I have the dreaded XP Internet Security 2012 issue. I thought I had removed all traces of the files yesterday, however, I've been re-infected today.
Below are my log files. I did run RKill in order to access the internet.
Looks like I need to re-run Malwarebytes. I will do that and post the log
GMER
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-11 00:52:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HTS541040G9SA00 rev.MB2IC60R
Running: dcp5t91h.exe; Driver: C:\DOCUME~1\Admin\LOCALS~1\Temp\pwqdraoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text mrxsmb.sys A88BE000 6 Bytes [00, C0, E9, 08, 0C, 00]
.text mrxsmb.sys A88BE007 46 Bytes [90, 90, 90, 90, 90, FF, 25, ...]
.text mrxsmb.sys A88BE036 24 Bytes [90, 90, 90, 90, 8B, FF, 55, ...]
.text mrxsmb.sys A88BE04F 31 Bytes [68, F0, 9B, 8D, A8, 56, E8, ...]
.text mrxsmb.sys A88BE070 246 Bytes [53, 68, 9A, E0, 8B, A8, 57, ...]
.text ...
? C:\WINDOWS\system32\DRIVERS\mrxsmb.sys suspicious PE modification
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1668] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 019C000A
.text C:\WINDOWS\System32\svchost.exe[1668] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 019D000A
.text C:\WINDOWS\System32\svchost.exe[1668] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 019B000C
.text C:\WINDOWS\system32\SearchIndexer.exe[3668] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Fastfat \Fat A6BA2D20
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) A8955000-A8971000 (114688 bytes)
---- Files - GMER 1.0.15 ----
File C:\RRbackups\common 0 bytes
File C:\RRbackups\common\hints.dat 8192 bytes
File C:\RRbackups\common\mnd.dat 8192 bytes
File C:\RRbackups\common\regcerts.dat 8192 bytes
File C:\RRbackups\common\rr.log 757 bytes
File C:\RRbackups\common\SAM 28672 bytes
File C:\RRbackups\common\secpolicy.dat 53248 bytes
File C:\RRbackups\common\settings.dat 28672 bytes
File C:\RRbackups\common\system.dat 12288 bytes
File C:\RRbackups\common\tvtns.bin 23 bytes
File C:\RRbackups\common\usersids.dat 15600 bytes
File C:\RRbackups\Documents and Settings 0 bytes
File C:\RRbackups\Documents and Settings\Admin 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005\43e3a4a9826996aba5d7727553958fbf_f98f56a2-efd3-4206-9e4e-8df438541ae1 1279 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005\6b29ae44e85efac3c72ff4d1865d73f1_f98f56a2-efd3-4206-9e4e-8df438541ae1 53 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005\83aa4cc77f591dfc2374580bbd95f6ba_f98f56a2-efd3-4206-9e4e-8df438541ae1 45 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005\8f71098770f72c7a67cd8f1151619865_f98f56a2-efd3-4206-9e4e-8df438541ae1 54 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\8d9e96a6-6040-41fe-9013-b5f97e847600 388 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-2892286239-3679062826-358022272-1005 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-2892286239-3679062826-358022272-1005\3dbd08ca-ba50-4043-bf2a-bfa8816fccec 388 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-2892286239-3679062826-358022272-1005\8230652c-d1ce-4bb7-9db5-3284a4a0f023 388 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-2892286239-3679062826-358022272-1005\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\d798298d-45cc-4c54-aec1-daa1a9828fe8 388 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My\Certificates\60EA223EDC33A88A5A48C90EA53CEFB1555815D1 824 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\Administrator 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\8d9e96a6-6040-41fe-9013-b5f97e847600 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\d798298d-45cc-4c54-aec1-daa1a9828fe8 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\All Users 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo\Client Security Solution\PreloadInstall.ini 26 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5bac492b8a12a9b6bf4a5681cc06a21_f98f56a2-efd3-4206-9e4e-8df438541ae1 888 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\42e7e898003fbdeb9585806ee1664b51_f98f56a2-efd3-4206-9e4e-8df438541ae1 57 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\6b29ae44e85efac3c72ff4d1865d73f1_f98f56a2-efd3-4206-9e4e-8df438541ae1 53 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\83aa4cc77f591dfc2374580bbd95f6ba_f98f56a2-efd3-4206-9e4e-8df438541ae1 45 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\8f71098770f72c7a67cd8f1151619865_f98f56a2-efd3-4206-9e4e-8df438541ae1 54 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_f98f56a2-efd3-4206-9e4e-8df438541ae1 893 bytes
File C:\RRbackups\Documents and Settings\Default User 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\8d9e96a6-6040-41fe-9013-b5f97e847600 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\d798298d-45cc-4c54-aec1-daa1a9828fe8 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\1929418354 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\bckfg.tmp 862 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\cfg.ini 198 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\kwrd.dll 223744 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\L 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\L\hvmonmrs 456320 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\lsflt7.ver 5176 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\00000001.@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\80000000.@ 11264 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\80000004.@ 12800 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\80000032.@ 77312 bytes
---- EOF - GMER 1.0.15 ----
Below are my log files. I did run RKill in order to access the internet.
Looks like I need to re-run Malwarebytes. I will do that and post the log
GMER
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-11 00:52:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HTS541040G9SA00 rev.MB2IC60R
Running: dcp5t91h.exe; Driver: C:\DOCUME~1\Admin\LOCALS~1\Temp\pwqdraoc.sys
---- Kernel code sections - GMER 1.0.15 ----
.text mrxsmb.sys A88BE000 6 Bytes [00, C0, E9, 08, 0C, 00]
.text mrxsmb.sys A88BE007 46 Bytes [90, 90, 90, 90, 90, FF, 25, ...]
