:07 . 2009-11-12 22:07 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-09 12:31 . 2009-12-09 08:10 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 08:10 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 08:10 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-29 09:17 . 2009-11-25 12:30 2048 ----a-w- c:\windows\system32\tzres.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-30 00:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-07-30 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-16 170520]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-16 150040]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-16 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-20 6244896]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ImageMixer 3 SE Camera Monitor for SD.lnk - c:\program files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe [2009-12-29 253952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
2007-11-19 22:17 1261568 ----a-w- c:\program files\Acer\Acer Assist\launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 21:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2007-07-22 01:18 159744 ----a-w- c:\program files\Apoint2K\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeDeluxeAgent]
2008-07-24 23:54 147456 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-26 04:36 28672 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-07-24 23:54 167936 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightLAN 01]
2005-08-11 01:10 380928 ----a-w- c:\program files\EarthLink TotalAccess\FastLane2\IPClient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
2005-08-11 01:10 122880 ----a-w- c:\program files\EarthLink TotalAccess\FastLane2\ipmon32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2008-07-02 18:35 850440 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
2008-07-19 00:04 167936 ------w- c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-06-20 00:52 6244896 ----a-w- c:\windows\RtHDVCpl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-04-01 02:37 136600 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b0,35,a0,51,33,99,ca,01

R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [1/14/2009 3:58 PM 61424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 3:11 PM 16384]
R2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [1/14/2009 3:59 PM 81504]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [8/18/2008 9:06 PM 24576]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/25/2008 11:36 PM 45056]
R2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [1/14/2009 3:59 PM 122368]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [8/15/2008 1:17 PM 93968]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [6/18/2009 6:48 PM 42480]
R3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\System32\drivers\netr28.sys [8/18/2008 9:15 PM 388096]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/25/2008 11:36 PM 131072]
S2 PremierOpinion;PremierOpinion;c:\program files\PremierOpinion\pmservice.exe /service --> c:\program files\PremierOpinion\pmservice.exe [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp32&d=0109&m=aspire_4730z
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-19 20:08
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(3592)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\System32\SysHook.dll
.
Completion time: 2010-01-19 20:11:15
ComboFix-quarantined-files.txt 2010-01-20 01:11

Pre-Run: 50,899,279,872 bytes free
Post-Run: 50,847,072,256 bytes free

- - End Of File - - 7D411E2DB101D3680A7F2364755B0DA7
 
CF Log 3:

ComboFix 10-01-19.08 - Owner 01/20/2010 11:11:56.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1977.1203 [GMT -5:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-842925246-1343024091-725345543-1003

.
((((((((((((((((((((((((( Files Created from 2009-12-20 to 2010-01-20 )))))))))))))))))))))))))))))))
.

