Hello all.
Well.. Where to begin? just over a month ago a rougue anti-malware program named antimalware doctor began appearing on my computer. This troubled me for quite some time, and i tried many different things to get rid of it. However in the end i did a sytem restore to about 1 month before the virus appeared.
This seemed to work but soon after i began to see some strange things happening. For starters, my computer would freeze and seemingly random intervals, but each time the screen would kind of scramble, also my browser began being redirected to websites which i had not told it to go to.
I figured something was up so i did some virus scans, some research and immediately stopped enetering passwords and other sensitive data. Some things turned up but the problems continued.
Then i began to notice worse things, google chrome stopped working, along with some other programs, things began missing files and glitching out more frequently. I also began getting the error message "this service cannot accept control messages at the current time" when launching some programs. This could only be temporarily fixed with a computer restart.
I also believer my computer has been getting slower lately (This has not been confirmed).
After some more research i have discovered that this is most likely a rootkit virus, as alot of these symptoms are similar to the rootkit symptoms.
Now i am also getting errors like: "Host process for windows services stopped working and was closed
A problem caused the application to stop working correctly. Windows will notify you if a solution is available" on a regular basis
When trying to partition my hard drive no C drive can be found under disk management.
I have looked at many different ways of solving this problem, however in the end i decided a c drive format would be best. however i even had problems with this. When attempting to format my computer by reinstalling windows (vista home premium 32 bit) but apparently i don't have a drive to install it on. Also administrative tools in the control pannel is missing.
So once again i am looking to try and solve the problem itself, and i definately need help. Therefore any help that can be provided will be so greatly appreciated.
I ran the scans listed in the stickied post and i have the details here and i will post them below.
GMER One
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-01-28 18:41:03
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\iaStor0 TOSHIBA_ rev.LV01
Running: lfn1n4wm.exe; Driver: C:\Users\MUMAND~1\AppData\Local\Temp\axrdipow.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00 (MBR): rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 29: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 39: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 49: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sectors 625142192 (+255): rootkit-like behavior;
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVHook.sys (PC Tools Filter Driver for Windows 2000/XP/PC Tools Research Pty Ltd.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Device\Ide\IAAStorageDevice-1 -> \??\IDE#DiskTOSHIBA_MK3252GSX_______________________LV010M__#4&4079406&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- EOF - GMER 1.0.15 ----
