ComboFix 09-11-09.02 - hari 11.11.2009 15:19.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1669 [GMT 1:00]
Running from: c:\documents and settings\hari\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\tel.xls.exe
c:\windows\backinf.tab
c:\windows\session.exe
c:\windows\svchost.exe
c:\windows\system32\filekan.exe
c:\windows\system32\socksa.exe
c:\windows\ufdata2000.log
D:\Autorun.inf
D:\tel.xls.exe
G:\Autorun.inf
G:\tel.xls.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-11 to 2009-11-11 )))))))))))))))))))))))))))))))
.
2009-11-10 18:01 . 2009-11-10 18:01 -------- d-----w- c:\program files\ESET
2009-11-10 14:49 . 2009-11-10 14:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-10 14:48 . 2009-11-10 14:48 -------- d-----w- c:\program files\Java
2009-11-10 14:48 . 2009-11-10 14:48 152576 ----a-w- c:\documents and settings\hari\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-11-09 21:13 . 2008-10-22 13:57 1419232 ----a-r- c:\windows\system32\WdfCoInstaller01005.dll
2009-11-09 20:57 . 2007-02-26 17:15 61984 ----a-w- c:\windows\system32\drivers\xusb21.sys
2009-11-09 20:57 . 2007-02-26 17:15 1421216 ----a-w- c:\windows\system32\WdfCoInstaller01001.dll
2009-11-09 20:57 . 2009-11-09 20:57 -------- d-----w- c:\program files\Microsoft Xbox 360 Accessories
2009-11-08 19:48 . 2009-11-08 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-08 19:48 . 2009-11-08 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-11-08 19:48 . 2009-11-08 19:48 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-11-08 19:48 . 2009-11-09 13:13 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-08 19:44 . 2009-11-08 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\KONAMI
2009-11-08 18:09 . 2009-11-08 21:01 -------- d-----w- c:\documents and settings\hari\Local Settings\Application Data\X-ray Anti-Cheat
2009-11-08 18:07 . 2009-11-08 18:07 -------- d-----w- c:\windows\Logs
2009-11-08 17:37 . 2009-11-10 14:46 -------- d-----w- c:\documents and settings\hari\Application Data\uTorrent
2009-11-08 17:25 . 2009-11-11 13:58 -------- d-----w- c:\documents and settings\hari\Tracing
2009-11-08 17:25 . 2009-11-08 17:25 -------- d-----w- c:\program files\Microsoft
2009-11-08 17:25 . 2009-11-08 17:25 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 17:24 . 2009-11-08 17:25 -------- d-----w- c:\program files\Windows Live
2009-11-08 17:22 . 2009-11-08 17:22 -------- d-----w- c:\program files\Common Files\Windows Live
2009-11-08 16:49 . 2009-11-08 16:57 -------- d-----w- c:\documents and settings\hari\Application Data\Ventrilo
2009-11-08 15:59 . 2006-10-26 18:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-11-08 15:59 . 2009-11-08 15:59 -------- d-----w- c:\program files\Microsoft Works
2009-11-08 15:59 . 2009-11-08 15:59 -------- d-----w- c:\program files\MSBuild
2009-11-08 15:57 . 2009-11-08 15:59 -------- d-----w- c:\windows\SHELLNEW
2009-11-08 15:56 . 2009-11-08 15:56 -------- d-----w- c:\documents and settings\hari\Local Settings\Application Data\Microsoft Help
2009-11-08 15:56 . 2009-11-08 15:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-08 15:52 . 2009-11-08 19:42 -------- d-----w- c:\documents and settings\hari\Application Data\DAEMON Tools Lite
2009-11-08 15:52 . 2009-11-08 15:52 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-11-08 13:16 . 2009-11-08 14:58 -------- d-----w- c:\documents and settings\hari\Local Settings\Application Data\PunkBuster
2009-11-08 13:02 . 2009-11-10 17:21 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-11-08 13:02 . 2009-11-08 13:16 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-11-08 13:02 . 2009-11-08 13:02 -------- d-----w- c:\windows\system32\LogFiles
2009-11-08 12:56 . 2009-11-08 12:56 -------- d-sh--w- c:\windows\ftpcache
2009-11-08 12:49 . 2009-11-08 12:49 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-11-08 12:44 . 2009-11-08 15:53 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-08 12:44 . 2009-11-08 12:56 -------- d-----w- c:\documents and settings\hari\Application Data\DAEMON Tools Pro
2009-11-08 12:40 . 2009-11-08 12:40 0 ----a-w- c:\windows\nsreg.dat
2009-11-08 12:40 . 2009-11-08 12:40 -------- d-----w- c:\documents and settings\hari\Local Settings\Application Data\Mozilla
2009-11-08 12:28 . 2009-11-08 17:21 68456 ----a-w- c:\documents and settings\hari\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-10 22:13 . 2009-11-08 11:20 -------- d-----w- c:\documents and settings\hari\Application Data\Xfire
2009-11-10 17:21 . 2009-11-08 13:03 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-10 14:16 . 2009-11-08 11:20 -------- d-----w- c:\program files\Xfire
2009-11-10 13:47 . 2009-11-08 10:53 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-09 21:13 . 2009-11-09 21:13 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SaiKCB03_01005.Wdf
2009-11-09 21:13 . 2009-11-09 21:13 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-11-09 21:13 . 2009-11-09 21:13 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2009-11-09 21:13 . 2009-11-09 21:13 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf
