Hi I'm Nackio and not very tech savvy.
I can't access my control panel on my Acer Aspire Windows Vista laptop. I already did some of the steps I saw outlined in previous threads.
Here is my Combo fix report log:
ComboFix 08-12-12.05 - Nadia&Shaq 2008-12-13 12:17:10.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1013.243 [GMT -5:00]
Running from: c:\users\Nadia&Shaq\Downloads\ComboFix.exe
* Created a new restore point
.
Error: Cfiles.dat
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Nadia&Shaq\AppData\Roaming\.#
.
((((((((((((((((((((((((( Files Created from 2008-11-13 to 2008-12-13 )))))))))))))))))))))))))))))))
.
2008-12-13 09:54 . 2008-12-13 09:54 <DIR> d-------- c:\users\Nadia&Shaq\AppData\Roaming\Uniblue
2008-12-13 00:12 . 2008-12-13 00:12 <DIR> d-------- c:\program files\Trend Micro
2008-12-12 10:52 . 2008-10-21 20:22 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-11 21:58 . 2008-10-31 20:21 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-11 21:58 . 2008-10-21 00:25 296,960 --a------ c:\windows\System32\gdi32.dll
2008-12-11 21:58 . 2008-10-31 22:44 28,672 --a------ c:\windows\System32\Apphlpdm.dll
2008-12-08 17:58 . 2008-12-08 17:58 <DIR> d-------- c:\users\All Users\LogMeIn
2008-12-08 17:58 . 2008-12-08 17:58 <DIR> d-------- c:\programdata\LogMeIn
2008-12-08 17:56 . 2008-10-16 20:35 87,352 --a------ c:\windows\System32\LMIinit.dll
2008-12-08 17:56 . 2008-10-16 20:35 83,288 --a------ c:\windows\System32\LMIRfsClientNP.dll
2008-12-08 17:56 . 2008-07-24 18:46 47,640 --a------ c:\windows\System32\drivers\LMIRfsDriver.sys
2008-12-08 17:56 . 2008-10-16 20:35 28,984 --a------ c:\windows\System32\LMIport.dll
2008-12-08 17:56 . 2008-12-08 17:56 1,024 --a------ C:\.rnd
2008-12-08 17:55 . 2008-12-13 00:08 <DIR> d-------- c:\program files\LogMeIn
2008-12-08 15:43 . 2008-12-08 15:43 <DIR> d-------- c:\program files\Microsoft Easy Assist
2008-12-08 15:42 . 2008-12-08 15:42 <DIR> d-------- c:\users\All Users\Applications
2008-12-08 15:42 . 2008-12-08 15:42 <DIR> d-------- c:\programdata\Applications
2008-12-08 14:56 . 2008-12-08 14:56 <DIR> d-------- c:\users\All Users\Citrix
2008-12-08 14:56 . 2008-12-08 14:56 <DIR> d-------- c:\programdata\Citrix
2008-12-08 14:38 . 2008-12-08 14:38 61,224 --a------ c:\users\Nadia&Shaq\GoToAssistDownloadHelper.exe
2008-12-08 14:28 . 2008-12-08 14:28 <DIR> d-------- c:\users\Nadia&Shaq\AppData\Roaming\McAfee
2008-12-03 23:42 . 2008-12-04 06:47 <DIR> d-------- c:\program files\3D LOTR Sauron Eye
2008-12-03 23:42 . 2008-12-04 06:46 65,879 --a------ c:\windows\System32\3D LOTR SAURON EYE.scr
2008-12-03 23:18 . 2008-12-03 23:20 <DIR> d-------- c:\users\Nadia&Shaq\AppData\Roaming\vlc
2008-12-03 23:16 . 2008-12-03 23:16 <DIR> d-------- c:\program files\VideoLAN
2008-12-03 21:48 . 2008-12-03 21:48 <DIR> d-------- c:\program files\uTorrent
2008-12-03 21:47 . 2008-12-09 07:32 <DIR> d-------- c:\users\Nadia&Shaq\AppData\Roaming\uTorrent
2008-11-30 00:13 . 2008-11-30 00:13 <DIR> dr------- c:\users\Guest\Searches
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> dr------- c:\users\Guest\Videos
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> dr------- c:\users\Guest\Saved Games
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> dr------- c:\users\Guest\Pictures
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> dr------- c:\users\Guest\Music
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> dr------- c:\users\Guest\Links
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> dr------- c:\users\Guest\Downloads
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> dr------- c:\users\Guest\Documents
2008-11-30 00:12 . 2008-11-30 00:12 <DIR> dr------- c:\users\Guest\Contacts
