|
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
Join Date: Sep 2004
Location: Carmichaels, PA-USA
Posts: 6,963
OS: Windows 7
|
Again..the logs are clean. This entry...
HKLM\HARDWARE\ACPI\FADT\GATEWA\04DT043_\20041215
Is the 20041215 a folder? If so...open it. Whats listed in the right side pane? Any entrys?
The normal folders for that location are..
HKLM\HARDWARE\ACPI\FADT
HKLM\HARDWARE\ACPI\RSDT
HKLM\HARDWARE\ACPI\DSDT
HKLM\HARDWARE\ACPI\RSDT
Since the next folder in is a Gateway folder it's unlikely any malware would use that directory. I think this is a false positive from the Ewido scan. Again...since this area is for motherboard chipset versions and bios info I don't think it's malware related.
Are you being hijacked to other sites when you start IE? Bascially thats what CWS is designed to do.
|