Help - Search - Members - Calendar
Full Version: pls help me with NTRootkit-J....
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
maverick
anyone please help me with this
i hv mcafee installed but somehow NTRootkit-J got in
now mcafee is flashing screen sayin removed
when i press continue it comes bck again
wt do i do
here is my HIJACK file
plsss help me!!!!

Logfile of HijackThis v1.99.1
Scan saved at 12:29:14 PM, on 05/07/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\progra~1\mcafee\MCAFEE~3\masalert.exe
C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\nithin\My Documents\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~3\masalert.exe
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
LoPhatPhuud
Please download RootKitRevealer from here:

http://www.sysinternals.com/files/rootkitrevealer.zip
Unzip it to the desktop, run it, and click Scan. This will generate a log file; please post the entire contents of the log file here for me to see.
maverick
thanks for responding
here is wt u askd for





HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Installed TimeX 06/07/2006 12:38 AM 42 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\RecordX 06/07/2006 12:38 AM 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s0 04/07/2006 08:47 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s1 04/07/2006 08:47 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s2 04/07/2006 08:47 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\g0 04/07/2006 08:47 PM 32 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\h0 04/07/2006 08:47 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 04/07/2006 08:47 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\CurrentUser 05/07/2006 10:07 PM 18 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\WaitToKillServiceTimeout 05/07/2006 10:07 PM 10 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\SystemStartOptions 05/07/2006 10:07 PM 22 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\SystemBootDevice 05/07/2006 10:07 PM 72 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\BootExecute 05/07/2006 10:07 PM 42 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\CriticalSectionTimeout 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\EnableMCA 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\EnableMCE 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\ExcludeFromKnownDlls 05/07/2006 10:07 PM 2 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\GlobalFlag 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\HeapDeCommitFreeBlockThreshold 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\HeapDeCommitTotalFreeThreshold 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\HeapSegmentCommit 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\HeapSegmentReserve 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\ObjectDirectories 05/07/2006 10:07 PM 46 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\ProtectionMode 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\ResourceTimeoutCount 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\ProcessorControl 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\RegisteredProcessors 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Control\Session Manager\LicensedProcessors 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\Type 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\Start 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\ErrorControl 05/07/2006 10:07 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\ImagePath 05/07/2006 10:07 PM 90 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\DisplayName 05/07/2006 10:07 PM 20 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\DependOnService 05/07/2006 10:07 PM 84 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\DependOnGroup 05/07/2006 10:07 PM 2 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\ObjectName 05/07/2006 10:07 PM 24 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\Description 05/07/2006 10:07 PM 576 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\WmiApRpl 04/07/2006 06:42 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\WmiApSrv 05/07/2006 10:07 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\wscsvc 04/07/2006 11:49 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\wuauserv 05/07/2006 10:07 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\WZCSVC 05/07/2006 10:07 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\{1E0640F6-5F51-40D9-9A1D-D5F724E3440F} 04/07/2006 06:52 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\12863DE3d01 06/07/2006 12:41 AM 17.44 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1F57540Ad01 06/07/2006 12:42 AM 18.50 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\3B5A8A82d01 06/07/2006 12:41 AM 16.51 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\3F50C327d01 06/07/2006 12:44 AM 19.80 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\7CC97D89d01 06/07/2006 12:42 AM 29.90 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\816008CFd01 06/07/2006 12:45 AM 24.88 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\B7A18D3Fd01 06/07/2006 12:41 AM 16.84 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\B9CD9C04d01 06/07/2006 12:44 AM 71.04 KB Hidden from Windows API.
C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf 06/07/2006 12:40 AM 45.98 KB Hidden from Windows API.
LoPhatPhuud
Nothing definitive from RKR. Where does McAfee say the infection is, and if possible, what is the file name?
maverick
a popup keeps appearin sayin
located trojan NTRootkit-J
file is c:/windows/system32/rdriv.sys
then when i press continue wt i was doing
this popup comes again
nd so on
my hijack nd rkr again

hijack:

Logfile of HijackThis v1.99.1
Scan saved at 02:18:44 AM, on 06/07/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\progra~1\mcafee\MCAFEE~3\masalert.exe
C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe
C:\WINDOWS\System32\ctfmon.exe
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdui.exe
C:\Documents and Settings\nithin\Desktop\New Folder (2)\RootkitRevealer\RootkitRevealer.exe
C:\DOCUME~1\nithin\LOCALS~1\Temp\IMQRQCB.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\nithin\My Documents\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~3\masalert.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Program Files\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: IMQRQCB - Sysinternals - www.sysinternals.com - C:\DOCUME~1\nithin\LOCALS~1\Temp\IMQRQCB.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner - C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RTSS - Sysinternals - www.sysinternals.com - C:\DOCUME~1\nithin\LOCALS~1\Temp\RTSS.exe

rkr:


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Installed TimeX 06/07/2006 02:15 AM 42 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\LastWaitTimeout 06/07/2006 02:10 AM 40 bytes Data mismatch between Windows API and raw hive data.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s0 04/07/2006 08:47 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s1 04/07/2006 08:47 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\s2 04/07/2006 08:47 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\g0 04/07/2006 08:47 PM 32 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\h0 04/07/2006 08:47 PM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 04/07/2006 08:47 PM 0 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\Type 06/07/2006 02:14 AM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\Start 06/07/2006 02:14 AM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\ErrorControl 06/07/2006 02:14 AM 4 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\ImagePath 06/07/2006 02:14 AM 90 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\DisplayName 06/07/2006 02:14 AM 20 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\DependOnService 06/07/2006 02:14 AM 84 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\DependOnGroup 06/07/2006 02:14 AM 2 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\ObjectName 06/07/2006 02:14 AM 24 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\Messenger\Description 06/07/2006 02:14 AM 576 bytes Hidden from Windows API.
HKLM\SYSTEM\ControlSet002\Services\{1E0640F6-5F51-40D9-9A1D-D5F724E3440F} 04/07/2006 06:52 PM 0 bytes Hidden from Windows API.
C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall\data\log.edb-journal 06/07/2006 02:16 AM 1.03 KB Visible in Windows API, MFT, but not in directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\update\UPD_vso 06/07/2006 02:15 AM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\update\UPD_vso\UpdReq.mcaf 06/07/2006 02:15 AM 1.74 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\Agent\update\UPD_vso\UpdResp.mcaf 06/07/2006 02:15 AM 2.96 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\UPD_vso 06/07/2006 02:06 AM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\UPD_vso\vso 06/07/2006 02:15 AM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\UPD_vso\vso\en-us 06/07/2006 02:06 AM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\UPD_vso\vso\en-us\us 06/07/2006 02:06 AM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\UPD_vso\vso\mcs3.tmp 06/07/2006 02:16 AM 4.03 MB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\UPD_vso\vso\vsodat.cab 06/07/2006 02:15 AM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\UPD_vso\vso\winnt 06/07/2006 02:09 AM 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Application Data\McAfee.com\download\UPD_vso\vso\winnt\vsoeng.cab 06/07/2006 02:10 AM 707.83 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Start Menu\Programs\McAfee\McAfee VirusScan\Scan for Viruses.lnk 04/07/2006 07:06 PM 774 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\All Users\Start Menu\Programs\McAfee\McAfee VirusScan\Scan.lnk 06/07/2006 02:21 AM 774 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\MSHist012006070620060707 06/07/2006 02:21 AM 0 bytes Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\MSHist012006070620060707\index.dat 06/07/2006 02:21 AM 32.00 KB Hidden from Windows API.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\F7EXY234\vs10dat[2].cab 06/07/2006 02:15 AM 870.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\QRMKLDNR\CAI3W0RG.lpk 06/07/2006 02:21 AM 1.80 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Desktop\New Folder (2)\gmer.zip.GetRight 06/07/2006 02:23 AM 215.02 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\025612A3d01 06/07/2006 12:03 AM 16.26 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\03098F01d01 06/07/2006 02:11 AM 46.32 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\08FA469Cd01 04/07/2006 11:58 PM 25.35 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\0A0B36E2d01 06/07/2006 12:32 AM 17.85 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\0C15B40Ed01 06/07/2006 01:55 AM 16.54 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\10157054d01 05/07/2006 12:42 AM 20.64 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\107A188Dd01 05/07/2006 12:51 AM 17.12 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\12863DE3d01 06/07/2006 12:41 AM 17.44 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\13953C1Bd01 05/07/2006 01:00 AM 29.59 