This one is a big one.....
GMER Two
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-01-28 20:26:33
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\iaStor0 TOSHIBA_ rev.LV01
Running: lfn1n4wm.exe; Driver: C:\Users\MUMAND~1\AppData\Local\Temp\axrdipow.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0x82B999A6]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0x82B99B98]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0x82B99656]
SSDT \SystemRoot\system32\drivers\PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateUserProcess [0x82B99DA0]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVHook.sys (PC Tools Filter Driver for Windows 2000/XP/PC Tools Research Pty Ltd.)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
Device \Device\Ide\IAAStorageDevice-1 -> \??\IDE#DiskTOSHIBA_MK3252GSX_______________________LV010M__#4&4079406&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\00037a919292
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\00037a919292 (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost@netsvc SPService?%
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00 (MBR): rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 29: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 39: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 49: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sectors 625142192 (+255): rootkit-like behavior;
---- Files - GMER 1.0.15 ----
File C:\Windows\Temp\Win42CD.tmp 0 bytes
File C:\Windows\Temp\Win3BD4.tmp 0 bytes
File C:\Windows\Temp\Win3BE1.tmp 0 bytes
File C:\Windows\Temp\Win3C3B.tmp 0 bytes
File C:\Windows\Temp\Win3C4F.tmp 0 bytes
File C:\Windows\Temp\Win3D33.tmp 0 bytes
File C:\Windows\Temp\Win3D4E.tmp 0 bytes
File C:\Windows\Temp\Win3DDE.tmp 0 bytes
File C:\Windows\Temp\Win3EC2.tmp 0 bytes
File C:\Windows\Temp\Win3F5F.tmp 0 bytes
File C:\Windows\Temp\Win3FC9.tmp 0 bytes
File C:\Windows\Temp\Win4059.tmp 0 bytes
File C:\Windows\Temp\Win4068.tmp 0 bytes
File C:\Windows\Temp\Win4069.tmp 0 bytes
File C:\Windows\Temp\Win40A7.tmp 0 bytes
File C:\Windows\Temp\Win40B6.tmp 0 bytes
File C:\Windows\Temp\Win4152.tmp 0 bytes
File C:\Windows\Temp\Win41B0.tmp 0 bytes
File C:\Windows\Temp\WER2618.tmp.hdmp 812223 bytes
File C:\Windows\Temp\WER4D16.tmp.version.txt 476 bytes
File C:\Windows\Temp\WER4D26.tmp.appcompat.txt 18542 bytes
File C:\Windows\Temp\WER55B0.tmp.hdmp 798867 bytes
File C:\Windows\Temp\WER5783.tmp.appcompat.txt 18548 bytes
File C:\Windows\Temp\WER6652.tmp.hdmp 32620398 bytes
File C:\Windows\Temp\WER98AF.tmp.version.txt 476 bytes
File C:\Windows\Temp\WER98B0.tmp.appcompat.txt 13314 bytes
File C:\Windows\Temp\Win8B2E.tmp 0 bytes
File C:\Windows\Temp\Win8B66.tmp 0 bytes
File C:\Windows\Temp\Win8B7E.tmp 0 bytes
File C:\Windows\Temp\Win8BC4.tmp 0 bytes
File C:\Windows\Temp\Win8D14.tmp 0 bytes
File C:\Windows\Temp\Win8D77.tmp 0 bytes
File C:\Windows\Temp\Win8D79.tmp 0 bytes
File C:\Windows\Temp\Win8D98.tmp 0 bytes
File C:\Windows\Temp\Win8DAD.tmp 0 bytes
File C:\Windows\Temp\Win8DC0.tmp 0 bytes
File C:\Windows\Temp\Win8E3A.tmp 0 bytes
File C:\Windows\Temp\Win8E59.tmp 0 bytes
File C:\Windows\Temp\Win8F0E.tmp 0 bytes
File C:\Windows\Temp\Win8FF9.tmp 0 bytes
File C:\Windows\Temp\Win900D.tmp 0 bytes