.text mrxsmb.sys A88BE036 24 Bytes [90, 90, 90, 90, 8B, FF, 55, ...]
.text mrxsmb.sys A88BE04F 31 Bytes [68, F0, 9B, 8D, A8, 56, E8, ...]
.text mrxsmb.sys A88BE070 246 Bytes [53, 68, 9A, E0, 8B, A8, 57, ...]
.text ...
? C:\WINDOWS\system32\DRIVERS\mrxsmb.sys suspicious PE modification
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[1668] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 019C000A
.text C:\WINDOWS\System32\svchost.exe[1668] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 019D000A
.text C:\WINDOWS\System32\svchost.exe[1668] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 019B000C
.text C:\WINDOWS\system32\SearchIndexer.exe[3668] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Fastfat \Fat A6BA2D20
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) A8955000-A8971000 (114688 bytes)
---- Files - GMER 1.0.15 ----
File C:\RRbackups\common 0 bytes
File C:\RRbackups\common\hints.dat 8192 bytes
File C:\RRbackups\common\mnd.dat 8192 bytes
File C:\RRbackups\common\regcerts.dat 8192 bytes
File C:\RRbackups\common\rr.log 757 bytes
File C:\RRbackups\common\SAM 28672 bytes
File C:\RRbackups\common\secpolicy.dat 53248 bytes
File C:\RRbackups\common\settings.dat 28672 bytes
File C:\RRbackups\common\system.dat 12288 bytes
File C:\RRbackups\common\tvtns.bin 23 bytes
File C:\RRbackups\common\usersids.dat 15600 bytes
File C:\RRbackups\Documents and Settings 0 bytes
File C:\RRbackups\Documents and Settings\Admin 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Lenovo\Client Security Solution\hibernation.dat 4 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005\43e3a4a9826996aba5d7727553958fbf_f98f56a2-efd3-4206-9e4e-8df438541ae1 1279 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005\6b29ae44e85efac3c72ff4d1865d73f1_f98f56a2-efd3-4206-9e4e-8df438541ae1 53 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005\83aa4cc77f591dfc2374580bbd95f6ba_f98f56a2-efd3-4206-9e4e-8df438541ae1 45 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Crypto\RSA\S-1-5-21-2892286239-3679062826-358022272-1005\8f71098770f72c7a67cd8f1151619865_f98f56a2-efd3-4206-9e4e-8df438541ae1 54 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\8d9e96a6-6040-41fe-9013-b5f97e847600 388 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-2892286239-3679062826-358022272-1005 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-2892286239-3679062826-358022272-1005\3dbd08ca-ba50-4043-bf2a-bfa8816fccec 388 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-2892286239-3679062826-358022272-1005\8230652c-d1ce-4bb7-9db5-3284a4a0f023 388 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-2892286239-3679062826-358022272-1005\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\d798298d-45cc-4c54-aec1-daa1a9828fe8 388 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My\Certificates\60EA223EDC33A88A5A48C90EA53CEFB1555815D1 824 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Admin\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\Administrator 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\8d9e96a6-6040-41fe-9013-b5f97e847600 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\d798298d-45cc-4c54-aec1-daa1a9828fe8 388 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Administrator\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\All Users 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo\Client Security Solution 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Lenovo\Client Security Solution\PreloadInstall.ini 26 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a5bac492b8a12a9b6bf4a5681cc06a21_f98f56a2-efd3-4206-9e4e-8df438541ae1 888 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18 0 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\42e7e898003fbdeb9585806ee1664b51_f98f56a2-efd3-4206-9e4e-8df438541ae1 57 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\6b29ae44e85efac3c72ff4d1865d73f1_f98f56a2-efd3-4206-9e4e-8df438541ae1 53 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\83aa4cc77f591dfc2374580bbd95f6ba_f98f56a2-efd3-4206-9e4e-8df438541ae1 45 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\8f71098770f72c7a67cd8f1151619865_f98f56a2-efd3-4206-9e4e-8df438541ae1 54 bytes
File C:\RRbackups\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_f98f56a2-efd3-4206-9e4e-8df438541ae1 893 bytes
File C:\RRbackups\Documents and Settings\Default User 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Lenovo 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Crypto\RSA 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\CREDHIST 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\8d9e96a6-6040-41fe-9013-b5f97e847600 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-1756038592-513179481-3750871285-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\d798298d-45cc-4c54-aec1-daa1a9828fe8 388 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\Protect\S-1-5-21-786017641-2925068380-3473360674-500\Preferred 24 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\Default User\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\LocalService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\Certificates 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CRLs 0 bytes
File C:\RRbackups\Documents and Settings\NetworkService\Application Data\Microsoft\SystemCertificates\My\CTLs 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\1929418354 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\bckfg.tmp 862 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\cfg.ini 198 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\Desktop.ini 4608 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\kwrd.dll 223744 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\L 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\L\hvmonmrs 456320 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\lsflt7.ver 5176 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U 0 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\00000001.@ 2048 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\00000002.@ 224768 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\00000004.@ 1024 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\80000000.@ 11264 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\80000004.@ 12800 bytes
File C:\WINDOWS\$NtUninstallKB61679$\3403627056\U\80000032.@ 77312 bytes
---- EOF - GMER 1.0.15 ----