I've been able to get the malware to stop generating all of its fake warnings, regained control of the Windows XP desktop for the most part, and have been able to run the DDS and GMER scans successfully. I haven't connected to the net, I'm sneakernetting the executables and logs back and forth here. I need to unhide some files -- I can see the start menu but there appears to be nothing in most folders, and it still looks to me as if the infection is active, and is the HDD variant of problem == the disk drive is blinking like mad all of the time.
Here is theDDS log, and I am attaching the other two files requested. Thanks, in advance, for your advice and help!!:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Owner at 9:39:29 on 2011-12-29
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1452 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\VERIZONDM\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\VERIZONDM\bin\tgsrvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Roxio\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\VERIZONDM\bin\sprtcmd.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\program files\real\realplayer\update\realsched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\All Users\Application Data\bhUKOKk56TwBTG.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.aol.com/?mtmhp=acm50mtmhpunauthgreeting2
uSearch Page = hxxp://www.bing.com
uSearch Bar = hxxp://www.bing.com/sphome.aspx
mSearchAssistant = hxxp://www.bing.com/sphome.aspx
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Simppull Toolbar: {627af46b-2076-42ae-a2fd-8428734d3e74} - c:\program files\simppulltoolbar\simppulldx.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Updater For Simppull Toolbar: {c4b8bab4-1667-11df-a242-ba9455d89593} - c:\program files\simppulltoolbar\auxi\simppulltoolbAu.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E4E6BF2A-1667-11DF-A01F-1F9655D89593} - No File
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Simppull Toolbar: {627af46b-2076-42ae-a2fd-8428734d3e74} - c:\program files\simppulltoolbar\simppulldx.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Weather] c:\program files\aws\weatherbug\Weather.exe 1
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [bhUKOKk56TwBTG] c:\documents and settings\all users\application data\bhUKOKk56TwBTG.exe
uRun: [McAfee Update] c:\docume~1\owner\locals~1\temp\mcupdate_1325168965.exe /syncfin c:\docume~1\owner\locals~1\temp\mcupdate_1325168965.ini
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [Desktop Disc Tool] "c:\program files\roxio\roxio burn\RoxioBurnLauncher.exe"
mRun: [VERIZONDM] "c:\program files\verizondm\bin\sprtcmd.exe" /P VERIZONDM
mRun: [Verizon_McciTrayApp] "c:\program files\verizon\McciTrayApp.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [jdiNQqhyasYS.exe] c:\documents and settings\all users\application data\jdiNQqhyasYS.exe
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe
dPolicies-explorer: NoDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1284849525187
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys --> c:\windows\system32\drivers\mfehidk.sys [?]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys --> c:\windows\system32\drivers\mfetdi2k.sys [?]
R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-10-13 249648]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2009-6-9 155648]
R2 IHA_MessageCenter;IHA_MessageCenter;c:\program files\verizon\iha_messagecenter\bin\Verizon_IHAMessageCenter.exe [2011-10-28 286736]
R2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);c:\program files\verizondm\bin\sprtsvc.exe [2010-9-2 206120]
R2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);c:\program files\verizondm\bin\tgsrvc.exe [2010-9-2 185640]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys --> c:\windows\system32\drivers\mfeavfk.sys [?]
S1 MpKsl33855a5c;MpKsl33855a5c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b9f544e5-c0e5-4d94-b3f1-7d250c8beee8}\mpksl33855a5c.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{b9f544e5-c0e5-4d94-b3f1-7d250c8beee8}\MpKsl33855a5c.sys [?]
S1 MpKsl38130eec;MpKsl38130eec;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{00f7c8bd-3f72-4f47-93b2-506b9daed471}\mpksl38130eec.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{00f7c8bd-3f72-4f47-93b2-506b9daed471}\MpKsl38130eec.sys [?]
S1 MpKsl3f46fa51;MpKsl3f46fa51;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{00f7c8bd-3f72-4f47-93b2-506b9daed471}\mpksl3f46fa51.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{00f7c8bd-3f72-4f47-93b2-506b9daed471}\MpKsl3f46fa51.sys [?]
S1 MpKslfde405b7;MpKslfde405b7;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{eaa3c52d-20e0-47b2-8475-d8077af80ad6}\mpkslfde405b7.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{eaa3c52d-20e0-47b2-8475-d8077af80ad6}\MpKslfde405b7.sys [?]
S2 0037931325168934mcinstcleanup;McAfee Application Installer Cleanup (0037931325168934);c:\docume~1\owner\locals~1\temp\003793~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\owner\locals~1\temp\003793~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?]
S2 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-10-21 196176]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-12-19 136176]
S2 McShield;McAfee McShield;"c:\program files\common files\mcafee\systemcore\\mcshield.exe" --> c:\program files\common files\mcafee\systemcore\\mcshield.exe [?]
S2 mfefire;McAfee Firewall Core Service;"c:\program files\common files\mcafee\systemcore\\mfefire.exe" --> c:\program files\common files\mcafee\systemcore\\mfefire.exe [?]
S2 mfevtp;McAfee Validation Trust Protection Service;"c:\windows\system32\mfevtps.exe" --> c:\windows\system32\mfevtps.exe [?]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys --> c:\windows\system32\drivers\cfwids.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-12-19 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys --> c:\windows\system32\drivers\mfebopk.sys [?]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys --> c:\windows\system32\drivers\mfefirek.sys [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys --> c:\windows\system32\drivers\mfendisk.sys [?]
S3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys --> c:\windows\system32\drivers\mfendisk.sys [?]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys --> c:\windows\system32\drivers\mferkdet.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-25 14336]
.
=============== Created Last 30 ================
.
