I'm infected with a vundo variant according to super anti spyware (completely updated).
Malwarebyte's also indicate that I'm infected by a BHO with the registry key {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}
Both programs say they'll delete the file upon rebooting, so I've rebooted when they prompted me to, but when I scan again the infection is still there.
When I do a google search in mozilla firefox it'll redirect me to several other links such as
<hxxp://78.47.100.188/check.php?t=5922218ec0213203bacce786d975c90e&q=seltzer+recipes&bi=1487289567-2269484681-3959674531-1044314100&p=ff&a=998&s=3&e=google&v=sni06040901ff&f=income&b=0.0213&u=aHR0cDovL2MuaW5jb21lcHBjLmNvbS8/ZD1yQWI5eDhoaGZ4dE51Ty1WRUJ3ejBpR3ZLalBQVVdKWWVxd3ZNZ1lwNVA0YnR1TnJzZjVaWmNBbklTWFlkeDE5a0RiTkRnVmRQYlg2QnpIeUJibmplWldUdFBZNm02TnRMUlJUUFRQdEZ6dkE0c0pxMlMwcVNfYzhjMjRLNzY3WVh2Q040eURFeG11SUREa2pYZlVzbHZtUHBGV1BBSFdfdk11V1JITEV2bUFTeE1EVkR1bGVGZG54RkVvd0ZWa0piWGt0R3EzQlFHN0FEcWtkR2duOVpObEtYaXdYY0lSQV9TT2lTcjFBb0k5X0E1TkU3OUFMbHp1X1pWVUlnbGVJQjAwbThyM2tZLTVULXR6cTN0T1BZbFk4N1VEcGFKUjlGV3lDWi1nZ3BPMVF1NDlhUURpOGJKb19pTXdseG5OaFFaMk9KVWliMWQ5ajV3NVEtVXcya1FOVTJTcUNlcUcwaFk2c3dGMWtoaXh6LUxzOW5zYjVhUHItZFpWbzk1Wi1jWU9fR2c1OUdqVktoV1A4QUNxVnc0QTQzakhDamZQeU03ek5ldVJTQUdpS2VHWlU1NmRhUEhmS0tyLXlFNHlDbVV4NjFRb1E4dGM4LXJlaDZKeC01aG5ydVpvcXpaQTdXcUNqemRHay1ITkFMd25DaHNrdXdHRFJ1NGo5RWVXTFdDWGNyRmNsZXA3b3FhaDZQYnJ2RmVoMGJQSWVZUC1LdjloVWxWblRYUWxPZnd2MEx2eHFVMEstLWNvRmZ5dzFaRURUQmNmbDlxSmVjZXNxMjFwUzNvalV2N1dtOWF4a0NwQVd5U0JfOUc4NjBjemdJSnh3cGlOZWpLTFpaOVRHR0FxTzVxakFDVWlvUHdpa0xmaUN4ZzZvaDhHcm4tVEhPeGhDeEplUUhneE1XLS10REQxQTZEdl9yaVh3Vzd5ZW9SLWg5MUpHOTNRbW4zdDh2T1dVN3pwWHcxOFlGVm9VNlZGREFxZXdOaTBmdlZHZVAxaml3MkJKRzlmOXJETGQwNGNVQW9XZzBIS3dWaDNUVEZzZzBOT19xQTlNTFdJMEozOEhDazY0WW9BaVJtc25KLXZTRjBUOXZfbU1XM1dYX3I3NzJ4WmxGWUlfTmx2bFBMWWNlcDlGaXZfbzducXBWUDQ5ajMzelhwLU8yNEpRSEc0bWlVdk1oaFpobXl3WEpGTXNPYjdhYjlzUzV2SGdlZkpyblVfLWVTUW5OUGtodFZWMkRaR2VkZGJvSXE3OFdpTktlS0pTNmtLdlZuR2xEYW5Kc1RtcFpHZXc4XzlSUHM5ZFNzX3VZTDhvOTNhczRHWTVzSVFIYXc2Wmx4MDBfSjZ0UFJoa2RUVlpWdmxhTmI0U3dURE9aTkphQk5BTV9RcDlUSFNELT0tPS1BbUxoQkY0a0F2NGtBR3BpTGw1am5VTi9wM2psQkdwanNRQThCUU5qc1VBeW9VRTZNS1Z0cHpJd25LT3lwM2prWlFSMFpRQThBS2pqc1FFdVpHTjVMd0g0c1FINEFHSDFNUVN2c1FPOEFKUjFaMkg1TXdxOFpHdXdaSlIzQlRXOHAySXVwekFiTVQ5d3FKMXlvYURobko1em9qPT0tPS09LTJmZTcwNDkxMWExNQ==&rf=hxxp://searchdocument.info/search.php>
Here's my DDS Log
DDS (Ver_09-05-14.01) - NTFSx86
Run by Ning at 19:13:29.96 on 05/17/2009 Sun
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.2.949.82.1033.18.2046.1518 [GMT -4:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Freeware Antispy\WinPatrol\winpatrol.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Ning\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://gundam.netmarble.net/
uInternet Connection Wizard,ShellNext = hxxp://www.sony.com/vaiopeople
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_07\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\Wcescomm.exe"
mRun: [WinPatrol] c:\program files\freeware antispy\winpatrol\winpatrol.exe -expressboot