2008-11-30 00:12 . 2006-11-02 07:37 <DIR> d-------- c:\users\Guest\AppData\Roaming\Media Center Programs
2008-11-30 00:12 . 2008-03-20 12:07 <DIR> d-------- c:\users\Guest\AppData\Roaming\Acer GameZone Console
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> d--h----- c:\users\Guest\AppData
2008-11-30 00:12 . 2008-11-30 00:13 <DIR> d-------- c:\users\Guest
2008-11-29 14:45 . 2008-11-29 14:45 <DIR> d-------- c:\users\All Users\Google
2008-11-29 14:43 . 2008-12-13 00:18 <DIR> d-------- c:\users\All Users\Google Updater
2008-11-29 14:43 . 2008-12-13 00:18 <DIR> d-------- c:\programdata\Google Updater
2008-11-29 14:43 . 2008-11-29 15:05 <DIR> d-------- c:\program files\Google
2008-11-29 13:29 . 2008-12-08 23:42 <DIR> d-------- c:\users\Nadia&Shaq\AppData\Roaming\LimeWire
2008-11-29 13:25 . 2008-11-29 13:24 410,976 --a------ c:\windows\System32\deploytk.dll
2008-11-29 13:24 . 2008-11-29 13:24 <DIR> d-------- c:\program files\Java
2008-11-29 13:04 . 2008-11-29 13:14 <DIR> d-------- c:\program files\Windows Live Toolbar
2008-11-29 12:59 . 2008-11-29 12:59 <DIR> d-------- c:\program files\MSN Messenger
2008-11-29 11:28 . 2008-11-29 11:32 <DIR> d-------- c:\users\All Users\Yahoo!
2008-11-29 11:28 . 2008-11-29 11:32 <DIR> d-------- c:\programdata\Yahoo!
2008-11-28 23:01 . 2008-11-28 23:01 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-28 22:48 . 2008-06-25 20:45 12,240,896 --a------ c:\windows\System32\NlsLexicons0007.dll
2008-11-28 22:48 . 2008-06-25 20:45 2,644,480 --a------ c:\windows\System32\NlsLexicons0009.dll
2008-11-28 22:48 . 2008-08-05 04:49 428,544 --a------ c:\windows\System32\EncDec.dll
2008-11-28 22:48 . 2008-08-05 04:49 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-11-28 22:48 . 2008-08-05 04:48 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-11-28 22:48 . 2008-08-05 04:48 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-11-28 22:48 . 2008-08-05 04:48 80,896 --a------ c:\windows\System32\MSNP.ax
2008-11-28 22:48 . 2008-04-22 23:41 57,856 --a------ c:\windows\System32\MSDvbNP.ax
2008-11-28 22:47 . 2008-06-25 22:29 801,280 --a------ c:\windows\System32\NaturalLanguage6.dll
2008-11-28 22:42 . 2008-02-29 02:11 988,216 --a------ c:\windows\System32\winload.exe
2008-11-28 22:42 . 2008-02-29 02:11 927,288 --a------ c:\windows\System32\winresume.exe
2008-11-28 22:42 . 2008-02-22 00:05 615,992 --a------ c:\windows\System32\ci.dll
2008-11-28 22:42 . 2008-02-29 02:14 19,000 --a------ c:\windows\System32\kd1394.dll
2008-11-28 22:41 . 2008-02-29 01:53 378,368 --a------ c:\windows\System32\srcore.dll
2008-11-28 22:41 . 2008-02-28 23:12 318,464 --a------ c:\windows\System32\rstrui.exe
2008-11-28 22:41 . 2008-02-29 01:53 46,592 --a------ c:\windows\System32\setbcdlocale.dll
2008-11-28 22:41 . 2008-02-29 01:53 40,960 --a------ c:\windows\System32\srclient.dll
2008-11-28 22:41 . 2008-02-28 23:12 14,848 --a------ c:\windows\System32\srdelayed.exe
2008-11-28 22:41 . 2008-02-29 01:35 6,656 --a------ c:\windows\System32\kbd106n.dll
2008-11-28 22:39 . 2008-03-07 23:21 1,695,744 --a------ c:\windows\System32\gameux.dll
2008-11-28 22:39 . 2008-10-21 00:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-28 22:39 . 2008-09-09 22:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-28 22:39 . 2008-04-26 03:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2008-11-28 22:39 . 2008-04-11 22:32 784,896 --a------ c:\windows\System32\rpcrt4.dll
2008-11-28 22:39 . 2008-06-18 22:31 361,984 --a------ c:\windows\System32\IPSECSVC.DLL
2008-11-28 22:39 . 2008-10-21 22:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-28 22:39 . 2008-04-04 20:21 72,192 --a------ c:\windows\System32\drivers\pacer.sys