File C:\Windows\Temp\Win901D.tmp 0 bytes
File C:\Windows\Temp\Win90B9.tmp 0 bytes
File C:\Windows\Temp\Win924F.tmp 0 bytes
File C:\Windows\Temp\Win9264.tmp 0 bytes
File C:\Windows\Temp\Win9296.tmp 0 bytes
File C:\Windows\Temp\Win9496.tmp 0 bytes
File C:\Windows\Temp\Win952D.tmp 0 bytes
File C:\Windows\Temp\Win95E7.tmp 0 bytes
File C:\Windows\Temp\Win9615.tmp 0 bytes
File C:\Windows\Temp\TarF6DE.tmp 78450 bytes
File C:\Windows\Temp\TMP0000000F55F63D6501094D2C 524288 bytes
File C:\Windows\Temp\WER9CE5.tmp.hdmp 0 bytes
File C:\Windows\Temp\Win138B.tmp 0 bytes
File C:\Windows\Temp\Win2116.tmp 0 bytes
File C:\Windows\Temp\Win32F1.tmp 0 bytes
File C:\Windows\Temp\Win3B3F.tmp 0 bytes
File C:\Windows\Temp\WinBDD1.tmp 0 bytes
File C:\Windows\Temp\WinBE56.tmp 0 bytes
File C:\Windows\Temp\WinBE6D.tmp 0 bytes
File C:\Windows\Temp\WinBFF2.tmp 0 bytes
File C:\Windows\Temp\WinC061.tmp 0 bytes
File C:\Windows\Temp\WinC0ED.tmp 0 bytes
File C:\Windows\Temp\WinC106.tmp 0 bytes
File C:\Windows\Temp\WinC150.tmp 0 bytes
File C:\Windows\Temp\WinC1B2.tmp 0 bytes
File C:\Windows\Temp\WinC1E3.tmp 0 bytes
File C:\Windows\Temp\WinC271.tmp 0 bytes
File C:\Windows\Temp\WinC2A.tmp 0 bytes
File C:\Windows\Temp\WinC3D6.tmp 0 bytes
File C:\Windows\Temp\WinC427.tmp 0 bytes
File C:\Windows\Temp\WinC521.tmp 0 bytes
File C:\Windows\Temp\WinC659.tmp 0 bytes
File C:\Windows\Temp\WinC68B.tmp 0 bytes
File C:\Windows\Temp\WinC726.tmp 0 bytes
File C:\Windows\Temp\WinC794.tmp 0 bytes
File C:\Windows\Temp\WinC86C.tmp 0 bytes
File C:\Windows\Temp\WinC8D2.tmp 0 bytes
File C:\Windows\Temp\Win5BD3.tmp 0 bytes
File C:\Windows\Temp\Win5C1.tmp 0 bytes
File C:\Windows\Temp\Win5DF6.tmp 0 bytes
File C:\Windows\Temp\Win5F10.tmp 0 bytes
File C:\Windows\Temp\Win5F2E.tmp 0 bytes
File C:\Windows\Temp\Win5F8C.tmp 0 bytes
File C:\Windows\Temp\Win6018.tmp 0 bytes
File C:\Windows\Temp\Win605D.tmp 0 bytes
File C:\Windows\Temp\Win60ED.tmp 0 bytes
File C:\Windows\Temp\Win6133.tmp 0 bytes
File C:\Windows\Temp\Win6179.tmp 0 bytes
File C:\Windows\Temp\Win6194.tmp 0 bytes
File C:\Windows\Temp\Win625C.tmp 0 bytes
File C:\Windows\Temp\Win63A3.tmp 0 bytes
File C:\Windows\Temp\Win63D0.tmp 0 bytes
File C:\Windows\Temp\Win63D6.tmp 0 bytes
File C:\Windows\Temp\Win65DF.tmp 0 bytes
File C:\Windows\Temp\Win65FA.tmp 0 bytes
File C:\Windows\Temp\Win65FC.tmp 0 bytes
File C:\Windows\Temp\Win6637.tmp 0 bytes
File C:\Windows\Temp\Win666D.tmp 0 bytes
File C:\Windows\Temp\Win6793.tmp 0 bytes
File C:\Windows\Temp\Win68A0.tmp 0 bytes
File C:\Windows\Temp\Win6975.tmp 0 bytes
File C:\Windows\Temp\Win69DA.tmp 0 bytes
File C:\Windows\Temp\Win6C48.tmp 0 bytes
File C:\Windows\Temp\Win6C96.tmp 0 bytes
File C:\Windows\Temp\Win6CA1.tmp 0 bytes
File C:\Windows\Temp\Win6CE4.tmp 0 bytes
File C:\Windows\Temp\Win6CFD.tmp 0 bytes
File C:\Windows\Temp\Win232F.tmp 0 bytes
File C:\Windows\Temp\Win2347.tmp 0 bytes
File C:\Windows\Temp\Win2394.tmp 0 bytes
File C:\Windows\Temp\Win23F2.tmp 0 bytes
File C:\Windows\Temp\Win2456.tmp 0 bytes
File C:\Windows\Temp\Win259D.tmp 0 bytes
File C:\Windows\Temp\Win259F.tmp 0 bytes
File C:\Windows\Temp\Win25C0.tmp 0 bytes
File C:\Windows\Temp\Win25FA.tmp 0 bytes
File C:\Windows\Temp\Win2890.tmp 0 bytes
File C:\Windows\Temp\Win28A4.tmp 0 bytes
File C:\Windows\Temp\Win2902.tmp 0 bytes
