Byrel:Not sure what exactly is wrong, but it seems to be more on the rootkit end. I think it probably replaced some DLL. However, no DLLs have modified times in the last month, and I know that we were infected this morning.
in "c:\windows\system32"
right-click on the column headers, this will give you a list of all possible columns to "view" and check the one called "Date Created"
the "modified date" is ok, but can be messed with easily, sort the new column in Reverse date oder, and see what has been added to that dir recently.
Do the same with the "c:\windows\system32\drivers" dir
I have used gmer rootkit detector software for a number of years now and not been disappointed though you need to google everything it finds as not all are rootkits, some are part of device drivers for devices on your system.
Tallon41
What weight does your Spirit have to be in order to be considered "heavy" ?
----------------------Me