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1783CA43d01 05/07/2006 12:36 AM 32.45 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1D1E70BDd01 06/07/2006 01:08 AM 19.79 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1D82CAD6d01 04/07/2006 11:57 PM 21.06 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1F76ABC6d01 04/07/2006 11:54 PM 49.45 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1F97B87Dd01 06/07/2006 01:01 AM 19.36 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1FC507B4d01 04/07/2006 11:58 PM 59.19 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1FC517B4d01 04/07/2006 11:58 PM 47.28 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1FC557B4d01 04/07/2006 11:58 PM 49.30 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1FC567B4d01 04/07/2006 11:59 PM 56.62 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1FC577B4d01 04/07/2006 11:58 PM 57.89 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\1FF6B87Bd01 06/07/2006 12:58 AM 19.28 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\216E2B63d01 04/07/2006 11:56 PM 22.53 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\22D5B5D8d01 05/07/2006 11:57 PM 261 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\24CDBF10d01 05/07/2006 12:45 AM 34.34 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\26D497C0d01 05/07/2006 11:49 PM 18.83 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\2884D3E6d01 05/07/2006 12:43 AM 16.26 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\28E9FCFCd01 06/07/2006 12:49 AM 18.42 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\29F35BADd01 05/07/2006 12:37 AM 112.87 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\2A9B9C09d01 05/07/2006 12:46 AM 14.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\2AD773B8d01 05/07/2006 12:34 AM 17.28 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\2EA0B872d01 06/07/2006 12:50 AM 18.66 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\318C1D91d01 05/07/2006 11:49 PM 15.39 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\32780C2Bd01 06/07/2006 12:41 AM 17.69 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\35D520F9d01 06/07/2006 01:49 AM 16.46 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\377FB87Bd01 06/07/2006 01:07 AM 19.51 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\386B339Ad01 05/07/2006 12:59 AM 17.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\3B5A8A82d01 06/07/2006 12:41 AM 16.51 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\3CF5C2DCd01 06/07/2006 12:47 AM 17.50 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\3F50C327d01 06/07/2006 12:44 AM 19.80 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\4092D369d01 04/07/2006 11:57 PM 21.05 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\42230B4Fd01 06/07/2006 01:50 AM 71.34 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\42452202d01 05/07/2006 11:49 PM 34.17 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\48B82A7Ad01 05/07/2006 12:42 AM 3.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\498ABF96d01 06/07/2006 01:49 AM 16.64 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\49F6B87Cd01 06/07/2006 01:07 AM 19.12 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\4A20B873d01 06/07/2006 12:52 AM 18.51 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\4A9D89BAd01 04/07/2006 11:43 PM 17.32 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\4AD4B873d01 06/07/2006 12:49 AM 18.67 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\4AF20EA9d01 05/07/2006 12:58 AM 51.43 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\4BB1B87Fd01 06/07/2006 01:04 AM 19.27 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\4D746921d01 05/07/2006 12:36 AM 20.81 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\4FD2C217d01 05/07/2006 01:03 AM 23.56 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\51355913d01 05/07/2006 12:50 AM 21.04 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\51F4ACBFd01 05/07/2006 11:51 PM 19.80 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\53F8573Fd01 05/07/2006 11:50 PM 41.10 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\541CDF20d01 06/07/2006 01:01 AM 16.97 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\541CDFF0d01 06/07/2006 01:56 AM 17.44 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\56472196d01 04/07/2006 10:28 PM 16.13 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\592B15A9d01 05/07/2006 11:49 PM 74.87 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\59B82056d01 06/07/2006 12:49 AM 16.87 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5A293C89d01 04/07/2006 10:40 PM 27.77 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5BD923E4d01 04/07/2006 11:58 PM 39.26 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5BD928E4d01 04/07/2006 11:58 PM 26.74 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5BD929E4d01 04/07/2006 11:58 PM 39.76 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5BD92DE4d01 04/07/2006 11:58 PM 21.07 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5BD92EE4d01 04/07/2006 11:58 PM 30.59 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5BD92FE4d01 04/07/2006 11:58 PM 16.93 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5C549BA1d01 04/07/2006 11:54 PM 19.25 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5C71B545d01 05/07/2006 12:36 AM 32.44 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5CF8C995d01 06/07/2006 01:08 AM 22.79 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5D0EDAEDd01 04/07/2006 10:40 PM 26.73 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5E732977d01 06/07/2006 01:04 AM 17.57 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5EC3B87Dd01 06/07/2006 12:57 AM 19.25 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\5EEFB87Fd01 06/07/2006 01:02 AM 19.