2010-01-20 16:19 . 2010-01-20 16:19 -------- d-----w- c:\users\Owner\AppData\Local\temp
2010-01-20 16:19 . 2010-01-20 16:19 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-20 16:19 . 2010-01-20 16:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-20 05:57 . 2010-01-20 05:57 -------- d-----w- c:\program files\Trend Micro
2010-01-20 05:41 . 2010-01-20 05:41 -------- d-----w- C:\VundoFix Backups
2010-01-20 05:26 . 2010-01-20 05:26 -------- d-----w- c:\program files\Windows Portable Devices
2010-01-20 05:10 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-01-20 05:09 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2010-01-20 05:09 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2010-01-20 05:09 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2010-01-19 23:34 . 2010-01-19 23:34 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-01-19 19:37 . 2010-01-14 16:12 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-19 19:33 . 2010-01-19 19:33 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-01-19 19:31 . 2010-01-19 19:31 -------- d-----w- c:\users\Owner\AppData\Roaming\Malwarebytes
2010-01-19 19:31 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-19 19:31 . 2010-01-19 19:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-19 19:31 . 2010-01-19 19:31 -------- d-----w- c:\programdata\Malwarebytes
2010-01-19 19:31 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-19 18:59 . 2010-01-20 04:53 -------- d-----w- c:\program files\iPod
2010-01-19 18:59 . 2010-01-20 04:54 -------- d-----w- c:\program files\iTunes
2010-01-19 18:28 . 2010-01-19 18:28 -------- d-----w- c:\program files\CCleaner
2010-01-19 18:06 . 2010-01-19 18:08 -------- d-----w- c:\windows\system32\ca-ES
2010-01-19 18:06 . 2010-01-19 18:07 -------- d-----w- c:\windows\system32\eu-ES
2010-01-19 18:06 . 2010-01-19 18:07 -------- d-----w- c:\windows\system32\vi-VN
2010-01-19 17:39 . 2010-01-19 17:39 -------- d-----w- c:\windows\system32\EventProviders
2010-01-14 03:23 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-14 03:23 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-02 16:34 . 2010-01-02 16:34 -------- d-----w- c:\users\Owner\AppData\Roaming\eSobi
2009-12-29 22:03 . 2009-12-29 22:03 -------- d-----w- c:\users\Owner\AppData\Local\CyberLink
2009-12-29 22:03 . 2009-12-29 22:03 -------- d-----w- c:\users\Owner\AppData\Local\PlayMovie
2009-12-29 22:03 . 2009-12-29 22:03 -------- d-----w- c:\users\Owner\AppData\Local\SoftDMA
2009-12-29 22:03 . 2009-12-29 22:03 -------- d-----w- c:\users\Owner\AppData\Local\Acer Arcade Deluxe
2009-12-29 22:03 . 2009-12-29 22:04 -------- d-----w- c:\users\Owner\AppData\Roaming\CyberLink
2009-12-29 20:47 . 2009-12-29 20:47 -------- d-----w- c:\program files\PIXELA
2009-12-26 22:47 . 2009-12-26 22:47 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-20 05:25 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-01-20 05:15 . 2010-01-20 05:15 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-01-20 05:15 . 2010-01-20 05:15 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-01-20 05:13 . 2008-08-19 02:29 -------- d-----w- c:\programdata\Microsoft Help
2010-01-20 05:03 . 2008-08-19 02:31 -------- d-----w- c:\program files\Microsoft Works
2010-01-20 04:54 . 2009-03-25 02:20 -------- d-----w- c:\programdata\Apple Computer
2010-01-20 04:51 . 2009-12-09 15:57 -------- d-----w- c:\program files\QuickTime
2010-01-19 18:29 . 2009-03-25 03:26 -------- d-----w- c:\programdata\Viewpoint
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2010-01-19 18:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2010-01-19 18:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2010-01-02 16:36 . 2009-01-14 20:56 -------- d-----w- c:\programdata\CyberLink
2009-12-29 23:22 . 2009-12-29 23:22 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-12-29 20:47 . 2008-08-19 01:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-25 23:15 . 2009-01-14 20:51 -------- d-----w- c:\program files\Google
2009-12-25 17:33 . 2008-08-19 02:11 -------- d-----w- c:\program files\Acer GameZone
2009-12-12 22:37 . 2009-04-01 02:39 -------- d-----w- c:\users\Owner\AppData\Roaming\LimeWire
2009-12-12 22:18 . 2009-04-01 02:36 -------- d-----w- c:\program files\LimeWire
2009-12-09 16:04 . 2009-12-09 16:03 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-09 15:50 . 2009-03-25 02:19 -------- d-----w- c:\programdata\Apple
2009-12-09 15:46 . 2009-03-25 03:26 -------- d-----w- c:\program files\Common Files\AOL
2009-12-09 15:14 . 2009-03-25 02:23 -------- d-----w- c:\users\Owner\AppData\Roaming\Apple Computer
2009-12-05 03:05 . 2009-12-05 03:05 484976 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtbAAA2.tmp.exe
2009-11-21 06:40 . 2010-01-19 17:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2010-01-19 17:21 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2010-01-19 17:21 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2010-01-19 17:21 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-09 12:31 . 2009-12-09 08:10 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 08:10 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 08:10 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-29 09:17 . 2009-11-25 12:30 2048 ----a-w- c:\windows\system32\tzres.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-30 00:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-07-30 526896]
"ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 405504]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-16 170520]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-16 150040]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-16 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-20 6244896]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
ImageMixer 3 SE Camera Monitor for SD.lnk - c:\program files\PIXELA\ImageMixer 3 SE for SD\CameraMonitor.exe [2009-12-29 253952]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
2007-11-19 22:17 1261568 ----a-w- c:\program files\Acer\Acer Assist\launcher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 21:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2007-07-22 01:18 159744 ----a-w- c:\program files\Apoint2K\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcadeDeluxeAgent]
2008-07-24 23:54 147456 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BkupTray]
2008-04-26 04:36 28672 ----a-w- c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CLMLServer]
2008-07-24 23:54 167936 ------w- c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2008-07-02 18:35 850440 ----a-w- c:\progra~1\LAUNCH~1\LManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayMovie]
2008-07-19 00:04 167936 ------w- c:\program files\Acer Arcade Deluxe\PlayMovie\PMVService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2008-06-20 00:52 6244896 ----a-w- c:\windows\RtHDVCpl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-04-01 02:37 136600 ----a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):b0,35,a0,51,33,99,ca,01

R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl [1/14/2009 3:58 PM 61424]
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [3/3/2008 3:11 PM 16384]
R2 CLHNService;CLHNService;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [1/14/2009 3:59 PM 81504]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [4/25/2008 11:36 PM 45056]
R2 NTIPPKernel;NTIPPKernel;c:\program files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\NTIPPKernel.sys [1/14/2009 3:59 PM 122368]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [8/15/2008 1:17 PM 93968]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\System32\drivers\MpNWMon.sys [6/18/2009 6:48 PM 42480]
R3 netr28;Ralink 802.11n Wireless Driver for Windows Vista;c:\windows\System32\drivers\netr28.sys [8/18/2008 9:15 PM 388096]
S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [8/18/2008 9:06 PM 24576]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [4/25/2008 11:36 PM 131072]
S2 PremierOpinion;PremierOpinion;c:\program files\PremierOpinion\pmservice.exe /service --> c:\program files\PremierOpinion\pmservice.exe [?]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 9:23 PM 21504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp32&d=0109&m=aspire_4730z
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-IPInSightLAN 01 - c:\program files\EarthLink TotalAccess\FastLane2\IPClient.exe
MSConfigStartUp-IPInSightMonitor 01 - c:\program files\EarthLink TotalAccess\FastLane2\IPMon32.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-20 11:19
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\PlayMovie\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(2276)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
c:\windows\System32\SysHook.dll
.
Completion time: 2010-01-20 11:22:43
ComboFix-quarantined-files.txt 2010-01-20 16:22
ComboFix2.txt 2010-01-20 01:11

Pre-Run: 46,025,203,712 bytes free
Post-Run: 45,998,792,704 bytes free

- - End Of File - - 16299628D8807E4874FC270A38C71411
 
Hey Vroom,

I have to leave for work shortly but i will look more into your logs when i get home later tonight. I can't access the uploaded one right now anyway, server is too busy.
 
Hey John

I wish I could tell ya, but it's not my computer and I don't have a clue. If I had to guess I would say within the month, but not sure.

Thanks for the help mate.
 
Back
Top