2009-11-08 16:45 . 2009-11-08 11:16 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-08 14:41 . 2009-11-08 11:01 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-08 13:03 . 2009-11-08 13:03 22328 ----a-w- c:\documents and settings\hari\Application Data\PnkBstrK.sys
2009-11-08 13:03 . 2009-11-08 13:03 22328 ----a-w- c:\documents and settings\hari\Application Data\PnkBstrK.sys
2009-11-08 13:02 . 2009-11-08 11:02 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-08 11:21 . 2009-11-08 11:21 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-11-08 11:16 . 2009-11-08 11:16 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-11-08 11:16 . 2009-11-08 11:16 -------- d-----w- c:\program files\NVIDIA Corporation
2009-11-08 11:04 . 2009-11-08 11:02 -------- d-----w- c:\program files\Realtek
2009-11-08 11:04 . 2009-11-08 11:04 -------- d-----w- c:\documents and settings\hari\Application Data\InstallShield
2009-11-08 11:03 . 2009-11-08 10:58 15600 ----a-w- c:\windows\gdrv.sys
2009-11-08 11:02 . 2009-11-08 11:02 315392 ----a-w- c:\windows\HideWin.exe
2009-11-08 10:59 . 2009-11-08 10:59 -------- d-----w- c:\program files\Intel
2009-11-08 10:59 . 2009-11-08 10:59 -------- d-----w- c:\program files\Yahoo!
2009-11-08 10:54 . 2009-11-08 10:54 -------- d-----w- c:\program files\microsoft frontpage
2009-11-08 10:51 . 2009-11-08 10:51 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-11-06 02:14 . 2009-11-06 02:14 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-09-27 17:20 . 2009-09-27 17:20 2173544 ----a-w- c:\windows\system32\nvcplui.exe
2009-09-27 17:20 . 2009-09-27 17:20 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-09-27 17:19 . 2009-09-27 17:19 3166208 ----a-w- c:\windows\system32\nvwss.dll
2009-09-27 17:19 . 2009-09-27 17:19 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-09-27 17:19 . 2009-09-27 17:19 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-09-27 17:19 . 2009-09-27 17:19 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-09-27 17:19 . 2009-09-27 17:19 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-09-27 17:19 . 2009-09-27 17:19 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-09-27 17:19 . 2009-09-27 17:19 4935680 ----a-w- c:\windows\system32\nvdisps.dll
2009-09-27 17:19 . 2009-09-27 17:19 172100 ----a-w- c:\windows\system32\nvsvc32.exe
2009-09-27 17:19 . 2009-09-27 17:19 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-09-27 17:19 . 2009-09-27 17:19 13918208 ----a-w- c:\windows\system32\nvcpl.dll
2009-09-27 17:19 . 2009-09-27 17:19 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-09-27 15:12 . 2009-09-27 15:12 888832 ----a-w- c:\windows\system32\nvapi.dll
2009-09-27 15:12 . 2009-09-27 15:12 7655872 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-09-27 15:12 . 2009-09-27 15:12 5900416 ----a-w- c:\windows\system32\nv4_disp.dll
2009-09-27 15:12 . 2009-09-27 15:12 2194024 ----a-w- c:\windows\system32\nvcuvid.dll
2009-09-27 15:12 . 2009-09-27 15:12 2007040 ----a-w- c:\windows\system32\nvcuda.dll
2009-09-27 15:12 . 2009-09-27 15:12 1714792 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-09-27 15:12 . 2009-09-27 15:12 170600 ----a-w- c:\windows\system32\nvcodins.dll
2009-09-27 15:12 . 2009-09-27 15:12 170600 ----a-w- c:\windows\system32\nvcod.dll
2009-09-27 15:12 . 2009-09-27 15:12 1604482 ----a-w- c:\windows\system32\nvdata.bin
2009-09-27 15:12 . 2009-09-27 15:12 10756096 ----a-w- c:\windows\system32\nvoglnt.dll
2009-09-04 16:44 . 2009-11-08 18:08 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-09-04 16:44 . 2009-11-08 18:08 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-09-04 16:44 . 2009-11-08 18:08 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 16:29 . 2009-11-08 18:08 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-09-04 16:29 . 2009-11-08 18:08 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-09-04 16:29 . 2009-11-08 18:08 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 16:29 . 2009-11-08 18:08 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 16:29 . 2009-11-08 18:08 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-05-25 1953792]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 734264]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"d:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\KONAMI\\Pro Evolution Soccer 2010\\pes2010.exe"=
S3 SaiKCB03;SaiKCB03;c:\windows\system32\drivers\SaiKCB03.sys [22.10.2008 14:57 106496]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - PROCEXP113
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://www.yahoo.com/
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ptec/defaults/su/*
http://www.yahoo.com
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\hari\Application Data\Mozilla\Firefox\Profiles\mi4psrmw.default\
---- FIREFOX POLICIES ----
d:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-nwiz - c:\program files\NVIDIA Corporation\nView\nwiz.exe
AddRemove-NVIDIA nView Desktop Manager - c:\program files\NVIDIA Corporation\nView\nViewSetup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-11 15:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A6E31F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x8a6e31f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
**************************************************************************
.
