Code:
Volume in drive C is ACER
Volume Serial Number is 320D-180E
Directory of C:\
27/04/2006 08:22 AM 0 dirdat.txt
27/04/2006 08:22 AM 22 windatfind.zip
27/04/2006 08:20 AM 234,278,912 hiberfil.sys
27/04/2006 08:20 AM 301,989,888 pagefile.sys
19/04/2006 03:52 PM 13,030 PDOXUSRS.NET
19/04/2006 03:50 PM 533 APD.TRC
19/04/2006 03:50 PM 7,783 APD.LOG
18/04/2006 12:23 PM 135 RootkitReveal.txt
18/04/2006 11:08 AM 1,280,000 MBSASetup-EN.msi
18/04/2006 10:56 AM 4,237 hijackthis.log
24/03/2006 10:17 AM 386,858 cpu-z-132.zip
23/03/2006 08:00 AM 12,241,103 AVG7QT.DAT
22/03/2006 02:43 PM 21,343,795 audio.zip
22/03/2006 02:39 PM 11,539,293 Chipset.zip
16/03/2006 07:58 AM 211 boot.ini
06/03/2006 11:39 PM 582 windatfind.bat
03/03/2006 05:52 PM 902,873 cpuz.exe
03/03/2006 03:10 PM 6,901 cpuz-readme.txt
03/03/2006 03:09 PM 146 cpuz.ini
02/11/2005 01:38 AM 6 ISACER.ID
18/06/2005 09:33 AM 76 PRELOAD.AAA
18/06/2005 07:43 AM 50 AUTOEXEC.BAT
18/06/2005 07:32 AM 0 MSDOS.SYS
18/06/2005 07:32 AM 0 IO.SYS
18/06/2005 07:32 AM 0 CONFIG.SYS
18/06/2005 07:08 AM 512 BOOTSECT.DOS
25/03/2005 05:08 PM 49,152 latency.exe
04/08/2004 05:00 AM 47,564 NTDETECT.COM
04/08/2004 05:00 AM 250,032 ntldr
29 File(s) 584,343,694 bytes
0 Dir(s) 33,786,462,208 bytes free
Volume in drive C is ACER
Volume Serial Number is 320D-180E
Directory of C:\WINDOWS\system32
27/04/2006 08:21 AM 736 eRLog.ini
27/04/2006 08:20 AM 1,158 wpa.dbl
07/04/2006 05:48 AM 5,143,456 MRT.exe
30/03/2006 07:16 PM 1,492,480 shdocvw.dll
30/03/2006 11:00 AM 16,384 xpsp3res.dll
24/03/2006 06:32 AM 3,053,568 mshtml.dll
23/03/2006 06:02 AM 53,640 perfc009.dat
23/03/2006 06:02 AM 382,022 perfh009.dat
23/03/2006 06:02 AM 441,142 PerfStringBackup.INI
23/03/2006 04:57 AM 75 LuResult.txt
23/03/2006 04:19 AM 103,418 Autorun.ini
22/03/2006 03:18 PM 176,264 FNTCACHE.DAT
18/03/2006 09:09 PM 613,376 urlmon.dll
Volume in drive C is ACER
Volume Serial Number is 320D-180E
Directory of C:\WINDOWS
27/04/2006 08:20 AM 0 0.log
27/04/2006 08:20 AM 3,630 ModemLog_Lucent Win Modem.txt
27/04/2006 08:20 AM 2,048 bootstat.dat
19/04/2006 03:53 PM 11,970 SchedLgU.Txt
19/04/2006 03:53 PM 688,659 WindowsUpdate.log
19/04/2006 11:53 AM 254 hpbafd.ini
18/04/2006 04:25 PM 991,941 setupapi.log
18/04/2006 10:06 AM 16,769 KB911562.log
18/04/2006 10:06 AM 123,941 comsetup.log
18/04/2006 10:06 AM 52,998 iis6.log
18/04/2006 10:06 AM 358,674 FaxSetup.log
18/04/2006 10:06 AM 137,424 tsoc.log
18/04/2006 10:06 AM 74,342 ntdtcsetup.log
18/04/2006 10:06 AM 1,374 imsins.log
18/04/2006 10:06 AM 17,507 msgsocm.log
18/04/2006 10:06 AM 19,629 ocmsn.log
18/04/2006 10:06 AM 178,862 ocgen.log
18/04/2006 10:06 AM 27,408 updspapi.log
18/04/2006 10:06 AM 1,374 imsins.BAK
18/04/2006 10:06 AM 19,005 KB912812.log
18/04/2006 10:06 AM 11,526 KB908531.log
18/04/2006 10:06 AM 10,736 KB911567.log
24/03/2006 06:05 PM 905 wiadebug.log
Volume in drive C is ACER
Volume Serial Number is 320D-180E
Directory of C:\DOCUME~1\ACER\LOCALS~1\Temp
27/04/2006 08:20 AM 0 JETB45B.tmp
27/04/2006 08:20 AM 6,760 jusched.log
19/04/2006 07:51 AM 0 INMEM000.REM
31/03/2006 09:38 AM 1,223 logfile.txt
31/03/2006 09:33 AM 2,729 CdMkr70.ini
23/03/2006 07:54 AM 32,768 RMS7.tmp
23/03/2006 07:54 AM 32,768 RMS6.tmp
23/03/2006 07:50 AM 158,974 avg7inst.log
23/03/2006 07:28 AM 13,318 netfxupdate.log
23/03/2006 07:27 AM 17,060 netfxsl.log
I ran RootkitRevealer as well and it turned up a data mismatch between WindowsAPI and raw hive data. Should I just reformat and reinstall? I dont know if the infection came with the computer or not, this machine is only a month or two old and did not come with a true WinXP disk but rather it forced me to burn a recovery disk upon first boot.