2011-12-29 02:27:33 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-29 02:27:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-28 18:37:57 356608 ----a-w- c:\documents and settings\all users\application data\bhUKOKk56TwBTG.exe
2011-12-21 23:34:35 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-12-21 23:34:35 -------- d-----w- c:\windows\system32\wbem\Repository
2011-12-21 23:32:38 -------- d-----w- c:\program files\McAfee.com
2011-12-21 23:32:28 -------- d-----w- c:\program files\McAfee
2011-12-21 23:32:25 -------- d-----w- c:\program files\common files\Mcafee
2011-12-21 23:04:28 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-12-21 23:04:27 -------- d-----w- c:\windows\system32\appmgmt
2011-12-21 23:03:42 -------- d-----w- c:\documents and settings\owner\local settings\application data\Deployment
2011-12-21 21:59:11 -------- d-----w- c:\program files\McAfee(3)
2011-12-21 21:58:57 -------- d-----w- c:\documents and settings\all users\application data\McAfee(3)
2011-12-21 18:52:24 -------- d-----w- c:\windows\LastGood(2)
2011-12-20 04:07:00 -------- d-----w- c:\documents and settings\owner\application data\ElevatedDiagnostics
2011-12-19 23:32:15 -------- d-----w- c:\program files\common files\Mcafee(2)
2011-12-19 23:32:14 -------- d-----w- c:\program files\McAfee(2).com
2011-12-19 22:43:44 -------- d-----w- c:\documents and settings\owner\application data\McAfee
2011-12-19 22:43:19 -------- d-----w- c:\program files\McAfee(2)
2011-12-19 21:47:33 -------- d-----w- c:\documents and settings\all users\application data\Spybot - Search & Destroy
2011-12-19 18:52:10 -------- d-----w- c:\documents and settings\owner\application data\Malwarebytes
2011-12-19 18:51:39 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-12-19 17:38:59 -------- d-----w- c:\documents and settings\owner\local settings\application data\Google
2011-12-19 03:45:05 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2011-12-19 03:45:02 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2011-12-19 03:45:02 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2011-12-19 03:45:00 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2011-12-19 03:43:59 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll
2011-12-19 03:42:58 26624 -c--a-w- c:\windows\system32\dllcache\umaxu22.dll
2011-12-19 03:41:59 138528 -c--a-w- c:\windows\system32\dllcache\tgiulnt5.sys
2011-12-19 03:40:59 106584 -c--a-w- c:\windows\system32\dllcache\spdports.dll
2011-12-19 03:39:57 68608 -c--a-w- c:\windows\system32\dllcache\sis6306p.sys
2011-12-19 03:38:58 41216 -c--a-w- c:\windows\system32\dllcache\s3mt3d.sys
2011-12-19 03:37:58 35328 -c--a-w- c:\windows\system32\dllcache\psisload.dll
2011-12-19 03:36:59 28032 -c--a-w- c:\windows\system32\dllcache\ovcd.sys
2011-12-19 03:35:59 59104 -c--a-w- c:\windows\system32\dllcache\n9i128v2.dll
2011-12-19 03:34:57 7680 -c--a-w- c:\windows\system32\dllcache\migregdb.exe
2011-12-19 03:33:59 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2011-12-19 03:32:59 9216 -c--a-w- c:\windows\system32\dllcache\ibmsgnet.dll
2011-12-19 03:31:59 2688 -c--a-w- c:\windows\system32\dllcache\hidswvd.sys
2011-12-19 03:30:59 174464 -c--a-w- c:\windows\system32\dllcache\es198x.sys
2011-12-19 03:29:59 102484 -c--a-w- c:\windows\system32\dllcache\digiinf.dll
2011-12-19 03:28:59 236032 -c--a-w- c:\windows\system32\dllcache\camext20.dll
2011-12-19 03:27:58 3775 -c--a-w- c:\windows\system32\dllcache\adv11nt5.dll
2011-12-19 01:48:17 -------- d-sh--w- c:\documents and settings\owner\IECompatCache
2011-12-18 23:53:45 -------- d-----w- c:\documents and settings\all users\application data\Citrix
2011-12-18 23:43:25 -------- d-----w- c:\documents and settings\owner\local settings\application data\Citrix
2011-12-18 23:42:21 0 ----a-w- c:\documents and settings\owner\GoToAssistDownloadHelper.exe
2011-12-17 22:57:53 -------- d-----w- c:\windows\system32\NtmsData
2011-12-01 17:50:27 260 ----a-w- c:\windows\system32\cmdVBS.vbs
2011-12-01 17:50:27 256 ----a-w- c:\windows\system32\MSIevent.bat
.
==================== Find3M ====================
.
2011-11-23 13:29:56 1868544 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20:51 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 19:32:30 150856 ----a-w- c:\windows\system32\mfevtps.exe.d0ce.deleteme
2011-10-18 11:13:22 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3320418AS rev.CC45 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A49D49F]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a4a4738]; MOV EAX, [0x8a4a48ac]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x8ADDFAB8]
3 CLASSPNP[0xBA0F8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000072[0x8AE251B0]
5 ACPI[0xB9F7F620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x8AE4CC80]
\Driver\atapi[0x8ACD3B10] -> IRP_MJ_CREATE -> 0x8A49D49F
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { MOV AX, 0x0; MOV SS, AX; MOV SP, 0x7c00; MOV DS, AX; CLD ; MOV CX, 0x80; MOV SI, SP; MOV DI, 0x600; MOV ES, AX; REP MOVSD ; JMP FAR 0x0:0x62d; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A49D2C6
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 9:41:15.21 ===============
Attached File(s)
-
attach.txt (28.32K)
Number of downloads: 1 -
gmerrootkitfound.log (172.41K)
Number of downloads: 3

Help
This topic is locked


Back to top