Completion time: 2009-11-11 15:21
ComboFix-quarantined-files.txt 2009-11-11 14:21
Pre-Run: 39.682.551.808 bytes free
Post-Run: 39.857.115.136 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=4 Default=4 Failed=0 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - D92AF2C3B74CFE2498DDBCF29B01FC71
DDS (Ver_09-10-26.01) - NTFSx86
Run by hari at 15:23:16,35 on sri 11.11.2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1627 [GMT 1:00]
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\explorer.exe
d:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\hari\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://www.yahoo.com/
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ptec/defaults/su/*
http://www.yahoo.com
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~1\office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [DAEMON Tools Lite] "d:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe
mRun: [36X Raid Configurer] c:\windows\system32\xRaidSetup.exe boot
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\progra~1\micros~1\office12\GR99D3~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~1\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\hari\applic~1\mozilla\firefox\profiles\mi4psrmw.default\
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
S3 SaiKCB03;SaiKCB03;c:\windows\system32\drivers\SaiKCB03.sys [2008-10-22 106496]
=============== Created Last 30 ================
2009-11-11 14:19:18 0 d-sha-r- C:\cmdcons
2009-11-11 14:18:25 98816 ----a-w- c:\windows\sed.exe
2009-11-11 14:18:25 77312 ----a-w- c:\windows\MBR.exe
2009-11-11 14:18:25 267264 ----a-w- c:\windows\PEV.exe
2009-11-11 14:18:25 161792 ----a-w- c:\windows\SWREG.exe
2009-11-10 18:01:25 0 d-----w- c:\program files\ESET
2009-11-10 14:49:05 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-11-10 14:49:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-09 20:57:45 61984 ----a-w- c:\windows\system32\drivers\xusb21.sys
2009-11-09 20:57:45 1421216 ----a-w- c:\windows\system32\WdfCoInstaller01001.dll
2009-11-09 20:57:44 0 d-----w- c:\program files\Microsoft Xbox 360 Accessories
2009-11-08 19:48:36 0 d-----w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
2009-11-08 19:44:09 0 d-----w- c:\docume~1\alluse~1\applic~1\KONAMI
2009-11-08 18:07:26 0 d-----w- c:\windows\Logs
2009-11-08 17:37:16 0 d-----w- c:\docume~1\hari\applic~1\uTorrent
2009-11-08 17:25:58 0 d-----w- c:\documents and settings\hari\Tracing
2009-11-08 17:25:33 0 d-----w- c:\program files\Microsoft
2009-11-08 17:25:19 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 17:22:18 0 d-----w- c:\program files\common files\Windows Live
2009-11-08 16:45:15 262 ----a-w- c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2009-11-08 15:59:47 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-11-08 15:57:00 0 d-----w- c:\windows\SHELLNEW
2009-11-08 15:52:50 0 d-----w- c:\docume~1\hari\applic~1\DAEMON Tools Lite
2009-11-08 15:52:48 0 d-----w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2009-11-08 14:09:26 215104 ----a-w- c:\windows\system32\PnkBstrB.xtr
2009-11-08 13:03:19 22328 ----a-w- c:\docume~1\hari\applic~1\PnkBstrK.sys
2009-11-08 13:02:42 215104 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-11-08 13:02:41 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-11-08 13:02:41 0 d-----w- c:\windows\system32\LogFiles
2009-11-08 13:02:40 287 ----a-w- c:\windows\game.ini
2009-11-08 12:56:04 0 d-sh--w- c:\windows\ftpcache
2009-11-08 12:49:25 0 d-----w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Pro
2009-11-08 12:44:29 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-08 12:44:25 0 d-----w- c:\docume~1\hari\applic~1\DAEMON Tools Pro
2009-11-08 11:43:15 0 d-----w- c:\program files\common files\ODBC
2009-11-08 11:43:12 0 d-----w- c:\program files\common files\SpeechEngines
2009-11-08 11:42:43 0 d-----r- c:\documents and settings\all users\Documents
2009-11-08 11:20:25 0 d-----w- c:\docume~1\hari\applic~1\Xfire
2009-11-08 11:20:22 0 d-----w- c:\program files\Xfire
2009-11-08 11:16:53 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-11-08 11:16:23 0 d-----w- c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2009-11-08 11:16:03 0 d-----w- c:\program files\NVIDIA Corporation
2009-11-08 11:02:05 0 d-----w- c:\program files\Realtek
2009-11-08 10:59:21 0 d-----w- c:\program files\Yahoo!
