Also looking at similar posts on the forum, I have installed and ran Kaspersky TDSS killer, which detects nothing and esage's TDSS remover, which says infection detected, then reboots my computer, then scans and catched nothing.
I am writing my dissertation thesis on this computer and I really really don't want to re-format it right now as my deadline is very close. I want to clean it up for now, get it to work until I'm done with my thesis and then I'll do a fresh install of Windows.
I'll appreciate any help tremendously.
(As a side note, I have bought this computer and installed windows XP in Jan 2010. I find it a bit suspicious that some files show the modification or creation date as 2008 or 2006. Also, I've been doing some manual search for system files with "TDSS" in the name from Start-->Search a few days ago, and since then I can't search for anything. It seems like the search algorithm enters an infinite loop and searches the same folders over and over again. I'm afraid any other anti malware programs' scan functions may have the same problem.)
Here is my DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Nergis at 17:33:12.12 on 18/08/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.500 [GMT 2:00]
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS.2\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS.2\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS.2\Explorer.EXE
C:\WINDOWS.2\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS.2\system32\igfxpers.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS.2\system32\ctfmon.exe
C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS.2\system32\svchost.exe -k imgsvc
C:\WINDOWS.2\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Nergis\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [CTFMON.EXE] c:\windows.2\system32\ctfmon.exe
uRun: [Active Desktop Calendar] c:\program files\xemicomputers\active desktop calendar\ADC.exe
mRun: [igfxtray] c:\windows.2\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows.2\system32\hkcmd.exe
mRun: [igfxpers] c:\windows.2\system32\igfxpers.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [HitmanPro35] "c:\program files\hitman pro 3.5\HitmanPro35.exe" /scan:boot
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\windows.2\system32\CTFMON.EXE
StartupFolder: c:\docume~1\nergis\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\nergis\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\documents and settings\nergis\start menu\programs\startup\Dropbox.lnk.disabled
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Microsoft Excel'e Gö&nder - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {3BCF05C8-E14E-4F52-ACFB-8FE7AE4829ED} = 213.191.92.86 62.109.123.6
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: egypack - egypack.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - No File
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\nergis\applic~1\mozilla\firefox\profiles\zr4f6f4z.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 SSHDRV85;SSHDRV85;c:\windows.2\system32\drivers\SSHDRV85.sys [2010-2-6 78848]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-7-31 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-7-31 267432]
