Tdsskiller ended up clean
rkill says this-
Rkill 2.4.8 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 05/17/2013 07:44:30 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* Windows Defender Disabled
[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware" = dword:00000001
* Windows Firewall Disabled
[HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = dword:00000000
Checking Windows Service Integrity:
* BFE (BFE) is not Running.
Startup Type set to: Automatic
* DHCP Client (Dhcp) is not Running.
Startup Type set to: Automatic
* DNS Client (Dnscache) is not Running.
Startup Type set to: Automatic
* COM+ Event System (EventSystem) is not Running.
Startup Type set to: Automatic
* Windows Firewall (MpsSvc) is not Running.
Startup Type set to: Automatic
* Network Connections (Netman) is not Running.
Startup Type set to: Manual
* Network Store Interface Service (nsi) is not Running.
Startup Type set to: Automatic
* Windows Defender (WinDefend) is not Running.
Startup Type set to: Manual
* Security Center (wscsvc) is not Running.
Startup Type set to: Automatic (Delayed Start)
* Windows Update (wuauserv) is not Running.
Startup Type set to: Automatic (Delayed Start)
* Ancillary Function Driver for Winsock (AFD) is not Running.
Startup Type set to: System
* Windows Firewall Authorization Driver (mpsdrv) is not Running.
Startup Type set to: Manual
* NetBT (NetBT) is not Running.
Startup Type set to: System
* NSI proxy service driver. (nsiproxy) is not Running.
Startup Type set to: System
* NetIO Legacy TDI Support Driver (tdx) is not Running.
Startup Type set to: System
* FontCache => %SystemRoot%\system32\svchost.exe -k LocalService [Incorrect ImagePath]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* No issues found.
Program finished at: 05/17/2013 07:44:39 PM
Execution time: 0 hours(s), 0 minute(s), and 8 seconds(s)
and my virus scan says 79 errors-
AVG 2013 AntiVirus command line scanner
Copyright (c) 1992 - 2012 AVG Technologies
Program version 2013.0.3336, engine 2013.0.3162
Virus Database: Version 3162/6332 2013-05-17
c:\Documents and Settings\ Locked file. Not tested.
c:\hiberfil.sys Locked file. Not tested.
c:\pagefile.sys Locked file. Not tested.
c:\ProgramData\AVG\AWL2012\TTUSvclrt.tt Locked file. Not tested.
c:\ProgramData\Desktop\ Locked file. Not tested.
c:\ProgramData\Documents\ Locked file. Not tested.
c:\ProgramData\Favorites\ Locked file. Not tested.
c:\ProgramData\Templates\ Locked file. Not tested.
c:\System Volume Information\ Locked file. Not tested.
c:\Users\Carlos\AppData\Local\Avg2013\log\avg-b1e03617-4de0-4f7d-b9fc-106773d5ca0f.tmp Locked file. Not tested.
c:\Users\Carlos\AppData\Local\History\ Locked file. Not tested.
c:\Users\Carlos\AppData\Local\Microsoft\Windows\UsrClass.dat Locked file. Not tested.
c:\Users\Carlos\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Locked file. Not tested.
c:\Users\Carlos\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Locked file. Not tested.
c:\Users\Carlos\Documents\My Music\ Locked file. Not tested.
c:\Users\Carlos\Documents\My Pictures\ Locked file. Not tested.
c:\Users\Carlos\Documents\My Videos\ Locked file. Not tested.
c:\Users\Carlos\NetHood\ Locked file. Not tested.
c:\Users\Carlos\ntuser.dat Locked file. Not tested.
c:\Users\Carlos\ntuser.dat.LOG1 Locked file. Not tested.
c:\Users\Carlos\ntuser.dat.LOG2 Locked file. Not tested.
c:\Users\Carlos\PrintHood\ Locked file. Not tested.
c:\Users\Carlos\Templates\ Locked file. Not tested.
c:\Users\Default\AppData\Local\History\ Locked file. Not tested.
c:\Users\Default\Documents\My Music\ Locked file. Not tested.
c:\Users\Default\Documents\My Pictures\ Locked file. Not tested.
c:\Users\Default\Documents\My Videos\ Locked file. Not tested.
c:\Users\Default\NetHood\ Locked file. Not tested.
c:\Users\Default\PrintHood\ Locked file. Not tested.