mRun: [VAIOCameraUtility] "c:\program files\sony\vaio camera utility\VCUServe.exe"
mRun: [VAIO Update 2] "c:\program files\sony\vaio update 2\VAIOUpdt.exe" /Stationary
mRun: [VAIO Recovery] c:\windows\sonysys\vaio recovery\PartSeal.exe
mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0_07\bin\jusched.exe
mRun: [SonyPowerCfg] "c:\program files\sony\vaio power management\SPMgr.exe"
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [PartSeal] c:\windows\sonysys\vaio recovery\PartSeal.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [EOUApp] "c:\program files\intel\wireless\bin\EOUWiz.exe"
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Download All Files by HiDownload - c:\program files\streamingstar\hidownload\HDGetAll.htm
IE: Download by HiDownload - c:\program files\streamingstar\hidownload\HDGet.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: netmarble.net\gundam
DPF: {00001025-A15C-11D4-97A4-0050BF0FBE67} - hxxp://download.netmarble.net/web/nmstarter/NMStarter25.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/swdir8d204.cab
DPF: {5C1B293E-DA77-4AFF-8B52-63DEF8C8A071} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/NMAutoUpdateX_1.0.1.0.cab
DPF: {89F434A7-4A49-4394-AC02-007480331AE2} - hxxp://download.netmarble.net/ActiveX/NMAutoUpdateX/SystemIDInfo/NMSystemIDInfo_1.0.0.1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {92E82FBB-DA00-41E0-ABFE-95482E21A4F6} - hxxp://download.netmarble.net/NMChatX/NMTransX.cab
DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} - hxxp://download.netmarble.net/kdefence/kdfense8237.cab
DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab
TCP: {5622F491-DB7D-4FB1-9FB7-6D639174C47A} = 24.29.103.15,24.29.103.16
Notify: !SASWinLogon - c:\program files\freeware antispy\superanti\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
Notify: VESWinlogon - VESWinlogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\freeware antispy\superanti\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\ning\applic~1\mozilla\firefox\profiles\3syfo8mt.default\
FF - plugin: c:\program files\java\jre1.5.0_07\bin\NPJava11.dll
FF - plugin: c:\program files\java\jre1.5.0_07\bin\NPJava12.dll
FF - plugin: c:\program files\java\jre1.5.0_07\bin\NPJava13.dll
FF - plugin: c:\program files\java\jre1.5.0_07\bin\NPJava14.dll
FF - plugin: c:\program files\java\jre1.5.0_07\bin\NPJava32.dll
FF - plugin: c:\program files\java\jre1.5.0_07\bin\NPJPI150_07.dll
FF - plugin: c:\program files\java\jre1.5.0_07\bin\NPOJI610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
============= SERVICES / DRIVERS ===============
R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [2006-7-22 9216]
R1 SASDIFSV;SASDIFSV;c:\program files\freeware antispy\superanti\sasdifsv.sys [2008-12-4 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\freeware antispy\superanti\SASKUTIL.SYS [2008-12-4 55024]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-3-8 24652]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2006-7-22 36352]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2006-7-22 30080]
