Followed general guidelines for removal
FixNCR
Rill
Malwarebytes
Reboot
There were some issues that remained and after reading a few posts I ran TDSSKiller
All seemed to be going well, but I continued to get alerts from Avira so I thought it would be in my best interest to switch AV since Avira was obviously not doing a good job. I downloaded AVG Free and installed. On installation I received an alert from my Spyware Guard alerting me to a BHO change and I remembered that I should have shut down SG during the installation. Since I could see that the BHO was from AVG I clicked to allow the BHO and the computer locked up and would not complete the AVG installation. I rebooted only to find some disturbing new nasty.
I now have a program that is starting on boot to windows. It is a blank
program screen about 3x3 square. No words, no title. Only an icon that looks like a square with yellow red and blue squares in it. Along with this, none of my programs will allow an Internet connection.
Windows firewall settings cannot be displayed because the associated service is not running. Do you want to start the windows firewall Internet connection sharing service. Yes
Windows cannot start the ICS service
Have seen redirects that start with testendonline and findfast before, when I had Internet connection.
I have logs from dds and gmer but have no way of getting them posted from the infected PC at this time, until I can get some sort of Internet connectivity.
I am almost certain some of my IP info has been reset or changed.
Thank you.
*edit copied logs to usb and updated post on another computer*
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.0.0
Run by (redacted) at 1:59:08 on 2011-12-24
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1367 [GMT -6:00]
.
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Wyse\PocketCloud Windows Companion\PocketCloudService.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Wyse\PocketCloud Windows Companion\WyseBrowser.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\AirPort\APAgent.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Programs\Spybot - Search & Destroy\TeaTimer.exe
C:\Programs\Eraser\eraser.exe
C:\Program Files\AirVideoServer\AirVideoServer.exe
C:\Program Files\PeerBlock\peerblock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\(redacted)\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Programs\SpywareGuard\sgmain.exe
C:\Programs\SpywareGuard\sgbhp.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\programs\spywareguard\dlprotect.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\programs\spybot~1\SDHelper.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
TB: {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - No File
uRun: [SpybotSD TeaTimer] c:\programs\spybot - search & destroy\TeaTimer.exe
uRun: [Eraser] c:\programs\eraser\eraser.exe -hide
uRun: [AirVideoServer] c:\program files\airvideoserver\AirVideoServer.exe
uRun: [PeerBlock] c:\program files\peerblock\peerblock.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [PocketCloud Location] c:\program files\wyse\pocketcloud windows companion\WyseBrowser.exe
mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe
mRun: [AirPort Base Station Agent] "c:\program files\airport\APAgent.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Monitor] "c:\program files\leapfrog\leapfrog connect\Monitor.exe"
StartupFolder: c:\docume~1\(redacted)\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\(redacted)\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\(redacted)\startm~1\programs\startup\itunes.lnk - c:\program files\itunes\iTunes.exe
StartupFolder: c:\docume~1\(redacted)\startm~1\programs\startup\spywar~1.lnk - c:\programs\spywareguard\sgmain.exe
uPolicies-explorer: NoSMHelp = 01000000
uPolicies-explorer: NoNetworkConnections = 01000000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\programs\spybot~1\SDHelper.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://secure.bmhcc.org/dana-cached/setup/JuniperSetupSP1.cab
TCP: DhcpNameServer = 10.0.1.1
TCP: Interfaces\{EE3D8277-8686-4376-81CF-30873D79C1A9} : DhcpNameServer = 10.0.1.1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\programs\spywareguard\spywareguard.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\(redacted)\application data\mozilla\firefox\profiles\kp0tg4ga.default\
FF - plugin: c:\documents and settings\(redacted)\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592]
R0 tdrpman228;Acronis Try&Decide and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [2009-8-11 902592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-12-12 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-12-12 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2011-12-12 110032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-8-11 74640]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 WysePocketCloud;Wyse PocketCloud;c:\program files\wyse\pocketcloud windows companion\PocketCloudService.exe [2011-3-24 83968]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720]
R3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2010-11-13 19056]
S2 AudioSrv32;Windows Audio ;c:\windows\system32\kbdfi32.exe --> c:\windows\system32\kbdfi32.exe [?]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-8-15 136176]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2009-8-12 12672]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [2011-12-19 18560]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-8-15 136176]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S3 yeddef;YEDDEF driver;c:\windows\system32\drivers\yeddef.sys --> c:\windows\system32\drivers\yeddef.sys [?]
.
=============== Created Last 30 ================
.