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\60672020d01 05/07/2006 11:49 PM 34.17 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\60C68C30d01 05/07/2006 11:51 PM 18.63 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\614D7854d01 05/07/2006 12:39 AM 42.20 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\614E1AE5d01 04/07/2006 11:57 PM 19.60 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\614E2AE5d01 04/07/2006 11:57 PM 24.56 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\614E3AE5d01 04/07/2006 11:57 PM 28.82 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\645037BEd01 04/07/2006 11:57 PM 20.17 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6850B872d01 06/07/2006 12:57 AM 19.31 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\686167BFd01 06/07/2006 12:03 AM 16.97 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\69A90EC5d01 04/07/2006 11:58 PM 39.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\69B50EC5d01 04/07/2006 11:58 PM 78.14 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\69F9557Ed01 04/07/2006 11:58 PM 20.25 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6AE99C1Ed01 05/07/2006 12:07 AM 50.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6AE99D1Ed01 05/07/2006 12:07 AM 27.63 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6AE99E1Ed01 05/07/2006 12:06 AM 27.40 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6AE99F1Ed01 05/07/2006 12:07 AM 16.74 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6AF3B87Bd01 06/07/2006 01:05 AM 19.37 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6B3EF9C2d01 05/07/2006 12:37 AM 18.80 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6DA2B872d01 06/07/2006 12:50 AM 18.48 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6DEFC30Bd01 06/07/2006 01:08 AM 18.16 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\6F46D97Ed01 05/07/2006 11:57 PM 7.12 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\74838489d01 05/07/2006 12:59 AM 51.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\79A4503Cd01 05/07/2006 11:52 PM 79.71 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\7CC97D89d01 06/07/2006 12:42 AM 29.90 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\7D8DC023d01 05/07/2006 11:52 PM 42.44 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\7EF7BF81d01 05/07/2006 12:58 AM 21.32 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\7FD5C63Bd01 05/07/2006 12:50 AM 50.21 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\8095BF93d01 06/07/2006 12:47 AM 14.12 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\81077179d01 04/07/2006 11:43 PM 16.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\816008CFd01 06/07/2006 12:45 AM 24.88 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\86A8A622d01 05/07/2006 12:42 AM 34.04 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\87900B4Cd01 04/07/2006 11:57 PM 36.97 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\8790AB4Cd01 04/07/2006 11:57 PM 22.69 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\8790BB4Cd01 04/07/2006 11:57 PM 23.66 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\8790EB4Cd01 04/07/2006 11:57 PM 38.94 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\8790FB4Cd01 04/07/2006 11:57 PM 33.20 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\87A2023Bd01 04/07/2006 11:44 PM 131.61 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\884CF67Ed01 04/07/2006 11:43 PM 2.91 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\885D366Ed01 04/07/2006 11:43 PM 1.14 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\885D374Ed01 04/07/2006 11:43 PM 161 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\887B971Ed01 04/07/2006 11:43 PM 224 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\898BBC2Ed01 04/07/2006 11:43 PM 1.06 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\8D0D7041d01 06/07/2006 01:49 AM 32.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\8D8F5BB5d01 05/07/2006 12:37 AM 29.45 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\8D9BF2AEd01 04/07/2006 11:54 PM 21.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\917A73B2d01 05/07/2006 01:04 AM 27.24 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\987151A0d01 04/07/2006 10:39 PM 8.54 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\9A4E1505d01 05/07/2006 12:42 AM 29.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\9BC8F3B6d01 04/07/2006 11:22 PM 24.62 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\9DC31D93d01 04/07/2006 10:40 PM 22.96 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\9E3E8205d01 04/07/2006 11:43 PM 16.75 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A21109BDd01 05/07/2006 11:57 PM 780 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A40D73DCd01 05/07/2006 01:01 AM 16.24 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A5C4B408d01 06/07/2006 01:55 AM 46.32 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A5E65CF5d01 06/07/2006 01:51 AM 16.22 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A7374254d01 04/07/2006 11:56 PM 22.06 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A7489EDBd01 04/07/2006 11:43 PM 17.29 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A851B1ABd01 04/07/2006 11:43 PM 9.99 