File C:\Windows\Temp\Win296A.tmp 0 bytes
File C:\Windows\Temp\Win2B0E.tmp 0 bytes
File C:\Windows\Temp\Win2BCF.tmp 0 bytes
File C:\Windows\Temp\Win2BFD.tmp 0 bytes
File C:\Windows\Temp\Win2D0.tmp 0 bytes
File C:\Windows\Temp\Win2F32.tmp 0 bytes
File C:\Windows\Temp\Win2FA5.tmp 0 bytes
File C:\Windows\Temp\Win2FC7.tmp 0 bytes
File C:\Windows\Temp\Win2FF4.tmp 0 bytes
File C:\Windows\Temp\Win312C.tmp 0 bytes
File C:\Windows\Temp\Win3283.tmp 0 bytes
File C:\Windows\Temp\Win32C2.tmp 0 bytes
File C:\Windows\Temp\WinE374.tmp 0 bytes
File C:\Windows\Temp\WinE4A2.tmp 0 bytes
File C:\Windows\Temp\WinE51B.tmp 0 bytes
File C:\Windows\Temp\WinE529.tmp 0 bytes
File C:\Windows\Temp\WinE582.tmp 0 bytes
File C:\Windows\Temp\WinE5BC.tmp 0 bytes
File C:\Windows\Temp\WinE609.tmp 0 bytes
File C:\Windows\Temp\WinE7D2.tmp 0 bytes
File C:\Windows\Temp\WinE804.tmp 0 bytes
File C:\Windows\Temp\WinE83B.tmp 0 bytes
File C:\Windows\Temp\WinE990.tmp 0 bytes
File C:\Windows\Temp\WinEA02.tmp 0 bytes
File C:\Windows\Temp\WinA14F.tmp 0 bytes
File C:\Windows\Temp\WinA2B8.tmp 0 bytes
File C:\Windows\Temp\WinA2BC.tmp 0 bytes
File C:\Windows\Temp\WinA2D9.tmp 0 bytes
File C:\Windows\Temp\WinA3BC.tmp 0 bytes
File C:\Windows\Temp\WinA40B.tmp 0 bytes
File C:\Windows\Temp\WinA4AB.tmp 0 bytes
File C:\Windows\Temp\WinA4BB.tmp 0 bytes
File C:\Windows\Temp\WinA4D8.tmp 0 bytes
File C:\Windows\Temp\WinA533.tmp 0 bytes
File C:\Windows\Temp\WinA5CC.tmp 0 bytes
File C:\Windows\Temp\WinA5FE.tmp 0 bytes
File C:\Windows\Temp\WinA79C.tmp 0 bytes
File C:\Windows\Temp\WinA89D.tmp 0 bytes
File C:\Windows\Temp\WinA924.tmp 0 bytes
File C:\Windows\Temp\Win4DE0.tmp 0 bytes
File C:\Windows\Temp\Win4DEE.tmp 0 bytes
File C:\Windows\Temp\Win4E2E.tmp 0 bytes
File C:\Windows\Temp\Win4E62.tmp 0 bytes
File C:\Windows\Temp\Win4F50.tmp 0 bytes
File C:\Windows\Temp\Win4F73.tmp 0 bytes
File C:\Windows\Temp\Win4FE3.tmp 0 bytes
File C:\Windows\Temp\Win508E.tmp 0 bytes
File C:\Windows\Temp\Win50DC.tmp 0 bytes
File C:\Windows\Temp\Win50EE.tmp 0 bytes
File C:\Windows\Temp\Win511B.tmp 0 bytes
File C:\Windows\Temp\Win5178.tmp 0 bytes
File C:\Windows\Temp\Win521A.tmp 0 bytes
File C:\Windows\Temp\Win5291.tmp 0 bytes
File C:\Windows\Temp\Win5342.tmp 0 bytes
File C:\Windows\Temp\Win538B.tmp 0 bytes
File C:\Windows\Temp\Win543A.tmp 0 bytes
File C:\Windows\Temp\Win553.tmp 0 bytes
File C:\Windows\Temp\Win556E.tmp 0 bytes
File C:\Windows\Temp\Win5625.tmp 0 bytes
File C:\Windows\Temp\Win5723.tmp 0 bytes
File C:\Windows\Temp\Win5831.tmp 0 bytes
File C:\Windows\Temp\Win583C.tmp 0 bytes
File C:\Windows\Temp\Win58ED.tmp 0 bytes
File C:\Windows\Temp\Win5A3F.tmp 0 bytes
File C:\Windows\Temp\Win5A49.tmp 0 bytes
File C:\Windows\Temp\Win5A8F.tmp 0 bytes
File C:\Windows\Temp\Win5A9C.tmp 0 bytes
File C:\Windows\Temp\WinC984.tmp 0 bytes
File C:\Windows\Temp\WinCA2C.tmp 0 bytes
File C:\Windows\Temp\WinCA8C.tmp 0 bytes
File C:\Windows\Temp\WinCAD0.tmp 0 bytes
File C:\Windows\Temp\WinCAF5.tmp 0 bytes
File C:\Windows\Temp\WinCB0A.tmp 0 bytes
File C:\Windows\Temp\WinCB20.tmp 0 bytes
File C:\Windows\Temp\WinCB39.tmp 0 bytes
File C:\Windows\Temp\WinCB58.tmp 0 bytes
File C:\Windows\Temp\WinCB7C.tmp 0 bytes
File C:\Windows\Temp\WinCC04.tmp 0 bytes
File C:\Windows\Temp\WinCC33.tmp 0 bytes