2008-11-28 22:39 . 2008-04-04 22:34 15,360 --a------ c:\windows\System32\pacerprf.dll
2008-11-28 22:38 . 2008-09-17 21:16 2,032,640 --a------ c:\windows\System32\win32k.sys
2008-11-28 22:38 . 2008-06-25 22:29 303,616 --a------ c:\windows\System32\wmpeffects.dll
2008-11-28 22:38 . 2008-04-18 00:48 269,312 --a------ c:\windows\System32\es.dll
2008-11-28 22:38 . 2008-08-26 20:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-28 22:37 . 2008-04-26 03:08 1,314,816 --a------ c:\windows\System32\quartz.dll
2008-11-28 22:37 . 2008-09-05 00:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-28 22:37 . 2008-08-27 22:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-28 22:37 . 2008-08-27 22:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-28 22:37 . 2008-08-27 22:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-28 22:37 . 2008-08-26 20:06 288,768 --a------ c:\windows\System32\drivers\srv.sys
2008-11-28 22:37 . 2008-09-17 23:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-11-28 22:36 . 2008-08-11 22:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-11-28 22:36 . 2008-05-08 16:59 430,080 --a------ c:\windows\System32\vbscript.dll
2008-11-28 22:36 . 2008-05-08 16:59 180,224 --a------ c:\windows\System32\scrobj.dll
2008-11-28 22:36 . 2008-05-08 16:59 172,032 --a------ c:\windows\System32\scrrun.dll
2008-11-28 22:36 . 2008-05-08 16:59 155,648 --a------ c:\windows\System32\wscript.exe
2008-11-28 22:36 . 2008-05-08 16:58 135,168 --a------ c:\windows\System32\wshom.ocx
2008-11-28 22:36 . 2008-05-08 16:58 135,168 --a------ c:\windows\System32\cscript.exe
2008-11-28 22:36 . 2008-09-17 23:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-11-28 22:36 . 2008-05-08 16:59 90,112 --a------ c:\windows\System32\wshext.dll
2008-11-28 22:35 . 2008-04-10 00:12 738,304 --a------ c:\windows\System32\inetcomm.dll
2008-11-28 22:35 . 2008-08-01 20:01 625,152 --a------ c:\windows\System32\drivers\dxgkrnl.sys
2008-11-28 22:35 . 2008-06-25 22:29 565,248 --a------ c:\windows\System32\emdmgmt.dll
2008-11-28 22:35 . 2008-05-19 21:07 148,480 --a------ c:\windows\System32\drivers\nwifi.sys
2008-11-28 22:35 . 2008-05-09 20:33 113,664 --a------ c:\windows\System32\drivers\rmcast.sys
2008-11-28 22:35 . 2008-06-25 22:29 45,056 --a------ c:\windows\System32\dataclen.dll
2008-11-28 22:35 . 2008-08-01 22:26 36,864 --a------ c:\windows\System32\cdd.dll
2008-11-28 22:34 . 2008-09-18 00:09 3,601,464 --a------ c:\windows\System32\ntkrnlpa.exe
2008-11-28 22:34 . 2008-09-18 00:09 3,549,240 --a------ c:\windows\System32\ntoskrnl.exe
2008-11-28 22:26 . 2008-11-28 22:26 <DIR> d-------- c:\program files\Convesoft
2008-11-28 22:11 . 2008-10-16 16:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-28 22:11 . 2008-10-16 15:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-28 22:11 . 2008-10-16 16:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-28 22:11 . 2008-10-16 16:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-28 22:10 . 2008-10-16 16:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-28 22:10 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-28 22:10 . 2008-10-16 15:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-28 22:10 . 2008-10-16 16:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-28 22:10 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-23 15:37 . 2008-11-23 15:37 <DIR> d-------- c:\program files\VirtualDJ
2008-11-20 09:16 . 2008-11-20 09:16 <DIR> dr------- c:\windows\System32\config\systemprofile\Music
2008-11-20 08:42 . 2008-11-20 08:42 <DIR> d-------- c:\users\Nadia&Shaq\AppData\Roaming\Yahoo!
2008-11-20 08:42 . 2008-12-08 14:32 <DIR> d-------- c:\users\All Users\Yahoo! Companion