c:\Users\Default\Recent\ Locked file. Not tested.
c:\Users\Default\Templates\ Locked file. Not tested.
c:\Users\Guest\AppData\Local\History\ Locked file. Not tested.
c:\Users\Guest\Documents\My Music\ Locked file. Not tested.
c:\Users\Guest\Documents\My Pictures\ Locked file. Not tested.
c:\Users\Guest\Documents\My Videos\ Locked file. Not tested.
c:\Users\Guest\NetHood\ Locked file. Not tested.
c:\Users\Guest\PrintHood\ Locked file. Not tested.
c:\Users\Guest\Templates\ Locked file. Not tested.
c:\Users\Public\Documents\My Music\ Locked file. Not tested.
c:\Users\Public\Documents\My Pictures\ Locked file. Not tested.
c:\Users\Public\Documents\My Videos\ Locked file. Not tested.
c:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Locked file. Not tested.
c:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Locked file. Not tested.
c:\Windows\ServiceProfiles\LocalService\ntuser.dat Locked file. Not tested.
c:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG1 Locked file. Not tested.
c:\Windows\ServiceProfiles\LocalService\NTUSER.DAT.LOG2 Locked file. Not tested.
c:\Windows\ServiceProfiles\NetworkService\ntuser.dat Locked file. Not tested.
c:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG1 Locked file. Not tested.
c:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT.LOG2 Locked file. Not tested.
c:\Windows\System32\catroot2\edb.log Locked file. Not tested.
c:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Locked file. Not tested.
c:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Locked file. Not tested.
c:\Windows\System32\config\default Locked file. Not tested.
c:\Windows\System32\config\DEFAULT.LOG1 Locked file. Not tested.
c:\Windows\System32\config\DEFAULT.LOG2 Locked file. Not tested.
c:\Windows\System32\config\RegBack\DEFAULT Locked file. Not tested.
c:\Windows\System32\config\RegBack\SAM Locked file. Not tested.
c:\Windows\System32\config\RegBack\SECURITY Locked file. Not tested.
c:\Windows\System32\config\RegBack\SOFTWARE Locked file. Not tested.
c:\Windows\System32\config\RegBack\SYSTEM Locked file. Not tested.
c:\Windows\System32\config\sam Locked file. Not tested.
c:\Windows\System32\config\SAM.LOG1 Locked file. Not tested.
c:\Windows\System32\config\SAM.LOG2 Locked file. Not tested.
c:\Windows\System32\config\security Locked file. Not tested.
c:\Windows\System32\config\SECURITY.LOG1 Locked file. Not tested.
c:\Windows\System32\config\SECURITY.LOG2 Locked file. Not tested.
c:\Windows\System32\config\software Locked file. Not tested.
c:\Windows\System32\config\SOFTWARE.LOG1 Locked file. Not tested.
c:\Windows\System32\config\SOFTWARE.LOG2 Locked file. Not tested.
c:\Windows\System32\config\system Locked file. Not tested.
c:\Windows\System32\config\SYSTEM.LOG1 Locked file. Not tested.
c:\Windows\System32\config\SYSTEM.LOG2 Locked file. Not tested.
c:\Windows\System32\LogFiles\WMI\RtBackup\ Locked file. Not tested.
c:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat Locked file. Not tested.
c:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat.LOG1 Locked file. Not tested.
c:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat.LOG2 Locked file. Not tested.
c:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{87bb9983-6ce7-11e2-8f9c-001fc68b08d3}.TM.blf Locked file. Not tested.
c:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{87bb9983-6ce7-11e2-8f9c-001fc68b08d3}.TMContainer00000000000000000001.regtrans-ms Locked file. Not tested.
c:\Windows\System32\Microsoft\Protect\Recovery\Recovery.dat{87bb9983-6ce7-11e2-8f9c-001fc68b08d3}.TMContainer00000000000000000002.regtrans-ms Locked file. Not tested.
------------------------------------------------------------
Test started: 17.5.2013 22:56:33
Duration of test: 26 minute(s) 3 second(s)
------------------------------------------------------------
Objects scanned : 191143
Found infections : 79
Found high severity : 0
Found med severity : 0
Found info severity : 79
Fixed high severity : 0
Fixed med severity : 0
Fixed info severity : 0
------------------------------------------------------------