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A85EFC4Ad01 04/07/2006 11:43 PM 13.14 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A8B92E95d01 05/07/2006 12:43 AM 17.82 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A8D9DE38d01 06/07/2006 01:27 AM 16.88 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\A8FC2C41d01 06/07/2006 12:33 AM 22.58 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\AB1BAFB8d01 05/07/2006 11:51 PM 27.50 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\ABFCA294d01 05/07/2006 12:57 AM 26.56 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\AC9C5AB5d01 04/07/2006 10:39 PM 5.79 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\ACC3EAFFd01 04/07/2006 11:43 PM 17.72 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\AD4720C4d01 06/07/2006 12:38 AM 19.53 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\AD913336d01 05/07/2006 12:42 AM 16.50 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\AF644E42d01 05/07/2006 12:42 AM 18.90 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\AF645D62d01 05/07/2006 11:50 PM 33.25 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\AF65463Dd01 06/07/2006 12:05 AM 17.70 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\AF6546C2d01 06/07/2006 02:11 AM 17.53 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\B05C63DFd01 06/07/2006 02:21 AM 17.61 KB Hidden from Windows API.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\B29B330Fd01 05/07/2006 01:04 AM 31.98 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\B7A18D3Fd01 06/07/2006 12:41 AM 16.84 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\B7DE1C6Ed01 06/07/2006 12:47 AM 16.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\B86083C4d01 06/07/2006 01:08 AM 23.95 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\BA851C42d01 05/07/2006 11:57 PM 23.43 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\BB44B0A8d01 05/07/2006 12:46 AM 16.60 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\BBF0C49Bd01 05/07/2006 11:49 PM 22.82 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\BCC63530d01 04/07/2006 10:40 PM 22.73 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\BD24B31Ed01 06/07/2006 01:52 AM 74.11 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\C15A59E3d01 06/07/2006 01:08 AM 17.04 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\C167B879d01 06/07/2006 12:51 AM 18.83 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\C272ABC9d01 05/07/2006 01:03 AM 91.02 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\C312C8FDd01 04/07/2006 11:57 PM 20.06 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\C5F1AB98d01 05/07/2006 11:50 PM 206.39 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\C8B61537d01 04/07/2006 10:31 PM 284.72 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\CB51B879d01 06/07/2006 12:49 AM 18.57 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\CBE265D4d01 04/07/2006 10:39 PM 78 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\CDC2B872d01 06/07/2006 12:56 AM 19.21 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\CDCDBAFCd01 04/07/2006 11:56 PM 40.22 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\CDCDBCFCd01 04/07/2006 11:57 PM 48.77 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D1118F75d01 04/07/2006 11:56 PM 20.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D1E6B878d01 06/07/2006 12:49 AM 18.78 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D331C4BAd01 05/07/2006 01:01 AM 23.19 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D3F2C7C7d01 05/07/2006 12:42 AM 16.84 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D4043C66d01 05/07/2006 12:39 AM 22.59 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D489BDB2d01 06/07/2006 01:08 AM 22.66 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D77C713Ed01 04/07/2006 11:44 PM 6.94 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D79AB6A0d01 06/07/2006 01:50 AM 16.19 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\D86FB87Dd01 06/07/2006 12:54 AM 19.10 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\DBF71A84d01 06/07/2006 12:33 AM 22.58 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\DCA5B87Ed01 06/07/2006 12:57 AM 19.36 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\DD85EABCd01 05/07/2006 11:57 PM 299 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\DED08C39d01 05/07/2006 12:58 AM 46.33 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\DFF6B879d01 06/07/2006 01:04 AM 19.43 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\E1BAACA5d01 05/07/2006 12:34 AM 28.31 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\E5DB87C2d01 05/07/2006 12:36 AM 85.58 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\E65FFC1Bd01 06/07/2006 01:05 AM 39.39 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\E682E1EFd01 05/07/2006 12:58 AM 21.92 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\E6AD7AC3d01 05/07/2006 12:06 AM 20.25 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\E6B3FFE2d01 05/07/2006 11:52 PM 23.81 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\E6FE8C95d01 05/07/2006 12:42 AM 39.56 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local Settings\Application Data\Mozilla\Firefox\Profiles\zzd5oul6.default\Cache\E9FEDA93d01 05/07/2006 01:04 AM 20.09 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\nithin\Local
LoPhatPhuud
Copy the below instructions (until you get to the purple text). Paste them into notepad and save it for use while in Safe Mode. This is important because it has to be done exactly in order to work