R2 avgntflt;avgntflt;c:\windows.2\system32\drivers\avgntflt.sys [2010-7-31 60936]
R3 SNCT511;PC Camera (6005 CIF);c:\windows.2\system32\drivers\snct511.sys [2010-7-9 229376]
S1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-7-31 11608]
S3 rk_remover-boot;rk_remover-boot;c:\windows.2\system32\drivers\rk_remover.sys [2010-8-18 52736]
S3 vsdatant;vsdatant;c:\windows.2\system32\vsdatant.sys [2007-11-14 394952]
=============== Created Last 30 ================
2010-08-18 15:31:57 0 ----a-w- c:\documents and settings\nergis\defogger_reenable
2010-08-18 10:08:51 16384 ----atw- c:\temp\Perflib_Perfdata_418.dat
2010-08-18 00:06:47 0 d-sha-r- C:\cmdcons
2010-08-18 00:04:11 98816 ----a-w- c:\windows.2\sed.exe
2010-08-18 00:04:11 77312 ----a-w- c:\windows.2\MBR.exe
2010-08-18 00:04:11 256512 ----a-w- c:\windows.2\PEV.exe
2010-08-18 00:04:11 161792 ----a-w- c:\windows.2\SWREG.exe
2010-08-17 23:28:42 52736 ----a-w- c:\windows.2\system32\drivers\rk_remover.sys
2010-08-17 11:10:11 0 d-----w- c:\program files\common files\Macrovision Shared
2010-08-16 22:31:03 73728 ----a-w- c:\windows.2\system32\javacpl.cpl
2010-08-16 22:31:03 423656 ----a-w- c:\windows.2\system32\deployJava1.dll
2010-08-16 21:00:10 1824 ----a-w- c:\windows.2\system32\.crusader
2010-08-16 11:36:15 152064 ----a-w- c:\temp\0.09192115260202871.exe
2010-08-15 17:40:52 16968 ----a-w- c:\windows.2\system32\drivers\hitmanpro35.sys
2010-08-15 17:40:22 0 d-----w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-08-15 17:40:21 0 d-----w- c:\program files\Hitman Pro 3.5
2010-08-13 20:43:14 4 ----a-w- c:\docume~1\nergis\applic~1\avdrn.dat
2010-08-13 11:14:54 54156 ---ha-w- c:\windows.2\QTFont.qfn
2010-08-13 11:14:54 1409 ----a-w- c:\windows.2\QTFont.for
2010-08-11 21:49:07 16384 ----atw- c:\temp\Perflib_Perfdata_380.dat
2010-08-07 15:20:05 16384 ----atw- c:\temp\Perflib_Perfdata_6c8.dat
2010-08-06 12:12:47 16384 ----atw- c:\temp\Perflib_Perfdata_404.dat
2010-08-04 22:51:36 16384 ----atw- c:\temp\Perflib_Perfdata_704.dat
2010-08-04 12:00:12 16384 ----atw- c:\temp\Perflib_Perfdata_374.dat
2010-08-04 11:23:35 16384 ----atw- c:\temp\Perflib_Perfdata_2fc.dat
2010-08-04 11:15:16 16384 ----atw- c:\temp\Perflib_Perfdata_754.dat
2010-08-04 10:57:36 0 d-sh--w- c:\windows.2\efee3f32f
2010-08-04 08:13:34 16384 ----atw- c:\temp\Perflib_Perfdata_700.dat
2010-08-02 18:11:43 16384 ----atw- c:\temp\Perflib_Perfdata_728.dat
2010-08-02 18:09:20 16384 ----atw- c:\temp\Perflib_Perfdata_630.dat
2010-08-02 10:57:31 0 d-----w- c:\temp\hsperfdata_SYSTEM
2010-08-02 10:43:27 0 d-sh--w- c:\windows.2\system32\lowsec
2010-07-31 17:11:46 16384 ----atw- c:\temp\Perflib_Perfdata_244.dat
2010-07-31 16:49:42 0 d-sh--w- c:\temp\Temporary Internet Files
2010-07-31 16:49:42 0 d-sh--w- c:\temp\History
2010-07-31 16:49:42 0 d-sh--w- c:\temp\Cookies
2010-07-31 16:31:23 0 d-----w- c:\docume~1\nergis\applic~1\Avira
2010-07-31 16:29:44 0 d-----w- c:\windows.2\system32\NtmsData
2010-07-31 16:21:46 60936 ----a-w- c:\windows.2\system32\drivers\avgntflt.sys
2010-07-31 16:21:46 0 d-----w- c:\program files\Avira
