Thanks for your interest in my logfiles for Hijack this. The www.hijackthis.de analysis tool is very interesting as well.
The first entry the AEIWLSTA.exe is foreign to me.
The Click Yes was was added by me as a tool to circumvent the security pop up in Outlook that has always asked me to verify its ok for my electronic organizer to access the names and addresses in my contacts folder of Microsoft Outlook. The outlook security gets in the way of an unattended synchronization of my organizer so click yes was purchased to get by the problem.
WinfernoUpdate is for the Secure IE browser I purchased from McAfee its ok.
I don't know what Pixelinstall is or Run once Reboo is.
The trusted zone ptaweb is where I log in my work hours for my job. Its ok.
The ibm stuff is a good question. It could be for the software / driver updating software that IBM has provided for the laptop. or it could be a rouge program posing as IBM stuff The link when clicked on trys to download a program called acpIR.cab..... I have heard of acp with respect to power management and IR has been used to describe infra red. The laptop indeed has an IR sensor.
Thanks Tolomir for your assistance any additional comments from all are welcome...
Thomas Starich RS
Food and Dairy Specialist
Madison, WI
Main Topics
Browse All Topics





by: TolomirPosted on 2007-07-30 at 21:53:27ID: 19597822
Hewre is the short result of www.hijackthis.de
TA.EXE e" 673D253994 4} (IASRunner Class) - https://www-307.ibm.com/pc /support/a ccess/asli bmain/cont ent/ AcpIR. cab
[?] - C:\WINDOWS\system32\AEIWLS
[?] - C:\Program Files\ClickYes Pro\ClickYesPro.exe
[?] - O4 - HKLM\..\Run: [WinfernoUpdate] "C:\Program Files\Common Files\Winferno\WSCUpdtr.ex
[?] - O4 - HKLM\..\RunOnce: [PixelInstall]
[?] - O4 - HKLM\..\RunOnce: [Reboot]
[?] - O4 - HKCU\..\Run: [ClickYes Pro] C:\Program Files\ClickYes Pro\ClickYesPro.exe
[?] - O15 - Trusted Zone: ptaweb.state.wi.us
[?] - O16 - DPF: {2DAD3559-2923-4935-AD49-B