I need you to reboot into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. use your up arrow key to highlight Safe Mode, then hit enter.

After getting into Safe Mode, Go to Start > Run type in:

cmd

Click OK.

A black window will open up.

Copy the below line, exactly, and paste it into the black window:

attrib -h -r -s C:\WINDOWS\system32\rdriv.sys

Hit Enter.

When it goes to the 2nd line, copy the below line, exactly, and paste it into the black window:

del C:\WINDOWS\system32\rdriv.sys

Hit Enter.

Then type exit


[END OF INSTRUCTIONS TO COPY FOR SAFE MODE]


Reboot into Normal Mode



Launch Notepad, and copy/paste in the box below to a new text file.
Save it on your Desktop as fixme.reg

CODE
REGEDIT4
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdriv]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\Legacy_RDRIV]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000

[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate]
"DoNotAllowXPSP2"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
"AUOptions"=dword:00000004

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
"EnableFirewall"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
"EnableFirewall"=-

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lanmanserver\parameters]
"AutoShareWks"=-

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lanmanserver\parameters]
"AutoShareServer"=-

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lanmanworkstation\parameters]
"AutoShareWks"=-

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\lanmanworkstation\parameters]
"AutoShareServer"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions]
"Installed Time"=-

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions]
"Record"=-

Locate fixme.reg on your Desktop and double-click on it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".
maverick
HII
the popup has stopped coming
does this mean that trojan is off my system??

And also i'd like to ave some advice
I am using
Mcafee AntiVirus+Firewall+AntiSpyware
is it the best.
Have you any other suggestions????
LoPhatPhuud
If the popups stopped, then yes, removal of rdriv.sys has fixed the problem. I need to check a new HiJackTHis log to be safe. Please run HJT again and post a new log in this thread,

As to best AV product, firewall, etc., the answer is left up to the user. Some love Norton, others McAfee, Trend Micro, etc. A lot is what you are familiar with, your computer harderware, and computer software, along with user need. Most AV manufacturers these days are going to suites for a broad platform of protection. If McAfee has served youwell, then no need to change.
maverick
I herd panda is better is AV nd ewdo is a better anti spyware. Is there any substance to these remarks or is everythin the same.


Logfile of HijackThis v1.99.1
Scan saved at 10:28:33 PM, on 08/07/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\progra~1\mcafee\MCAFEE~3\masalert.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
D:\Program Files\Yahoo!\Messenger\YPager.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\Setup\NTRootkit-J\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.in/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program

Files\GetRight\xx2gr.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -

c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~3\masalert.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [RegistryOptimizer] "C:\Program Files\Registry Optimizer

2006\RegistryOptimizer.exe" ShowError
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download with GetRight Pro - C:\Program

Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program

Files\GetRight\GRbrowse.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -

D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program

Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner -

C:\NVIDIA\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file

missing)
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee

antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program

files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. -

c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc -

c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc -

C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation -

C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: ForceWare user log service (nSvcLog) - Unknown owner -

C:\NVIDIA\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RTSS - Sysinternals - www.sysinternals.com -

C:\DOCUME~1\nithin\LOCALS~1\Temp\RTSS.exe
LoPhatPhuud
Your log is clean.

Thw top two AntiVirus programs are Kaspersky and NOD32. The top AntiSpyware programs are CounterSpy, Ewdio, and WindowsDefender. These are my opinions. Again user usage and comfort has a lot to do with it.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.