Well . . . looks like the VUNDO was just a remnant like the smitfraud. You'll need to manually delete these remnants.
C:\WINDOWS\system32\klnmp.bak2
C:\WINDOWS\system32\klnmp.bak1
For the life of me, I cannot find anything in these logs! I am at a loss.
I'm thinking sfc might be a good idea. Something is definitely borked, but whatever did it (if malware) isn't present any longer.
BTW - What scanner popped up the Darksma reference?
PP![]()




Reply With Quote