2008-11-20 08:42 . 2008-12-08 14:32 <DIR> d-------- c:\programdata\Yahoo! Companion
2008-11-20 08:37 . 2008-11-20 08:37 <DIR> d-------- c:\windows\A5W_DATA
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-13 14:48 --------- d-----w c:\program files\McAfee
2008-12-12 16:07 --------- d-----w c:\program files\Windows Mail
2008-12-12 15:55 --------- d-----w c:\programdata\Microsoft Help
2008-12-11 16:08 --------- d-----w c:\program files\Common Files\Adobe
2008-12-08 19:29 --------- d-----w c:\programdata\McAfee
2008-12-01 02:09 --------- d-----w c:\program files\Microsoft Works
2008-11-29 16:28 --------- d-----w c:\program files\Yahoo!
2008-11-29 16:12 --------- d-----w c:\programdata\SiteAdvisor
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-10-17 01:35 23,736 ----a-w c:\windows\System32\lmimirr.dll
2008-10-17 01:35 10,040 ----a-w c:\windows\System32\lmimirr2.dll
2008-10-16 04:47 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 21:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
2008-07-28 05:47 160496 --a------ c:\progra~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-01-03 04:00 39472 --a------ c:\acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-20 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-29 39408]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-20 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-04 582992]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-03-05 525360]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-22 133656]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-01-04 768520]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2008-01-22 200704]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-21 159744]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-29 136600]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-11 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-11-20 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2008-03-20 535336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= command.com
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{FC1EF117-9858-44F7-95CC-A3DC4313EAE0}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{ED2FC4EB-32A1-4E56-904D-4EA0614FD500}"= c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{33EEE166-85DE-46AC-87E1-E20A5A5434EB}"= c:\program files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{BDA5D874-16EF-4B10-8BA6-5856E0B56CE3}"= c:\program files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{0FDC3C5C-F4E1-4111-B538-9BCA586D69A3}"= c:\program files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{6C8BF0A6-8497-4690-A024-11A85EAD1B0E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{7E422C72-CDB8-4FA4-A345-DC20BD82DD47}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{78033C92-06D3-4A55-913A-B06406669F70}"= c:\program files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{3812D509-2657-457B-AD54-B5D98534A92A}"= c:\program files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{43BB7FD7-AE73-486E-A17E-032081D8B1A6}"= c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{F6398282-9C3E-4A5F-B203-206AF22BF206}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C5371192-20E5-44BF-8B0E-75ED1AA54FF7}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{36DEF293-BB86-42EA-AACA-27FED8C4BB37}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{DC34A87D-33C2-43DD-9632-C256E6DCA0DD}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{D28E8693-C2E2-41DE-92D4-F7300677E353}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDSfsu.exe"= c:\acer\Empowering Technology\eDataSecurity\x86\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\encryption.exe"= c:\acer\Empowering Technology\eDataSecurity\x86\encryption.exe:*:Enabled:encryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\decryption.exe"= c:\acer\Empowering Technology\eDataSecurity\x86\decryption.exe:*:Enabled:decryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDSMgr.exe"= c:\acer\Empowering Technology\eDataSecurity\x86\eDSMgr.exe:*:Enabled:eDSMgr