2011-12-24 04:50:05 -------- d--h--w- c:\documents and settings\all users\application data\Common Files
2011-12-24 04:49:46 -------- d-----w- c:\windows\system32\drivers\AVG
2011-12-24 04:49:46 -------- d-----w- c:\documents and settings\all users\application data\AVG2012
2011-12-24 04:49:19 -------- d-----w- c:\program files\AVG
2011-12-24 04:47:27 -------- d-----w- c:\documents and settings\all users\application data\MFAData
2011-12-20 01:08:51 18560 ----a-w- c:\windows\system32\drivers\FlyUsb.sys
2011-12-19 23:57:56 -------- d-----w- c:\windows\F9D59E62845F49A28B75DDB00661673C.TMP
2011-12-19 23:47:28 -------- d-----w- c:\program files\LeapFrog
2011-12-19 23:47:28 -------- d-----w- c:\documents and settings\all users\application data\Leapfrog
2011-12-18 07:43:42 -------- d-----w- c:\program files\iPod
2011-12-18 07:43:40 -------- d-----w- c:\program files\iTunes
2011-12-13 05:00:03 -------- d-----w- c:\documents and settings\(redacted)\application data\Avira
2011-12-13 04:54:30 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-12-13 04:54:29 -------- d-----w- c:\program files\Avira
2011-12-13 04:54:29 -------- d-----w- c:\documents and settings\all users\application data\Avira
.
==================== Find3M ====================
.
2011-12-21 17:29:20 187776 ----a-w- c:\windows\system32\drivers\acpi.sys
2011-10-24 00:39:24 680624 ----a-w- c:\windows\system32\Toyota Sponsafier 4.scr
2011-10-19 22:56:50 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-10-19 04:23:02 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-07 12:23:48 230608 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 12:21:42 16720 ----a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-25 16:39:45 398760 ----a-r- c:\windows\system32\cpnprt2.cid
.
============= FINISH: 2:00:11.68 ===============
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-24 10:27:23
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD10 rev.05.0
Running: gmer.exe; Driver: C:\DOCUME~1\(redacted)\LOCALS~1\Temp\fxtdipod.sys
---- System - GMER 1.0.15 ----
SSDT B872574C ZwClose
SSDT B8725706 ZwCreateKey
SSDT B8725756 ZwCreateSection
SSDT B87256FC ZwCreateThread
SSDT B872570B ZwDeleteKey
SSDT B8725715 ZwDeleteValueKey
SSDT B8725747 ZwDuplicateObject
SSDT B872571A ZwLoadKey
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xACED5F3C]
SSDT B87256ED ZwOpenThread
SSDT B872576F ZwQueryValueKey
SSDT B8725724 ZwReplaceKey
SSDT B8725760 ZwRequestWaitReplyPort
SSDT B872571F ZwRestoreKey
SSDT B872575B ZwSetContextThread
SSDT B8725765 ZwSetSecurityObject
SSDT B8725710 ZwSetValueKey
SSDT B872576A ZwSystemDebugControl
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xACED5FE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xACED6080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xACED611C]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6281380, 0x3DF545, 0xE8000020]
? C:\DOCUME~1\(redacted)\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\PeerBlock\peerblock.exe[4056] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes JMP 004314E0 C:\Program Files\PeerBlock\peerblock.exe (PeerBlock/PeerBlock, LLC)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs tdrpm228.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 tdrpm228.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 tdrpm228.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys (Acronis Snapshot API/Acronis)
Device \Driver\atapi \Device\Ide\IdePort0 dvd43llh.sys (dvd43llh.sys/RIF)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 dvd43llh.sys (dvd43llh.sys/RIF)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat tdrpm228.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\$NtUninstallKB29965$\2766590443 0 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\bckfg.tmp 814 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\cfg.ini 208 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\keywords 131 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\kwrd.dll 223744 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\L 0 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\L\eheknimp 138496 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\lsflt7.ver 5176 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\U 0 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\U\00000001.@ 1536 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\U\80000000.@ 11264 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\U\80000004.@ 12800 bytes
File C:\WINDOWS\$NtUninstallKB29965$\2766590443\U\80000032.@ 97792 bytes
File C:\WINDOWS\$NtUninstallKB29965$\3323087063 0 bytes
---- EOF - GMER 1.0.15 ----
Attached File(s)
-
attach.txt (16.26K)
Number of downloads: 3
This post has been edited by WhiskeyCop: 24 December 2011 - 05:06 PM

Help
This topic is locked


Back to top