File C:\Windows\Temp\WinCD3C.tmp 0 bytes
File C:\Windows\Temp\WinCE29.tmp 0 bytes
File C:\Windows\Temp\WinCEAA.tmp 0 bytes
File C:\Windows\Temp\Win6FBE.tmp 0 bytes
File C:\Windows\Temp\Win701.tmp 0 bytes
File C:\Windows\Temp\Win709C.tmp 0 bytes
File C:\Windows\Temp\Win70A2.tmp 0 bytes
File C:\Windows\Temp\Win710D.tmp 0 bytes
File C:\Windows\Temp\Win7136.tmp 0 bytes
File C:\Windows\Temp\Win7149.tmp 0 bytes
File C:\Windows\Temp\Win7196.tmp 0 bytes
File C:\Windows\Temp\Win7203.tmp 0 bytes
File C:\Windows\Temp\Win72D8.tmp 0 bytes
File C:\Windows\Temp\Win7385.tmp 0 bytes
File C:\Windows\Temp\Win739C.tmp 0 bytes
File C:\Windows\Temp\Win75DA.tmp 0 bytes
File C:\Windows\Temp\Win76F2.tmp 0 bytes
File C:\Windows\Temp\WinB45.tmp 0 bytes
File C:\Windows\Temp\WinB461.tmp 0 bytes
File C:\Windows\Temp\WinB4C8.tmp 0 bytes
File C:\Windows\Temp\WinB4FC.tmp 0 bytes
File C:\Windows\Temp\WinB58A.tmp 0 bytes
File C:\Windows\Temp\WinB5E9.tmp 0 bytes
File C:\Windows\Temp\WinB5FD.tmp 0 bytes
File C:\Windows\Temp\WinB605.tmp 0 bytes
File C:\Windows\Temp\WinB69C.tmp 0 bytes
File C:\Windows\Temp\WinB78F.tmp 0 bytes
File C:\Windows\Temp\WinB7BF.tmp 0 bytes
File C:\Windows\Temp\WinB7CB.tmp 0 bytes
File C:\Windows\Temp\WinB807.tmp 0 bytes
File C:\Windows\Temp\WinB83A.tmp 0 bytes
File C:\Windows\Temp\WinB911.tmp 0 bytes
File C:\Windows\Temp\WinBA35.tmp 0 bytes
File C:\Windows\Temp\WinBAB2.tmp 0 bytes
File C:\Windows\Temp\WinBB61.tmp 0 bytes
File C:\Windows\Temp\WinBC0D.tmp 0 bytes
File C:\Windows\Temp\WinBC2C.tmp 0 bytes
File C:\Windows\Temp\TarF70E.tmp 78450 bytes
File C:\Windows\Temp\TarF73E.tmp 78450 bytes
File C:\Windows\Temp\TarF859.tmp 78450 bytes
File C:\Windows\Temp\TarFF09.tmp 78450 bytes
File C:\Windows\Temp\Temporary Internet Files 0 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5 0 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF 0 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\bg_bottom_left[1].png 4304 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\bg_bottom_right[1].png 4325 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\bg_status[1].png 3710 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\bg_status_warning_x[1].png 308 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\btn_primary_left[1].png 3723 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\btn_primary_right[1].png 3756 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\config[1].js 1474 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\desktop.ini 67 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\lang_strings[1].htm 12206 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\shadow-top[1].png 132 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\styles-ie7[1].css 62 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\styles[1].css 20791 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\082B9SRF\WebResource[1].axd 20931 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8 0 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\arrowleft[1].png 1925 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\bg-content-1[1].png 197 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\bg-header-table[1].jpg 20969 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\bg_bottom_x[1].png 3641 