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x86\\eDStbmngr.exe"= c:\acer\Empowering Technology\eDataSecurity\x86\eDStbmngr.exe:*:Enabled:eDStbmngr
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x64\\eDSfsu.exe"= c:\acer\Empowering Technology\eDataSecurity\x64\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x64\\encryption.exe"= c:\acer\Empowering Technology\eDataSecurity\x64\encryption.exe:*:Enabled:encryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x64\\decryption.exe"= c:\acer\Empowering Technology\eDataSecurity\x64\decryption.exe:*:Enabled:decryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x64\\eDSMgr.exe"= c:\acer\Empowering Technology\eDataSecurity\x64\eDSMgr.exe:*:Enabled:eDSMgr
"c:\\Acer\\Empowering Technology\\eDataSecurity\\x64\\eDStbmngr.exe"= c:\acer\Empowering Technology\eDataSecurity\x64\eDStbmngr.exe:*:Enabled:eDStbmngr
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};\??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [2008-06-06 23:22:38 41456]
R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2008-03-20 51200]
R2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys [2008-07-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\c:\windows\system32\drivers\LMIRfsDriver.sys [2008-12-08 47640]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\McAfee\SiteAdvisor\McSACore.exe" [2008-11-29 203280]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-03-20 180736]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0a0558cc-b999-11dd-bb5c-d641401f22e2}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-12-13 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 17:39]
2008-03-20 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-03-20 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-000 - c:\users\Nadia&Shaq\AppData\Roaming\csrss.exe
HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
HKLM-Run-ALaunch - c:\acer\ALaunch\AlaunchClient.exe
HKLM-Run-Acer Tour Reminder - c:\acer\AcerTour\Reminder.exe
HKLM-Run-SetPanel - c:\acer\APanel\APanel.cmd
HKLM-Run-eRecoveryService - (no file)
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-13 12:20:04
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-13 12:24:18
ComboFix-quarantined-files.txt 2008-12-13 17:24:13
Pre-Run: 17,242,034,176 bytes free
Post-Run: 17,022,099,456 bytes free
281 --- E O F --- 2008-12-12 15:55:46
And here is the Hijack this version 2.0.2. report:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:15:36 AM, on 12/13/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\PLFSetI.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\NADIA&~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.uk.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.uk.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0983.0\msneshellx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0983.0\msneshellx.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [000] C:\Users\Nadia&Shaq\AppData\Roaming\csrss.exe
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Orion.lnk = C:\Convesoft\Orion\Messenger.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?e=1227983169368&h=51be089aba0e2510d19862f564c43c88/&filename=jinstall-6u10-windows-i586-jc.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 11839 bytes
Please assist in any way possible!