2010-07-31 16:21:46 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-07-31 16:16:25 0 d-----w- c:\temp\AVSETUP_4c544c59
2010-07-31 11:58:02 0 d-----w- c:\temp\6391539b-ca14-42e3-8faf-d9ef9eaa68fa
2010-07-30 15:57:29 0 d-----w- c:\temp\19df6969-fe2e-42cd-8737-bfd00bc54dc0
2010-07-30 06:54:41 0 d-----w- c:\temp\5df7fe96-34dd-4806-bcf5-ab15a3456914
2010-07-29 14:22:38 0 d-----w- c:\temp\0475e675-967b-448e-8f7f-86d81f43dc36
2010-07-28 15:02:35 0 d-----w- c:\temp\75779733-192b-479b-ab57-edc813902a9b
2010-07-27 23:50:35 0 d-----w- c:\temp\983f670b-761d-4508-9d91-cd3f2996001e
2010-07-27 07:35:42 0 d-----w- c:\temp\daeeb8be-2c4a-4992-b6e2-c74cd0f993f2
2010-07-26 16:05:15 0 d-----w- c:\temp\bb2c1df3-2369-4228-9990-3841d308d986
2010-07-26 07:53:47 0 d-----w- c:\windows.2\ERUNT
2010-07-26 07:26:28 505856 ----a-w- C:\sdfixinfo.doc
2010-07-26 07:23:08 0 d-----w- C:\How to use SDFix_files
2010-07-26 07:23:05 47265 ----a-w- C:\How to use SDFix.htm
2010-07-26 07:22:04 0 d-----w- C:\SDFix
2010-07-26 06:31:04 0 d-----w- c:\temp\a217e2f3-9698-46cc-b305-ebd963351e37
2010-07-25 21:08:39 16384 ----atw- c:\temp\Perflib_Perfdata_1d4.dat
2010-07-25 20:57:52 16384 ----atw- c:\temp\Perflib_Perfdata_1d8.dat
2010-07-25 07:26:13 0 d-----w- c:\temp\65e8d795-ebab-4020-a4af-fe2e74940c0e
2010-07-24 17:12:59 0 d-----w- c:\temp\a4c1e86b-ad76-4b21-a01e-a05a20e28e20
2010-07-24 07:25:48 0 d-----w- c:\temp\30b9ae92-4ed3-4b3b-918c-57af29271be7
2010-07-23 16:51:12 0 d-----w- c:\temp\6ffa23f7-7e11-4d6c-89f3-e1486f105aa9
2010-07-23 07:26:28 0 d-----w- c:\temp\641ab798-fa35-40cb-a32e-4410b712bf70
2010-07-22 15:52:17 0 d-----w- c:\temp\45b6238e-640e-4e14-8da0-a2e27e0410ff
2010-07-22 15:25:10 0 d-----w- c:\temp\drra.tmp
2010-07-22 06:39:51 0 d-----w- c:\temp\262f62d2-9876-490c-ad2e-b2822b5328af
2010-07-21 20:15:03 0 d-----w- c:\temp\lbxb.tmp
2010-07-21 15:48:21 0 d-----w- c:\temp\48d04280-f72a-49c8-989d-e01669bd46c8
2010-07-21 06:09:11 0 d-----w- c:\temp\f29d65a7-41c1-4ac1-961a-b7d4cc6ab162
2010-07-20 20:36:38 0 d-----w- c:\docume~1\nergis\applic~1\Dropbox
2010-07-20 15:50:32 0 d-----w- c:\temp\6c9ea955-d8eb-491b-8f67-f8eb0deaf98a
2010-07-20 06:06:04 0 d-----w- c:\temp\74d6fd90-f3e8-41dc-a6c3-ee1fa538c052
2010-07-19 19:27:06 225 ----a-w- c:\windows.2\wininit.ini
2010-07-19 18:00:51 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-07-19 18:00:51 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-07-19 17:07:43 150 ----a-w- C:\zrpt.xml
2010-07-19 17:04:08 0 d-----w- c:\docume~1\nergis\applic~1\CCB1F9C298A877998363D724252FE2D3
2010-07-19 16:53:35 0 d-----w- c:\temp\68a12cdb-0d29-4ec7-b3b7-c20b1e91e9bb
==================== Find3M ====================
2010-08-02 13:16:56 60976 ----a-w- c:\windows.2\fonts\TradeGothicLTStd-BdCn20.ttf
2010-07-26 07:28:32 24576 ----a-w- c:\windows.2\system32\userinit.exe
2010-05-24 21:08:05 420864 ----a-w- c:\windows.2\system32\ntvdm.exe
2010-01-20 13:35:16 32768 --sha-w- c:\windows.2\system32\config\systemprofile\local settings\history\history.ie5\mshist012010012020100121\index.dat
============= FINISH: 17:34:14.64 ===============
Sorry forgot the GMER attachment.
EDIT: Posts merged ~BP
Attached Files
Edited by Budapest, 18 August 2010 - 05:09 PM.