the second half
c:\windows\d3dx.dat
2009-06-16 18:54 . 2009-06-16 18:54 2829 ----a-w- c:\windows\DiabUnin.pif
2009-06-16 18:54 . 2009-06-16 18:54 118784 ----a-w- c:\windows\DiabUnin.exe
2009-06-16 18:54 . 2009-06-19 18:51 -------- d-----w- c:\program files\Diablo
2009-06-16 18:54 . 2009-06-16 18:54 6122 ----a-w- c:\windows\DiabUnin.dat
2009-06-16 16:09 . 2009-06-16 16:09 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-06-16 16:03 . 2009-06-25 03:13 -------- d-----w- c:\program files\THQ
2009-06-16 15:38 . 2009-06-16 15:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DAEMON Tools Lite
2009-06-16 15:29 . 2009-06-16 15:55 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-06-16 15:29 . 2009-06-16 16:00 -------- d-----w- c:\documents and settings\Administrator.XPPROSP3\Application Data\DAEMON Tools Lite
2009-06-16 12:20 . 2009-06-16 12:20 -------- d-----w- c:\documents and settings\Administrator.XPPROSP3\Application Data\FileMaker
2009-06-15 22:45 . 2009-06-15 22:47 -------- d-----w- c:\program files\InterActual
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 19:19 . 2009-02-24 04:23 -------- d-----w- c:\documents and settings\Administrator.XPPROSP3\Application Data\Ahead
2009-06-26 12:58 . 2009-01-11 22:48 -------- d-----w- c:\program files\Java
2009-06-25 07:00 . 2009-01-12 00:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-25 03:43 . 2009-01-12 01:14 -------- d-----w- c:\program files\Common Files\AOL
2009-06-25 03:13 . 2009-01-12 00:21 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-24 23:16 . 2009-02-04 13:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\McAfee
2009-06-24 18:21 . 2009-02-04 03:35 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AOL OCP
2009-06-24 18:20 . 2009-02-04 03:28 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AOL Downloads
2009-06-24 18:20 . 2009-06-24 18:19 2439824 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AOL Downloads\ccu_suite\4.3.38.1\ccu_suite_4.3.38.1\ocpinsti.exe
2009-06-24 18:08 . 2009-02-03 03:17 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\DriverScanner
2009-06-23 03:07 . 2009-02-04 05:07 1 ----a-w- c:\documents and settings\Administrator.XPPROSP3\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-21 00:26 . 2009-02-04 16:36 -------- d-----w- c:\documents and settings\Administrator.XPPROSP3\Application Data\LimeWire
2009-06-14 18:43 . 2009-02-04 03:35 -------- d-----w- c:\program files\AOL 9.1
2009-06-08 23:57 . 2009-02-23 14:53 -------- d-----w- c:\program files\Download Direct
2009-05-14 04:25 . 2009-05-14 04:25 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-05-07 15:32 . 2008-04-14 10:41 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2008-04-14 10:42 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2008-04-14 10:41 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2008-04-14 06:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2008-04-14 10:42 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-26_13.20.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-04 17:48 . 2009-06-26 12:50 39124 c:\windows\system32\perfc009.dat
+ 2008-11-04 17:48 . 2009-06-29 17:33 39124 c:\windows\system32\perfc009.dat
- 2009-02-02 09:25 . 2009-06-26 12:53 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-02 09:25 . 2009-06-29 17:34 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-02 09:25 . 2009-06-26 12:53 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-02 09:25 . 2009-06-29 17:34 16384 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-02-02 09:25 . 2009-06-26 12:53 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-02 09:25 . 2009-06-29 17:34 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-11-04 17:48 . 2009-06-29 17:33 309662 c:\windows\system32\perfh009.dat
- 2008-11-04 17:48 . 2009-06-26 12:50 309662 c:\windows\system32\perfh009.dat
+ 2009-06-26 15:23 . 2009-06-26 15:23 364726 c:\windows\Installer\{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}\SkypeIcon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-24 143360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-02 24264488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostManager"="c:\program files\Common Files\AOL\1233718513\ee\AOLSoftware.exe" [2008-06-24 41824]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-16 335872]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-05-01 645328]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-04-29 124928]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-2-19 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):6c,6f,67,6f,6e,75,69,63,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 ALiIRDA;ALi Infrared Device Driver;c:\windows\system32\drivers\alifir.sys [2/1/2009 10:09 PM 26624]
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;c:\windows\system32\drivers\DP83815.sys [10/17/2003 1:38 PM 16512]
.
Contents of the 'Scheduled Tasks' folder
2009-06-24 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-24 13:57]
2009-06-24 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-24 13:57]
2009-06-29 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-06-26 03:18]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uInternet Connection Wizard,ShellNext =
hxxp://www.google.com/uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/keyword/%s.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-29 13:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-29 13:04
ComboFix-quarantined-files.txt 2009-06-29 18:04
ComboFix2.txt 2009-06-26 13:23
Pre-Run: 52,417,609,728 bytes free
Post-Run: 52,453,318,656 bytes free
205 --- E O F --- 2009-06-26 03:17