R3 SPI;Sony Programmable I/O Control Device;c:\windows\system32\drivers\SonyPI.sys [2006-7-22 71961]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-7-22 226304]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\freeware antispy\superanti\SASENUM.SYS [2008-12-4 7408]
S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2009-3-8 1120960]
=============== Created Last 30 ================
2009-05-17 18:31 161,792 a------- c:\windows\SWREG.exe
2009-05-17 18:31 98,816 a------- c:\windows\sed.exe
2009-05-17 18:16 <DIR> --d----- c:\windows\pss
2009-05-17 15:26 <DIR> --d----- c:\program files\Trend Micro
2009-05-15 22:31 2,785,582 a------- c:\windows\system32\GameMon.des
2009-05-15 20:39 <DIR> --d----- c:\docume~1\ning\applic~1\Malwarebytes
2009-05-15 20:39 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-05-15 20:39 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-15 20:39 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-05-15 20:39 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-05-15 20:26 <DIR> --d----- c:\program files\MP3+G Toolz .NET 4
2009-05-15 20:10 <DIR> --d----- c:\windows\system32\NtmsData
2009-05-15 19:31 1,406,496 ---sh--- c:\windows\system32\utowahag.ini
2009-05-15 15:56 34 a------- c:\windows\cdplayer.ini
2009-05-15 15:52 <DIR> --d----- c:\program files\audiograbber
2009-05-15 14:33 <DIR> --d----- c:\program files\common files\cdrdao
2009-05-15 14:33 <DIR> --d----- c:\program files\Doblon
2009-05-13 23:02 <DIR> --d----- c:\program files\DVD Shrink
2009-05-13 23:01 <DIR> --d----- c:\program files\DVD Decrypter
2009-05-12 19:21 33,846 a------- c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.bmp
2009-05-12 19:21 3,400 a------- c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.dat
2009-05-12 19:18 33,846 a------- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.bmp
2009-05-12 19:18 14,373 a------- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2009-05-12 19:13 <DIR> --d----- C:\hidownload
2009-05-12 19:13 <DIR> --d----- c:\program files\StreamingStar
2009-05-12 00:00 9,662 a------- c:\windows\EPISME00.SWB
2009-05-09 14:51 1,306,624 a------- c:\windows\system32\msxml6.dll
2009-05-09 14:51 662,288 a------- c:\windows\system32\MSCOMCT2.OCX
2009-05-09 14:51 224,016 a------- c:\windows\system32\TABCTL32.OCX
2009-05-09 14:51 150,528 a------- c:\windows\system32\TLBINF32.DLL
2009-05-09 14:51 224 a------- c:\windows\system32\filerenamerred.sys
2009-05-09 14:51 <DIR> --d----- c:\program files\Winsometech
2009-05-09 13:03 <DIR> --d----- C:\8462912a81d2fcfac4ebe54c56
2009-05-09 13:02 <DIR> --d----- c:\docume~1\ning\applic~1\AccurateRip
2009-05-09 13:02 10,890,928 a------- c:\windows\system32\SpoonUninstall.exe
2009-05-09 13:02 <DIR> --d----- c:\program files\Illustrate
2009-05-09 12:33 <DIR> --d----- c:\program files\AliveMedia
2009-05-09 12:29 <DIR> --d----- c:\docume~1\ning\applic~1\GetRightToGo