2009-11-08 10:53:29 0 d-sh--w- c:\documents and settings\all users\DRM
2009-11-08 10:53:16 0 d--h--w- c:\program files\WindowsUpdate
2009-11-08 10:52:14 0 d-----w- c:\program files\common files\MSSoap
2009-11-08 10:50:59 0 d-----w- c:\program files\Online Services
2009-11-08 10:50:54 0 d-----w- c:\program files\Messenger
2009-11-08 10:50:49 0 d-----w- c:\program files\MSN Gaming Zone
2009-11-08 10:49:57 0 d-----w- c:\program files\Windows NT
==================== Find3M ====================
2009-11-10 17:21:49 138576 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-11-09 21:13:45 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SaiKCB03_01005.Wdf
2009-11-09 21:13:44 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-11-09 21:13:09 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01001.Wdf
2009-11-09 21:13:08 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf
2009-11-08 11:03:51 15600 ----a-w- c:\windows\gdrv.sys
2009-11-08 11:02:02 315392 ----a-w- c:\windows\HideWin.exe
2009-11-08 10:51:15 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-11-06 02:14:42 41872 ----a-w- c:\windows\system32\xfcodec.dll
2009-09-27 17:20:04 2173544 ----a-w- c:\windows\system32\nvcplui.exe
2009-09-27 17:20:00 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-09-27 17:19:52 3166208 ----a-w- c:\windows\system32\nvwss.dll
2009-09-27 17:19:50 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-09-27 17:19:48 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-09-27 17:19:48 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-09-27 17:19:48 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-09-27 17:19:46 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-09-27 17:19:46 4935680 ----a-w- c:\windows\system32\nvdisps.dll
2009-09-27 17:19:46 172100 ----a-w- c:\windows\system32\nvsvc32.exe
2009-09-27 17:19:46 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-09-27 17:19:46 13918208 ----a-w- c:\windows\system32\nvcpl.dll
2009-09-27 17:19:40 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-09-27 15:12:22 888832 ----a-w- c:\windows\system32\nvapi.dll
2009-09-27 15:12:22 7655872 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-09-27 15:12:22 5900416 ----a-w- c:\windows\system32\nv4_disp.dll
2009-09-27 15:12:22 2194024 ----a-w- c:\windows\system32\nvcuvid.dll
2009-09-27 15:12:22 2007040 ----a-w- c:\windows\system32\nvcuda.dll
2009-09-27 15:12:22 1714792 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-09-27 15:12:22 170600 ----a-w- c:\windows\system32\nvcodins.dll
2009-09-27 15:12:22 170600 ----a-w- c:\windows\system32\nvcod.dll
2009-09-27 15:12:22 1604482 ----a-w- c:\windows\system32\nvdata.bin
2009-09-27 15:12:22 10756096 ----a-w- c:\windows\system32\nvoglnt.dll
2009-09-04 16:44:40 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-09-04 16:44:40 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2009-09-04 16:44:40 238936 ----a-w- c:\windows\system32\xactengine3_5.dll
2009-09-04 16:29:34 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2009-09-04 16:29:34 235344 ----a-w- c:\windows\system32\d3dx11_42.dll
2009-09-04 16:29:32 5501792 ----a-w- c:\windows\system32\d3dcsx_42.dll
2009-09-04 16:29:32 1974616 ----a-w- c:\windows\system32\D3DCompiler_42.dll
2009-09-04 16:29:30 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
============= FINISH: 15:23:19,67 ===============