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\bg_status_idle_left[1].png 1466 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\bg_top_x[1].png 3673 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\btn_close[1].gif 103 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\default[1].htm 200632 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\desktop.ini 67 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\icn_drawer_btn_up[1].png 205 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\shutdown[1].htm 5821 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\18R8I6N8\spin_icon_onstatusbar[1].gif 8361 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT 0 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\bg-topline[1].png 190 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\bg_status_idle_x[1].png 1153 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\bg_status_warning_right[1].png 1052 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\btn_min[1].gif 96 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\btn_normal_left[1].png 3712 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\btn_normal_right[1].png 3746 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\ctnr_hilite[1].png 306 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\desktop.ini 67 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\icon_secure[1].png 3810 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\lang_urls[1].htm 1406 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\SecurityScanner[1].css 1505 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\shadow-bottom[1].png 131 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\7VTSVWUT\teamviewer[1].png 14162 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ 0 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\arrow[1].png 1903 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\bg-header-1[1].jpg 404 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\bg_left_y[1].png 3607 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\bg_right_y[1].png 3608 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\bg_status_idle_right[1].png 1457 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\bg_status_warning_left[1].png 788 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\bg_top_left[1].png 4027 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\bg_top_right[1].png 4681 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\desktop.ini 67 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\favicon[1].ico 1150 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\icn_drawer_btn_down[1].png 205 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\icon_atrisk[1].png 3812 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\AWMSHBKQ\s_code_prod[1].js 41309 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
File C:\Windows\Temp\Temporary Internet Files\Content.IE5\index.dat 49152 bytes
File C:\Windows\Temp\Win96C0.tmp 0 bytes
File C:\Windows\Temp\Win984B.tmp 0 bytes
File C:\Windows\Temp\Win9BF9.tmp 0 bytes
File C:\Windows\Temp\Win9C00.tmp 0 bytes
File C:\Windows\Temp\Win9C46.tmp 0 bytes
File C:\Windows\Temp\Win9C7E.tmp 0 bytes
File C:\Windows\Temp\Win9C8E.tmp 0 bytes
File C:\Windows\Temp\Win9D29.tmp