2009-05-09 12:09 <DIR> --d----- c:\docume~1\ning\applic~1\VoiceEditor
2009-05-09 00:53 <DIR> --d----- c:\docume~1\ning\applic~1\GARMIN
2009-05-09 00:28 <DIR> --d----- C:\CNNANT2009
2009-05-09 00:28 <DIR> --d----- C:\WebUpdater
2009-05-09 00:27 <DIR> --d----- C:\Garmin
2009-05-09 00:27 <DIR> --d----- C:\MapSource
2009-05-08 12:33 <DIR> --d----- c:\docume~1\ning\applic~1\Mobile Master
2009-05-08 12:15 <DIR> --d----- c:\docume~1\ning\applic~1\Jumping Bytes
2009-05-08 11:42 <DIR> --d----- c:\program files\Windows Mobile Device Handbook
2009-05-06 23:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avanquest Bluetooth SDK
2009-05-06 23:33 <DIR> --d----- c:\program files\common files\Motorola Shared
2009-05-06 23:19 <DIR> --d----- c:\program files\Avanquest update
2009-05-06 23:17 24,192 a------- c:\windows\system32\drivers\OLDEBB.tmp
2009-05-06 23:17 25,600 ac------ c:\windows\system32\dllcache\usbser.sys
2009-05-06 23:17 25,600 a------- c:\windows\system32\drivers\usbser.sys
2009-05-06 23:16 <DIR> --d----- c:\program files\Motorola Phone Tools
2009-05-01 12:21 4,682 a------- c:\windows\system32\npptNT2.sys
2009-05-01 12:21 5,174 a------- c:\windows\system32\nppt9x.vxd
2009-05-01 12:20 <DIR> --d----- c:\program files\common files\INCA Shared
2009-05-01 12:04 <DIR> --d-h--- c:\docume~1\ning\applic~1\netmarble
2009-05-01 11:54 <DIR> --d----- c:\windows\system32\Adobe
2009-05-01 11:38 66,082 ac------ c:\windows\system32\dllcache\c_20833.nls
2009-05-01 11:38 66,082 a------- c:\windows\system32\c_20833.nls
2009-05-01 11:36 57,398 ac------ c:\windows\system32\dllcache\imjpdadm.exe
2009-05-01 11:31 159,744 a------- c:\windows\system32\kdfmgr.exe
2009-05-01 11:31 73,728 a------- c:\windows\system32\kdfapi.dll
2009-05-01 11:31 47,104 a------- c:\windows\system32\Kdfhok.dll
2009-05-01 11:31 61,440 a------- c:\windows\system32\kdfmod.dll
2009-05-01 11:30 373,248 a------- c:\windows\system32\kdfinj.dll
2009-05-01 11:30 <DIR> --d----- c:\windows\kdefense
2009-05-01 11:16 <DIR> --d----- C:\Netmarble
2009-04-27 23:44 30,592 -------- c:\windows\system32\drivers\rndismpx.sys
2009-04-27 23:44 12,800 -------- c:\windows\system32\drivers\usb8023x.sys
2009-04-27 23:43 <DIR> --d----- c:\program files\Microsoft ActiveSync
2009-04-21 12:33 <DIR> --d----- c:\documents and settings\ning\Tracing
2009-04-21 12:31 <DIR> --d----- c:\program files\Microsoft
2009-04-21 12:31 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-04-21 12:24 <DIR> --d----- c:\program files\common files\Windows Live
2009-04-17 22:11 1,409,571 ---sh--- c:\windows\system32\uguzazir.ini
==================== Find3M ====================
2009-03-26 12:03 374,256 a------- c:\windows\NMAutoUpdateXModule.dll
2009-03-19 21:17 78,054 a------- c:\windows\War3Unin.dat
2009-03-13 17:21 2,829 a------- c:\windows\War3Unin.pif
2009-03-13 17:21 139,264 a------- c:\windows\War3Unin.exe
============= FINISH: 19:13:37.89 ===============
Also attached the "Attach.txt" here.
Thanks again
Attached Files
Edited by Orange Blossom, 11 February 2013 - 04:53 AM.
Deactivate link. ~ OB